Key findings

  • AI use has expanded quickly among larger UK businesses, but remains relatively shallow: around 35% reported using at least one AI technology in June 2026, while AI-using firms used around 1.6 technologies on average. (Office for National Statistics, 2026) [[ons2026]]
  • Agentic AI remains early-stage. Among businesses that used or planned to use AI, 5% reported current agentic-AI use and 13% planned adoption; this is an AI-engaged subset, not the whole business population. (GOV.UK, 2026) [[dsit_adoption2026]]
  • The strongest near-term use cases will be bounded workflows with restricted data and action permissions, a named accountable owner, human oversight and an effective route to pause or reverse activity. (National Cyber Security Centre, 2026) [[ncsc_agentic2026]] (GOV.UK, 2025) [[ai_cyber_code2025]]
  • Management capability is likely to separate experimentation from operational deployment. ONS identifies an association between stronger management practices, advanced-technology adoption and action on AI plans, though this evidence does not establish causation. (Office for National Statistics, 2025) [[ons_management2025]]
  • Sanctuary’s base case is uneven diffusion: firms will build small portfolios of supervised agents where integration produces measurable net gains after the costs of review, security and remediation are included.

The UK question is no longer access to AI, but controlled delegation

**Forecast horizon: late 2026 to late 2028.** The next phase of UK AI adoption will be determined less by whether firms can buy capable models than by whether they can connect them safely to the information, software and decisions that make work happen.

This is the distinction between using AI to draft or search and using it to support—or initiate—actions in a workflow. A system that prepares a customer response for review has a different risk profile from one that can retrieve records, open a case, alter a ticket or trigger a follow-on task. Delegated action can reduce delays and administrative effort. It can also convert an inaccurate output, manipulated input or excessive permission into an operational, customer-service or cyber-security incident.

UK evidence suggests that broad awareness has moved ahead of embedded organisational use. Around 35% of businesses with 10 or more employees reported using at least one AI technology in June 2026, compared with around 12% in late 2023. Yet AI users employed only around 1.6 technologies on average, and 10% said they used AI extensively. (Office for National Statistics, 2026) More than half of people in Great Britain reported using AI for work or education, a much higher figure than formal business adoption. (Office for National Statistics, 2026)

The gap matters. Individual use can reveal repetitive, search-heavy or slow tasks. It does not create approved data boundaries, reliable source material, decision rights or accountability when something goes wrong.

**Sanctuary interpretation.** The practical unit of adoption is the workflow, not the model or the software licence. Over the next two years, the firms most likely to secure durable value will choose defined activities, constrain what the system can see and do, and assess whether the complete process—not simply the quality of an AI response—has improved.

Interest is rising, but integration reveals the implementation gap

Agentic AI is not yet a mainstream UK operating model. Among businesses that used or planned to use AI, 5% reported current use of agentic AI, including pilots, and a further 13% planned to adopt it. (GOV.UK, 2026) The denominator is important: these figures indicate momentum among AI-engaged businesses, not imminent adoption across the wider economy.

The same research indicates where value creation and risk will increasingly meet. Among organisations using, planning to use or actively considering AI, 65% identified off-the-shelf applications and 59% identified embedding AI in existing tools or systems as planned investment areas over the next 12 months. (GOV.UK, 2026) Integration is what can make an agent economically useful: it can draw on an approved knowledge base, assemble information for a decision, or prepare an action within an established process. It is also where weak records, unclear hand-offs and broad user permissions cease to be minor irritants and become material constraints.

Readiness is markedly less widespread than interest. While 54% of current AI users said they were ready to scale, only 34% of businesses planning to use AI felt ready to implement it. Nearly half of firms planning adoption in the following year had not set a specific budget. (GOV.UK, 2026) This is consistent with a straightforward mechanism: buying an application is easier than mapping a process, preparing data, configuring access, training staff and redesigning how exceptions are handled.

