Your AI Rollout Already Happened
By Jonny Davey · 15 September 2026
If you run a business in the UK, there is a good chance your AI rollout happened without an announcement. It arrived in a software update. A summarise button appeared in your meeting tool, a drafting assistant turned up in the corner of your email client, and the CRM you have paid for since 2019 quietly grew a feature that writes the follow up for you. Nobody signed a strategy document, nobody ran a pilot, and yet AI now sits in the middle of the working day for a fair number of your staff.
Of everything I have read this year, that is the trend I keep coming back to. Not the models, which change every few weeks, but the fact that generative AI has stopped being a place you go and has become part of the software you already own. For a business reader that matters far more than which model is on top this month. The question is no longer whether you adopt AI. It is what you wrap around the AI that has already turned up.
The Rollout Nobody Signed Off
Gen AI started in the public imagination as a destination. You went to a website, you typed something, you got an answer. That phase is over. The work now happens inside productivity suites, browsers, contact centre tools and the line of business applications that keep a company running.
The practical consequence is that adoption and governance have come apart. Adoption is happening whether or not you have a policy, because the features are switched on by default in tools you already license. Governance, for a lot of organisations, is still a document somebody drafted in 2024 and nobody has opened since. I am not pointing at anyone in particular. The gap is created by the way the software is sold, not by anybody being careless.
Why the Usual Fix Does Not Work
The instinct when something new lands in the business is to write a policy. I understand it, and I have helped write more than one. A policy has a serious limitation though: it tells people what you would like to happen. It does not tell the tool what it is allowed to do.
That distinction is the argument of this post in one line. A model on its own is just a model. It has no idea where your customer records live, no idea which of your staff should be able to see payroll data, and no idea what your organisation has decided is off limits. All of that comes from the wrapping: the tools you hand it, the connections those tools are allowed to make, and the instructions that tell it when to act and when to stop. Get the wrapping right and you have something useful and predictable. Get it wrong and you have a very confident intern with the keys to everything.
A policy tells people what you would like to happen. The wrapping tells the machine what it is allowed to do.
What the 74% Figure Leaves Out
Deloitte's 2025 Tech Value Survey found that 74% of the businesses it surveyed were prioritising tech spending on AI and generative AI, nearly twenty percentage points above the next most popular areas, which were data management, cloud, IoT and ERP. That number gets quoted constantly as proof that AI has gone mainstream, and in one sense it has. Read it closely though, because it measures where money is going, not what the money produced.
The survey points at something more useful as well: AI is mostly arriving as an assistant layered into work that already exists rather than as a new job title or a new department. That is where the value is, because it takes the repetitive part out of a task somebody was already doing. It is also where the risk sits, because the assistant is close to your data by design.
So the two trends worth a UK business reader's attention are really one trend seen from both ends. AI has been embedded into your estate, and the rules for using it have not caught up. The first is happening to you. The second is something you can do something about, starting this week.
Governance Is the Wrapper
Everything I would call governance here is practical rather than philosophical, and it comes down to four questions.
- What can it reach? Which model, which endpoint, and which systems the assistant is actually connected to.
- What can it see? What goes into a prompt, whether that leaves your tenant, where it is processed and how long it is kept.
- What is it told? The instructions, the approved use cases, and the things it must refuse or hand back to a person.
- What did it do? Logs, so that when somebody asks six months from now what happened, you can answer.
None of that is glamorous, and none of it is legal advice, since I am not a lawyer. Two things are worth knowing anyway. UK GDPR does not stop applying because the processing happens in a chat window, and the ICO has been clear that it expects organisations to understand what their AI tools do with personal data. If you sell into the EU, the EU AI Act reaches you as well. It is not only regulators asking either. Procurement questionnaires are starting to include questions about how AI is used in delivery, and a business that can answer those quickly has an advantage over one that has to go and find out.
Where I Would Start
There is a version of this that takes an afternoon. Open the admin console for your main productivity suite and look at what is switched on. Then look at what people have signed up for with a work email address, because that part rarely appears in a licence report. Then choose the three processes where an assistant would save the most time and decide what data each one may touch before you enable anything.
I do most of my testing in the home lab before it goes anywhere near production, and one thing that testing makes obvious is that keeping data in house is a real option rather than a talking point. A model running on your own hardware never sends a prompt anywhere. The catch is cost. Not long ago you could buy one of the ex-mining Nvidia cards for a couple of hundred pounds and few people were interested. Once the full 64GB of VRAM became usable for inference, the same cards went past £2000, which changes the maths on a home lab and on a small business rack alike. If you are weighing local against cloud for anything sensitive, that is the number to keep in front of you.
What I Am Still Unsure About
I am not sure how quickly the rules will settle in the UK. The direction of travel here has been principles and existing regulators rather than one new act, whilst the EU has legislated, and I would not want to guess what that gap looks like in three years. I am also unsure how much of the embedded AI will still be in use once the novelty wears off. Some of the assistants I have tried earn their place within a week. Others I have switched off and not missed. The honest answer is that the useful ones are wrapped around a job somebody was already doing badly or slowly.
So start with the tools rather than the policy. Find out what is already switched on, decide what it may reach, and write that down somewhere people can find it. Get that far and you have something you can actually govern, rather than a document that describes a business you do not quite run. If you would like help wrapping this properly for your business, get in touch.