Research · run 4 September 2026
The UK AI Disclosure Audit 2026
A governance claim is worth only what its evidence will bear. That is the test this audit applies to artificial intelligence: not what an organisation does, but what its published documents show. We read the most recent published annual report, governance statement or trustees’ report of 150 large UK organisations across five sectors, and scored what those documents say about AI against a ten-point rubric.
So AI has arrived in the language of UK governance reporting and has not yet arrived in its accountability structures. Boards are talking about it. Almost none of the documents we read say who owns it.
What we found
Three numbers carry the study
Of the 147 organisations we were able to score, for documents with a period end on or after 31 December 2024.
01
What we did
We built a defined population of 150 large UK organisations, 30 each from charities, education, healthcare, housing associations and local authorities, and for each one fetched the most recent published annual report, governance statement or trustees’ report with a period end on or after 31 December 2024. Two independent coders using the same ten-indicator rubric scored a sample of the population blind, so we could measure how repeatable the scoring is. Every non-zero score is backed by a verbatim quote from the document. The summary scores are published below with organisations anonymised, and the named evidence table with every quote and source URL is available to journalists and researchers on request. Where an indicator is not scored we say the evidence was not found in the documents we read, which is a statement about the documents, not about the organisation.
02
The ten indicators
Percentages below are of the 147 organisations scored, for documents with a period end on or after 31 December 2024.
I01 · AI named at all
66.7 per cent of 147 name AI somewhere in the document.
I02 · AI as a principal or strategic risk
7.5 per cent of 147 record a standalone AI risk with mitigation; a further 17.7 per cent mention AI inside another risk, usually cyber or data.
I03 · Board-level owner or committee
1.4 per cent of 147 name an individual owner; a further 9.5 per cent give a committee a remit that names AI.
I04 · AI or acceptable-use policy
1.4 per cent of 147 point to a policy we could fetch and read; a further 12.9 per cent reference a policy as existing.
I05 · AI in internal audit or assurance
1.4 per cent of 147, that is 2 organisations, record AI in an audit plan, audit committee report or assurance map.
I06 · Staff training or capability
11.6 per cent of 147 describe training, skills or literacy work that names AI.
I07 · Data protection tied to AI
6.8 per cent of 147 link AI to a DPIA, UK GDPR, automated decision-making or ICO guidance.
I08 · Disclosed AI use cases
36.7 per cent of 147 name a specific system or use case; a further 16.3 per cent describe AI use only in general terms.
I09 · Framework or standard referenced
9.5 per cent of 147 cite a standard, sector framework or their own published AI principles.
I10 · AI on a board or committee agenda
10 of the 147, which is 6.8 per cent, show AI as an item in public board or committee papers. The indicator is not applicable to 74 of the 147, which is 50.3 per cent, because no public minutes were found in the documents we read. Read against the 73 organisations where minutes were found, the figure is 10 of 73, which is 13.7 per cent. Both bases are given wherever this indicator appears.
The shape is consistent. Disclosure is strongest where AI is a story to tell and weakest where it is a control to evidence. More than a third of the 147 name a system they use. Two of the 147, which is 1.4 per cent, record AI in an internal audit or assurance document.
03
By sector
All figures are of the organisations scored in that sector, for documents with a period end on or after 31 December 2024.
| Sector | Scored | AI named (I01) | Standalone AI risk (I02 at 2) | Named AI owner (I03 at 2) | Financial year mostly |
|---|---|---|---|---|---|
| Charities | 30 of 30 | 66.7% | 6.7% | 0% | 2025 |
| Education | 29 of 30 | 100% | 17.2% | 3.4% | 2025 |
| Healthcare | 28 of 30 | 71.4% | 0% | 0% | 2025 |
| Housing associations | 30 of 30 | 56.7% | 6.7% | 0% | 2025 |
| Local authorities | 30 of 30 | 40% | 6.7% | 3.3% | 2025 |
We name good practice on one published rule: an organisation is an exemplar if it is in the top five by total score in its sector and its documents also name a board-level owner of AI, which is I03 at level 2. Two organisations meet it: East Sussex County Council (total 13 of a possible 14) and the University of Bristol (total 9). They are the only two organisations in the 147 scoring I03 at level 2. The University of Exeter ties Bristol on total, also 9, but no named AI owner was found in its documents, so it does not meet the second half of the rule. Organisations are named here only as good practice.
