Half of UK founders fed sensitive data into public AI in a month
TL;DR:
- Half of surveyed UK founders shared sensitive company information with public AI tools in the past 30 days.
- 90% of AI users worry private data entered into tools could end up training someone else’s model.
- 62% of firms with dedicated AI budgets report wasting significant time fixing broken tool integrations.
A survey of more than 400 UK founders, owners and C-suite executives, run by Startups.co.uk in partnership with Sage, finds that half have entered sensitive company information into public AI tools in the past month — and for over a quarter, it has become a weekly habit.
Informed risk, not ignorance
The notable finding is that this is not naivety. Some 90% of AI users are concerned the private information they enter could train another party’s model, and 27% report little or no trust in AI handling core business processes. Founders know the exposure and proceed anyway.
The pressure is structural. Once information enters a public model it cannot be recalled or contained, with client data potentially resurfacing in another user’s output and GDPR consequences following. Avoiding that means anonymising figures and scrubbing documents before every prompt — work 56% of respondents said takes a moderate amount of time and 23% found self-defeating. Meanwhile 83% said they feel overwhelmed by the number of options and default to whatever is available.
The alternative path is not obviously better. Firms building their own AI stacks to control data flows report a different cost: 62% of those with dedicated AI budgets say significant time goes on fixing broken connections between isolated tools.
Read alongside ONS findings that UK firms adopt AI widely but shallowly and FSB research showing 92% of small firms hold data and liability concerns, a consistent picture emerges: the governance layer is missing, not the tools.
Looking forward
The report is produced with a commercial partner, so treat the framing accordingly — the findings themselves are survey data, not independent research. The practical gap is unglamorous: most UK small firms have no written AI usage policy, and a one-page document naming what may not be pasted into a public tool would address more of this exposure than any procurement decision.