Skip to content

Agentic AI assessment and adoption

We start from the tasks, set how far AI may act on each, test the strongest candidate on your own past cases, and write down what happens when it gets something wrong, before anything is switched on.

Request an agentic AI assessment
Consulting

How far AI may act is a decision, not a feature.

What we do

Decide which work AI should do, how far it may act, and what happens when it is wrong.

If a supplier is offering an agent that can update records or send replies on its own, if staff already paste client emails or case notes into chatbots on personal accounts, or if your board has asked for an AI plan by a fixed date, the tool is being chosen before anyone has listed the work it is meant to do, decided how far it may act, or named who checks what it produces.

We start from the tasks. We list a team's work with its volume and the judgement each task needs, rank where AI could change the cost or quality of that work, and set the level of autonomy and the rules for each use before a tool is chosen.

We test the strongest candidate on a sample of your own past cases, and write down how an error would be caught, who would put it right and when the agent would be switched off.

We also build software, including AI features, so wherever a recommendation could lead to work for us, the report says so and names the other routes. The recommendation may be to use a product you already license, to buy one, or to change nothing.

AI use in UK businesses, from official statistics

35%
of UK businesses with 10 or more employees reported using at least one AI technology in June 2026, just under three times the share in September 2023, when it was around 12%.Office for National Statistics, Artificial intelligence in UK businesses: 2023 to 2026 (Business Insights and Conditions Survey, Wave 159), 20 July 2026
10%
of businesses with 10 or more employees that use AI reported using it extensively, in June 2026. The question is new, and the ONS reads the result as an early indication.Office for National Statistics, Artificial intelligence in UK businesses: 2023 to 2026 (Business Insights and Conditions Survey, Wave 159), 20 July 2026
24%
of businesses using AI, adopting it or actively considering it had cyber security practices or processes to manage the risks from that use. That group was 31% of all businesses.Department for Science, Innovation and Technology and the Home Office, Cyber security breaches survey 2025/2026, 30 April 2026

The ONS figures come from the Business Insights and Conditions Survey, which the ONS publishes as official statistics in development. They cover businesses with 10 or more employees and exclude some industries, including public administration and defence, finance and insurance, and public provision of education and health. The ONS counts a business as using AI if it reports any technology on its list, which treats light and embedded use alike, and says its new question on extent of use should be read as an early indication. The DSIT and Home Office survey is self-reported, with fieldwork from August to December 2025, and asked about AI for the first time in 2025/2026. It covers businesses of all sizes except sole traders and those with no IT capacity or online presence, so its figures do not compare directly with the ONS figures. Figures retrieved 19 September 2026.

From ranking the tasks to governing the pilot

Take any one on its own, or run them in order: rank the tasks, check the ground they sit on, then pilot and govern the uses that survive.

Two colleagues at a shared office desk. One points to a line in an open notebook while the other reads along.
Illustrative photography. The work is shaped around your organisation.
Agentic AI assessment

List a team's tasks with their volume and the judgement each needs, then rank where AI could change the cost or quality of the work, how far it could act on each task, and where it should not be used. Show the method and sample behind every estimate, and keep the ruled-out list beside the shortlist.

  • A task inventory by team: volume, time taken, judgement needed and the cost of an error
  • Scores for suitability, value, risk and the effort to adopt
  • The autonomy level each shortlisted task would run at
  • A ranked shortlist, with the method and sample behind each estimate
  • A ruled-out list, with the reason for each
Workplace AI assistant readiness

Check who can open what across your shared drives, team sites and chat channels before switching on an assistant that searches them, such as Microsoft 365 Copilot or Gemini in Google Workspace, because it can show each user anything that user can already open. Decide which roles should have it switched on, and which need a paid licence.

  • A sharing report for sites, folders and links open to everyone or to anyone with the link
  • Guest and external user access reviewed
  • A clean-up list ranked by what each overshared location holds
  • Labelling and retention settings checked against your data classes
  • An access and licence plan by role, starting with a trial group and the measures to read after it
Shadow AI review

Find the AI tools staff already use, on which accounts and with what data, and decide which to approve, replace or stop. Move client and case work off personal logins and onto accounts your organisation controls.

  • A staff survey on the tools, accounts and tasks each is used for
  • Third-party app consents (OAuth grants) that give AI tools access to mail, files or calendars
  • Sign-ins and browser extensions, where your identity and device management systems record them
  • A register of tools in use, with the data class each has touched
  • An approved-tool list, with the business-account route for each
AI supplier due diligence

Put the same questions to every AI vendor before anyone signs: data retention, use of your data for training, sub-processors, processing location and exit terms. File the answers with the contract, and leave the legal terms with your advisers.

