Key findings
- AI adoption is rising quickly, but organisational use remains shallow: 35% of UK businesses with 10 or more employees reported using at least one AI technology in June 2026, while only 10% of adopters described use as extensive.
- The difference between employee-reported AI use and business-reported adoption is not a measure of “shadow AI”. It does, however, indicate that practical experimentation may be advancing faster than formal integration, visibility and governance.
- The near-term market is likely to favour workflow integration, permissions, monitoring, exception handling and implementation support over broad deployment of autonomous agents.
- Cyber security and data-protection controls are not compliance add-ons. They determine whether an AI-enabled workflow can be trusted with operational data, customer interactions and business-system access.
- For most SMEs and mid-market organisations, management capability—not access to frontier compute—is the immediate constraint on productive AI adoption.
The thesis: UK AI spending will move from access to controlled execution
**Forecast horizon: October 2026 to April 2028.** The central question for UK organisations is no longer whether employees can access capable AI tools. It is whether those tools can be connected to real work without diluting accountability for data, decisions, customer outcomes or financial consequences.
The evidence suggests a market that has moved beyond novelty but has not yet reached broad operational transformation. In June 2026, 35% of UK businesses with 10 or more employees reported using at least one AI technology, compared with around 12% in late 2023. Yet adopters used an average of 1.6 technologies, only modestly above around 1.4 in late 2023, and just 10% described their use as extensive. That is rapid diffusion of access, but not evidence that most firms have redesigned core operations around AI. (Office for National Statistics, 2026) ↗
Sanctuary’s base case is therefore selective scaling rather than rapid, economy-wide delegation to autonomous agents. Organisations will increasingly invest in **controlled workflow execution**: systems that retrieve approved information, classify documents, prepare case files, draft responses, reconcile routine records and route exceptions to people with authority to resolve them.
This distinction matters because the economic value of AI is usually created beyond the chat interface. An assistant may save time for an individual employee. A connected workflow can alter backlog, response time, rework, collections or service quality. But integration also raises the stakes. Once a system can read sensitive records, write to a customer relationship platform or act through a business account, the organisation must decide what it may access, what it may change and how mistakes can be detected and reversed.
For SMEs, high-street businesses and local service firms, this is a more useful frame than a race for frontier capability. Many do not need to train models or build proprietary infrastructure to improve booking administration, supplier queries, customer communications or document-heavy back-office work. They need clear process ownership, reliable source information, sensible action boundaries and a way to demonstrate that the workflow has improved the business.
The informal-use gap is a leading indicator, not a shadow-AI statistic
A useful early signal is the distance between employee use and formal business adoption. In May and June 2026, 55% of employees in Great Britain said they used AI for work or education, while 35% of businesses with 10 or more employees reported using at least one AI technology. (Office for National Statistics, 2026) ↗
The 20-point difference should not be misrepresented. The measures cover different populations and activities, so it is not a precise estimate of unapproved use or “shadow AI”. It does nonetheless support a cautious interpretation: individual experimentation may be spreading faster than central visibility, system integration and formal governance.
That gap has two implications. First, informal use can reveal genuine operational demand. Employees often adopt tools where work is repetitive or frustrating: finding information, summarising correspondence, translating material, drafting routine communications or preparing documents. A blanket ban may conceal these signals rather than solve the underlying workload problem.
Second, experimentation is not the same as organisational capability. A person using AI to improve a first draft is operating in a different risk environment from a system that draws on customer records, recommends an eligibility outcome or sends a communication automatically. The latter requires agreed data sources, permissions, auditability, review and a named owner of the process.
The ONS business measure covers organisations with 10 or more employees, so it should not be mechanically extrapolated to microbusinesses. Still, smaller firms face the same directional pressure: staff and customers will increasingly expect quicker responses and more efficient administration, while many enterprises lack dedicated technology, legal and cyber-security teams. Their advantage will come from proportionate controls and practical implementation support, not from copying enterprise governance frameworks wholesale.
Why agentic AI will advance through bounded tasks
Agentic systems can plan steps, use tools, retrieve information and take actions rather than simply produce an answer. That makes them potentially useful for multi-stage administration, but it also increases the consequences of poor instructions, insecure integrations or excessive permissions.
