Why AI governance stopped being an enterprise problem
AI governance used to be something banks did, in a room, with a committee. Then chatbots turned up inside Word, Outlook, the CRM and every browser tab your staff have open, and the question landed on businesses that have no compliance department to hand it to.
Tuesday, 3.40pm, a four-partner accountancy practice in Leeds. A trainee has a client's management accounts open and a filing deadline at five. He pastes the lot into a free chatbot and asks it to write the commentary. It does, in about nine seconds, and it is genuinely good.
Nobody did anything wrong, exactly. There was no rule to break. That is the whole problem, in one afternoon.
The scale of it, in UK numbers
This is not a fringe scenario. The Office for National Statistics found that self-reported AI use in UK businesses with 10 or more employees rose from around 12% to around 35% between late 2023 and June 2026 — almost tripling in under three years. Adoption varies sharply by sector: 58% in information and communication, 13% in construction.
The governance side has not kept pace. The government's Cyber Security Breaches Survey 2025/2026 found that around a third of businesses (31%) were using AI, adopting it or actively considering it — and that of that group, only 24% reported having cyber security practices or processes in place to manage the risks from it.
Read that the other way round: roughly three in four UK businesses touching AI have no process for what it might do. For a practice of nine people, that is not negligence. It is that nobody has had a spare Tuesday to think about it.
Three ways it goes wrong before anyone notices
The data leaves. A client's figures pasted into a consumer chatbot are now being processed by a third party you have no contract with, that your privacy notice does not mention, and that your client did not agree to. If those figures identify anyone, that is a UK GDPR problem, not an IT preference.
A decision arrives that nobody can explain. Six months in, a customer asks why they were put to the back of the queue, or declined, or quoted more. "The system worked it out" is not an answer you can give them, and under UK data protection law it is not one you are allowed to give either.
Something goes out that nobody read. AI writes confidently whether or not it is right. The failure mode is not gibberish, which anyone would catch. It is a plausible paragraph with one wrong number in it, on your letterhead, sent to a client.
None of the three needs a committee to prevent. They need someone to have written a page.
