Copy article

Warning over UK businesses letting staff feed sensitive company data into AI tools: "Deploying AI without basic safety checks is reckless"

ended 29. October 2025

EXPERTS have warned about UK businesses letting staff feed sensitive company data into unvetted AI tools with zero oversight – as they say "deploying AI without basic safety checks is reckless".

Overconfidence and fragmented governance are leaving UK organisations vulnerable to avoidable failures and reputational damage, the British Standards Institution (BSI) warns after surveying business leaders.

The research found a total of 78% of firms let staff feed company data into unvetted AI tools with zero oversight.

Only 40% have protocols for handling confidential data in AI training and 33% have developed AI training programmes for staff.

Just 33% have AI governance programmes, plummeting to under 25% for smaller businesses – meaning there's nobody officially overseeing these systems and no solid process to fix them.

Only 28% of executives know which data sources their AI uses for training, down from 35% earlier this year – so they can't trace why it made a decision, spot embedded bias, or prove compliance if the regulators come knocking.

And 30% have formal risk assessment processes – meaning most firms are deploying AI blind, discovering problems only after customers, staff, or the business are harmed.

Filiz Demirci, AI Governance & Cybersecurity Consultant at Technoserve IT Consulting, said AI needs oversight.

She added: "The BSI data here confirms what I see with clients: insufficient controls and lack of traceability are causing real regulatory and reputational risks. Deploying AI without basic safety checks is reckless, not innovative. 'Move fast and break things' might suit start-ups, but when you’re handling client or personal data, breaking things means breaking trust, compliance and sometimes the law.

"When 78% of firms let staff upload confidential information into public AI tools, the responsibility rests squarely with leadership. AI use without policy or oversight is a governance failure, not a staff error. 

“Companies should not deploy AI without clear risk and impact assessments, training, and accountability measures in place. Responsible AI doesn’t slow innovation, it builds trust, protects data and ensures resilience.”

Colette Mason, Author & AI Solution Architect at London-based Clever Clogs AI, said you can't build competent AI by “pouring money” into the problem.

She added: "BSI's research confirms what anyone building real AI systems already knows: you can't buy your way to competence, and you definitely can't automate your way out of accountability. 

“The underpinning AI strategy is critical infrastructure, not a side hustle to bolt on when the board gets nervous about competitor advantage. If your governance strategy is 'hope nothing breaks', you're not ready to scale. You're ready for an expensive lesson in why shortcuts always cost more than doing it properly the first time.”

Kate Underwood, Managing Director / HR Director at Southampton-based Kate Underwood HR and Training, said AI isn't a “magic wand”.

She continued: "Too many organisations are treating AI like a magic wand rather than a system. When staff are free to upload client data, financial models or HR files into public tools without oversight, it is not innovation, it is negligence. It is strange, really. 

"Many people refused Covid jabs because they were worried the vaccines had not been tested enough, yet the same people will happily hand over personal photos to AI apps that turn them into cartoon or action-figure versions of themselves. They give away their data for entertainment without thinking twice. The British Standards Institution’s findings point to overconfidence and poor governance. 

“You would not launch a new product without testing it, yet many businesses are using AI without even the most basic safety checks in place. Whether you are running a council, a company or a small team, the rule is the same: people will support technology when they understand it and when leaders take responsibility for how it is used.”

Clive Bonny, MD at Strategic Management Partners, said AI could lead to a legal complaint.

He continued: "The creative content and design industry is reporting how corporate retailers are using AI to scoop up and freely distribute copyrighted online content and digital designs. SMEs and creators are losing jobs. It’s not just designers who are now at risk. 

"If you are involved in publishing website content, trademark logos, new product designs, unique business processes, or any innovations then AI dragnets may be heading your way too. Unwitting suppliers are receiving cease and desist letters from competitor lawyers seeking financial compensation for alleged copyright infringement on their websites. 

“Website designers who use AI content can put their clients in the firing line for serious infringement penalties and themselves for consequential liabilities. AI has become a feeding frenzy for lawyers. So what can you do to protect yourself? Explicit designation of IP protection helps. Clarify your IP ownership with clearly marked IP registrations.”

Pete Mugleston, Mortgage Advisor & Managing Director at Derby-based onlinemortgageadvisor.co.uk, said you can't trust AI without checking it.

He added: “Keeping a human in the loop and understanding the data protection risks of uploading sensitive information are critical if businesses want to avoid potential legal liability and damage to their reputation.”

8 responses from the Newspage community

Copy all

Star Quote
Copy

BSI's research confirms what anyone building real AI systems already knows: you can't buy your way to competence, and you definitely can't automate your way out of accountability.

