Key findings
- UK business AI adoption has risen quickly, but evidence of deep organisational integration remains limited. The most credible near-term forecast is therefore selective deployment in defined workflows, rather than widespread autonomous operation (ONS, 2026) [[ons2026]].
- Agentic AI began from a low base: 7% of AI-adopting UK businesses in 2025 reported using it, compared with 85% using natural-language processing or text generation. This suggests that familiar text assistance is likely to diffuse faster than systems empowered to take actions (DSIT, 2025) [[dsit2025adoption]].
- The binding constraint is likely to be organisational as much as technical. Firms most often identify suitable use cases as the barrier to adoption, while stronger management practices are associated with technology adoption and AI planning (ONS, 2025) [[ons2025management]].
- The control gap is material. Only 24% of businesses using, adopting or considering AI reported AI-specific cyber-security practices or processes, despite the additional exposure created when systems can access data or invoke business tools (DSIT, 2026) [[dsit2026cyber]].
- The practical prize is not a claim to autonomy. It is a portfolio of measurable, reversible and trustworthy workflows that improve service or capacity without delegating decisions beyond an organisation’s ability to supervise and correct them.
Thesis: bounded agency will outpace the autonomous enterprise
The UK agentic-AI story over the next two years is unlikely to be one of fully autonomous businesses. It is more likely to be a contest over whether organisations can embed agents safely in selected workflows: preparing case files, retrieving approved information, checking document completeness, drafting routine communications, triaging requests or proposing updates for review.
That distinction matters. A conversational AI tool primarily produces an answer; an agent connected to enterprise software may retrieve data, call an application programming interface, send a message or alter a record. Those capabilities can remove administrative delay, but they also turn weak instructions, poor data, excessive permissions or compromised content into operational risks. The National Cyber Security Centre (NCSC) advises organisations to think carefully before adopting agentic AI, including on scope, permissions, dependencies, monitoring and incident response. It highlights threats such as prompt injection and jailbreaking that are particularly consequential when a system can act through connected tools (NCSC, 2026) ↗.
**Sanctuary assessment:** between late 2026 and late 2028, controlled workflow integration will be more commercially important than broad, free-ranging autonomy. This is a forecast, not a claim that every sector will move at the same speed. It follows from the UK starting point: AI use is increasing, but management capability and AI-specific controls remain uneven. The firms that convert agents into productivity gains will be those that can specify a task, constrain authority, measure outcomes and resolve exceptions.
This is especially relevant beyond large enterprises. Vendor features may make agents accessible to SMEs, high-street businesses and growing service firms without an in-house AI team. But easier access does not settle the core business questions: what may the system do, which data may it use, who is accountable for its output, and how will an error be detected and remedied?
The UK starting point: adoption is broadening faster than operational depth
The available data point to rapid uptake, but not yet to economy-wide operational transformation. The Office for National Statistics reports that 35% of UK businesses with 10 or more employees used at least one AI technology in June 2026, compared with around 12% in late 2023. Among adopters, the average number of AI technologies used increased only from around 1.4 to 1.6 across that period, while 10% reported using AI extensively (ONS, 2026) ↗. The pattern is consistent with more firms experimenting or using a small number of tools, rather than most firms having rebuilt core processes around AI.
There is also a useful, though imperfect, signal in the difference between employee and organisational measures. The ONS found that 55% of employees had used AI for work or education, compared with 35% of businesses reporting AI use. These measures are not directly comparable: one concerns individuals and the other businesses. Nevertheless, the gap matters to management. Staff familiarity can surface practical use cases and improve readiness, but it can also mean that use develops before procurement, data rules and leadership oversight catch up (ONS, 2026) ↗.
Agentic AI starts further behind. Research conducted from February to May 2025 among 3,500 UK private-sector businesses with at least five employees found that 7% of AI adopters used agentic AI, compared with 85% using natural-language processing or text generation (DSIT, 2025) ↗. This should not be treated as a current penetration estimate: products and definitions are changing quickly. It does establish the relevant baseline. Text-based assistance was already familiar; delegated action was not.