  • Processor terms under UK GDPR Article 28, and the sub-processor list
  • Retention periods and training use for prompts and files, by account type
  • Processing location, and the basis for any transfer outside the UK
  • Security evidence set against the Software Security Code of Practice and the OWASP Top 10 for LLM Applications
  • Exit terms: export format, confirmation of deletion, and notice before a model or feature is withdrawn
AI pilot design and failure plan

Fix the baseline, success measures, sample, duration and stop conditions before a pilot starts, and write down what happens when the agent gets something wrong. Test on your own past cases, and hand the result to the people who decide.

  • A baseline measured on current work before the tool arrives
  • Success and failure measures, including an error rate checked by a named reviewer
  • A test set drawn from your own past cases, with personal data removed where the test allows
  • Stop conditions and a fixed end date, written down before the first day
  • A failure plan: how an error is caught, who corrects the record and tells the person affected, how an action is undone, and who can pause or switch off the agent
  • A results template for the decision at the end: stop, change or extend
AI use policy and governance

Write the acceptable-use policy, data rules and approval route that let a team start, referenced to the ICO's Guidance on AI and data protection and to your regulator's published guidance. Your advisers sign off the legal position.

  • An acceptable-use policy with red, amber and green data classes for prompts and uploads
  • DPIA screening for each shortlisted use of personal data (UK GDPR Article 35)
  • An approval route for new tools, and a record of tool, version, reviewer and date
  • Sector references where they apply: the SRA's warning notice on misuse of AI, the CQC's principles for AI in health and social care
  • For public bodies, the AI Playbook for the UK Government and the Algorithmic Transparency Recording Standard; where the EU AI Act applies to your use, its Article 4 duty to take measures supporting staff AI literacy, as rewritten in July 2026
Download the professional services guide (PDF, 13 pages)

What you get

What is agreed before anything is switched on

  1. Your team's tasks are ranked by where AI could change cost or quality, each task on the shortlist has a level of autonomy, and the ruled-out list carries a reason for each.
  2. Move client and case work off personal logins and onto accounts your organisation controls, under data rules staff can follow.
  3. Each pilot ends in a decision, measured against a baseline and stop conditions set before it began, with a written plan for when the agent is wrong.

The levels

Four levels of autonomy

Set how far a tool may act before choosing the tool. Each level carries the governance of the levels below it, and adds its own. The assessment names a level for every shortlisted task.

  1. 1

    1. Suggest

    The tool proposes, and a person decides and does the work: a suggested category on an incoming request, or a passage found in a policy library.

    Needs an approved tool on a business account, data rules for prompts and uploads, and a periodic check of suggestions against what people decided. We build at this level.

  2. 2

    2. Draft for approval

    The tool prepares a reply, a case note or a summary, and nothing leaves until a named person approves it.

    Adds drafts marked as drafts, a record of tool, version, reviewer and date, and a log of the edits made before approval. We build at this level.

  3. 3

    3. Act with approval

    The tool prepares an action in another system, such as raising an order or updating a record, and carries it out only after a person confirms it.

    Adds permissions limited to that one action, an audit log, a test set from past cases run before launch and after every model or prompt change, and a DPIA where personal data is involved. We build at this level for bounded actions.

  4. 4

    4. Act and report

    The tool acts within set limits and reports afterwards. Keep it to actions that are low in consequence and can be reversed.

    Adds limits on value and scope, monitoring with a stop condition, a sampled human review, and, for significant decisions about people taken without meaningful human involvement, the safeguards in UK GDPR Articles 22A to 22D, inserted by the Data (Use and Access) Act 2025 and in force since 5 February 2026. We assess this level, and decide case by case, with your advisers, whether to build it.

The four levels are our working scale, not a published standard. Your advisers sign off the legal position at each level.

How it runs

From task list to decision

  1. 01

    Inventory the work

    List each team's tasks with their volume, time and the judgement each needs, from interviews with the people doing the work, counts from your systems and a sample of recent cases.

  2. 02

    Score and rank

    Score each task for suitability, value, risk and the effort to adopt, and set the autonomy level it would run at. Record what was ruled out, and why.

  3. 03

    Check the ground

    Check the data, permissions, accounts and contracts each shortlisted use depends on, including the AI tools staff already use.

