AI Governance in UK Retail

Naveen Jalagadugu

by Naveen Jalagadugu

How far UK retail has got with governing AI

Retailers are adopting AI quickly, and most security teams have started to put governance around it. Adoption has run ahead of that work, though. Incidents are already happening, and a lot of the groundwork is still unfinished.

None of this reads as panic however as most leaders believe the risk can be managed.

This report, based on feedback from over 200 UK retail cyber security leaders,  sets out the findings and what they mean. It also draws on our work with UK retailers, and on what security teams tell us directly.

Get the full report

Key findings

  • Have had an AI-related security incident with real-world impact in the past 12 months. Close to 60% say the impact was meaningful.

  • Are running AI tools with no formal security approval.

  • Feel pressure to adopt AI faster than their governance and risk processes can keep up.

  • Do not put every AI use case through a documented security review before it goes live.

  • Fully control what their AI agents can access without human sign-off. The rest have partial control or none.

  • Carry gaps governing how AI connects into core systems such as pricing, checkout and customer data.

  • Still manage AI governance on spreadsheets and manual processes.

  • Have not fully adapted their supplier risk process for AI.

  • Believe AI-related security risk in retail can be brought to an acceptable level with strong governance in place.

Where retailers actually are

The pattern across these findings is consistent:

Adoption is ahead of control, incidents are not the future, they are happening now, ownership is unsettled, and investment has followed regulation rather than risk.

The practical sequence is to start with a reliable picture of what AI is actually in use, then name who owns the risk and where it sits within existing governance.

With those in place the control gaps become visible and can be closed in priority order, beginning with what agents are allowed to reach.

Detection and response is where most leaders are heading next, and it works far better built on that footing than stood up on its own.

The full report sets out what retailers are doing about each of these, with the underlying data.

Read the full findings.

Find the AI already running, and rank what to do about it

If the findings sound familiar, a useful first step is a clear view of the AI already in use across your business. We can help your team to surface it, sanctioned or not, and rank it by risk and value. You come away with a ranked list, a decision on each use case, and a named owner to carry it forward.

Talk to us

Read the full report

RiverSafe works with retailers across the UK, giving security teams both the advisory perspective to know what to prioritise and the technical hands to deliver it.