The management evidence helps explain why that difference may persist. Among firms considering AI adoption, identifying suitable activities or use cases was the most commonly reported barrier, at 39%, ahead of cost at 21% and skills or expertise at 16%. Stronger management practices were associated with greater adoption of advanced technologies and with AI adoption planning (ONS, 2025) ↗. Model access is becoming easier to buy. Process ownership, dependable information, role redesign and exception management are much harder to procure off the shelf.
Why integration creates value — and why it also raises the stakes
An agent becomes operationally useful when it can work with business context. Customer-service, finance, booking, procurement, document-management and workflow systems contain the records, rules and process stages that turn a generic model into a practical tool. They can also supply approval gates, identity controls and audit trails. This is why integration into established software is the likely route to scale.
The resulting advantage will not map neatly onto business size. Larger organisations may benefit from better structured data, identity management and specialist capacity. Yet a smaller firm with a clear enquiry, fulfilment or back-office process may activate a well-designed vendor feature faster than a larger business with fragmented systems and ambiguous decision rights. The more meaningful divide is between organisations with an intelligible operating model and those whose work depends on undocumented judgement, inaccessible data and unclear ownership.
There is a credible counterargument: more capable general-purpose agents may navigate messy interfaces and reduce the need for process design. That may prove true for research, drafting and low-stakes administration. It is less persuasive where an incorrect action could create financial loss, confidentiality failures, customer detriment or service disruption. In these settings, process design is not bureaucracy surrounding the technology; it is how an organisation decides what authority can safely be delegated.
A sensible early use case therefore has bounded inputs, a repeatable purpose, reversible actions and a meaningful route for human intervention. An agent that assembles an internal knowledge pack or proposes an account update for approval may save time without taking consequential action. Giving the same system authority to amend payment details, issue refunds or send unrestricted external communications changes the risk and assurance burden substantially. The NCSC’s guidance supports this emphasis on constrained scope, least privilege, monitoring and preparation for failure rather than an assumption that a capable model is inherently a safe operator (NCSC, 2026) ↗.
Governance is a constraint, but it can become productive capacity
The most important near-term warning is the distance between AI interest and AI-specific controls. The 2025/26 Cyber Security Breaches Survey found that 31% of UK businesses were using AI, adopting it or actively considering it. Within that group, only 24% reported cyber-security practices or processes specifically for AI risks, while 31% had no plans to introduce them (DSIT, 2026) ↗. This is evidence on AI generally, not agentic AI alone, and it does not establish that agents are causing incidents. It does indicate that a substantial share of firms may be considering increasingly capable systems without equivalent governance maturity.
The wider resilience context makes this more than a technical concern. The same survey found that 43% of businesses had identified a cyber breach or attack in the preceding 12 months, alongside declines among small businesses in formal cyber-risk assessment, cyber policy and cyber-inclusive business-continuity planning (DSIT, 2026) ↗. An agent does not create every underlying weakness, but it may increase the speed and reach with which weaknesses in instructions, credentials or source material affect operations.
For consumer-facing firms, the accountability question extends beyond cyber security. Competition and Markets Authority guidance makes clear that businesses remain responsible for compliance with consumer law when they use AI agents. That is highly relevant where agents handle customer queries, marketing, recommendations or redress-related interactions (CMA, 2026) ↗. Delegating an interaction does not delegate responsibility for its outcome.
**Sanctuary interpretation:** proportionate governance can be a source of productive capacity. A business that can evidence a limited agent’s purpose, permissions, data sources, actions and escalation route can approve safe experiments faster and learn from them. By contrast, blanket bans can push useful activity into informal use, while poorly supervised pilots can erode trust after the first serious failure. The objective is not maximal process. It is a control plane proportionate to the consequence of the action being delegated.
What could alter the forecast by 2028
**Base case: controlled integration becomes normal.** Agent features become common within mainstream business software, but most deployments remain limited by approved tools and data sources, transaction thresholds, audit records and human review. Early benefits appear in cycle time, case preparation, service consistency and administrative capacity. The strategic divide is between firms that integrate and improve selected workflows and those that remain at the stage of individual prompting.
