Most predictions about artificial intelligence age badly. The useful question for a UK board is not “what will AI look like in 2030?” but “which shifts are already underway, and what should we do about them in the next twelve months?” This article sets out the trends we see repeatedly in client work, and the governance response each one demands.
1. Foundation models become infrastructure, not projects
Three years ago, adopting AI meant commissioning a bespoke model. Today the default is to consume a general-purpose foundation model through an API or an existing productivity suite. The competitive advantage has moved from building models to the quality of the data, prompts, and processes wrapped around them.
What it means for you: stop scoping “an AI project” and start scoping the workflow you want to improve. Model choice is a procurement decision that should be reversible.
Governance response: maintain a model register: which models are in use, for what purpose, under whose contract, and with what data residency. Reversibility is a control, not a nice-to-have.
2. Agentic AI moves from demo to production
Autonomous agents that chain tools together (reading a mailbox, drafting a reply, updating a CRM record) are becoming genuinely usable. They are also where the risk concentrates, because an agent takes actions rather than producing suggestions a human reviews.
Governance response: define an authority boundary for every agent. What systems can it write to? What is the maximum value of a transaction it can initiate? Where is the human checkpoint? Log every action in a form that can be replayed during an audit.
3. Multimodal becomes the default interface
Text-only interaction is already the exception. Models that handle documents, images, audio, and structured data in one request remove much of the integration work that used to make AI projects expensive.
Governance response: update your data protection impact assessments. A model that can read a scanned form is processing personal data in ways your original DPIA almost certainly did not contemplate.
4. Small, specialised models close the gap
Smaller models fine-tuned on domain data now match or beat far larger general models on narrow tasks, at a fraction of the cost and with the option of on-premises or UK-hosted deployment. For organisations handling sensitive data (health, legal, safeguarding), this is the most consequential trend on this list.
Governance response: treat “can this run in a controlled environment?” as a first-class selection criterion, not an afterthought.
5. Regulation stops being optional
The UK’s sector-led approach means your regulator (the ICO, FCA, Ofqual, the Charity Commission) is the body setting expectations, not a single AI act. The EU AI Act’s obligations reach UK organisations that serve EU customers. Procurement is doing the enforcement in practice: buyers now ask for AI assurance evidence in tenders.
Governance response: build the evidence pack before you are asked for it. An AI policy, a risk register, a record of human oversight, and a DPIA covering AI processing will answer most questions you receive.
6. The workforce question shifts from replacement to redesign
The organisations getting value are not cutting headcount; they are redesigning roles so people spend more time on judgement and less on assembly. That only works when staff trust the tools, which in turn depends on transparency about how outputs are used in performance and decision-making.
Governance response: publish an internal AI use policy that states clearly what staff may use, what they must not put into a model, and how AI-assisted work is reviewed.
7. Measurement finally catches up
Early adopters could justify AI spend on curiosity. That window has closed. Boards now expect a stated baseline, a measured delta, and an honest account of the cost of running the system, including review time, licences, and governance overhead.
Governance response: define success metrics before you build. If you cannot state the baseline, you cannot claim the improvement.
What we would do in the next twelve months
- Inventory. List every AI tool already in use, including the ones nobody approved.
- Policy. One short, readable AI use policy that staff will actually follow.
- Two pilots, properly measured. One efficiency case, one quality case, both with a baseline.
- Assurance pack. Risk register, DPIA, model register, human oversight record.
- Review cadence. Quarterly, at board level, with the numbers in front of you.
None of this depends on guessing which model wins. That is the point: the organisations that will handle the next five years well are the ones whose governance is stable enough to make the technology choice a detail.
Want a view on where your organisation sits? Our AI readiness assessment gives you a structured baseline in a fortnight.

