UK cyber research, 2026
The 7% Problem
Everyone told you AI would change everything about cyber security this year. The UK data says the threat arriving at most businesses is not the one being sold to them.
report both AI in use or planned and practices to govern it.
have used AI tools their employer never approved.
Foreword
Nobody in your organisation set out to create a security problem. They were just trying to do their job.
That is how AI arrived in most British businesses. Not through a procurement process or a board decision, but through people finding something that made a difficult task faster. Drafting the proposal. Summarising the call. Tidying the spreadsheet before it goes out. This is something we should celebrate, it’s what you would want from good staff.
But it leaves most business leaders in an uncomfortable position.
Can you say which AI tools your people used last month? Can you say what information went into them? And if you have a policy, can you show that it is being followed rather than simply written down?
Most organisations can’t. Our industry has spent this year talking about what attackers might do with AI. That is a fair conversation to have, but it has left considerably less time for what is already happening inside the building, which is measurable and, right now, mostly unmeasured.
This report is about that second question. The gap between how many businesses are using AI and how many have decided what should be allowed is wider than I expected.
The answer is not to ban it. It never was. The answer is to be able to answer the three questions that matter most: which tools, what data and whether the rules are actually working.
Key findings
- Only 24% of UK businesses using, adopting or considering AI have any security practices in place to manage it. A further 31% have no plans to introduce any.
- Around 7% of all UK businesses report both AI in use or planned and practices to govern it, roughly one in fourteen.
- 71% of UK employees have used AI tools their employer never approved, per Microsoft and Censuswide research referenced by the NCSC.
- UK data does not measure whether attacks are AI-driven, so confident claims in either direction run ahead of the evidence.
- Staff training has not moved in two years, flat at 19% of businesses. Only 22% run mock phishing exercises.
Is AI making cyber attacks worse in the UK?
Nobody can tell you.
The UK’s official measurement of cyber attacks records what kind of attack an organisation identified, not what the attacker used to build it. So when a vendor tells you AI-driven attacks are up by some precise percentage, they are not drawing on the national evidence base, because the national evidence base doesn’t capture it.
What the data does show is the shape of what businesses experienced. In the most recent survey, 43% of UK businesses identified a cyber attack or breach in the previous twelve months, unchanged on the year before. Phishing was by far the most common, at 38%, and 69% of those affected called it the most disruptive thing they faced. Ransomware was identified by 1% of businesses, down from 3%, and impersonation attacks hit 12% of businesses, down from 17% in 2023.1
identified an attack or breach, unchanged on the year1
identified phishing, the most common by far1
identified ransomware, down from 3%1
identified impersonation attacks, down from 17% in 20231
Those are counts of attacks identified, not of successful breaches, and none of them say anything about whether AI was involved. They are a useful picture of what organisations are dealing with, not evidence either way about how attackers are building it.
The closest thing to a signal comes from the interviews rather than the numbers. Security teams told government researchers that phishing had become easier to commit, and that the grammatical errors which once made a malicious email obvious were becoming less common.1 That is perception rather than measurement, but it is consistent with what most practitioners will tell you.
So the external threat may well be growing. But the industry has spent the year on a question the evidence cannot yet answer, while a second exposure, one the evidence can measure, has gone largely unexamined.
That one is happening inside the building.
How many UK businesses have AI security controls in place?
Your staff adopted AI. Almost nobody secured it.
Nearly a third of UK businesses (31%) are now either using AI, adopting it or actively considering it. Among medium businesses that rises to 39%.1
Of that number, just 24% have any security practices or processes in place to manage the risks AI introduces. Another 38% say they plan to within twelve months, and 31% have no plans at all.1
- 24% have practices in place
- 38% plan to within 12 months
- 31% have no plans at all
- remainder not reported
of UK businesses using, adopting or considering AI have any security practices or processes in place to manage the risks AI introduces.1
That means that three quarters of the UK businesses that have brought AI into their organisation have not put anything in place to govern it.
Applied across the whole business population, that gives the number this report is named after: only around 7% of UK businesses, roughly one in fourteen, have both adopted AI and put practices in place to manage it.2
of UK businesses report both AI in use or planned and security practices to manage it. Roughly one in fourteen.2
of UK employees have used AI tools their employer never approved.3
The 7% problem shows just how few UK businesses have both adopted AI and decided what should be allowed. Most of the other 93% have not adopted it at a business level, regardless of what their staff are doing. Within that, three quarters have nothing in place to govern it, and a third, roughly one in ten of all UK businesses, say they have no plans to.2
If a third sounds low, look at what is being counted. DSIT asks whether the business has adopted AI, not whether anyone in it has opened ChatGPT. The ONS finds the same picture with a different survey: around 35% of UK businesses with ten or more staff use at least one AI technology, against 55% of working people who say they use it for work or study.5 Adoption also runs with sector, from 13% of construction firms to 58% in information and communication, so anyone in a tech or professional services job sees far more of it than the average business does. The gap between what organisations report and what individuals do is telling.
Employees just aren’t waiting for board approval. Microsoft and Censuswide research, referenced by the NCSC in September 2026, found that 71% of UK employees have used AI tools their employer never approved.3 Whilst the two figures count different things – organisations and individuals – the direction is clear. Governance covers roughly a quarter of AI adopters, while individual adoption has already gone past two thirds of the workforce.
The NCSC’s own framing is blunt. Policies and guidance “have not always developed at the same pace” as adoption, so staff reach for tools that were never assessed.3
None of this is new. In our last survey, 65% of the UK organisations we spoke to already allowed unrestricted app downloads with no visibility into what staff were using.4 The gap was there before AI became a workplace tool. AI did not create it. It’s just made it more obvious.
