Key findings

  • Among UK businesses handling digitised data, 41% reported using AI in 2025–26, but only 21% of AI users said their tools were integrated into existing business systems. The gap is widest among smaller firms. (DSIT, 2026) [[dsit2026ukbds]]
  • Only 17% of AI-using businesses reported AI policies or guidance, including 5% with a formal written policy. This signals an operational governance gap, although a policy document alone is not evidence of effective control. (DSIT, 2026) [[dsit2026ukbds]]
  • The practical risk changes when AI moves from stand-alone drafting and research into connected workflows: permissions, supplier changes, traceability and exception handling become management issues as well as technical ones. (DSIT, 2025) [[dsit2025aicybercode]]
  • For most SMEs, controlled augmentation is a better near-term objective than broad autonomy: select bounded use cases, restrict access, retain meaningful human review and assess performance before scaling.
  • Local business-support organisations can lower the cost of safe adoption through shared supplier questions, workflow templates and routes to specialist support, rather than presenting AI assurance as an enterprise-only compliance exercise.

AI adoption is no longer the same as productive deployment

<p><strong>Thesis.</strong> The UK’s immediate SME AI challenge is shifting from access to deployment assurance. Generative AI tools are now readily available and are being used for general knowledge work. Yet the more consequential productivity gains are likely to come when those tools are connected to internal information, customer records and operational software. That move can reduce repeat work and improve the speed of routine processes, but it also makes errors, weak permissions and unclear accountability more consequential.</p><p>The latest UK Business Data Survey makes the distinction visible. Among businesses handling digitised data, 41% reported using AI in 2025–26. Reported use was concentrated in relatively contained activities: 28% used AI to research information, while 21% used it to summarise or collect in-house information or draft correspondence. Only 21% of AI-using businesses reported integrating AI tools into existing business systems. The reported rate was 57% among large businesses, compared with 31% among small and medium-sized businesses, 27% among microbusinesses and 18% among sole traders. (DSIT, 2026) ↗</p><p>This does not show that smaller firms are unwilling to innovate, nor does integration by itself demonstrate productive or secure deployment. The survey is self-reported, and it does not establish the depth, quality or commercial outcome of any connection. But it identifies a credible fault line. A stand-alone tool used to prepare a first draft is relatively easy to reverse. A tool connected to a shared drive, customer relationship management system or transaction process can create repeated value, but it can also act repeatedly on incomplete information or overly broad access.</p><p><strong>Sanctuary interpretation.</strong> The emerging AI divide may therefore be less about which firms have opened an account than which can safely embed a useful capability in a routine workflow. For UK SMEs, high-street businesses and growing entrepreneurial firms, this is a management-capability question: can the business define a task, set decision rights, test a service and recognise when it should stop?</p>

The evidence indicates a governance gap, but not a case for bureaucracy

<p>Governance appears to be lagging reported use. Just 17% of AI-using businesses said they had a policy or guidelines for AI use or development in 2025–26; 5% reported a formal written policy and 12% informal guidance. The size gradient was marked: 56% of large businesses reported a formal written policy, compared with 22% of medium-sized businesses, 17% of small businesses, 8% of microbusinesses and 3% of sole traders. (DSIT, 2026) ↗</p><p>It would be a mistake to translate this finding into a demand for every small firm to create an extensive AI rulebook. Written policies can be ceremonial, while blanket prohibitions may encourage staff to use unapproved tools without support. The more useful test is operational: can a business identify its approved tools, define what data may be entered, name the person accountable for the use case, specify where human review is required and control who authorises a connection to business systems?</p><p>The survey also shows that data confidence cannot simply be assumed. Seventy-three per cent of businesses handling digitised data said they would be uncomfortable with business-owned data being used to train external AI models, while 18% said they would be comfortable. This does not reveal the contractual terms, technical settings or practices of any particular provider; it is not evidence that a provider necessarily trains on a firm’s data. It does, however, reveal a substantial concern that procurement and implementation processes need to address. (DSIT, 2026) ↗</p><p><strong>Trade-off.</strong> Controls imposed before a use case is understood can slow experimentation. Controls omitted until after an integration is live can make experimentation needlessly risky. The proportionate middle ground is not a long approval chain, but a clear boundary around a defined workflow: what the tool can access, what it may produce or do, who checks it and how the firm can withdraw it.</p>