The National Cyber Security Centre advises organisations to begin with tightly bounded, low-risk tasks; apply least privilege; limit access to credentials; monitor behaviour; and prepare for incidents. (National Cyber Security Centre, 2026) ↗ These are not merely security preferences. They describe the commercial conditions under which a business can test automation without creating an unacceptable operational risk.
The mechanism is straightforward. More access usually makes an agent more useful, but it also enlarges its potential blast radius. An agent that drafts a reply using an approved knowledge base is materially different from one that changes core records, commits a customer to a contractual term or initiates a payment. Improved model performance may reduce some errors, but it cannot determine who is authorised to act or who bears responsibility when an outcome is wrong.
This supports a base case in which, by April 2028, more organisations use AI to prepare work for people than to delegate consequential decisions to it. Likely early applications include enquiry triage, case-file preparation, routine reconciliation, communications drafted for review and escalation of exceptions. Broad, unsupervised authority over payments, employment outcomes, contracts or high-impact customer decisions is less likely to become normal practice.
There is an important counterargument. Vendors may make secure connectors, agent-management interfaces, testing tools and granular permissions substantially easier to deploy. That would lower the cost of controlled autonomy, particularly for mid-market buyers. It would not eliminate the underlying requirement for accountable permissions, oversight and recovery when a workflow fails.
The control deficit is both a business risk and a supplier opportunity
Cyber-security evidence indicates that AI interest is running ahead of AI-specific preparedness. The 2025/26 Cyber Security Breaches Survey found that 31% of businesses were using AI, adopting it or actively considering it. Of that group, only 24% reported cyber-security practices or processes to manage AI risks. (GOV.UK, 2026) ↗ This does not establish that every remaining organisation is unsafe, and it does not isolate agentic deployments. It does show that formal risk management is not yet moving at the pace of the wider AI conversation.
The broader environment makes this significant. Forty-three per cent of UK businesses reported a breach or attack in the previous 12 months, and phishing-only incidents accounted for 51% of incidents among affected businesses. (GOV.UK, 2026) ↗ AI-enabled workflows should therefore enter established cyber-security, supplier-assurance and incident-management processes rather than sit outside them as innovation pilots.
For buyers, an appropriate control layer is proportionate to the workflow. It may include an inventory of approved tools, role-based access, tightly managed credentials, approved data and knowledge sources, testing environments, logs, exception queues, monitoring and a stop or escalation mechanism. These capabilities are unglamorous, but they make automation reviewable and recoverable.
For UK software firms, managed service providers and consultancies, this is a meaningful market opportunity. Many organisations will not purchase a single all-purpose “AI platform”. They will need help combining existing software, process knowledge and security controls into a workflow that staff can operate. The supplier that reduces implementation burden while preserving evidence of who acted, on what data and under whose authority will be better positioned than one selling capability without operational accountability.
Privacy will shape where early value can be realised
Data protection is not a reason to avoid AI. It is a design discipline that becomes more important when systems access varied personal data, draw from external sources or coordinate multiple agents. The Information Commissioner’s Office has identified risks that agentic systems can make oversight harder during employee experimentation and can amplify issues around accountability, accuracy and security. (Information Commissioner’s Office, 2026) ↗
The trade-off is sharpest where decisions have legal or similarly significant effects on people. Organisations need to consider how automated processing is communicated, whether a decision can be challenged and whether human intervention is meaningful. (Information Commissioner’s Office, 2026) ↗ A nominal human review does not provide genuine control if the reviewer lacks the time, evidence or authority to question the output.
This means high-stakes HR, eligibility, pricing, credit-like and redress workflows may promise large apparent savings but require stronger evidence, review design and accountability. Lower-risk internal workflows can offer less dramatic value per transaction, but may create earlier operational gains while building the management capability needed for more complex deployment.
The ICO’s 2026 technology roadmap set out planned final guidance on agentic AI in autumn 2026, alongside further work on automated decision-making and profiling in winter 2026. (Information Commissioner’s Office, 2026) ↗ That guidance trajectory is an important implementation variable. However, organisations do not need to wait for it to establish basic data mapping, purpose limitation, access controls and named accountability for the workflows they are already considering.
Compute matters strategically, but management capacity is the nearer constraint
The UK Compute Roadmap forecasts a need for at least 6GW of AI-capable data-centre capacity by 2030—three times the capacity available at publication—and distinguishes between the requirements of training and inference workloads. It also sets out planned expansion of public compute and AI infrastructure. (GOV.UK, 2026) ↗ This matters for national resilience, research, AI suppliers and infrastructure-intensive industries.
For most organisations over the next 18 months, however, compute is unlikely to be the binding constraint. A typical SME, charity, local authority supplier or mid-market service firm can already access adequate cloud capability for bounded text, document and knowledge workflows. Its harder problems are fragmented records, unclear ownership of processes, weak integration between systems, limited staff confidence and an inability to measure outcomes.
The UK is therefore likely to see two speeds of adoption. Compute and power availability will influence frontier research, data-centre investment and specialist AI supply. Wider productivity gains will depend more immediately on whether organisations can standardise work, improve data quality and equip managers to redesign processes responsibly.
This distinction matters for local economic development. A data-centre announcement does not automatically translate into productivity gains for firms in the surrounding area. Those gains are more likely where infrastructure investment is paired with skills, business support and the practical adoption capacity of local employers and entrepreneurs.
What would change the forecast—and what leaders should do now
The base case is governed workflow scaling. Formal adoption should continue to rise, but depth will grow unevenly as spending shifts from broad licences towards integration, security, workflow-specific products and implementation support. This interpretation is consistent with shallow current adoption, the employee-use signal and official guidance favouring bounded deployment. (Office for National Statistics, 2026; National Cyber Security Centre, 2026) ↗ ↗
The upside case is that suppliers make controlled autonomy materially cheaper through better interoperability, permissions, testing and traceability. The downside case is that serious security incidents, persistent failures in connected workflows, unclear accountability or worsening vendor lock-in cause boards to limit AI largely to personal productivity tools.
Leaders should monitor adoption depth rather than adoption headlines alone: the ONS measures of extensive use and technologies per adopter; evidence of AI-specific cyber practices; ICO guidance as it develops; and deployed rather than announced compute capacity. The forecast should be revised down if formal use rises without corresponding evidence of controls or deeper operational deployment. It should be revised up if organisations demonstrate repeatable gains from connected workflows without rising correction, reversal or incident rates.
**Sanctuary recommendation: buy a controlled outcome, not an “AI programme”.** Start with one frequent, information-rich and measurable workflow. Establish a baseline for cycle time, backlog, rework, conversion, service quality or cash impact. Define the action boundary: what the system may read, draft, recommend, update or send. Assign a process owner and a technical owner. Test predictable failure modes—including misleading instructions, unavailable source systems and incorrect outputs—before production. Then assess net value after review time, corrections, training, software costs and control overhead.
The competitive advantage to April 2028 is unlikely to belong simply to the organisation with the most AI licences. It is more likely to belong to the organisation that can make a small number of valuable workflows safe, repeatable, measurable and transferable across teams.
Research foundation
References
- Office for National Statistics (2026). Artificial intelligence in UK businesses: 2023 to 2026. Office for National Statistics.Source ↗
- Department for Science, Innovation and Technology; Home Office (2026). Cyber security breaches survey 2025/2026. GOV.UK.Source ↗
- Martin R; Dr Kate S (2026). Thinking carefully before adopting agentic AI. National Cyber Security Centre.Source ↗
- Information Commissioner’s Office (2026). Data protection and privacy risks. Information Commissioner’s Office.Source ↗
- Information Commissioner’s Office (2026). Technology: planned new and updated guidance. Information Commissioner’s Office.Source ↗
- Department for Science, Innovation and Technology (2026). UK Compute Roadmap. GOV.UK.Source ↗
- Digits.co.uk Images. Hero image: In person management training session for employees.jpg. Wikimedia Commons · CC BY 2.0.Image source ↗
Related Sanctuary capabilities
From analysis to implementation.
Discussion

No approved comments yet.