**Upside case: assurance becomes practical beyond large organisations.** Adoption could accelerate if suppliers materially improve granular permissions, connector security, testing environments, logging and rollback. It would also help if smaller and mid-sized firms could access affordable independent support in assessing systems and controls. The government’s trusted third-party AI assurance roadmap sets out plans to support a trusted assurance market, including adoption support and assurance innovation (DSIT, 2025) ↗. This is an important direction of travel, rather than proof that usable assurance is already available at scale.
**Downside case: delegated action loses commercial trust.** Data leakage, manipulated instructions, fraudulent transactions or harmful consumer outcomes could prompt boards, insurers, auditors and customers to demand much stronger controls before approving new deployments. New legislation would not be necessary for this brake to operate; contractual obligations, liability and reputational damage could be sufficient. The NCSC’s emphasis on the specific risks of agentic systems makes this a credible commercial downside, not a remote technical edge case (NCSC, 2026) ↗.
National AI infrastructure will remain strategically relevant. The government’s response to the AI Opportunities Action Plan places AI Growth Zones within its infrastructure ambitions (DSIT, 2025) ↗. For most firms in this forecast window, however, compute will be accessed through cloud and software providers. The nearer productivity constraint is more likely to be whether the business can define a valuable workflow and connect it safely to the systems required to complete it.
A practical operating agenda: scale authority, not just capability
**Sanctuary recommendation:** use the next 90 days to build evidence around two carefully chosen workflows, rather than acquiring a long list of AI tools. The purpose is to establish where delegated action creates genuine capacity or service value, and where exception handling removes the apparent gain.
First, use an authority ladder. Begin with an agent that can read approved information, then draft an output, then recommend an action, and only later execute reversible actions within explicit thresholds. Progress should depend on evidence about accuracy, exceptions, customer outcomes and control performance. Good drafting performance does not, by itself, justify authority to change a customer account.
Second, name a workflow owner before integration begins. That person should define the intended outcome, permitted data, permitted actions, approval points, escalation route, stop authority and review cycle. Technology and security teams should validate the design, but operational leaders must own the decision to delegate work. This addresses the central UK adoption challenge: selecting a viable use case and embedding it in a managed operating process (ONS, 2025) ↗.
Third, measure the baseline and test failure conditions. Record current turnaround time, rework, error rates, exception volumes, cost to serve and relevant customer outcomes. Test misleading instructions, malicious content in emails or documents, unavailable systems, duplicate actions and unusual requests. Least-privilege access, constrained scope, temporary credentials, monitoring and incident planning should be designed into the workflow before a successful demonstration creates pressure to scale (NCSC, 2026) ↗.
For SMEs, entrepreneurs and local service businesses, this staged approach is not a lesser version of innovation. It is often the most credible route to productivity: use agents to reduce routine coordination and administration while preserving human judgement for complex cases, relationships and growth. The durable advantage will not be a headline claim of autonomy. It will be an explainable portfolio of workflows whose performance, limits and local business value can be measured and improved.
Research foundation
References
- Office for National Statistics (2026). Artificial intelligence in UK businesses: 2023 to 2026. Office for National Statistics.Source ↗
- Office for National Statistics (2025). Management practices and the adoption of technology and artificial intelligence in UK firms: 2023. Office for National Statistics.Source ↗
- Department for Science, Innovation and Technology (2025). AI Adoption Research. GOV.UK.Source ↗
- Department for Science, Innovation and Technology; Home Office (2026). Cyber security breaches survey 2025/2026. GOV.UK.Source ↗
- National Cyber Security Centre (2026). Thinking carefully before adopting agentic AI. National Cyber Security Centre.Source ↗
- Competition and Markets Authority (2026). Complying with consumer law when using AI agents. GOV.UK.Source ↗
- Department for Science, Innovation and Technology (2025). Trusted third-party AI assurance roadmap. GOV.UK.Source ↗
- Department for Science, Innovation and Technology (2025). AI Opportunities Action Plan: government response. GOV.UK.Source ↗
- USDAgov. Hero image: SNAP Employment and Training at Cafe Reconcile in New Orleans (20230216-FNS-CDP-0306).jpg. Wikimedia Commons · Public domain.Image source ↗
Related Sanctuary capabilities
From analysis to implementation.
Discussion

No approved comments yet.