Data ProtectionDigital TransformationIAM
Most UK retailers hit by AI security incidents, survey finds
Mon, 24th Aug 2026 (Today)
MARK TARRENews Chief
Most large UK retailers have experienced an AI-related security incident in the past year citing a survey of 200 senior cyber and information security leaders
Nearly 60% of respondents said their organisation had suffered an AI-related security incident with real-world impact in the previous 12 months. The study covered retailers with annual turnover of at least GBP £250 million and workforces of 500 or more.
The findings suggest security teams are struggling to keep pace with the spread of AI tools across retail operations. Almost all respondents, or 99%, said they were under pressure to adopt AI faster than governance and risk processes could keep up, while 48% said that pace was already creating gaps.
Retailers also reported weak oversight of how AI tools enter the business. RiverSafe found that 88% do not put every AI use case through a documented security review before it goes live, and respondents estimated they were running about 10 AI tools on average without formal security approval.
Access control is another concern. Just over half of respondents, or 52%, said they had full control over what their AI agents and tools could access without human sign-off.
The survey points to continuing concern over supplier and third-party exposure. Around 40% of respondents said they had not fully adapted their supplier risk processes to account for AI, even as AI tools are being connected to pricing systems, checkout functions and customer data.
That matters in a sector where supplier relationships and software integrations are deeply embedded in day-to-day operations. AI systems introduced through external vendors can create another route into core retail infrastructure if governance checks do not keep pace.
The findings also suggest many security teams expect unauthorised AI adoption to continue. Every respondent acknowledged that their organisation would be running AI tools without security approval.
Even so, the survey did not present a wholly pessimistic view of the risks. RiverSafe found that 93% of respondents believe AI-related security risk can be reduced to an acceptable level with the right governance in place.
The issue is not simply whether retailers use AI, but whether internal controls can keep up with deployment across business functions. That tension appears strongest where operational demands are immediate and security reviews take longer.
Oseloka Obiora, Chief Technology Officer at RiverSafe, said: “AI is being wired into pricing, checkout and customer data faster than teams can secure it, and most retailers have already had an incident. AI agents especially can carry real identity and access rights, often reaching further into the business than anyone intended, and that exposure is easy to underestimate when things are moving this fast. The teams handling it well are getting a grip on what each agent can reach and what it can do before it reaches the systems the business runs on.”
The results reflect a wider management challenge around AI adoption in large organisations. Security leaders appear to be under pressure from boards and operating teams to roll out AI tools quickly, even where formal review and approval processes are incomplete.
One senior retail security leader described that pressure in remarks from a RiverSafe roundtable discussion.
The security leader said: “The board wants AI everywhere, yesterday. We find out it’s live when it’s already live. The job now is putting a front door on something that’s already in the building.”
The research was conducted by Censuswide among senior cyber and information security leaders at UK retailers. Respondents were drawn from businesses with at least 500 employees and turnover of GBP £250 million or more.
The data adds to evidence that AI governance is becoming a more immediate operational issue for retailers rather than a longer-term policy concern. In this survey, the gap between adoption and oversight appeared in incident rates, supplier checks, access controls and the number of tools introduced without formal approval.
ChatGPT
Key takeawaysExplain why it mattersCreate action planFuture watch
Claude
Key takeawaysExplain why it mattersCreate action planFuture watch
Perplexity
Key takeawaysExplain why it mattersCreate action planFuture watch
Grok
Key takeawaysExplain why it mattersCreate action planFuture watchShareShareAdd us as a preferred source on Google
Image: Oseloka Obiora
Related stories
TalkTalk Business warns SMEs on AI agent access risksCyera launches tools to secure enterprise AI agentsBedrock Data launches AI agent data loss preventionAI leaders stress governance & trust as adoption growsAI trust & governance seen as key to safe adoption
Top stories
Tes launches cloud-based school timetabling software8x8 adds Krisp voice AI tools to contact centre suiteGoogle buys Spirit data for AI training, say executivesClearPath AI launches in Birmingham with GBP £1 millionCoupa launches largest AI release for procurement teams
