AI adoption and
governance

AI adoption accelerating whilst governance catches up

AI has become part of everyday work, and the pressure to govern it well is growing just as quickly.

More people now have access to a wider range of AI tools, often used across different systems and for many different tasks.

But as AI systems become increasingly embedded into day-to-day operations – particularly with the emergence of agentic systems and user generated AI workflows – organisations face growing legal, ethical and operational challenges. Typical challenges remain, such as from data protection and accountability to explainability, procurement risks and regulatory readiness. But new challenges are on the near horizon, including the potential proliferation of AI systems whilst governance processes remain slow to work and evolve.

Adoption of AI is widespread but inconsistent, with no single use case leading the way.

0%

Of respondents already use AI

0%

Have yet to adopt it

At the same time, organisations are under growing pressure to strengthen governance frameworks. While 41% feel confident in their AI risk management, 29% do not.

This raises an essential question: with the governance burden increasing rapidly, how can organisations scale AI safely, responsibly and in line with evolving legal, regulatory, and stakeholder expectations?

How confident are you in the risk management of AI within your organisation?

Regulation is accelerating faster than adoption maturity

The rapid increase in AI adoption is occurring alongside intensifying regulatory, industry and societal focus on responsible and transparent use of algorithmic tools. More than half of organisations surveyed (53%) believe that AI regulation and the ethical use of technology will grow in significance in the coming years.

This aligns with the UK’s emerging regulatory direction – a principles‑based, outcomes or risk‑focused framework emphasising safety, accountability, fairness and compliance with existing laws and sector‑specific requirements.

Learning by doing

However, governance readiness is far from uniform. Large organisations report substantially higher concern about data and AI governance, with 66% of firms with over 1,000 employees calling for greater government focus in this area, compared to roughly a third of smaller businesses.

This reflects different stages of maturity: smaller organisations are often beginning their AI journey and often lack the infrastructure, expertise or frameworks to elevate AI governance to the strategic level. Meanwhile, larger enterprises who are already embedding AI are learning the hard way where their AI governance is reaction and their AI adoption scales and evolves.

Risk – from afterthought, to front of mind

For legal teams, these trends highlight a crucial shift. AI governance is no longer a niche technical issue, but a core organisational risk area and opportunity to support responsible AI adoption that needs to be addressed proactively.

AI adoption: from pilots to patterns

With 68% of organisations surveyed now using AI, business leaders clearly recognise its commercial potential.

Yet the absence of a dominant use case suggests an ongoing experimentation phase or scattered productivity gains. Some deploy AI for data analytics, others for automation or customer experience, while many experiment in marketing or internal risk management.

This “many pilots, few programmes” pattern creates inconsistency: where AI is deployed in fragments, governance becomes harder to standardise across the organisation.

Which of the following, if any, are the primary use cases for AI in your organisation?

Industry and geographical variances

Regional and sectoral maturity also varies. Confidence levels in AI risk management differ significantly across the UK, with regions such as the North West reporting stronger confidence, while areas such as the South West and Wales demonstrate lower perceived readiness.

These differences often mirror broader digital maturity and investment levels.

That may be because the organisation’s AI governance framework is lagging.

However, it could also reflect a capable AI governance framework that is ineffectively communicated to the right stakeholders at the right time. This creates two key risks.

First, responsible AI is also a people issue. If an organisation’s people don’t understand what policies, processes or support is in place, it may discourage adoption and mean risks are not identified, reported or addressed.

Second, an organisation may struggle to engage with its external stakeholders, including customers and investors, about how it is (and isn’t) using AI responsibly.

Why AI governance must accelerate

For organisations scaling AI, the message is clear: responsible AI governance must develop proactively. The data shows that while AI adoption is accelerating, structures for accountability, transparency and risk management are not yet keeping up.

Organisations that delay governance risk more than regulatory non-compliance. Fragmented AI adoption – the “many pilots, few programmes” pattern our data reveals – creates operational blind spots where AI systems operate without consistent oversight, auditability or clear accountability. Opportunities for extracting value, such as what works and what does not, are lost. And when something goes wrong (a biased output, a data breach, a flawed automated decision), the absence of governance infrastructure makes remediation slower, costlier and harder to defend to regulators, customers and investors.

Organisations lacking confidence in their AI risk management

For the 29% of organisations lacking confidence in their AI risk management, this isn’t a theoretical concern – it’s an operational vulnerability that grows with every new AI deployment.

Tailoring your approach to maturity

Our data shows that governance readiness varies significantly by organisation size and sector, so solutions must be proportionate:

For organisations early in their AI journey

Focus first on understanding and foundations, knowing what AI tools are already in use across the business and by whom. Establish baseline policies that extend existing data protection and procurement frameworks to cover AI-specific risks, and designate clear ownership for AI governance decisions.

For organisations with established AI programmes

The priority shifts to standardisation and scalability. Where AI has been deployed in fragments across departments, governance frameworks need to catch up, using consistent classification systems, risk assessment processes, governance platforms, and accountability structures that can accommodate both current deployments and future expansion.

Building a practical governance framework

Regardless of maturity, effective AI governance frameworks typically address:

Policy integration

Reviewing and updating existing data protection, information security and procurement policies to address AI-specific considerations — such as how training data is sourced, how outputs are validated, and how automated decisions can be explained and challenged.

AI system classification

Creating a clear inventory of AI tools in use and categorising them by risk level, regulatory sensitivity and operational criticality. This enables proportionate oversight rather than treating all AI systems identically.

Lifecycle governance

Establishing processes for the full AI lifecycle — from procurement and development through deployment, monitoring and eventual decommissioning. Each stage presents distinct governance requirements.

Targeted training

Ensuring that individuals understand their responsibilities based on their role. A procurement lead needs different AI literacy than a developer or an end user. Training should be practical and role-specific, not generic awareness-raising.

Third-party due diligence

Implementing robust vendor assessment processes, including contractual safeguards around data handling, audit rights, liability allocation and transparency about how AI systems function.

Accountability pathways

Clarifying who is responsible for AI-related decisions at each level — from day-to-day operational choices to strategic governance oversight. This includes establishing escalation routes when issues arise and ensuring human oversight of high-risk automated decisions.

Legal teams should lead or be closely involved in AI governance, not as a compliance function but as strategic advisors. This includes shaping policy, conducting regulatory horizon scanning, advising on contractual frameworks for AI procurement, and ensuring that AI-enabled processes can withstand regulatory and stakeholder scrutiny.

As the regulatory environment evolves, organisations that can demonstrate robust, documented governance will be better placed to scale AI safely, respond to regulatory enquiries with confidence, meet stakeholder expectations and maintain the trust that underpins commercial relationships.

Tom Whittaker profile photo

“As AI moves from pilots to scale and business critical workflows, governance challenges escalate fast. Existing governance practices can be built upon but need to adapt to new technologies and ways of working. The organisations gaining real value are those treating governance as a strategic discipline, not a compliance tick box.”

Tom Whittaker profile photo

Tom Whittaker Director and Head of AI (Advisory), Burges Salmon

01
01

Explore how we are working with businesses on their AI journey

Explore now