Why a connected workflow creates a different risk mechanism

<p>The risk profile changes when AI moves from a personal assistant to an operational component. Four mechanisms matter particularly.</p><p><strong>Permissions.</strong> A connected assistant may gain access to documents, inboxes, customer fields or workflow actions. The question is not whether broad access is convenient, but whether each permission is necessary for the task. <strong>Supplier change.</strong> Changes to models, features or interfaces may alter how a workflow behaves after it has been introduced. <strong>Traceability.</strong> Where an output informs a consequential decision, managers need enough records to understand what data, instructions and system actions materially shaped it. <strong>Exception handling.</strong> Human review must sit where an error could have financial, customer, employment or safety consequences.</p><p>The government’s voluntary Code of Practice for the Cyber Security of AI provides a useful reference point. Its principles cover risk assessment, human responsibility, supply-chain security, documentation, testing, updates, monitoring and secure disposal. It calls for due diligence around external components, documentation of security-relevant system information, and logging of system and user actions to support investigation and remediation. (DSIT, 2025) ↗</p><p>The Code is principally directed at developers, system operators and data custodians. A small business buying standard software should not claim to replicate a model developer’s technical assurance. Its practical value to buyers is as a disciplined set of questions for suppliers and implementation partners: what information is accessed and retained; can permissions be restricted; what is logged; how are material changes communicated; and what happens if the service must be withdrawn or replaced?</p><p>Those questions turn an abstract AI strategy into a procurement and operating discipline. They also avoid a common false choice between innovation and control. Narrow permissions, documented change arrangements and review points do not guarantee a good outcome, but they make failure more visible and more reversible.</p>

Security, data protection and quality are related—but they are not interchangeable

<p>Security and data protection should be designed into a workflow rather than added after a pilot has proved popular. The National Cyber Security Centre assesses that AI will almost certainly make elements of cyber intrusion more effective and efficient through to 2027. It also warns that incorporating AI into the UK technology base without sufficient cyber controls will almost certainly create a larger attack surface and more opportunities for adversaries. (NCSC, 2025) ↗</p><p>This is a strategic threat assessment, not a prediction that every AI deployment will lead to an incident. Its practical implication is narrower and more useful: decisions to connect AI to business systems should be treated as security decisions, with attention to access, suppliers, monitoring and recovery.</p><p>Data protection introduces a distinct discipline. The ICO’s AI guidance applies UK data-protection principles to AI systems processing personal data and advocates a risk-based approach to impacts on individuals’ rights and freedoms. It also provides a risk toolkit for organisations assessing their use cases. (ICO, 2026) ↗</p><p><strong>Sanctuary interpretation.</strong> SMEs should resist collapsing these issues into a vague category of “AI compliance”. Security asks whether systems, access and suppliers are resilient against misuse or compromise. Data protection asks whether personal data is used lawfully, fairly, transparently and with appropriate safeguards. Quality assurance asks whether an output is reliable enough for the decision being made. A sound deployment addresses all three, but the accountable person and evidence required may differ.</p><p>A practical proportionality rule is to classify use cases by consequence, not technical novelty. A non-sensitive internal meeting summary is generally lower consequence than a customer response generated from account data, a ranking of applicants, a price change or an action that initiates a transaction. Higher-consequence uses warrant tighter data boundaries, clearer escalation, sampled review and retained records of meaningful actions. This is not an argument against such uses; it is an argument for matching the control to the consequence.</p>

