Warning over UK businesses letting staff feed sensitive company data into AI tools: "Deploying AI without basic safety checks is reckless"
EXPERTS have warned about UK businesses letting staff feed sensitive company data into unvetted AI tools with zero oversight – as they say "deploying AI without basic safety checks is reckless".
Overconfidence and fragmented governance are leaving UK organisations vulnerable to avoidable failures and reputational damage, the British Standards Institution (BSI) warns after surveying business leaders.
The research found a total of 78% of firms let staff feed company data into unvetted AI tools with zero oversight.
Only 40% have protocols for handling confidential data in AI training and 33% have developed AI training programmes for staff.
Just 33% have AI governance programmes, plummeting to under 25% for smaller businesses – meaning there's nobody officially overseeing these systems and no solid process to fix them.
Only 28% of executives know which data sources their AI uses for training, down from 35% earlier this year – so they can't trace why it made a decision, spot embedded bias, or prove compliance if the regulators come knocking.
And 30% have formal risk assessment processes – meaning most firms are deploying AI blind, discovering problems only after customers, staff, or the business are harmed.
Filiz Demirci, AI Governance & Cybersecurity Consultant at Technoserve IT Consulting, said AI needs oversight.
She added: "The BSI data here confirms what I see with clients: insufficient controls and lack of traceability are causing real regulatory and reputational risks. Deploying AI without basic safety checks is reckless, not innovative. 'Move fast and break things' might suit start-ups, but when you’re handling client or personal data, breaking things means breaking trust, compliance and sometimes the law.
"When 78% of firms let staff upload confidential information into public AI tools, the responsibility rests squarely with leadership. AI use without policy or oversight is a governance failure, not a staff error.
“Companies should not deploy AI without clear risk and impact assessments, training, and accountability measures in place. Responsible AI doesn’t slow innovation, it builds trust, protects data and ensures resilience.”
Colette Mason, Author & AI Solution Architect at London-based Clever Clogs AI, said you can't build competent AI by “pouring money” into the problem.
She added: "BSI's research confirms what anyone building real AI systems already knows: you can't buy your way to competence, and you definitely can't automate your way out of accountability.
“The underpinning AI strategy is critical infrastructure, not a side hustle to bolt on when the board gets nervous about competitor advantage. If your governance strategy is 'hope nothing breaks', you're not ready to scale. You're ready for an expensive lesson in why shortcuts always cost more than doing it properly the first time.”
Kate Underwood, Managing Director / HR Director at Southampton-based Kate Underwood HR and Training, said AI isn't a “magic wand”.
She continued: "Too many organisations are treating AI like a magic wand rather than a system. When staff are free to upload client data, financial models or HR files into public tools without oversight, it is not innovation, it is negligence. It is strange, really.
"Many people refused Covid jabs because they were worried the vaccines had not been tested enough, yet the same people will happily hand over personal photos to AI apps that turn them into cartoon or action-figure versions of themselves. They give away their data for entertainment without thinking twice. The British Standards Institution’s findings point to overconfidence and poor governance.
“You would not launch a new product without testing it, yet many businesses are using AI without even the most basic safety checks in place. Whether you are running a council, a company or a small team, the rule is the same: people will support technology when they understand it and when leaders take responsibility for how it is used.”
Clive Bonny, MD at Strategic Management Partners, said AI could lead to a legal complaint.
He continued: "The creative content and design industry is reporting how corporate retailers are using AI to scoop up and freely distribute copyrighted online content and digital designs. SMEs and creators are losing jobs. It’s not just designers who are now at risk.
"If you are involved in publishing website content, trademark logos, new product designs, unique business processes, or any innovations then AI dragnets may be heading your way too. Unwitting suppliers are receiving cease and desist letters from competitor lawyers seeking financial compensation for alleged copyright infringement on their websites.
“Website designers who use AI content can put their clients in the firing line for serious infringement penalties and themselves for consequential liabilities. AI has become a feeding frenzy for lawyers. So what can you do to protect yourself? Explicit designation of IP protection helps. Clarify your IP ownership with clearly marked IP registrations.”
Pete Mugleston, Mortgage Advisor & Managing Director at Derby-based onlinemortgageadvisor.co.uk, said you can't trust AI without checking it.
He added: “Keeping a human in the loop and understanding the data protection risks of uploading sensitive information are critical if businesses want to avoid potential legal liability and damage to their reputation.”







