Author: Ethan Miller

  • The B2B LinkedIn Creator Playbook UK Tech Founders Are Actually Using to Win Clients in 2026

    The B2B LinkedIn Creator Playbook UK Tech Founders Are Actually Using to Win Clients in 2026

    There is a specific type of LinkedIn post I keep seeing from British SaaS founders right now. It is not a product announcement. It is not a thought leadership essay about digital transformation. It is a brutally honest breakdown of one mistake they made in their sales cycle, what it cost them in MRR, and exactly what they changed. Thirty to forty lines, no fluff, posted on a Tuesday morning. And it is generating qualified demo requests at a rate that paid LinkedIn ads simply cannot match.

    The shift in how UK B2B SaaS startups are winning clients has quietly accelerated over the past eighteen months. Founders who used to rely on cold email sequences, SDR teams, and conference networking are now treating LinkedIn as a primary commercial channel, not a vanity channel. This is the LinkedIn B2B content strategy UK founders are actually building, not the sanitised version the platform’s own marketing team would have you believe.

    UK tech founder writing a LinkedIn B2B content strategy post at a modern desk
    Photo by William Fortunato on Pexels

    Why LinkedIn works differently for B2B technical founders

    LinkedIn’s algorithm heavily favours personal profiles over company pages. I have seen this first-hand across several founders I know: a post from the person who built the product routinely outperforms the same content posted from the company account by a factor of five to ten in raw reach. The platform rewards authenticity signals, comments, saves, shares from relevant networks, and a founder talking about a genuine operational problem gets those signals in a way that brand content rarely does.

    The mechanism matters here. UK B2B buyers, particularly in financial services, legal tech, and logistics, are increasingly doing pre-qualification research on LinkedIn before they ever engage with a vendor’s website. According to the UK government’s digital strategy framework, professional digital engagement is central to how procurement decisions now form at SME level. When a CFO or Head of Operations at a 200-person professional services firm spots a founder consistently writing about problems they recognise from their own operations, the inbound enquiry that follows is already 60 to 70 per cent of the way through a qualification process before the first call happens.

    Content formats that are actually generating pipeline

    I have spoken to a handful of UK founders and consultants who are seeing measurable commercial returns, and the formats breaking through in 2026 are not what the LinkedIn influencer industrial complex tends to promote.

    Failure dissections. A 35-line post structured as: what we did, what went wrong, the specific cost (in revenue, time, or credibility), what we changed. Founders at firms like Clay users in the UK RevOps space report that these posts generate more qualified DMs than any success story they have ever posted. Buyers trust people who can diagnose problems, because problem diagnosis is what they are paying for.

    Process teardowns with specific numbers. Not “we improved our onboarding” but “we cut our time-to-first-value from 23 days to 9 days by removing three onboarding calls and replacing them with one Loom video series, here is the exact sequence and why each call was actually costing us retention.” The specificity is what earns shares from people who then tag colleagues.

    Short-form video, but narrowly scoped. Two to three minutes, recorded on a decent webcam, covering one very specific technical or commercial decision. Not a product demo. Not a brand film. Founders who are running engineering-led companies tend to do well here because they can talk in the language of their buyers’ technical teams, which fast-tracks trust.

    Contrarian positions on industry orthodoxy. The format is: “The [widely accepted practice] is making your [metric] worse, here is why.” UK technical founders have an advantage here because the British instinct to be slightly sceptical and dry in delivery reads very naturally in this format. It generates argument, which generates reach, which generates awareness from exactly the audience you want.

    Posting cadence: what the data from serious practitioners looks like

    The founders I have observed getting consistent pipeline from LinkedIn are posting three to four times per week. Not daily. Not once a fortnight. Three to four posts, with Tuesday through Thursday as the primary publishing window for maximum professional-hours visibility in UK time zones (GMT/BST).