The emerging supply of specialist cyber capability reinforces the point, while requiring caution. In 2026, 111 UK firms offered AI-security products or services. Twenty-one per cent identified AI red teaming and penetration testing, but 5% identified agentic-AI identity-and-access security. (GOV.UK, 2026) These are supply-side figures: they do not measure customer demand or prove that controls are ineffective. They do, however, suggest that safeguards for systems with delegated access are less mature than the wider conversation about AI adoption.

Why bounded workflows are the economic and governance sweet spot

The relevant choice is not innovation versus caution. It is whether the incremental value of delegated action exceeds the incremental cost of control, review and remediation.

Conventional automation will often remain the better option where inputs are structured and rules are stable. Agents have a stronger potential role where work involves unstructured information, variable language or contextual judgement: assembling a case file, triaging an enquiry, preparing a hand-off or supporting routine service activity. But these use cases depend on the organisation being able to specify trusted sources, permitted actions, escalation thresholds and the person accountable for the outcome.

The National Cyber Security Centre recommends tightly bounded pilots and lower-risk tasks, meaningful human oversight, limits on access to sensitive data and critical systems, and preparation for incidents. It highlights least-privilege access, temporary credentials, constrained actions, monitoring and threat modelling. (National Cyber Security Centre, 2026) The Government’s AI Cyber Security Code of Practice likewise identifies risk-assessed permissions as central when AI interacts with other systems or data sources. (GOV.UK, 2025)

**Sanctuary framework: six tests for a controlled workflow.** An initial deployment should have: a defined objective; approved data sources; bounded authority; a named accountable owner; a measurable business outcome; and a tested intervention route. These conditions cannot eliminate risk. They make the trade-offs visible before a pilot becomes embedded practice.

This framework also identifies cases where an agent is the wrong tool. If rules are known and inputs are structured, conventional automation may be cheaper, more predictable and easier to assure. If the underlying process is inconsistent, an agent may briefly conceal the weakness while recreating any saved effort through checking, exception handling and customer corrections. Selectivity is therefore not a lack of ambition; it is a way of protecting the economics of early deployment.

Management capability will shape the SME and local-productivity outcome

The likely result is uneven diffusion. Larger organisations may have more capacity to integrate systems, configure controls and absorb a failed pilot. But SMEs, high-street firms and new ventures may also benefit substantially where off-the-shelf tools reduce the cost of capabilities previously available only through specialist staff. The constraint is not simply firm size. It is whether a business can devote time to process mapping, supplier assessment, data classification, permissions and supervision.

Management quality is therefore a plausible divider between experimentation and implementation. ONS research finds an association between stronger management practices, advanced-technology adoption and firms acting on their AI plans. (Office for National Statistics, 2025) This should not be read as proof that management practice causes AI adoption or productivity gains: better-managed firms may also have stronger digital foundations, more resources and more usable data. Even so, the operational mechanism is credible. Managers define exceptions, allocate authority, set performance thresholds and ensure that staff feedback changes the workflow.

There is a material governance gap. Only 24% of businesses using, adopting or considering AI reported having security practices or processes to manage AI risks, while 31% had no plans to implement them. (GOV.UK, 2026) This is reported AI-risk practice, not a direct measure of agent-control maturity. It is nevertheless a warning that governance capacity may lag commercial interest. Where checking workloads or access risks remain high, boards may rationally restrict systems to read-only or advisory roles.

For local economies, the effect is practical. A small firm that shortens response times, improves case hand-offs or removes avoidable administration may release capacity for customers, sales and higher-value work. A poorly configured system can generate the opposite outcome through inaccurate outputs, customer corrections, staff distrust and remedial work. AI access alone will not determine local value creation; operational discipline will.

A measured base case—and the decisions leaders should take now

**Sanctuary’s base case** is that UK organisations will move beyond drafting and search into small portfolios of supervised workflows over the next two years. Likely categories include internal knowledge retrieval, triage, case preparation, routine service support and administrative coordination. The principal effect is more likely to be task redesign, faster handling and greater consistency in routine work than immediate, organisation-wide labour substitution.

