At Kaizen AI, we specialize in delivering innovative solutions that drive sustainable growth and success for your business, Let us help you transform your vision

Get In Touch

43% of UK Businesses Were Breached This Year. Almost None Have an AI Policy For It.

  • Home
  • Blog
  • 43% of UK Businesses Were Breached This Year. Almost None Have an AI Policy For It.
A UK small business owner at a desk beside an unlocked padlock and an AI chat icon, representing the gap between AI adoption and AI security

43% of UK businesses were breached or attacked in the last twelve months. That is roughly 612,000 organisations, according to the government’s own Cyber Security Breaches Survey 2025/2026, run by Ipsos for the Department for Science, Innovation and Technology and the Home Office. We read that figure alongside a second one from the same survey that matters just as much: of the businesses now using, adopting or actively considering AI, only around a quarter say they have any security practices in place to manage the risks it brings.

Put those two numbers side by side and the shape of the problem is obvious. AI adoption in UK small business has raced ahead all year, and we have written about that race here more than once. Security has not kept pace. We are handing AI tools access to customer data, invoices, drafts of contracts and internal chat, and three in four of us have done nothing formal to manage what that access means.

The breach numbers, in plain terms

The survey covered 2,112 UK businesses and 1,085 charities, fielded between August and December 2025 and published in April 2026. Phishing remains the way in: it was involved in around 85% of the breaches businesses reported, by far the most common route. Basic defences are patchy too. Only 30% of businesses had carried out a cyber risk assessment in the past year, 47% held any form of cyber insurance, 47% used two-factor authentication, and just 36% had a VPN in place for remote staff.

None of that is exotic. A risk assessment, 2FA on your email and accounting logins, a VPN for anyone working from a laptop outside the office: these are the basics, and most small businesses still have not done them. That was already true before AI tools entered the picture. What has changed is what is now sitting behind that unlocked door.

AI adoption outran the policy that should sit under it

We have covered the adoption side of this before: Simply Business’s 2026 SME Insights Report found AI use among UK small firms had more than doubled to 47%, up from 22% the year before. Most of that use is exactly where you would expect: drafting content, problem solving, generating ideas, saving time on admin.

What we had not seen sourced clearly until this survey is the other half of that picture. Adoption and security readiness are meant to move together. They have not. The businesses turning on AI tools this year are, on the government’s own numbers, mostly doing so with no written policy on what data can go into them, no review of which tools staff are actually using day to day, and no plan for what happens if a breach involves an AI system rather than a traditional one.

We would call that shadow AI: the free version of a chatbot a member of staff signs up to on their own account because it is faster than asking permission, used to draft a client email or tidy up a spreadsheet, with nobody in the business tracking what has gone into it. It is not malicious. It is exactly how most small teams behave when a useful tool appears and nobody has said no. The survey’s technical report is the clearest official confirmation yet that this gap is now the norm, not the exception.

What an AI policy for a small business actually needs to cover

We are not going to pretend every small business needs a security team or a six-figure audit. Most do not, and we would rather point at the four or five things that close most of the gap than sell a bigger fix than the problem calls for.

  • Write down which tools are approved. A single page naming the AI tools staff can use, and what kind of data must never go into them (client financial details, health information, anything under an NDA), closes most of the shadow AI problem on its own.
  • Turn on two-factor authentication everywhere it is offered. Email, accounting software, your AI tool logins themselves. This is free, it takes an afternoon across a small team, and it is still missing from more than half of UK businesses.
  • Do one risk assessment a year. It does not need a consultant. Walking through what data you hold, where it lives, and who could get at it if a password leaked is enough to surface the obvious gaps.
  • Check what your AI tools actually do with your data. Free consumer tiers of most chatbots use conversations to train future models unless you turn that off. Business and paid tiers usually let you opt out. That setting is worth five minutes of anyone’s time.
  • Train staff on phishing specifically. Given it sits behind 85% of reported breaches, and that AI now makes a convincing scam email cheaper to write than a genuine one, this is the single highest-value five minutes a business can spend on the whole list.

The uncomfortable part

We would rather say this plainly than soften it. If your business has picked up an AI tool this year, and most now have, the government’s own data says you are more likely than not to have done so without any policy on what goes into it or any basic protection around the accounts that touch it. That is not a reason to stop using AI. The productivity case for it is real and we have covered that too. It is a reason to spend the one afternoon a small policy and a round of 2FA actually takes, before the 43% breach figure includes your business rather than someone else’s.

We built our own AI use policy the same way we are describing here: one page, five rules, reviewed every quarter rather than written once and forgotten. It cost us an afternoon, not a consultancy fee. That is the standard worth holding a small business to, and it is the one this survey suggests most of the country has not yet met.

Leave A Comment

Fields (*) Mark are Required