Three in four UK businesses (75%) are concerned about the cyber risks arising from their vendors and suppliers using Artificial Intelligence (AI), yet only 28% of AI-using businesses have taken steps to assess or audit their third-party suppliers’ AI systems, new research from business insurer QBE reveals.
Using AI is now standard practice for UK businesses, with 97% already using it or looking into it, up from 95% last year. Despite this, only 35% of AI-using businesses have a formal AI usage or governance policy.
QBE warns the growing gap between AI adoption and risk management means businesses could be exposed through their supply chains at a time where cyber threats are accelerating.
Both the number of UK businesses experiencing cyber events, and the number linking those to supply chain, are increasing.
The share of UK businesses that experienced a cyber event in the last 12 months rose from 53% in 2025 to 59% in 2026. Among those affected, 59% reported supplier-related events (up from 56%), with 22% saying that all or most of the attacks they suffered involved a supplier.
“AI is now commonplace for UK businesses. While this brings commercial benefits, it also increases cyber risks, especially across supply chains,” David Warr, Portfolio Manager – Cyber, QBE Europe, said.
“Our research reveals that three in four businesses recognise this risk, but only a small proportion are checking how their suppliers are using AI. This widening gap is concerning. Even with robust internal controls, an organisation could be exposed to attack through a third party with weaker defences.
“As AI adoption accelerates, businesses need to address this emerging risk. Auditing the supply chain is now a key responsibility of cyber risk management.”
Recommended reading
- Less Than A Quarter of Supply Chain Leaders Have An AI Strategy
- What Are the Top Supply Chain Tech Trends for 2025?
- Tech Integration and Talent Major Roadblocks to Scaling AI Supply Chain
- Report: Cybersecurity Tops Tariffs as Q1 Priority for Supply Chains
The financial consequences and business interruption are also worsening year-on-year. Among businesses that experienced a cyber event, the proportion suffering revenue loss rose from 50% in 2025 to 59% in 2026. Of all UK businesses, 22% experienced a cyber event that caused a disruption of more than one working day, up from 16% in 2025.
Concern about cyber threats remains high, with 82% of UK businesses saying they are concerned about the threats they may face over the next 12 months. A new type of risk seems to be emerging, with 23% of UK businesses experiencing a cyber incident which they believe leveraged AI. The most commonly reported methods included phishing (49%), malware (46%) and Business Email Compromise (42%).
UK businesses are responding to the changing cyber risk landscape with increased investment. Indeed, 79% expect their IT cybersecurity budget to increase over the next 12 months (up from 74% in 2025), with 32% planning increases beyond the rate of inflation.