The upside case is credible. Enterprise software could make approval gates, role-based access, logging, sandboxing and monitoring easier to deploy. If those safeguards become simpler and cheaper, firms with repeatable processes and usable records may scale controlled agents without building large specialist teams.

The downside case is equally credible. Review costs may remain high; integration may expose poor data and unclear ownership; or security incidents may cause firms to withdraw permissions. In that scenario, agentic systems may retain value but remain primarily advisory. Neither outcome will be settled by model capability alone.

Leaders should therefore judge pilots by **net workflow performance**, not demonstration fluency. Measure cycle time, error rates, rework, exception volumes, customer waiting time and staff effort before and after deployment. Include the costs of integration, security testing, review and remediation. Faster output that produces more downstream checking is not a productivity gain.

**Sanctuary recommendations**

1. **Choose one reversible workflow.** Select work valuable enough to measure, documented enough to govern and low-consequence if paused. Do not begin with unrestricted access to sensitive customer data, payments, employment decisions or critical systems.

2. **Create a pre-deployment control sheet.** Record the business owner, authorised users, approved data sources, allowed and prohibited actions, access duration, human approval points, escalation route and log-retention arrangements. This translates least privilege and meaningful oversight into operating requirements. (National Cyber Security Centre, 2026) (GOV.UK, 2025)

3. **Repair the process before delegating activity.** Map exceptions, duplicate approvals and unclear hand-offs. Use conventional automation where rules are stable rather than using an agent to scale an unresolved process problem.

4. **Build managerial capability alongside technical capability.** Responsible managers must set thresholds, challenge outputs and retain accountability; this is an implementation requirement, not merely a training add-on. (Office for National Statistics, 2025)

The forecast would strengthen if bounded workflows repeatedly deliver measurable gains, controls become less costly to operate and AI-risk practices become more common. It would weaken if review burdens persist, integrations are curtailed after incidents, or smaller firms cannot access workable governance. The immediate opportunity is real, but the sound sequence is clear: improve one valuable workflow under conditions that allow the organisation to verify, intervene and learn.

Sanctuary controlled-workflow framework for agentic AI adoptionOriginal Sanctuary analytical framework. It expresses an implementation sequence rather than numerical evidence.
1. Select a bounded, measurable workflow
2. Simplify the process and establish baseline performance
3. Define approved data, tools and permissions
4. Configure agent scope, human approval gates and stop controls
5. Test through sandboxed or limited live deployment
6. Monitor value, exceptions, security events and staff experience
7. Scale only when controls and net benefits are evidenced

Research foundation

References

  1. Office for National Statistics (2026). Artificial intelligence in UK businesses: 2023 to 2026. Office for National Statistics.
    Source ↗
  2. Department for Science, Innovation and Technology; IFF Research; Technopolis Group (2026). AI Adoption Research. GOV.UK.
    Source ↗
  3. Office for National Statistics (2025). Management practices and the adoption of technology and artificial intelligence in UK firms: 2023. Office for National Statistics.
    Source ↗
  4. National Cyber Security Centre (2026). Thinking carefully before adopting agentic AI. National Cyber Security Centre.
    Source ↗
  5. Department for Science, Innovation and Technology (2025). AI Cyber Security Code of Practice. GOV.UK.
    Source ↗
  6. Department for Science, Innovation and Technology; Home Office; Ipsos (2026). Cyber security breaches survey 2025/2026. GOV.UK.
    Source ↗
  7. Department for Science, Innovation and Technology; Ipsos; Perspective Economics (2026). Cyber security sectoral analysis 2026. GOV.UK.
    Source ↗
  8. Digits.co.uk Images. Hero image: In person management training session for employees.jpg. Wikimedia Commons · CC BY 2.0.
    Image source ↗

Discussion

Challenge the analysis.

No approved comments yet.