
The failure was authorisation, not containment
Britain’s AI Security Institute let its agents onto the real internet on purpose. What broke was the authority boundary, not the sandbox.

The read
Gartner Survey Finds Audit Teams' AI Use is Common, But Most Teams are Lacking Strategic Adoption and ApplicationGartner · 11 August 2026
Gartner polled 743 audit professionals this year and found 93% report using AI in some form but only 38% have a strategy for it.
So when we dive a bit deeper, 60% use it to draft audit issues, ratings or reports, 41% use it to review drafts and 12% use it for quality assurance reviews. So the tools are used right across the stages of work being produced, and hardly used at all where the work gets QA'd.
Given the use is not on strategic use cases but mostly on moderate productivity improvements, the high adoption is not generally resulting in transformation of the process or the outcomes.
So what? Well, that is a question for every function in the organisation, not just audit. If AI is mainly helping people produce the existing work faster, has anything actually changed? The workflow is the same, the controls are the same, the decisions are the same, and the reports simply arrive sooner.
(bear in mind, this was a webinar and Gartner sells AI strategy advice to these attendees so we can treat it as directional).
The question I would sit with
Don't just ask what percentage of your people use AI, because that number is almost certainly high by now. Ask which decisions, controls, workflows and outcomes are now materially different.
Alex Collins
Co-founder & COO of RAI Digital, a consulting venture builder · Ex-EY Consulting Partner · Writing on agentic AI, venture building, logistics platforms and transformation leadership.
One honest read every fortnight on what agentic AI is doing to consulting, and what to do about it. For people moving from advice to outcomes, rebuilding a firm, or done buying decks. No hype, no fluff.

Britain’s AI Security Institute let its agents onto the real internet on purpose. What broke was the authority boundary, not the sandbox.

Across 44 countries the public has granted permission for AI in public services. The operating answers are the part still missing.

Very few organisations measured what their people were actually doing before removing them, so the value only became visible once it had gone.