Your staff are probably using AI already. Does your business
21 September 2026
By Toby Beevers
AI adoption may already be happening inside your business without a formal strategy. What does the growth of informal AI use mean for SMEs, and how much governance is actually necessary?
AI adoption is often discussed as though it starts with a business decision, a company chooses a platform, agrees a budget, trains its staff and begins using AI. The reality appears to be rather messier.
According to the Office for National Statistics (ONS), 55% of employed and self-employed people surveyed in Great Britain reported using AI for work or education in May and June 2026. By comparison, around 35% of UK businesses with 10 or more employees reported using at least one AI technology.
Those figures are not directly comparable, the employee measure includes work or education, while the business survey measures specific AI technologies being used within firms, and the ONS explicitly cautions about those differences.
But the gap is still interesting.
It suggests that at least some AI adoption is happening from the bottom up. Employees are discovering tools, experimenting with them and incorporating them into their work before the organisation necessarily has a complete picture of what is happening. For a small or medium-sized business, that changes the AI conversation.
The question may no longer be simply:
“Should we start using AI?”
It may be:
“How are we already using it?”
AI is unusually easy to adopt
Most significant business technology changes are relatively visible, a new CRM system needs to be purchased. A finance platform needs implementing. A new data platform requires technical work. Somebody normally approves a budget and knows the project exists.
Generative AI is different ... An employee can open an AI assistant in a browser and start using it within minutes, AI capabilities are also increasingly appearing inside software businesses already pay for.
There doesn't necessarily need to be an AI project, someone writing a proposal might ask an AI tool to improve it. Someone in marketing might generate ideas or analyse content. An administrator might summarise a long document. A manager might use AI to work through a spreadsheet or prepare for a meeting.
Individually, these can be perfectly sensible uses of the technology. Collectively, however, they can create something the business has never formally designed: an informal layer of AI running through everyday work.
The government's 2026 AI Adoption Research gives some indication of where this activity is happening. Among businesses already using AI, natural language processing and text generation were by far the most commonly adopted technologies, used by 85% of AI adopters. Marketing and administration were also among the most common business areas using, or planning to use, AI. These are precisely the kinds of activities where employees can start experimenting without a significant technology project.
There is a term increasingly used for this: shadow AI. Like shadow IT before it, it describes technology being used within an organisation without necessarily being formally approved, managed or even known about.
The problem isn't that people are experimenting
It would be easy to look at shadow AI and conclude that businesses need to lock everything down, but that risks solving the wrong problem. Employees often adopt technology because it helps them get something done. If somebody finds a sensible way to reduce repetitive work or get through information more quickly, that is worth understanding rather than automatically stopping.
There is also clear evidence that businesses using AI see potential benefits. DSIT's AI Adoption Research found that 75% of businesses currently using AI reported improved workforce productivity, while 57% reported developing new or improved processes or operations. Those are self-reported results, so they should not be treated as proof that AI caused a particular productivity gain, but they do help explain why people and businesses are continuing to experiment.
The issue is not experimentation itself, but whether anyone understands what is being used, what information is being shared with it, and what happens to the output afterwards.
What are people putting into AI?
This is probably the most immediate question for many businesses, an AI assistant becomes considerably more useful when you give it context. That might mean a customer email, meeting notes, a contract, a spreadsheet, a supplier document, a report or information copied from an internal system. And that's where a simple productivity tool starts becoming a data governance question.
The Information Commissioner's Office (ICO) is clear that where AI systems process personal data, organisations need to consider their security obligations and assess the risks appropriately.
The National Cyber Security Centre (NCSC) also highlights specific weaknesses associated with generative AI systems. Large language models can produce incorrect information confidently, and systems built around them can be vulnerable to attacks such as prompt injection, which can potentially cause unintended behaviour or disclosure of confidential information.
None of that means businesses should avoid AI though, it simply means the same basic principle that applies to other business technology should apply here too:
understand where your information is going.
If employees are putting customer information, commercially sensitive documents or internal data into external AI services, somebody should understand which service is being used, under what terms, and whether that use is appropriate. That doesn't require every SME to build an AI governance department, but it does require some awareness.
Most businesses still don't have formal AI rules
The UK's 2026 Business Data Survey provides another useful indication of how early this process still is, among businesses that said they use AI, only 17% reported having either a formal or informal policy or guidelines covering AI use and development, and just 5% had a formal written policy.
The position changes considerably with company size., large businesses were much more likely to have formal policies than smaller organisations, which isn't particularly surprising. A 40-person company doesn't need the same governance structure as a multinational bank. But having no rules at all is different from having proportionate rules.
Interestingly, among businesses that did have formal or informal AI guidance, 62% said it covered AI access to company data and files, that feels like a sensible place for smaller businesses to start, not with a 30-page AI policy.
What would useful AI guidance actually cover?
For many SMEs, the first version could be relatively straightforward:
- Which AI tools are people allowed to use for work?
- What types of company, customer or employee information should not be entered into public AI services?
- When should an AI-generated answer be checked by a person?
- Are there activities perhaps involving financial decisions, personal information, legal documents or customer commitments where additional review is required?
- And who should somebody ask when they are unsure?
The objective is not to predict every possible use of AI, you probably cannot. But it's to give people enough guidance to experiment responsibly without having to guess where the boundaries are. That matters because human oversight remains an important part of how businesses currently use AI. DSIT found that 84% of businesses using AI reported at least some human input or checking of AI-produced outputs or decisions, with 67% reporting significant checking.
Start by finding out what is already happening
For a business beginning to think seriously about AI, there is a temptation to start by researching products, but I think there's a more useful first step, Ask your team!
- What tools are they already using?
- What are they using them for?
- Which tasks genuinely become easier?
- Where are they unsure about what they should or should not do?
- What information are they putting into those systems?
- And where are they getting results they do not trust?
You may discover that AI adoption has already started, if it has, that is not necessarily a problem. In fact, some of the best potential use cases may already be visible in the experiments employees have started themselves. But informal experimentation and business adoption are not quite the same thing.
The next stage is understanding which uses are genuinely useful, which introduce unnecessary risk, what needs clearer guidance, and which experiments are worth turning into repeatable business processes. For many SMEs, an AI strategy does not need to begin with a transformation programme.
It can begin with something much simpler: finding out what your business is already doing.
Further reading
- Office for National Statistics: Artificial intelligence in UK businesses, 2023 to 2026
- Department for Science, Innovation and Technology: AI Adoption Research
- Department for Science, Innovation and Technology: UK Business Data Survey 2026
- Information Commissioner's Office: How should we assess security and data minimisation in AI?
- National Cyber Security Centre: AI and cyber security, what you need to know