04
What this means for boards
Education
Every one of the 29 universities we scored names AI, and 17.2 per cent of those 29 record a standalone AI risk with mitigation. That is the strongest position in the study, and it still leaves most of the sector describing AI without a risk entry a regulator could test. The gap is not awareness. It is the paper trail.
What the audit found in educationHealthcare
Of the 28 trusts we scored, 71.4 per cent name AI, and a standalone principal risk for AI with its own mitigation was not found in the documents we read for any of the 28. Fifteen of the 28, which is 53.6 per cent, name a specific AI system or use case. So these documents describe AI in use far more often than they evidence a control over it: 53.6 per cent against nil on standalone risk.
What the audit found in healthcareLocal authorities
Of the 30 councils we scored, 40 per cent name AI. That is the lowest of the five sectors: education 100 per cent of 29, healthcare 71.4 per cent of 28, charities 66.7 per cent of 30, housing associations 56.7 per cent of 30. Read that rate with care. Blind double coding covered four councils and the two coders disagreed on three of them, in the same direction, with the second coder finding AI mentions the first did not, so the council figure is the least reliable of the five. On data protection, 20 per cent of the 30 councils tie AI to a DPIA, UK GDPR or ICO language, the highest of the five sectors: housing associations 6.7 per cent of 30, healthcare 3.6 per cent of 28, education 3.4 per cent of 29, charities nil of 30. The annual governance statement is the natural place to record both.
What the audit found in local authoritiesHousing associations
Of the 30 we scored, 56.7 per cent name AI and 23.3 per cent name a specific system or use case. An individual owner of AI was not found in the documents we read for any of the 30. Where AI touches repairs triage, arrears or allocations, the published record does not show who is accountable for those decisions.
What the audit found in housing associationsCharities
Of the 30 charities we scored, 66.7 per cent name AI and 43.3 per cent name a specific use case, against 6.7 per cent that record a standalone AI risk with a mitigation and nil that name an individual owner. The use cases are written up; the risk, the owner and the policy mostly are not. One paragraph in the trustees' report naming all three would move a charity to the top of this table.
What the audit found in charities05
Limitations
- 1.
Coverage
We set out to score 150 organisations and scored 147. Three documents could not be fetched. For two of the three the host blocked automated retrieval. For the third, Frimley Health NHS Foundation Trust, no 2024/25 annual report was located by any of the routes we tried. Those 3 are counted as unreachable, not as non-disclosing. The three losses fall in education (1) and healthcare (2).
- 2.
The window
Every primary document scored has a period end on or after 31 December 2024. Two universities carry a secondary minutes document dated November 2024, which is before the window; neither contributed a score. Eight of the 150 organisations, all December year-end charities, are represented by accounts ending 31 December 2024 because that was the most recent set filed. No organisation in the final 147 falls outside the window.
- 3.
Repeatability
Eighteen of the 150 organisations were coded twice, blind. Seventeen pairs were comparable, because one organisation came back unreachable on the second pass, giving 170 indicator comparisons. The two coders agreed exactly on 147 of those 170, which is 86.5 per cent. Agreement was highest on I04, I05 and I09 at 94.1 per cent of 17 each, and lowest on I07 and I10 at 76.5 per cent of 17 each. Treat single-indicator differences of a few percentage points as noise; treat the headline gaps, which are far larger, as real.
- 4.
What “not found” means
Every zero in this study means the evidence was not found in the documents we read. It does not mean the organisation lacks the policy, the owner or the training. Many will have all three and simply have not written them into the published record. That is the point of the study: governance that is not disclosed cannot be relied on by anyone outside the organisation.
Methodology
How this audit was run
Every score rests on a fetched document, a section and a quote. Run date 4 September 2026. The two CSVs below carry the per-organisation detail this section summarises.
Population and registers
The 30 largest organisations in each of five sectors, 150 in all, drawn from registers downloaded on 3 September 2026: the Regulator of Social Housing providers list, the Charity Commission register of charities, ONS names and codes with mid-2024 population estimates, the Office for Students register, and the NHS England provider directory.
Size bands: homes owned (20k to 50k, 50k+); charity income (500k to 1m, 1m+, 500m+); population (1m+); university income (100m to 500m, 500m to 1bn, 1bn+); NHS revenue (300m to 500m, 500m to 1bn, 1bn to 1.5bn, 1.5bn+).