So what happens when someone uses a tool nobody assessed? The NCSC is specific. Information moved into consumer AI services “may be stored, retained or used to improve the service, outside established security and governance arrangements”.3 There is no breach to detect. The data leaves during ordinary working hours, a paste at a time, and the organisation’s control over it goes with it.
There is an attacker dimension too, and it is more concrete than the deepfake demos. AI agents are software, with the vulnerabilities software has. The NCSC warns that an attacker exploiting one gains “the same data, services, and privileges that the agent has legitimate access to”, and that attackers are highly likely to target agents with looser guardrails as a route into the wider corporate estate.3 Every agent connected to a live system adds to that exposure.
Why the human layer is the weak point
If attacks are concentrating on phishing, and phishing is getting harder to spot, you would expect defences around people to be strengthening. They’re not.
| Control | UK businesses |
|---|---|
| Staff training or awareness activity in the last 12 months | 19% |
| Test staff with mock phishing exercises | 22% |
| Formal incident response plan | 25% |
| Monitoring of user activity | 33% |
| Policy to apply software updates within 14 days | 34% |
| Any two-factor authentication | 47% |
Staff training has sat at 19% for two consecutive years, and at 14% among micro businesses.1 Phishing is the attack businesses face most often, and training is the main defence against it. Four in five UK businesses are not doing it.
Small businesses went backwards on several measures this year, undoing gains made the year before. Cyber risk assessments fell from 48% to 41%. Formal security policies fell from 59% to 52%. Business continuity plans covering cyber fell from 53% to 44%.1
This is what makes the AI adoption figures serious. New technology is entering organisations whilst human and procedural defences are static or eroding.
Want the numbers behind this?
Get the stat pack: every figure in this report with its source and publication date, the working behind the 7% calculation, and the full DSIT breakdown by business size. Useful if you are building a board paper or a budget case.
What UK businesses should do about AI risk in 2026
Start by answering three questions about your own organisation: which tools your people are using, what information is going into them, and whether your rules are enforced. If you cannot answer them today, the six steps below are how you get there.
- Find out what is already in use.Most organisations discover adoption is well ahead of their assumptions. As the NCSC puts it, you cannot manage what you do not know.
- Decide what data may leave.A short, specific rule about what can be pasted into an external tool beats a long policy nobody reads, and it takes about an hour to write.
- Put approved tools in front of people.This is the NCSC’s central recommendation, and the one most organisations skip. Banning tools without replacing them moves the usage somewhere you cannot see it.
- Harden the email layer.Phishing is 38% of the threat and rising as a share of it. If your defences depend on staff spotting bad grammar, they are already out of date.
- Train for the attack you are getting.Only 22% of businesses run mock phishing. It is cheap, it is measurable, and it targets the vector that dominates UK breach data.
- Get visibility across email, cloud, apps and users together.You cannot govern AI use you cannot see, and siloed tools will not show it to you.
Where this leaves you
The AI conversation this year has been dominated by what attackers might be building. That is a legitimate question, and the UK evidence base cannot yet answer it.
It can however answer a different one. Three quarters of the UK businesses using or planning to use AI have no practices in place to govern it, most employees are already using tools nobody approved, and the controls that would catch either of those have barely moved in two years.
None of that is a forecast. It is a description of where things stand today, and it is within any organisation’s power to change.
“A business should think about how to make AI safe to use, not pretend people aren't using it.”
Find out where you sit
Six questions, about two minutes, no sign-up. Nothing you click leaves your browser.
If you want real numbers rather than an estimate, the AI Health Check runs for two weeks and reports which AI services are genuinely in use across your organisation, who is using them, and where data is leaving. It is free.
Sources and method
- Department for Science, Innovation and Technology and Home Office, Cyber Security Breaches Survey 2025/2026, published 30 April 2026. Fieldwork conducted by Ipsos between August and December 2025, covering 2,112 UK businesses, weighted to be representative of the UK business population.
- TrustLayer analysis of the above. DSIT reports that 31% of businesses are using, adopting or considering AI, and that 24% of that group have security practices in place to manage AI risk; 31% of that group have no plans to implement such practices. Applying these proportions to the business population gives approximately 7% and approximately 10% respectively. Figures are rounded and derived from separately reported percentages, so should be treated as close estimates rather than precise counts. The survey records whether practices are reported, not whether they are effective.
- National Cyber Security Centre, The hidden risks of shadow AI, published 7 September 2026. The 71% figure originates in Microsoft and Censuswide research on UK employees, referenced by the NCSC, and should be attributed to that research rather than to the NCSC. It counts individual employees and is not directly comparable with figures counting businesses.
- TrustLayer, 2025 UK Cyber Resilience Report. Fieldwork conducted with market research specialist 3Gem between 8 and 21 January 2024, covering 280 IT leaders in UK SMBs.
- Office for National Statistics, Artificial intelligence in UK businesses: 2023 to 2026, released 20 July 2026, drawing on the Business Insights and Conditions Survey (Wave 159, 15 to 28 June 2026) and the Opinions and Lifestyle Survey (May to June 2026). Business figures cover firms with ten or more employees unless stated; the employee figure covers employed and self-employed people reporting AI use for work or education. BICS excludes some industries, including finance and insurance, so it is not directly comparable with the DSIT survey.
This report draws on published UK official statistics, TrustLayer analysis of them, and one figure from TrustLayer's own previous survey as noted above. It does not include new primary fieldwork.