The underpinning AI strategy is critical infrastructure, not a side hustle to bolt on when the board gets nervous about competitor advantage.

If your governance strategy is 'hope nothing breaks', you're not ready to scale. You're ready for an expensive lesson in why shortcuts always cost more than doing it properly the first time.
Copy

Too many organisations are treating AI like a magic wand rather than a system. When staff are free to upload client data, financial models or HR files into public tools without oversight, it is not innovation, it is negligence.

It is strange, really. Many people refused COVID jabs because they were worried the vaccines had not been tested enough, yet the same people will happily hand over personal photos to AI apps that turn them into cartoon or action-figure versions of themselves. They give away their data for entertainment without thinking twice.

The British Standards Institution’s findings point to overconfidence and poor governance. You would not launch a new product without testing it, yet many businesses are using AI without even the most basic safety checks in place.

Whether you are running a council, a company or a small team, the rule is the same: people will support technology when they understand it and when leaders take responsibility for how it is used.
Copy

Businesses are eager to reap the productivity benefits of AI, but blind trust in these tools can backfire, as evidenced by the recent scandal in Australia. A $440,000 government report generated with AI was riddled with fabricated quotes and court cases, leading to an embarrassing admission by consulting firm Deloitte.

Keeping a human in the loop and understanding the data protection risks of uploading sensitive information are critical if businesses want to avoid potential legal liability and damage to their reputation.
Copy

AI leaks don’t happen because the tech fails. They happen because leadership does. It’s shocking that 78% of firms let staff dump confidential data into unvetted tools, and roughly two-thirds have no risk checks, no AI training and no governance. That isn’t innovation. It’s weak leadership. Big shifts like AI sort the wheat from the chaff. As Warren Buffett said, “Only when the tide goes out do you discover who’s been swimming naked.” That’s exactly what’s happening with AI. We’re in a 'AI ignorance boom' where everyone wants to look innovative, but few truly understand what they’re deploying with no governance, no audit trail and no data boundaries. Regulators will tighten, customers will ask harder questions, and the reputational bill will come due. And when that happens, many organisations will be exposed, not because AI failed, but because their leadership did. Real leaders build culture, training and oversight so AI serves people and purpose. Responsible AI is boardroom duty.
Copy

Everyone’s throwing money at AI like it’s going to magicaly fix everything, but you can’t buy your way to competence. We are seeing companies invest in tools they don’t even understand, often feeding client data into systems they couldn’t explain if you asked. It’s the digital equivalent of giving your filing cabinet to a stranger because they promised to ‘streamline your admin’. AI can be brilliant when used properly, but most firms are running before they’ve even learned to walk.
Copy

The creative content and design industry is reporting how corporate retailers are using AI to scoop up and freely distribute copyrighted online content and digital designs. SMEs and creators are losing jobs. It’s not just designers who are now at risk. If you are involved in publishing website content, trademark logos, new product designs, unique business processes, or any innovations then AI dragnets may be heading your way too.
Unwitting suppliers are receiving cease and desist letters from competitor lawyers seeking financial compensation for alleged copyright infringement on their websites. Website designers who use AI content can put their clients in the firing line for serious infringement penalties and themselves for consequential liabilities. AI has become a feeding frenzy for lawyers. So what can you do to protect yourself?
Explicit designation of IP protection helps. Clarify your IP ownership with clearly marked IP registrations.
Copy

The BSI data here confirms what I see with clients: insufficient controls and lack of traceability are causing real regulatory and reputational risks.

Deploying AI without basic safety checks is reckless, not innovative. 'Move fast and break things' might suit start-ups, but when you’re handling client or personal data, breaking things means breaking trust, compliance and sometimes the law.

When 78% of firms let staff upload confidential information into public AI tools, the responsibility rests squarely with leadership. AI use without policy or oversight is a governance failure, not a staff error.

Companies should not deploy AI without clear risk and impact assessments, training, and accountability measures in place. Responsible AI doesn’t slow innovation, it builds trust, protects data and ensures resilience.
Copy

Unfortunately this is a painful truth even going back to the good old days of "Digital Transformations". Throwing money at something as they believe its going to work for them. Gartner have done some other studies on this too and they found that only 10% of AI projects have resulted in a financial benefit.

The reason why is pretty simple. Time and again the projects are almost always led by the technology team, with very little focus on a specific business outcome or how the solution will fit into the way people actually work.

This isn't just a corporate problem though. We see the same waste in SMEs, who are sold whitelabeled ChatGPT prompts as a silver bullet, only to find they deliver no real value because they aren't tied to a specific business need.

All of it resulting in wasted money to try and fit disparate solutions and tools together into your own business framework