Documents and date window
We read the latest annual report and accounts, trustees' report or annual governance statement, plus published AI policies and public board papers where reachable: 173 documents, 172 PDFs and 1 HTML page. A qualifying document has a period end on or after 31 December 2024 and was published before 4 September 2026. The year-end mix of the 150 is 8 in 2024, 127 in 2025, 14 in 2026 and 1 unknown.
A first pass used a window of 31 March 2025; a retry pass widened it to 31 December 2024 for December year-end bodies whose latest filed accounts were otherwise excluded. Blocked documents were retried via archive copies.
The ten indicators, as scored
I01 AI named at all: any occurrence of “artificial intelligence”, “AI” used as the technology, “machine learning”, “generative AI”, “large language model”, or a named product in the primary document. Scored 0 or 1.
I02 AI as a principal or strategic risk: 0 not found; 1 AI mentioned inside another risk; 2 a standalone AI risk with a stated mitigation. I03 board-level owner or committee: 0 not found; 1 a committee remit or report names AI; 2 a named director, non-executive or executive is stated to own AI. I04 AI or acceptable-use policy: 0 not found; 1 referenced as existing; 2 published and fetched.
I05 AI in internal audit or assurance, I06 staff training or capability, I07 data protection tied to AI, and I09 framework or standard referenced are each scored 0 or 1. I08 disclosed AI use cases: 0 not found; 1 generic; 2 a named system or specific use case.
I10 AI on a board or committee agenda in the period: 0 or 1, and “n/a” where no public minutes were found in the documents we read. Across the 147 this splits 10 scored 1, 63 scored 0 and 74 n/a, so the informative base is 73. Every use of I10 gives both bases, 10 of 147 and 10 of 73, and carries the caveat that it is the weakest indicator.
Any non-zero score carries a document URL, a section heading and a verbatim quote of at most 300 characters. The named evidence table is available on request; the published summary CSV is anonymised to sector and size band except the two exemplars.
Fetch, status and double coding
Documents were fetched with a browser user agent, retried once on a 403, then via archive copies and an HTTP/1.1 route; text was extracted and read in context. Of the 150, 147 were scored and 3 are unreachable; none ended as no document found or out of window. Only the 147 enter a percentage.
Eighteen of the 150 were scored again by a separate coder that did not see the first scores. One came back unreachable on the second pass, so 17 pairs were comparable, giving 170 indicator comparisons, of which the coders matched exactly 147 times, 86.5 per cent. By indicator, each out of the same 17 pairs: I01 88.2, I02 82.4, I03 88.2, I04 94.1, I05 94.1, I06 88.2, I07 76.5, I08 82.4, I09 94.1, I10 76.5. Four local authorities were double-coded and the coders disagreed on three of them, in the same direction, so the local-authority figures are the least reliable of the five sectors.
Naming, evidence and corrections
We publish by sector and size band, and name organisations only as good-practice exemplars, with a quote and a URL. None is named as a laggard, because “not found” is a statement about the documents we read, not about the organisation.
The scoring coders logged 86 rubric problems across two runs. The main ones: I02, combined cyber and AI headings and standalone risks without a mitigation fit no band, so the closest band was used; I07, there is no threshold for how explicit the link from AI to data protection has to be; I10, board papers are not keyword-searchable within the fetch budget, so a zero means no AI item was found in what we read, and should be treated as unverified; and the window admits documents a year apart, so old and new reports are not fully comparable.
Spotted an error in a score or a quote? Tell us at hamada@governanceai.io and we will check it against the source document.
06
How to cite this study
Governance AI, The UK AI Disclosure Audit 2026, edition 2026, run date 4 September 2026. Population: 150 large UK organisations across five sectors; 147 scored; documents with a period end on or after 31 December 2024. Full per-organisation scores and verbatim evidence quotes are published in the accompanying evidence table.
Downloads
The underlying data
Plain CSV, free to reuse with attribution to Governance AI.
- Download the summary scores (CSV)
One row per organisation, anonymised to sector and size band except the two exemplars: status, period end, total score and the ten indicator scores I01 to I10.
The named evidence table
One row per evidence item with the organisation, document URL, location and verbatim quote. Not published, so no organisation is listed as a laggard; available to journalists and researchers on request.
Reading the audit alongside our wider desk research? See The State of AI Governance in UK Organisations 2026.
Would your annual report pass this audit?
The ten indicators are the questions an outsider can check. Score your own board on oversight in about two minutes, or talk to us about an independent AI governance diagnostic.
Free · no sign-up to see your score.