Spend five minutes reading about artificial intelligence and you could be forgiven for thinking humanity is edging towards an existential crisis. The headlines are full of superintelligence, runaway systems, and predictions about machines replacing people. Yet inside most UK businesses, a very different conversation is unfolding.
Insights from Professor Lee Doughty, Director of Security, Resilience and AI Practice at Intercity Technology and Visiting Professor at Aston University, and David Newson, cyber security consultant with 25 years of experience, who leads Intercity's 'Think Secure' efforts.
The challenge, as Professor Lee Doughty explains, is that much of the public debate is driven by organisations building frontier AI models and exploring what the technology might become. Most businesses are focused on something far more immediate: improving productivity, automating repetitive work and delivering measurable business value.
According to the Office for National Statistics, AI adoption across UK businesses stands at around 35%, and up to 49% for larger organisations. That's a genuinely fast curve, but it's also exactly the kind of fast curve that invites overreaction. Dramatic framing simply gets easier cut-through than a nuanced one, and existential risk is about as dramatic as framing gets.
AI adoption has nearly tripled.
12% → 35%
Of UK businesses using at least one AI technology, since late 2023.
Governance hasn't kept pace.
71%
Of UK employees have used unapproved AI tools at work.
OVER-USING THE TERM "AI"...
Ask ten people what they mean when they say AI and you'll probably get ten different answers: a chatbot, a recommendation engine, an algorithm that identifies fraudulent transactions, a customer service platform, a tool that summarises emails, or a hypothetical superintelligence. They all get filed under the same two letters despite having wildly different capabilities, risks, and timelines, and that's a problem, because it encourages organisations to talk about AI as though it's a single thing. It isn't.
"Strip back the buzzwords, and what you're often left with is development, automation, process improvement, and critically - governance. Once the discussion becomes more specific, the interesting questions start to emerge: which capability, doing what, with access to which systems, and with access to which data? Those questions matter far more than broad debates about AI in the abstract."
Prof. Lee Doughty, Intercity
Research among UK business decision-makers points to the same pattern: businesses are identifying specific problems, applying AI where it can help, measuring the result, and then expanding its use if the outcome is worthwhile. In practice, that means finding information faster, summarising documents and communications, drafting content, supporting customer service teams, analysing larger sets of data, automating repetitive processes.
Useful, unglamorous, incremental improvements, the kind of thing that makes a process faster, improves customer response times, or helps somebody make a better decision.
"Automation done badly can absolutely cause real damage, and it deserves proper scrutiny, but it's a very different category of challenge to the scenarios dominating many AI headlines. Most business leaders aren't deciding whether to deploy superintelligence, they're deciding whether an AI tool should be connected to their CRM, customer records, document repository, or service management platform. And that's where the conversation actually starts to get interesting."
David Newson, Intercity
KNOW THE DIFFERENCE BETWEEN CAPABILITY AND ACCESS
Consider a simple example: AI connected to SharePoint is a capability question. AI doing something with your SharePoint data is an access question. Those statements sound almost identical, but they aren't.
-
Capability is about what the technology can technically do, can it read documents, summarise information, identify patterns, generate content?
-
Access is about what the technology has been allowed to do those things with: which documents can it see, who granted that access, what information is restricted, how is it monitored, and what happens if its reach is wider than anyone intended?
Most organisations spend far more time talking (and marketing) about capability rather than access, yet access is where much of the risk sits. Shadow AI perpetuates that risk further: The tools employees adopt without formal approval, oversight, or security review.
A Microsoft survey found that 71% of UK employees have used unapproved consumer AI tools at work.
ROGUE AI STRIKES AGAIN?
It's worth pausing on the term "rogue AI," which has dominated so much coverage recently with models going on the attack autonomously. It's something we explored with our experts in Did OpenAI's model really 'go rogue'? Our experts respond. Professor Lee Doughty shares his thoughts on why in the video alongside this piece.
