
Outlook
Part of Reading productivity software signals with a label on each, from products to economic data
Five productivity software risks to rehearse, from leaky connectors to trapped capability
Rehearse five productivity software risk scenarios with concrete triggers, controls and recovery actions for organisations operating in England.
Risk scenarios are rehearsals, not predictions. The five cases below were prepared on 5 September 2026 for an organisation operating in England and cover the period to September 2027. No probability, loss figure or expected outcome is assigned. Their purpose is to reveal missing owners, evidence and recovery routes before a problem occurs.
What to take away
- Rehearse risk scenarios to expose missing owners, evidence and recovery routes before a real problem occurs.
- A connector with broad scopes can leak restricted data into drafts sent to the wrong group.
- Supplier changes often surface as rising exceptions rather than a full outage, so compare outputs with the last accepted baseline.
- Pilot time savings are a hypothesis until managers show effects on service, quality and workload.
- Capability trapped with one administrator or supplier leaves nobody able to safely modify or retire the system.
1. A connector exposes more data than the workflow needs
A team enables an AI assistant to summarise project updates. Its service identity can also read restricted client folders, so confidential material appears in a draft sent to the wrong group.
Connector data exposure response
- Detect broad scopes and shared credentials
- Revoke the connector immediately
- Preserve logs as evidence
- Contain further disclosure
- Involve privacy, security and legal
The National Cyber Security Centre's secure AI development guidelines cover supply-chain security, documentation, logging, monitoring and secure operation. For a customer, the warning signs are broad scopes, shared credentials and no record of the content boundary.
Preventive controls include a data inventory, least-privilege access, a test tenant and representative sensitive cases. The response plan should revoke the connector, preserve logs, contain further disclosure and involve the organisation's privacy, security and legal specialists.
2. A customer agent makes a consequential error
An agent gives incorrect contractual information or blocks a valid refund, and the customer cannot reach a person. The Competition and Markets Authority's guidance for businesses using AI agents says responsibility remains with the business even when a third party supplies the technology.
Set strict action limits, disclose automated interaction where required, test difficult cases and provide an accessible human route. Monitor complaints and overturned decisions. This scenario needs qualified consumer-law advice because the correct safeguard depends on the service and customer journey.
3. A supplier change breaks a dependable process
A provider alters an integration, model or plan condition. The workflow still runs, but creates duplicate tasks or omits a required field. The first signal is an increase in exceptions rather than a complete outage.
The NCSC framework treats operation, maintenance and update management as part of security, not an afterthought. Maintain a configuration record, release-note owner, versioned test cases and a manual continuity procedure. After a material change, compare outputs with the last accepted baseline before restoring full automation.
4. A productivity claim becomes a budget assumption
A pilot records faster task creation. Leaders multiply the saving across every employee and remove capacity before measuring rework, quality or demand effects. The Office for National Statistics' June 2026 business AI analysis reports adoption and purposes among UK businesses with 10 or more employees, not a guaranteed return from any product.
Preserve the pilot population, comparison period, denominator and exception costs. Treat released time as a hypothesis until managers can show what happened to service, quality and workload. Financial and employment consequences require specialist review.
5. Capability is trapped with one person or supplier
One administrator understands the automations, credentials and export process. When that person leaves or the contract changes, nobody can safely modify or retire the system.
Skills England's employer guide to AI upskilling favours practical, integrated and sustainable learning. Government guidance on managing technical lock-in is written for public-sector cloud buyers, so it is not a private-sector rule, but its attention to exit planning and portability is a useful due-diligence prompt.
Use named deputies, runbooks, controlled credential transfer and periodic export tests. At renewal, check data format, deletion, support and transition time rather than waiting for an urgent exit.
Run the rehearsal
Select the two cases closest to the proposed workflow. Ask who detects the event, who may stop the system, which evidence must be preserved, how work continues and who decides recovery is safe. Record unresolved questions with dates and owners.
A scenario has done its job when it changes a control, contract question or operating procedure. If the exercise produces only a risk score, it has not yet shown that the organisation can respond.
Before you act
- Map the data inventory and apply least-privilege access.
- Set strict action limits and provide an accessible human route.
- Keep a configuration record and versioned test cases.
- Preserve the pilot population, comparison period and denominator.
- Name deputies and test credential transfer and exports.
- Record unresolved questions with dates and owners.
Common questions
What warning signs suggest an AI connector has too much access?
The article points to broad scopes, shared credentials and no record of the content boundary. Preventive controls include a data inventory, least-privilege access, a test tenant and representative sensitive cases. If disclosure occurs, revoke the connector, preserve logs, contain further disclosure and involve privacy, security and legal specialists.
Who is responsible when a third party supplies an AI customer agent?
Responsibility remains with the business even when a third party supplies the technology, according to the Competition and Markets Authority guidance cited in the article. Safeguards include strict action limits, disclosure of automated interaction where required, testing difficult cases and an accessible human route. Qualified consumer-law advice is needed because the correct safeguard depends on the service and customer journey.
How should leaders treat productivity gains recorded in a pilot?
Treat released time as a hypothesis until managers can show what happened to service, quality and workload. Preserve the pilot population, comparison period, denominator and exception costs. The Office for National Statistics analysis reports adoption and purposes among UK businesses, not a guaranteed return from any product. Financial and employment consequences require specialist review.