  4. 04

    Test the strongest candidate

    Run a bounded test on a sample of your own past cases, against a baseline and stop conditions fixed in advance.

  5. 05

    Hand over the plan

    Deliver the ranked shortlist, a verdict to build, buy or stop for each use, the failure plan, the policy and approval route, and a phased plan with its measures, marked where your advisers need to sign off. If the verdict is to build, our development team can quote for it, or you can take the plan to another supplier.

Read and try

Read the research. Open the demo.

Cover of the BespokeWorks publication

Insight report

What an answer costs

Its section 'What this means for a business' sets out two decisions this page turns on: routing routine work to the smallest model that does the job, and keeping client work on business accounts, not personal logins.

Format
PDF, 17 pages
Published
September 2026
Read 'What an answer costs' (PDF, 17 pages)
Knowledge Desk ask view showing a question about homeworking costs answered with two quoted clauses from different documents, a notice that they disagree, and the match strength for each clause

Working demo, on sample data

  • A policy question answered by quoting the matching clause and naming its document, from fictional sample policies, using scripted keyword matching and no language model.
  • A plain 'not covered' answer when the library is silent, and a notice when two documents disagree.
  • Unanswered and challenged questions queued for a suggested document owner, with the outcome recorded and no one notified.
Open the Knowledge Desk demo

Worth asking first

  • Which actions would an agent take in your systems, and which should always wait for a person?
  • Which tasks in each team are high in volume and low in judgement?
  • Where would a confident wrong answer reach a client, a patient or a court?
  • Which AI tools are staff using today, and on whose account?
  • Who approves a new AI tool before it touches personal or client data?
  • What would you show the ICO, or your sector regulator, about a decision AI contributed to?

Talk to us if

  • A supplier is offering an AI agent that would update records or send replies without a person checking each one.
  • Staff use chatbots on personal accounts for client or case work, outside any approved list.
  • A supplier is proposing AI assistant licences for every seat, and you cannot yet say which roles would use them.
  • Your board or trustees have asked for an AI plan and a policy by a set date.
  • A pilot has run without a baseline, and no one can say whether it worked.
  • An AI vendor contract is waiting for signature and its data terms have not been read against your policy.
  • Your regulator has published guidance on AI, such as the SRA's warning notice or the CQC's principles, or you are a public body that may need to publish an Algorithmic Transparency Recording Standard record.

Questions

Questions buyers ask

What do you mean by agentic AI?

Software that completes steps in your systems, such as updating a record, raising an order or sending a reply, rather than only answering a question. Some products sold as agents are assistants or rule-based automations under a new name, so we describe each tool by what it may do on its own, using the four levels on this page.

What happens when an agent gets something wrong?

The failure plan settles that before launch: the error rate you will accept, how errors are caught, who corrects the record and tells the person affected, how an action is undone, and the point at which the agent is paused or switched off. It names the person in your organisation who is accountable for the agent.

Do you give legal or data protection advice?

No. We reference the ICO's Guidance on AI and data protection, UK GDPR and your regulator's published guidance, and we write policies and DPIA screening notes against them. The legal position, and sign-off on any DPIA, stays with your advisers and your data protection officer or lead. The ICO says its guidance is under review following the Data (Use and Access) Act 2025, so we mark each place a policy relies on it.

Could the assessment shortlist an AI feature you would build?

We also build software, including AI features, so the question is fair. Where a recommendation could lead to work for us, the report says so and names the other routes: a product you already license, one you could buy, or no change. The ruled-out list shows what we considered and why. We explain any commercial relationship that could affect a recommendation before you decide.

Do we need to buy AI licences first?

No. The assessment works from your task list and the tools you already hold. A licence plan by role comes out of it, starting with a trial group and the measures to read before any wider purchase.

Do you certify or audit AI systems?

No. We do not certify, audit or assure AI systems, and we hold no accreditation to do so. We assess tasks, write policy, design pilots and put questions to suppliers. Where an AI feature needs a security test, we say so and describe the kind of accredited tester to look for.

What should we have ready?

A sponsor who can make decisions, time with the people who do the work, counts from your systems where they exist, and your current policies and AI supplier contracts. For the assistant readiness review, an administrator who can export sharing and permission reports.

Every use is set to a level of autonomy.

We rank one team's tasks, set the autonomy level for each task on the shortlist, test the strongest on your own past cases and record why the others were ruled out.

Request an agentic AI assessment