Editorial

AI adoption outpaces governance across UK public sector, research finds

Only eight percent of UK public sector IT pros say AI is fully embedded and actively governed.

Posted 24 September 2026 by Christine Horton


UK public sector organisations are deploying AI faster than they are putting governance and security controls around the technology, according to new research from SolarWinds.

The IT management and observability software firm found that just eight percent of UK respondents said AI was fully embedded and actively governed across their IT environment.

Meanwhile, 24 percent explicitly said governance was lagging behind adoption, with AI tools being deployed before clear policies were established.

The findings come from SolarWinds’ Racing to Deploy: How Public Sector AI Adoption Is Moving Faster Than the Foundations Needed to Support It report, with more than 200 UK respondents working across healthcare, government and defence taking part.

Secure by Design compliance remains uneven

The research also points to gaps in organisations’ security foundations as AI adoption expands.

The government’s AI Playbook says AI systems used by government should follow Secure by Design principles, which are intended to ensure cyber security is considered throughout the lifecycle of digital services.

However, while 51 percent of UK respondents to the SolarWinds survey said their organisations were either fully or mostly compliant with Secure by Design, only 16 percent reported full compliance.

AI governance appears similarly uneven. Thirty percent said their organisation had a formal AI governance framework that was actively enforced, while another 29 percent reported that implementation was incomplete or inconsistent.

Rich Giblin, head of public sector and defence at SolarWinds, said the consequences of weak governance could extend beyond technology teams because of the role IT systems play in delivering public services.

“Public sector technology underpins services that millions of people depend on every day, so gaps in governance can have serious consequences far beyond the IT department,” he said.

“When AI is helping to run such essential services, getting it right matters to everyone.”

Visibility creates another challenge

The research also highlighted the difficulty public sector IT teams face in understanding what AI systems are doing after deployment.

Some 41 percent of UK respondents identified insufficient visibility into AI tool behaviour and activity as a major AI cyber security vulnerability.

Although 84 percent said they monitored AI behaviour to some extent, only 29 percent described that monitoring as comprehensive. Across their wider IT environments, just 18 percent reported having comprehensive visibility.

At the same time, 44 percent of UK public sector IT professionals surveyed said they had seen an increase in AI-related security incidents or escalations during the previous 12 months.

Giblin said public sector organisations were understandably looking to AI to improve efficiency while operating under pressure to deliver services with limited resources, but argued governance needed to keep pace.

“Once AI is inside an organisation, public sector teams need a clear view of what it’s doing, what it can access, who’s responsible for it and how it interacts with the wider environment,” he said.

“Putting the brakes on innovation should not be the goal. Secure by Design provides a strong foundation, but its principles need to translate into clear ownership, consistent controls and visibility in practice.”

He added: “The public sector has opened the door to AI. It now needs to make sure the house rules are clear.”

Event Logo

If you are interested in this article, why not register to attend our Think AI for Government conference, where digital leaders tackle the most pressing AI-related issues facing government today.


Register Now