A new report circulating this week puts hard numbers on something that will feel familiar to anyone who’s sat in both a boardroom and a server room. Heimdal’s State of AI Risk Management in 2026, based on responses from 1,000 IT professionals across the UK and US, found that AI adoption inside organisations has outpaced the security controls meant to govern it by roughly two to one. More striking is the confidence gap: 18% of UK executives believe AI risk is fully under control, against just 11% of the practitioners actually running the tools day to day. Only around four in ten IT teams rate their security stack as genuinely ready for AI-related risk.
For UK SMEs, this isn’t an abstract enterprise problem. ChatGPT is already present in 72% of UK IT environments surveyed, and Microsoft Copilot in 68% — meaning the tools this report is worried about are very likely already running somewhere inside your business, used by staff, whether or not leadership signed off on them.
Why the gap gets worse the smaller you are
The report’s authors specifically flag that this confidence-versus-reality gap tends to widen for smaller organisations, not narrow. Fewer dedicated IT or security staff means less formal review of which AI tools are in use, less enforced governance, and heavier reliance on whatever default settings a tool ships with. Among teams with full visibility into how AI is being used in their organisation, 56% flag data leakage as a top concern — versus just 27% among teams with no visibility at all. That’s not because visibility creates risk; it’s because visibility is what lets you actually see the risk that was already there.
In other words: if nobody in your business feels particularly worried about AI risk right now, that’s more likely a sign of low visibility than low risk. The same pattern shows up in how leaders and staff describe their own tool use — senior people are often more confident they know what’s happening across the business than the data actually supports, precisely because they see less of the day-to-day workaround culture that builds up on the ground.
Closing the gap without a big IT budget
You don’t need an enterprise security team to make meaningful progress here. Start by finding out, plainly, which AI tools staff are actually using day to day — not which ones were officially approved. Then look specifically at what kind of company or customer data might be passing through those tools, since that’s where the real exposure sits, not in the existence of the tools themselves.
A short written policy on what can and can’t be pasted into an AI chatbot, plus a nominated approved tool list, closes most of the practical gap quickly. It’s also worth making the confidence check itself explicit: ask whoever is closest to day-to-day tool use, not just whoever holds the budget, how sure they actually are that customer or company data isn’t leaking through an AI tool somewhere. Their answer is usually more accurate than the one you’d get from the top of the org chart, and it’s free to ask.
For businesses ready to go further — matching the right tools to the risk, rather than banning AI outright or leaving it to chance — this is exactly the assessment ApplyAI works through with SMEs, translating a report like this into a concrete, right-sized action plan.
The takeaway
The most useful reaction to this report isn’t to assume it’s talking about someone else’s business — it’s to ask your own team, this week, what they’re actually using and how confident they genuinely are that it’s safe. The gap the data describes exists precisely because that conversation usually hasn’t happened yet.