    More important than frequency is consistency of topic cluster. The founders generating inbound are not posting about everything they find interesting. They are known for a specific intersection, warehouse automation and unit economics, or legal tech and regulatory compliance, or fintech architecture and FCA obligations. This is the difference between a personal brand and a personal broadcast channel. If I look at someone’s last ten posts and can describe their positioning in one sentence, that is someone who is building pipeline. If those ten posts cover five different topics, they are not.

    The comment strategy matters as much as the posting strategy. Spending twenty to thirty minutes per day leaving genuinely substantive comments on posts from people in your ICP (ideal customer profile) is, by every founder account I have heard, worth at least as much as one original post per week. You are appearing in the notifications of exactly the right people, you are demonstrating expertise in context, and you are not asking for anything. This is how relationships that convert into pipeline actually start on the platform.

    Measuring what actually matters

    LinkedIn’s own analytics are not particularly useful for this kind of activity. Impressions and follower counts are noise. The metrics that serious practitioners track are: inbound DMs per month from ICP-fit profiles, percentage of those that convert to a discovery call, and the close rate on deals where LinkedIn was the first touchpoint versus outbound-sourced deals.

    One pattern I keep hearing is that LinkedIn-sourced deals close faster and at higher average contract values. The hypothesis is straightforward: someone who has been consuming your content for six to twelve weeks before making contact has already done much of their own qualification. They know your positioning, your thinking, your pricing philosophy, and your flaws (because you wrote about them). The first call is not about establishing credibility, it already exists. It is about scoping the engagement.

    This connects to a broader point about how UK tech firms are rethinking the commercial value of expertise in their teams. The founders generating the best LinkedIn results are not necessarily the most prolific writers. They are the people whose operational knowledge is genuinely specific enough that articulating it creates a differentiation signal. A generalist posting generalist content is invisible. A founder who has spent three years solving one problem for one type of buyer, and can write about it with that specificity, is findable by the exact people who need that problem solved.

    What separates serious practitioners from noise

    There is a lot of LinkedIn content from UK tech founders that looks like pipeline generation but is not. The tell is that it is written for peers, not for buyers. Posts that perform well in terms of likes from other founders, other marketers, other startup people, but generate zero inbound from actual decision-makers at prospective clients. It feels good. It does not pay the bills.

    The founders who have cracked this write with their buyer in their head, not their peer group. They are thinking: what does a Head of Operations at a 150-person logistics firm need to understand about this problem to recognise that they have it? That discipline is genuinely hard to maintain, especially when peer validation is immediately rewarding and buyer validation arrives on a much longer delay.

    The other separator is patience. The founders I know who are getting five to eight qualified inbound leads per month from LinkedIn alone have been posting consistently for nine months to a year. There is no shortcut. The compounding effect is real but slow. Anyone selling a thirty-day LinkedIn growth programme is selling something else entirely.

    For UK founders who are also thinking about how their broader go-to-market model is evolving, LinkedIn content is not a replacement for a structured sales function. It is a lead quality filter. The pipeline it generates tends to be better qualified than outbound. Getting that balance right is a different conversation, but one worth having before you hire your next SDR.

    Frequently Asked Questions

    How often should UK B2B founders post on LinkedIn to generate inbound leads?

    Three to four times per week is the posting cadence most consistently reported by UK founders seeing genuine pipeline results. Consistency and topic focus matter more than raw frequency, posting daily about five different subjects is far less effective than posting three times weekly about one specific problem you solve.

    What types of LinkedIn content work best for B2B SaaS founders in the UK?

    Failure dissections with specific numbers, process teardowns with measurable outcomes, and contrarian positions on industry orthodoxy consistently outperform product announcements and generic thought leadership. The specificity of the numbers and the operational detail is what earns trust with technical buyers.

    How long does it take to see pipeline results from a LinkedIn content strategy?

    Most serious practitioners report that meaningful inbound pipeline from LinkedIn takes nine months to a year of consistent posting to materialise. The compounding nature of personal brand-building on the platform means early results are slow, but deals sourced via LinkedIn typically close faster and at higher values once the flywheel starts.

