The single most striking finding in this research concerns the AI use that organisations have not sanctioned. Asked whether they use AI tools in their work that their organisation has not formally provided or approved, more than 42% of tech professionals said yes: 20% regularly and a further 22% occasionally. Only 56% said no. This is not a fringe behaviour, and it is not unique to our respondents. Wider research points the same way, with one January 2026 survey finding that nearly half of workers had adopted AI tools without their employer's approval. The plain reading is that ‘shadow AI’ has entered the workplace faster than the rules. Practice is running ahead of governance.

More than two in five use AI their employer has not approved

This finding can be read two ways, and both are correct. On the one hand, it is a story of ‘enterprising workers’: individuals recognising the value of these tools, often before their organisations do, and reaching for them to work more quickly or effectively. Innovation of this kind frequently starts at the operational level, with the people closest to the work spotting where AI can help. On the other hand, unapproved use is, by definition, ungoverned use. When tools have not been vetted, sensitive data can flow into systems no one has assessed, outside the organisation's oversight and control. Both readings lead to the same conclusion: the demand is real and adoption is inevitable, so the task is to govern it well, not to look the other way.

The finding also raises a question the survey cannot answer, but which is worth posing. If workers are turning to tools their organisations have not provided, some may be absorbing the cost themselves, paying personally for the means to do their jobs better. We have no data on this, and make no claim about how common this may be. But it would be a striking state of affairs if the impetus to adopt AI were coming from individual employees rather than the organisations set to benefit from it. Responsibility for closing that gap sits, for the most part, with leadership; deciding which tools to approve and provide, and ensuring that AI is adopted responsibly, are executive functions rather than operational ones. 

This research cannot tell us where within organisations the shortfall lies, and we do not claim it can. But given the nature of these decisions, the pattern suggests a gap at the strategic level, and it points to a need for executive teams to hold enough digital literacy, and to be given enough support and resource, to see both the opportunities and the risks that AI presents. We return to what that requires in our conclusions.

The idea that the problem lies with leadership is reinforced by how tech professionals rate their organisations' progress overall. Asked how effectively AI adoption is taking place where they work, the average score was just 2.84 out of 5. This is only fractionally above the midpoint; in the assessment of the people best placed to judge, adoption is falling short. Confidence that AI is being used in an ethical and responsible way is a little higher, at 3.28, though it too leaves clear room for improvement. The gap between the two is modest but telling: tech professionals are somewhat more confident that AI is being used responsibly than that it is being used effectively, which suggests the more pressing problem today is making adoption work.

Taken together, the governance skills gap this report identifies is not a theoretical concern. It is manifesting, in real time, in organisations across the country: AI is being adopted faster than it is being governed, and the assessments of those closest to it suggest there is considerable work still to do, much of it at the strategic level. The question that follows is whether the way organisations are responding is equal to the task.