Information security decision-makers across Europe, the Middle East, and Africa are grappling with significant concerns surrounding the governance, or lack thereof, of Artificial Intelligence (AI) within their organizations. A recent survey by information technology company Veeam has illuminated a critical gap: 70% of leaders acknowledge that AI is interacting with sensitive data without comprehensive oversight. This widespread lack of control is creating a fertile ground for compliance challenges and escalating anxieties among IT and security professionals.
The Veeam survey, which polled 1,000 enterprise IT, data, and security decision-makers at large organizations across the EMEA region, also found that two-thirds of respondents believe employees are developing agentic AI workflows that their companies cannot fully track. Agentic AI refers to AI systems capable of autonomously planning and executing a sequence of actions to achieve a goal, often involving interaction with external systems or data. This uncontrolled proliferation of powerful AI tools poses a significant risk, as it can lead to data breaches, unauthorized access to sensitive information, and unintended consequences that are difficult to remediate.
As AI governance increasingly demands attention within the risk oversight frameworks of these organizations, a palpable sense of pressure is emerging. The Veeam findings indicate that 37% of leaders are experiencing heightened stress and anxiety due to expanding compliance obligations related to AI. Furthermore, a substantial 40% of respondents cited the potential for personal liability or severe consequences stemming from AI-related regulatory failures. This personal accountability underscores the gravity of the situation, pushing executives to prioritize robust AI governance strategies. The survey also revealed that nearly 60% of respondents’ enterprises are already operating under new corporate accountability laws within their respective regions, adding another layer of urgency to the need for proactive AI risk management.
The implications of these findings are far-reaching. The rapid adoption of AI technologies, while promising immense benefits, has outpaced the development of commensurate governance and compliance structures. This disconnect creates a precarious situation where organizations are exposing themselves to significant legal, financial, and reputational risks. The lack of transparency and control over AI deployments, particularly those involving sensitive data, leaves companies vulnerable to sophisticated cyber threats and regulatory scrutiny.
AI Output Inaccuracies Plague UK Financial Services Amidst Rapid Adoption
Parallel concerns are emerging within the United Kingdom’s financial services sector, where the adoption of AI is accelerating, yet the accuracy and governance of its output remain a point of contention. A separate survey conducted by training provider Skillcast has revealed that nearly a third of financial services employees in the UK are encountering inaccurate or misleading AI outputs. This figure, standing at 32% of workers, highlights a significant challenge in ensuring the reliability of AI-generated information, a critical factor in the highly regulated financial industry.
The Skillcast poll, which surveyed 148 UK employees in financial services, found that despite the prevalence of poor AI results, the technology’s integration into daily workflows is remarkably high. An overwhelming 72% of workers report using AI on a daily basis, with an additional 89% utilizing it at least once a week. This widespread daily reliance on AI underscores the urgency of addressing the accuracy issue, as flawed outputs can lead to erroneous financial advice, incorrect data analysis, and potentially costly operational errors.
While guidance on AI usage is increasing within these organizations, it is not yet ubiquitous. Just over 60% of financial services workers reported having access to a clear and accessible AI policy. Skillcast noted that this figure, while higher than observed in other industries, still indicates a substantial portion of the workforce operating without explicit guidelines. This gap in policy coverage exacerbates the risk of inconsistent AI application and potential misuse.
The expectations for AI within the UK financial services sector remain exceptionally high. Approximately 75% of financial services firms are currently leveraging AI, with an additional 10% planning to implement the technology within the next three years. The industry overwhelmingly believes in AI’s transformative potential, with 93% of firms anticipating that AI and machine learning will have the most significant impact on the UK financial services landscape over the next five years. This forward-looking optimism is juxtaposed with the current reality of unreliable AI outputs and the ongoing need to establish robust governance frameworks.
Employers Lag in Disability and Neurodiversity Training Amidst Rising Discrimination Claims
Beyond the immediate concerns of AI, a separate and critical compliance gap has been identified within UK employers concerning disability and neurodiversity training. A survey by compliance training company VinciWorks has revealed that a significant majority of UK employers are failing to adequately train their managers and staff on issues related to disability discrimination and neurodiversity. This oversight comes at a time when claims related to these protected characteristics are experiencing a notable surge.
