Skip to content
Start with an audit 

What seven UK AI audits kept finding

Seven AI audits, and the same findings kept surfacing: ungoverned personal AI, the ask to search the firm's own documents, and data deciding the route.

Ibrahim Mizi Ibrahim Mizi  · 6 min read
Seven drawn core samples standing in a row, with one seam marked at the same depth in each

OpenKit has now run seven AI audits, for organisations with very little in common: a luxury interiors brand, a programme management consultancy, a commercial design and build business, a healthcare diagnostics body, an international oil and gas service provider, a London estate agency, and a UK-listed lighting manufacturer. The smallest has around twenty staff and the largest is an enterprise division. Seven sectors should produce seven different sets of findings. Mostly, we kept writing the same ones, and this article is the countable version of what repeated.

Published 17 August 2026.

A note on the numbers before we start. Where a client is named, the figure is already public in our portfolio. Where a client is not named, the figure comes from the engagement’s own records and the client stays anonymous. Every claim is stated as “X of the seven”, counted, never averaged or extrapolated.

Someone is already paying for AI on a personal card

In all three of the audits we have documented in full, ungoverned AI use predated our arrival. At one brand we counted five to six individual ChatGPT subscriptions bought on company cards, used on customer, supplier and financial data, with nothing managing them centrally. At a consultancy, the firm’s most advanced AI practice was running on personal paid accounts, while colleagues who wanted to adopt were holding back because no sanctioned route existed. At a design and build business we documented six separate instances of shadow AI across four interview sessions.

This finding is commercial as much as it is a governance problem. The subscriptions people have already bought are the first saving the audit identifies, and consolidating them onto a managed tier typically funds a good part of doing it properly. The risk side is real too, since the data going into those personal accounts was rarely data anyone had agreed could leave the building.

People ask to search their own documents before anyone suggests it

We walk into every audit expecting to hear about content generation. What we actually hear about first, in all three of the fully documented engagements, is retrieval. At the consultancy, five of the ten people we interviewed independently raised the same request, unprompted: let me ask a question in plain English and have it answered from our own documents. At the design and build business the request surfaced in every single interview session. At the brand it appeared as a workaround everyone had normalised, downloading files, manipulating them by hand, and emailing the results around.

The reason this matters for anyone planning an AI programme is that it inverts the usual buying order. The tools people are sold are generators. The thing their staff are asking for is search, and search over your own estate is mostly a data problem before it is an AI problem.

Where the data lives decides the recommendation

In at least four of the seven audits, data sovereignty or data readiness shaped the core recommendation. EMQN, a healthcare diagnostics body handling assessment data across borders, needed sovereign EU hosting, and we analysed seven European hosting providers before recommending an architecture. Thorlux required UK-region processing for its building occupancy data. An international oil and gas service provider went fully on premises, because pipeline integrity data could not leave its estate. And at the consultancy, the honest recommendation was that a document migration had to come before any AI at all, since the firm’s knowledge sat on an inconsistently filed server AI could not reach. One live programme folder alone held roughly 129 gigabytes across some 45,000 files.

If you take one planning lesson from the seven, take this one. Where your data lives, and what state it is in, will decide more of your AI roadmap than any model choice.

Every audit produced a counted number

All seven audits put a figure on what the work costs today, measured from the client’s own operation rather than from an industry benchmark. Stow Brothers’ admin came to 172 hours a month, of which around 50 were reclaimable in the first pilot. Thorlux’s proof of concept validated roughly 6.5 million occupancy records against the live dashboard and benchmarked seven language models for the reporting job. At EMQN the tested marking accuracy came out at 93 to 96 percent per criterion, with more than 200 assessor hours a year projected back. At House of Hackney, 20 hours a week of finance reconciliation is now automated.

The anonymous engagements counted just as concretely. One firm was sending 41 sales invoices a month as 41 individually written emails. In a live session, an analysis one interviewee put at three hours by hand came back in about five minutes. At another firm, a contract extraction that takes six hours was demonstrated in twenty to thirty minutes including verification. Single instances, counted on site, never averaged into a headline.

The report says no as well as yes

In at least two of the seven audits, the deliverable included a written list of workflows where we advised against using AI, one of those lists eight items long. Both lists were specific, tied to accountability or to data that should not move, rather than a general caution. And in at least two of the seven, the recommendation was gated behind a pilot with an explicit go or no-go decision before anything scaled, including a two-stage pilot inside the oil and gas engagement.

That discipline is what makes the rest of a report worth acting on. A document that only says yes is a brochure.

What this means if you are weighing an audit

The pattern across seven engagements is that the valuable findings were rarely the ones anyone predicted. Clients expected a conversation about tools, and got a counted case built from their own invoices, folders and interview transcripts, plus a shorter list than they expected of things worth doing first. If you want to see how we get to those findings, what an AI audit actually looks like walks through the method, and the AI Audit and Transformation page lays out the engagement that carries an audit through to the first working rollout.

Ibrahim Mizi

Ibrahim Mizi

Co-founder & CEO · Full-Stack AI Engineer · OpenKit

Co-founded OpenKit in 2020 and runs the consultancy side end to end. Eight years of full-stack development, then production AI for SMEs and the public sector.

What do AI audits most often find?

Across the seven audits OpenKit has run, three findings repeat: staff already paying for AI on personal accounts before any rule exists, an unprompted ask for plain-English search over the firm's own documents, and the location and condition of the data deciding what gets recommended. In every one of the seven, the audit also produced a counted number for what the work costs today, measured from the client's own operation.

How long does an AI audit take?

A standard OpenKit audit runs three to four weeks. Across the seven engagements behind this post the range was two to eight weeks, because scope varies: a two-week workflow mapping for an estate agency sits at one end and an eight-week audit inside an enterprise engineering workflow at the other.

Do AI audits ever recommend against using AI?

Yes, in writing. In at least two of the seven audits the deliverable included an explicit list of workflows where we advised not to use AI, one of them eight items long. A recommendation you can defend has to say no somewhere, and clients tell us that list is among the most useful pages in the report.

Where do the numbers in this article come from?

Every figure attached to a named client is already published in that client's case study in the OpenKit portfolio. The remaining figures come from audit engagements whose clients are anonymised, and each one was verified against the engagement's own records before publication. Nothing here is an industry benchmark or an extrapolation.

Take the question to an audit.

If this raised a question about your own operation, the AI Audit and Transformation is where we answer it. It runs three to four weeks, and your first automation is live before it ends. You leave with a written report your board can read in one sitting alongside a prioritised 12 month roadmap. Your fee is fixed and agreed before anything starts.

Find your first workflow.

We start with a conversation, audit where AI actually pays back, and build the first automation into how your team already works. We reply within one working day.