IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
UK firms struggle to prove GenAI policy compliance

UK firms struggle to prove GenAI policy compliance

Wed, 2nd Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

SAS has published research showing that only 12% of UK and Irish enterprises can demonstrate that employee use of generative AI follows internal policy. The findings highlight a gap between policy adoption and governance.

Among 100 enterprise technology decision-makers surveyed in the United Kingdom and Ireland, seven in 10 said their organisation has written rules covering staff use of generative AI. Yet only one in eight said they could show those rules were being followed in practice.

The figures come as companies face tighter scrutiny over how artificial intelligence is deployed, particularly in customer-facing tools and regulated processes. Just 12% of respondents described their current AI governance framework as well-established and comprehensive, while only 13% said they expected to be fully prepared for current and upcoming regulation.

For businesses operating across borders, the issue goes beyond internal controls. Under the EU AI Act, the most serious breaches can attract penalties of up to €35 million or 7% of worldwide annual revenue.

Policy gap

The research suggests many organisations have found it easier to write guidance than to enforce it. The share of UK and Irish firms with a formal generative AI policy rose from 59% in the earlier study to 77%, but most respondents said the systems needed to monitor and audit use remain incomplete.

Some 63% said their governance infrastructure was still in development, up from 55% in the previous research. The increase suggests that even as adoption spreads, many companies are still building the controls needed to track how AI tools are used across the business.

The findings also show deployment moving ahead in areas likely to attract greater regulatory attention. Nearly a quarter, or 23%, of firms actively using generative AI said they had already integrated it into customer-facing or regulated decision-making workflows.

Human supervision appears limited in many of those cases. Only 25% of active users said they were running generative AI systems with human-in-the-loop oversight, while 9% said AI was already operating autonomously across selected workflows with only exception-based human intervention.

Regulatory pressure

The study points to a mismatch between the speed of adoption and the pace of governance work. While the UK has largely maintained a sector-led approach to AI regulation, companies with European exposure may still need to meet EU requirements where their systems fall within scope.

That is particularly relevant for organisations using chatbots, AI-assisted content tools or other systems that interact directly with customers. Transparency and audit obligations are expected to weigh more heavily on businesses that cannot clearly document what data is entering and leaving their models.

Dr Iain Brown, Global Head of AI & Data Science at SAS, said: "For years, responsible AI has lived comfortably as a promise. But as legal deadlines phase into force, that comfort is rapidly eroding. Many UK firms have likely treated the absence of a standalone AI regulation as an excuse to focus elsewhere, but the rules have been changing around them. The challenge now is being able to demonstrate that those policies are operating in practice.

"Organisations must avoid a situation where underlying data pipelines cannot track, log or audit what information is entering and leaving a model in real time. If you cannot audit your software, you do not have governance."

He said the first problem for many companies is basic visibility over where generative AI is being used. Without that, businesses may struggle to identify which data sets, workflows and outputs are affected.

"Most organisations don't actually know where GenAI is running inside their business right now, which data it's touching, which workflows it's influencing. That's the starting point.

"Everything else flows from the data layer: can you show what went into the model, what came out and whether that was appropriate? That needs live telemetry. And the Omnibus delay on high-risk systems is not an excuse to put it at the bottom of the pile. EU regulators have been clear: use this time to build, because the bar in 2027 will be higher than the bar set this year. Governance has to become an operational capability."

The survey covered senior enterprise technology and data decision-makers across sectors including banking, insurance, public services, life sciences and healthcare. Forty per cent of respondents worked at organisations with more than 5,000 employees.

The earlier study found that 8% of technology leaders felt fully prepared for existing and upcoming regulation. The latest figure of 13% shows some movement, but also suggests that two years of investment and policy drafting have not yet translated into broad confidence that governance systems are ready for closer oversight.