IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
Most UK retailers hit by AI security incidents, survey finds

Most UK retailers hit by AI security incidents, survey finds

Mon, 24th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Most large UK retailers have experienced an AI-related security incident in the past year, according to RiverSafe, citing a survey of 200 senior cyber and information security leaders.

Nearly 60% of respondents said their organisation had suffered an AI-related security incident with real-world impact in the previous 12 months. The study covered retailers with annual turnover of at least GBP £250 million and workforces of 500 or more.

The findings suggest security teams are struggling to keep pace with the spread of AI tools across retail operations. Almost all respondents, or 99%, said they were under pressure to adopt AI faster than governance and risk processes could keep up, while 48% said that pace was already creating gaps.

Retailers also reported weak oversight of how AI tools enter the business. RiverSafe found that 88% do not put every AI use case through a documented security review before it goes live, and respondents estimated they were running about 10 AI tools on average without formal security approval.

Access control is another concern. Just over half of respondents, or 52%, said they had full control over what their AI agents and tools could access without human sign-off.

Supplier risks

The survey points to continuing concern over supplier and third-party exposure. Around 40% of respondents said they had not fully adapted their supplier risk processes to account for AI, even as AI tools are being connected to pricing systems, checkout functions and customer data.

That matters in a sector where supplier relationships and software integrations are deeply embedded in day-to-day operations. AI systems introduced through external vendors can create another route into core retail infrastructure if governance checks do not keep pace.

The findings also suggest many security teams expect unauthorised AI adoption to continue. Every respondent acknowledged that their organisation would be running AI tools without security approval.

Even so, the survey did not present a wholly pessimistic view of the risks. RiverSafe found that 93% of respondents believe AI-related security risk can be reduced to an acceptable level with the right governance in place.

The issue is not simply whether retailers use AI, but whether internal controls can keep up with deployment across business functions. That tension appears strongest where operational demands are immediate and security reviews take longer.

Oseloka Obiora, Chief Technology Officer at RiverSafe, said: "AI is being wired into pricing, checkout and customer data faster than teams can secure it, and most retailers have already had an incident. AI agents especially can carry real identity and access rights, often reaching further into the business than anyone intended, and that exposure is easy to underestimate when things are moving this fast. The teams handling it well are getting a grip on what each agent can reach and what it can do before it reaches the systems the business runs on."

Board pressure

The results reflect a wider management challenge around AI adoption in large organisations. Security leaders appear to be under pressure from boards and operating teams to roll out AI tools quickly, even where formal review and approval processes are incomplete.

One senior retail security leader described that pressure in remarks from a RiverSafe roundtable discussion.

The security leader said: "The board wants AI everywhere, yesterday. We find out it's live when it's already live. The job now is putting a front door on something that's already in the building."

The research was conducted by Censuswide among senior cyber and information security leaders at UK retailers. Respondents were drawn from businesses with at least 500 employees and turnover of GBP £250 million or more.

The data adds to evidence that AI governance is becoming a more immediate operational issue for retailers rather than a longer-term policy concern. In this survey, the gap between adoption and oversight appeared in incident rates, supplier checks, access controls and the number of tools introduced without formal approval.