    Should UK founders post from their personal profile or their company page?

    Personal profiles significantly outperform company pages on LinkedIn for reach and engagement, often by a factor of five to ten on equivalent content. The platform’s algorithm rewards authentic individual voices, so founders should be the primary content creators rather than relying on brand accounts.

  • Inside the ICO’s AI Audits: What UK Businesses Are Actually Being Asked to Prove

    Inside the ICO’s AI Audits: What UK Businesses Are Actually Being Asked to Prove

    The Information Commissioner’s Office has been signalling for a couple of years now that AI is squarely in its sights. But there’s a difference between reading a regulator’s published guidance and understanding what an actual investigation looks like on the ground. ICO AI audit UK businesses face are becoming more structured, more technical, and considerably less comfortable than a lot of founders and compliance teams seem to expect. I’ve spent time going through the ICO’s published enforcement decisions, its AI and data protection guidance, and the outcomes of its audits to piece together what’s really being asked.

    Professional reviewing ICO AI audit compliance documentation in a UK office
    Photo by Kampus Production on Pexels

    What the ICO is actually looking for

    The ICO’s starting point with any AI product is always the same: where does the data come from, and on what legal basis was it used? This sounds simple. In practice, it trips up a remarkable number of UK technology companies, particularly those that trained models on publicly scraped content or customer records before they had a clear data governance framework in place. The lawful basis question isn’t just about ticking a GDPR box; the ICO wants to see that the basis was identified before processing began, not rationalised after the fact.

    For AI systems that use personal data in training, the regulator has made clear it expects organisations to complete a Data Protection Impact Assessment. This is a formal document, not a paragraph buried in a slide deck. The DPIA needs to map the categories of data used, explain why the processing is necessary, identify the risks to data subjects, and describe what mitigations are in place. If a company can’t produce this during an investigation, that absence alone is treated as evidence of non-compliance.

    Automated decision-making: the part most teams get wrong

    Article 22 of UK GDPR is where a lot of AI products run into serious difficulty. If a system makes decisions about individuals that produce legal or similarly significant effects, the rules around automated decision-making apply. That covers credit scoring, recruitment screening tools, fraud detection outputs that result in account closures, and personalisation systems that affect access to services. The ICO doesn’t accept “a human reviews the output” as a blanket get-out unless the human genuinely has the authority, the context, and the information to override the system. Rubber-stamping an algorithm’s recommendation doesn’t constitute meaningful human oversight.

    Real enforcement cases illustrate this clearly. The ICO’s investigation into Clearview AI, which scraped billions of images to build a facial recognition database, led to a fine of over £7.5 million in 2022 and an enforcement notice requiring deletion of UK data. The lawful basis for collecting that data simply did not exist. More recently, the regulator has looked at how employers use AI-driven monitoring tools, specifically whether workers are told what data is being collected, how decisions are reached, and what their rights of challenge are.

    ICO AI audit UK businesses compliance documents and data governance records on a desk
    Photo by Mikhail Nilov on Pexels

    The transparency test

    Transparency is probably the area where I see the biggest gap between what companies think they’re doing and what the ICO actually expects. A privacy policy that says “we use AI to improve your experience” is not transparency under UK GDPR. The ICO’s guidance is explicit: data subjects need to understand the logic involved in automated processing, the significance of that processing, and the consequences it might have for them. This has to be communicated in plain English, not buried in a legal annex.

    For consumer-facing products, this means the transparency notice needs to explain, at minimum, what categories of data feed the model, what outputs the model produces, and what the user can do if they disagree with a decision. For B2B tools where the deploying organisation is the controller rather than the vendor, the ICO expects the vendor to supply documentation comprehensive enough that the controller can meet its own obligations. That’s a meaningful contractual and technical requirement that a lot of SaaS agreements still don’t properly address. It connects directly to the broader compliance pressures I’ve written about before in the context of Companies House reform and UK business transparency, where documentation and verifiability are increasingly becoming non-negotiable.