Often, the technology has done exactly what it was designed to do, and the problem emerged because somebody gave it access to information, systems, or permissions without sufficient oversight.
On a wider scale, employees are already using unapproved AI tools and sharing work-related information with public platforms, often with leaders having limited visibility into what's being shared or where it's going.
Most AI incidents are governance failures wearing a capability costume. The technology works. The controls around it often lag behind.
SO, WHAT SHOULD UK BUSINESSES BE FOCUSING ON?
Before adopting a new capability, understand the problem it's solving; before connecting a new tool, understand what it can access; before rolling out AI at scale, understand how its use will be governed.
-
What AI tools are already being used inside the organisation?
-
Which business problems are they solving?
-
What information can they access, and who approved that access?
-
How is usage monitored?
-
Where does company data reside?
-
Who remains accountable when decisions are made with AI support?
None of these questions are especially exciting, and none are likely to generate headlines. They're also the questions most likely to determine whether AI becomes a valuable business asset or an avoidable governance problem.
If you are getting a demo of an AI tool and its capabilities, make sure to ask: "so what?"
David Newson, Cyber Security Consultant, Intercity.
RECOGNISE THE CAPABILITY, MANAGE THE ACCESS.
The shift underway is real: more automation, more pattern recognition, more decisions supported by technology, and more infrastructure, data, and governance considerations colliding at once. The organisations that handle this well are unlikely to be the ones with the flashiest AI adoption stories. They will be the ones that pause long enough to ask two simple questions, so what, and what does this technology now have access to?
Frequently asked questions:
Is AI actually an existential risk?
For most UK organisations, no. Current adoption data shows widespread but shallow use (research, drafting, and automation of routine tasks), not the kind of autonomous, high-stakes deployment that existential-risk scenarios describe. The more immediate risk is governance: who has access to what.
Is there software that can combat rogue AI?
No single piece of technology can effectively neutralise "rogue AI" or the wider risks associated with it — there isn't a switch you can buy. What does work is adopting and enabling AI safely from the outset: clear governance, controlled access, and ongoing visibility into how tools are actually being used. A trustworthy MSP or consultant will usually have a structured programme to help with exactly this. Take control of how AI is used across your organisation.
What's the difference between AI capability and AI access?
Capability is what an AI tool can technically do;read documents, summarise information, generate content. Access is what it has actually been permitted to do those things with, and by whom. Most AI-related incidents stem from unmanaged access, not a failure of capability.
What is shadow AI?
Shadow AI refers to AI tools that employees use at work without their employer's formal approval, oversight, or security review. UK research shows this is widespread, with a majority of employees at some organisations having used unapproved tools despite general awareness of the associated risks.
What questions should leaders ask before adopting a new AI tool?
At minimum: What problem is this solving? What data or systems can it access, and who approved that? How will its use be monitored? Where does the data it touches actually reside? And who's accountable if something goes wrong? None of these questions are exciting, but they're the ones that determine whether a tool becomes a genuine asset or a governance gap.
Want to know more about AI enablement?
Alternatively, reach out and speak to one of our experts to review your current estate:
0808 500 1436 enquiries@intercity.technology
About the experts:
Professor Lee Doughty is the Director of Security, Resilience and AI Practice at Intercity Technology and a Visiting Professor at Aston University. He specialises in cybersecurity, resilience, and artificial intelligence, and chairs a Knowledge Transfer Partnership between Intercity and Aston University focused on applying AI to strengthen cyber defence and organisational resilience. Read more about the partnership at Aston University.
David Newson has worked in cybersecurity since 2001, starting at Computer Associates before spending years with cyber resellers and MSPs, and more recently at O2 Telefonica launching a Threat Intelligence solution. He has also worked with Tier 1 solution providers positioning the Palo Alto Networks technology range for some of EMEA's largest businesses. David now leads the Intercity's Cyber Security effort, championing its "Think Secure" messaging across the business.
Subscribe to our newsletter
YOU MAY ALSO BE INTERESTED IN:
