Two of this month's five free Independent AI Audits are still open — included when you start an AI health check.Check eligibility →
Technology & SaaS

The highest adoption of any sector. Developers calling models directly.

Information and communication firms lead UK adoption — engineers call model APIs straight from code, and customers now ask whether you can evidence ISO/IEC 42001.

SECTOR SNAPSHOT Technology & SaaS 58%
Technology & SaaSGenWA · sector view
58%

of UK information and communication firms use AI, the highest of any sector (ONS, 2026)

56%

of AI cost now goes to premium models, up from 6% in ten months (Ramp, 2026)

ISO 42001

now appears in enterprise procurement questionnaires (BSI/UKAS, 2026)

What your regulator has said

Accountability stays with a named person.

The ICO (2026): organisations remain responsible for their use of agentic AI, and hallucinations can cascade across tools and databases. Any product sold into the EU carries AI Act obligations, and a supplier that substantially modifies a high-risk system is treated as its provider. NCSC guidance (August 2026) asks for scoped credentials, dedicated identities, logging and a kill-switch for every agent.

Regulator statements summarised from the published guidance; see the sources on the Problems page. This supports compliance; it is not legal advice.

Where AI is already used
  • Code generation and review
  • AI features inside your own product
  • Support and success automation
  • Sales research and outbound
What goes wrong
  • API spend with no budget line
  • Customer data in product AI with no record
  • Procurement blocked on evidence you do not have
What we do

Gateway routing and metering for API spend with per-team budgets. Ledger for product AI. Change Control and sandbox testing before model switches. Compliance Mapping and ISO/IEC 42001 readiness for the sales cycle.

Built in for this sector

The rules, as controls.

  • ISO/IEC 27001 and 42001
  • UK GDPR and DUAA
  • Consumer Rights Act 2015
  • Online Safety Act (where applicable)
The first ninety days
StartSet up with your teamRegister across managed accounts and the systems this sector runs on, set up by our team with your IT lead. Nothing for your people to install.
48 hFirst findingsEvery tool, account and pound. Personal accounts named. Sector rules checked.
Day 10Report and planAudit, evidence pack outline, 90-day plan, and the cost of doing it with us.
Day 90Under controlGateway live, rules enforced, first agent on a job with a named owner, value register running.
insight.genwa.co.uk/overview
Overview · September 2026example data · 310 people
Policy breaches · 30 days143 open · 11 resolved
Data stopped before leaving128items redacted or blocked
Personal AI accounts31 → 4migrating to managed
Spend vs budget£11,240of £14,000 · saved £4,870
Issues detected · needs attention first
Issue Rule Severity Owner Status
Payroll file uploaded to an external AI tool R-15 High HR Director Blocked · reviewed
31 personal AI accounts found in Sales R-02 High Head of Sales Migrating · 27 done
Customer data in a prompt without redaction R-01 High Ops lead Redacted · 0 left
Premium model used for internal drafts · 412 requests R-07 Medium Engineering lead Rerouted
CRM "AI assist" running without a DPIA Policy Medium Head of Sales DPIA in progress
Agent attempted an external email R-12 Low S. Reid Held · approved
Questions we are asked

From this sector.

Our engineers will resist a gateway.

It is one endpoint change and it gives them model choice, budgets and a record. Most prefer it to a spend freeze.

Where does our data go?

Nowhere new. Everything runs inside your own cloud account. Nothing routes through GenWA's infrastructure. Sensitive data is removed before a request leaves your environment.

Find out where your AI stands. Then decide.

Under a minute, an upload, or a visit. Something for the board either way.