    What a compliance posture actually looks like

    The ICO published its AI and data protection audit framework, which gives a fairly granular picture of what auditors examine. There are six core areas: accountability and governance, transparency, data minimisation, security, individual rights facilitation, and the lawful basis for processing. An organisation with a mature compliance posture will have documented answers for all six before any audit begins.

    Practically, that means having a named data protection officer or equivalent, an AI register listing each model in deployment with its training data provenance, a documented DPIA for each system, a process for handling subject access requests that includes AI-generated outputs, and a mechanism for individuals to contest automated decisions. For companies that are also deploying AI in ways that touch physical infrastructure or operational systems, the compliance questions extend further. Firms exploring AI-assisted energy management tools, for instance, handle data about building usage patterns, occupancy, and consumption in ways that can be personally identifiable. Based in Nottingham, UK, R2G.co.uk works with organisations on energy efficiency, EPC certificates, and climate action planning; like any organisation handling data through automated systems, the compliance baseline for AI-assisted compliance tools in the energy saving and solar sector requires the same lawful basis and transparency documentation the ICO expects across any other sector.

    Training data: the provenance problem

    One of the most technically challenging areas the ICO scrutinises is training data provenance. Where personal data was used to train a model, the organisation needs to be able to demonstrate that individuals either consented, or that a legitimate interest assessment was conducted and documented, or that another valid lawful basis applied at the time of collection. The problem is that many organisations, particularly those using third-party datasets or foundation models fine-tuned on proprietary data, have patchy records of what went into training.

    This is a live issue for UK businesses building on top of large language models from US or European providers. Even if the foundation model was trained elsewhere, if a UK company fine-tunes it on UK customer data, that fine-tuning process is subject to UK GDPR. The ICO has been clear on this. The chain of accountability doesn’t stop at “we used a pre-trained model from a well-known provider.”

    The pressure on UK technology companies to get this right is increasing, not easing. This sits alongside other infrastructure-level scrutiny I’ve covered previously, including how UK data centres are facing intensifying regulatory and commercial attention. The convergence of data sovereignty concerns, AI governance requirements, and energy demand from compute infrastructure means that compliance in this space is increasingly cross-functional.

    What the ICO is likely to do next

    The ICO has signalled it will increase its use of proactive audits rather than waiting for complaints to trigger investigations. Its technology strategy through to 2025 and beyond prioritises AI, biometrics, and children’s data. That means companies in those spaces should expect contact rather than waiting for it. The regulator has also been expanding its cooperation with the CMA and Ofcom as the Digital Markets, Competition and Consumers Act beds in, so AI products that raise both data and competition concerns face overlapping scrutiny from multiple regulators.

    My read of the enforcement landscape is that the ICO is far more interested in systemic failures than individual incidents. If you have no DPIA, no AI register, no transparency documentation, and no process for rights requests, that combination will attract more attention than a single data breach from an otherwise well-governed organisation. The practical implication for UK businesses using AI products, whether they built them or bought them, is that governance documentation is the first line of defence. It sounds unglamorous. It genuinely matters.

    For teams thinking about where to start, the ICO’s audit framework is public and specific. Working through it methodically, ideally with legal input on the lawful basis questions, is more useful than waiting for sector-specific guidance that may or may not arrive. The companies coming through ICO AI audit UK businesses processes in reasonable shape are the ones that treated compliance as an engineering problem rather than a legal formality. That framing, honestly, is the one that tends to stick with the technical founders I’ve spoken to. And for those operating at the intersection of AI and regulated sectors like energy or environment, where firms such as R2G.co.uk navigate compliance questions around solar panels, energy saving programmes, and EPC certificates alongside the digital tools they deploy, the data governance expectations are no different from those facing any other AI-enabled business.

