Spend five minutes reading about artificial intelligence and you could be forgiven for thinking humanity is edging towards an existential crisis. The headlines are full of superintelligence, runaway systems, and predictions about machines replacing people. Yet inside most UK businesses, a very different conversation is unfolding.

Insights from Professor Lee Doughty, Director of Security, Resilience and AI Practice at Intercity Technology and Visiting Professor at Aston University, and David Newson, cyber security consultant with 25 years of experience, who leads Intercity's 'Think Secure' efforts.

The challenge, as Professor Lee Doughty explains, is that much of the public debate is driven by organisations building frontier AI models and exploring what the technology might become. Most businesses are focused on something far more immediate: improving productivity, automating repetitive work and delivering measurable business value.

According to the Office for National Statistics, AI adoption across UK businesses stands at around 35%, and up to 49% for larger organisations.  That's a genuinely fast curve, but it's also exactly the kind of fast curve that invites overreaction. Dramatic framing simply gets easier cut-through than a nuanced one, and existential risk is about as dramatic as framing gets. 

AI adoption has nearly tripled.

12% → 35%

Of UK businesses using at least one AI technology, since late 2023.

Source: Office for National Statistics, 2026

Governance hasn't kept pace.

71%

Of UK employees have used unapproved AI tools at work.

Source: Microsoft UK / Censuswide, 2025.

 

 

OVER-USING THE TERM "AI"...

Ask ten people what they mean when they say AI and you'll probably get ten different answers: a chatbot, a recommendation engine, an algorithm that identifies fraudulent transactions, a customer service platform, a tool that summarises emails, or a hypothetical superintelligence. They all get filed under the same two letters despite having wildly different capabilities, risks, and timelines, and that's a problem, because it encourages organisations to talk about AI as though it's a single thing. It isn't.

"Strip back the buzzwords, and what you're often left with is development, automation, process improvement, and critically - governance. Once the discussion becomes more specific, the interesting questions start to emerge: which capability, doing what, with access to which systems, and with access to which data? Those questions matter far more than broad debates about AI in the abstract."

Prof. Lee Doughty, Intercity

Research among UK business decision-makers points to the same pattern: businesses are identifying specific problems, applying AI where it can help, measuring the result, and then expanding its use if the outcome is worthwhile. In practice, that means finding information faster, summarising documents and communications, drafting content, supporting customer service teams, analysing larger sets of data, automating repetitive processes.

Useful, unglamorous, incremental improvements, the kind of thing that makes a process faster, improves customer response times, or helps somebody make a better decision.

 "Automation done badly can absolutely cause real damage, and it deserves proper scrutiny, but it's a very different category of challenge to the scenarios dominating many AI headlines. Most business leaders aren't deciding whether to deploy superintelligence, they're deciding whether an AI tool should be connected to their CRM, customer records, document repository, or service management platform. And that's where the conversation actually starts to get interesting." 

David Newson, Intercity

 

KNOW THE DIFFERENCE BETWEEN CAPABILITY AND ACCESS

Consider a simple example: AI connected to SharePoint is a capability question. AI doing something with your SharePoint data is an access question. Those statements sound almost identical, but they aren't.

  1. Capability is about what the technology can technically do, can it read documents, summarise information, identify patterns, generate content?

  2. Access is about what the technology has been allowed to do those things with: which documents can it see, who granted that access, what information is restricted, how is it monitored, and what happens if its reach is wider than anyone intended?

Most organisations spend far more time talking (and marketing) about capability rather than access, yet access is where much of the risk sits. Shadow AI perpetuates that risk further: The tools employees adopt without formal approval, oversight, or security review.

A Microsoft survey found that 71% of UK employees have used unapproved consumer AI tools at work.

 

ROGUE AI STRIKES AGAIN?

It's worth pausing on the term "rogue AI," which has dominated so much coverage recently with models going on the attack autonomously. It's something we explored with our experts in Did OpenAI's model really 'go rogue'? Our experts respond. Professor Lee Doughty shares his thoughts on why in the video alongside this piece.

Often, the technology has done exactly what it was designed to do, and the problem emerged because somebody gave it access to information, systems, or permissions without sufficient oversight.

On a wider scale, employees are already using unapproved AI tools and sharing work-related information with public platforms, often with leaders having limited visibility into what's being shared or where it's going.

Most AI incidents are governance failures wearing a capability costume. The technology works. The controls around it often lag behind. 

 

 

 

 

SO, WHAT SHOULD UK BUSINESSES BE FOCUSING ON?

Before adopting a new capability, understand the problem it's solving; before connecting a new tool, understand what it can access; before rolling out AI at scale, understand how its use will be governed.

  • What AI tools are already being used inside the organisation?

  • Which business problems are they solving?

  • What information can they access, and who approved that access?

  • How is usage monitored?

  • Where does company data reside?

  • Who remains accountable when decisions are made with AI support?

None of these questions are especially exciting, and none are likely to generate headlines. They're also the questions most likely to determine whether AI becomes a valuable business asset or an avoidable governance problem.

If you are getting a demo of an AI tool and its capabilities, make sure to ask: "so what?"

David Newson, Cyber Security Consultant, Intercity.

 

RECOGNISE THE CAPABILITY, MANAGE THE ACCESS.

The shift underway is real: more automation, more pattern recognition, more decisions supported by technology, and more infrastructure, data, and governance considerations colliding at once. The organisations that handle this well are unlikely to be the ones with the flashiest AI adoption stories. They will be the ones that pause long enough to ask two simple questions, so what, and what does this technology now have access to?

 

Frequently asked questions:

Is AI actually an existential risk?

For most UK organisations, no. Current adoption data shows widespread but shallow use (research, drafting, and automation of routine tasks), not the kind of autonomous, high-stakes deployment that existential-risk scenarios describe. The more immediate risk is governance: who has access to what.

Is there software that can combat rogue AI?

What's the difference between AI capability and AI access?

What is shadow AI?

What questions should leaders ask before adopting a new AI tool?

 

 

Want to know more about AI enablement?

 

Alternatively, reach out and speak to one of our experts to review your current estate:

  0808 500 1436        enquiries@intercity.technology

 

About the experts:

lee_doughty_

Professor Lee Doughty is the Director of Security, Resilience and AI Practice at Intercity Technology and a Visiting Professor at Aston University. He specialises in cybersecurity, resilience, and artificial intelligence, and chairs a Knowledge Transfer Partnership between Intercity and Aston University focused on applying AI to strengthen cyber defence and organisational resilience. Read more about the partnership at Aston University.

Dave Newson

David Newson has worked in cybersecurity since 2001, starting at Computer Associates before spending years with cyber resellers and MSPs, and more recently at O2 Telefonica launching a Threat Intelligence solution. He has also worked with Tier 1 solution providers positioning the Palo Alto Networks technology range for some of EMEA's largest businesses. David now leads the Intercity's Cyber Security effort, championing its "Think Secure" messaging across the business.