A 90-day deployment-assurance sprint for smaller firms

<p><strong>Sanctuary recommendation.</strong> SMEs do not need to begin with an organisation-wide transformation programme. They should begin with one frequent, bounded and measurable workflow. The aim is to build a repeatable deployment method before attempting wider integration.</p><ol><li><strong>Select a real bottleneck.</strong> Choose a task such as producing a first draft from enquiry notes, checking standard documentation for missing fields or preparing a routine internal report. At the outset, avoid delegating decisions on employment, credit, safeguarding, eligibility or payment release.</li><li><strong>Create a one-page workflow charter.</strong> Record the objective, intended user, systems touched, permitted inputs, expected output, accountable manager, human review point, expected benefit and stop condition. This makes the operational hypothesis testable.</li><li><strong>Set data and permission boundaries.</strong> Specify what must not be entered; use test, redacted or restricted information during early trials where appropriate; and grant only the access needed for the task. Scoped connections are preferable to broad, persistent access where the workflow does not require it.</li><li><strong>Conduct buyer-level supplier checks.</strong> Record the relevant data terms, retention settings, security information, support route, version or service configuration, and arrangements for significant changes. The Cyber Security Code’s emphasis on supply-chain security, documentation and monitoring provides a useful structure for this exercise. (DSIT, 2025) ↗</li><li><strong>Test failures deliberately.</strong> Use conflicting source material, incomplete instructions, unusual language, unavailable systems and requests beyond the tool’s authority. Assess whether a reviewer can identify and correct the result before it has an external effect.</li><li><strong>Operate with evidence for 30 days.</strong> Maintain a light record of material errors, overrides, access issues, staff feedback, time saved and customer effects. Continue, redesign or stop the workflow on that evidence—not on enthusiasm or vendor claims.</li></ol><p>This is deliberately less dramatic than “AI transformation”. Its strength is that it creates reusable managerial capability. Staff learn where judgement remains necessary, managers learn how to set decision rights, and the business accumulates evidence for later procurement and scaling. Where personal data is involved, the ICO’s risk-based guidance should inform the assessment of the specific use case. (ICO, 2026) ↗</p>

The local economic opportunity is shared assurance capacity

<p>The government’s SME Digital Adoption Taskforce has set an ambition for UK SMEs to become the most digitally capable and AI-confident in the G7 by 2035. (DBT, 2026) ↗ Achieving that ambition will require more than tool access and occasional training. Smaller businesses often lack the procurement capacity, specialist cyber capability and managerial time needed to interpret overlapping supplier claims and public guidance.</p><p>That creates a local economic opportunity. Chambers, growth hubs, sector networks, enterprise programmes and business-support organisations can reduce duplicated effort by providing shared infrastructure: a plain-English supplier questionnaire, model workflow charters, examples of low- and higher-consequence use cases, peer sessions focused on what has worked, and referral routes for issues requiring specialist cyber or data-protection advice.</p><p>The purpose should not be to certify a firm as permanently “AI-ready”. Readiness changes with the workflow, data, supplier and consequence of a decision. The more useful goal is to improve the quality of the next decision: whether to proceed, what to restrict, what to test and when to seek support.</p><p><strong>Conclusion.</strong> The UK’s AI adoption story is entering a harder phase. The 2026 survey evidence suggests that use is spreading faster than integration and formal guidance, particularly outside larger firms. That is not a case for holding SMEs back. It is a case for making deployment assurance lightweight, teachable and repeatable. Firms that can connect AI to a valuable workflow while retaining control of data, accountability and service quality will be better placed to convert experimentation into durable productivity.</p>

Sanctuary controlled-AI workflow frameworkOriginal Sanctuary conceptual framework, informed by the lifecycle controls in the UK AI Cyber Security Code of Practice and ICO risk-based AI guidance.
1. Define the bounded business problem
2. Classify consequence and data sensitivity
3. Scope permissions and supplier obligations
4. Test normal and failure conditions
5. Operate with human review and logs
6. Measure value, incidents and overrides
7. Scale, redesign or stop

Research foundation

References

  1. Department for Science, Innovation and Technology (2026). UK Business Data Survey 2026. GOV.UK.
    Source ↗
  2. Department for Science, Innovation and Technology (2025). Code of Practice for the Cyber Security of AI. GOV.UK.
    Source ↗
  3. National Cyber Security Centre (2025). Impact of AI on cyber threat from now to 2027. National Cyber Security Centre.
    Source ↗
  4. Information Commissioner’s Office. About this guidance: Guidance on AI and data protection. Information Commissioner’s Office.
    Source ↗
  5. Department for Business and Trade (2026). SME Digital Adoption Taskforce: 2026 update. GOV.UK.
    Source ↗
  6. Department for Science, Innovation & Technology. Hero image: Secretary of State Peter Kyle visits Culham Campus as part of the AI Opportunities Action plan announcement, Culham, United Kingdom on 9 January 2025 - 11.jpg. Wikimedia Commons · CC BY 2.0.
    Image source ↗

Discussion

Challenge the analysis.

No approved comments yet.