The VinciWorks poll, which surveyed 398 HR, legal, and compliance professionals, found that a concerning 71% of UK employers have not provided training on disability discrimination or neurodiversity to either their managers or their staff. Further disaggregating the data, the survey revealed that 50% of employers have not trained managers on disability discrimination, while 57% have not provided staff with training on neurodiversity. This widespread lack of awareness and education among those responsible for managing teams and interacting with employees creates an environment ripe for inadvertent discrimination and potential legal challenges.
The findings are particularly pertinent given recent analyses highlighting a sharp increase in employment tribunal cases linked to neurodiversity. Data indicates that cases related to autism and ADHD have nearly doubled between 2020 and 2025, reaching record levels and becoming the most prevalent type of tribunal case in the UK. This trend suggests that the workforce is becoming more aware of their rights and more willing to seek recourse when these rights are infringed upon, making employer-preparedness crucial.
Compounding these issues, the VinciWorks survey also uncovered a significant lapse in updating whistleblowing policies and training. A substantial 43% of companies have not revised their whistleblowing policies and training since April, the month when sexual harassment disclosures were granted protected whistleblowing status. Alarmingly, more than one in ten companies (11%) have no plans to update their policies, or possess no whistleblowing policy or training whatsoever. This oversight leaves employees vulnerable and companies exposed to potential legal repercussions if sensitive issues are not reported and addressed effectively.
Broader Implications and the Path Forward
The convergence of these survey findings paints a clear picture of evolving compliance landscapes and the challenges organizations face in adapting to them. The rapid advancement of AI, coupled with increasing awareness and legal protections for diverse employees, necessitates a proactive and comprehensive approach to governance and training.
For AI governance, the Veeam survey’s stark statistics underscore the immediate need for organizations to implement robust AI risk management frameworks. This includes establishing clear policies for AI development and deployment, ensuring data privacy and security protocols are adhered to, and developing mechanisms for monitoring and auditing AI systems. The personal liability highlighted by respondents suggests that boards and senior management must actively champion these initiatives to mitigate individual and organizational risk. Industry bodies and regulators are also likely to intensify their scrutiny, potentially leading to more prescriptive guidelines and enforcement actions in the coming years. The timeline for developing effective AI governance is rapidly contracting, demanding immediate strategic attention.
In the UK financial services sector, the prevalence of inaccurate AI outputs points to a critical need for enhanced quality assurance and validation processes for AI-driven tools. Firms must invest in rigorous testing, ongoing monitoring, and clear escalation procedures for any AI-generated information that deviates from expected accuracy. Furthermore, fostering a culture where employees feel empowered to question and report AI errors is paramount. The high adoption rates indicate that AI is not a passing trend but a fundamental shift in how financial services operate, making the resolution of these accuracy issues a strategic imperative for maintaining trust and operational integrity.
The findings from VinciWorks regarding disability and neurodiversity training are a wake-up call for UK employers. The legal and ethical imperative to create inclusive workplaces demands a significant investment in education. Companies need to move beyond mere compliance and actively foster environments where all employees feel valued and respected. Updating whistleblowing policies to reflect new legal protections is not just a matter of compliance but a fundamental aspect of good corporate governance and employee well-being. The lack of action by a significant portion of businesses suggests a considerable gap between legal requirements and practical implementation.
In conclusion, these recent surveys collectively highlight critical areas where organizations are falling short in their compliance and governance efforts. The rapid evolution of technology like AI, coupled with increasing societal awareness and legal protections, demands a dynamic and adaptive approach. Businesses that prioritize robust governance, comprehensive training, and proactive risk management will be better positioned to navigate these complexities, mitigate potential risks, and harness the benefits of innovation and diversity in the modern workplace. The call to action is clear: organizations must move beyond passive observation and actively build the foundations for responsible and compliant operations in an increasingly complex world.
