eCommerceNews UK - Technology news for digital commerce decision-makers
United Kingdom
UK public sector AI use outpaces governance, survey

UK public sector AI use outpaces governance, survey

Wed, 23rd Sep 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

SolarWinds has published research suggesting AI adoption in the UK public sector is outpacing governance. The findings are based on responses from 210 UK public sector IT professionals.

Only 8% of respondents said AI is fully embedded and actively governed across their IT environment. Just 16% reported full compliance with Secure by Design principles, despite broader use of AI tools across healthcare, government and defence.

The research highlights a mismatch between deployment and oversight as public sector bodies bring AI into essential services. Nearly a quarter, 24%, said AI governance is lagging behind adoption, with tools introduced before clear policies are in place.

Another 30% said their organisation has a formal AI governance framework that is actively enforced. A further 29% said implementation remains incomplete or inconsistent, suggesting many bodies have started governance work but have not yet applied it across their operations.

Security gap

The findings also suggest basic security arrangements have not kept pace. While 51% of UK respondents said their organisations are fully or mostly compliant with Secure by Design principles, only a small minority described that compliance as complete.

That gap matters because AI systems are being used in areas of the public sector that support frontline services and sensitive data. The survey found that 44% of respondents had seen an increase in AI-related security incidents or escalations over the past 12 months.

Visibility also emerged as a concern. Some 41% of respondents identified insufficient visibility into AI tool behaviour and activity as a major AI cybersecurity vulnerability.

While 84% said they monitor AI behaviour to some extent, only 29% described that monitoring as comprehensive. Across the wider IT estate, just 18% said they have comprehensive visibility across their entire environment.

These figures suggest many public sector IT teams are trying to oversee AI systems without a full picture of how they behave or interact with existing networks and applications. That can make it harder to assign responsibility, identify misuse and respond quickly when incidents occur.

Rich Giblin, Head of Public Sector and Defence at SolarWinds, said: "Public sector technology underpins services that millions of people depend on every day, so gaps in governance can have serious consequences far beyond the IT department. When AI is helping to run such essential services, getting it right matters to everyone."

Pressure on teams

The results reflect wider pressure on public sector organisations to improve efficiency while working within tight budgets and staffing constraints. AI has been promoted across government as a tool to help departments do more with less, but the survey suggests implementation is moving faster than the controls intended to manage risk.

That tension is visible in the responses on both governance and monitoring. Many organisations appear to accept the need for policy frameworks, but fewer have reached the point where those frameworks are consistently applied or backed by full operational visibility.

The study surveyed 810 public sector IT professionals across the UK and the US. In the UK, the 210 respondents came from government, national healthcare and defence organisations.

Giblin outlined the challenge facing teams as adoption spreads across public services: "Public sector organisations have embraced AI as a way to drive efficiency and improve outcomes. That's understandable in an environment where teams are under constant pressure to deliver more with limited resources, but governance needs to develop at the same pace as adoption.

"Once AI is inside an organisation, public sector teams need a clear view of what it's doing, what it can access, who's responsible for it and how it interacts with the wider environment.

"Putting the brakes on innovation should not be the goal. Secure by Design provides a strong foundation, but its principles need to translate into clear ownership, consistent controls and visibility in practice. The public sector has opened the door to AI. It now needs to make sure the house rules are clear."