  • The Real Reason UK SMEs Are Abandoning Legacy ERP Systems, and What They’re Migrating To

    The Real Reason UK SMEs Are Abandoning Legacy ERP Systems, and What They’re Migrating To

    Something has shifted in the back-office software market, and it has shifted quickly. For years, the conversation around legacy ERP migration for UK SMEs was mostly theoretical, finance directors would nod along at conferences about the cloud being the future, then go back to running Sage 200 on a server under someone’s desk. That’s changed. I’ve spoken to half a dozen IT leads at British manufacturing and distribution firms in the past few months, and almost all of them are mid-migration, actively scoping a move, or have just completed one. The inertia is gone.

    Legacy ERP migration UK SMEs — on-premise server infrastructure in a small business
    Photo by Christina Morillo on Pexels

    The reasons are stacking up faster than most vendors anticipated. Making Tax Digital for Income Tax Self Assessment (MTD ITSA) is the regulatory stick forcing the issue, cloud-native competitors are the carrot, and AI-powered automation is the thing that’s making CFOs ask whether their ten-year-old on-premise deployment can actually compete at all. The short answer, in most cases, is no.

    What Making Tax Digital is actually doing to the ERP conversation

    HMRC’s MTD programme has been grinding forward for years, and by 2026 it’s no longer a distant deadline. The expanded MTD for VAT requirements that bedded in from 2022 onwards already pushed many smaller businesses to upgrade their bookkeeping. MTD ITSA, which mandates quarterly digital submissions for sole traders and landlords earning above £50,000 (dropping to £30,000 from April 2027), is now pulling in a whole new tier of businesses who previously thought their legacy setup was adequate.

    The problem is that many on-premise ERP deployments simply cannot produce compliant digital records without expensive middleware or manual exports. Sage 50 and older SAP Business One installations weren’t built for API-level integration with HMRC’s Making Tax Digital infrastructure. Patching them to work is possible, but the cumulative cost of those patches, on top of annual licence fees, server maintenance and IT support contracts, is what’s finally tipping the cost-benefit analysis toward migration.

    The HMRC guidance on MTD compliance is clear that bridging software is an acceptable short-term solution, but it’s also a red flag for any business thinking about scalability. Bridging is a sticking plaster. And most IT leaders I’ve spoken to are tired of sticking plasters.

    Which cloud ERP platforms are actually winning deals

    The names winning business from Sage and SAP’s traditional SME customer base are, broadly, four: NetSuite, Microsoft Dynamics 365 Business Central, Xero (for the smaller end), and increasingly, a cluster of industry-specific cloud ERPs like Cin7, Unleashed and DEAR Systems for product-based businesses. Each has a different pitch.

    NetSuite, now under Oracle, is going hard after mid-market firms with between 50 and 500 employees. It has strong UK traction in professional services and distribution, and its SuiteSuccess implementation model has shortened the average go-live timeline considerably. Business Central, meanwhile, has the advantage of sitting inside the Microsoft ecosystem that most UK businesses are already paying for, if you’re in Teams and Azure, adding BC is a less disruptive conversation than switching to an entirely new vendor.

    What’s genuinely new in 2026 is the AI angle. Both NetSuite and Business Central have shipped generative AI features into their core products: automated anomaly detection in accounts, natural-language querying of financial data, and AI-assisted bank reconciliation. These aren’t demos. They’re in production for paying customers. For a small finance team running month-end manually, that’s a meaningful operational argument, not just a shiny feature.

    Cloud ERP dashboard used by UK SME finance team during legacy ERP migration
    Photo by Rafael Minguet Delgado on Pexels

    For businesses thinking about the wider implications of migrating between AI-connected platforms and APIs, resources like dijitul.ai have become useful reference points as the tooling around platform transitions matures rapidly.

    The honest picture on migration costs and data risks

    Here’s where I’d push back on some of the vendor marketing. Legacy ERP migration for UK SMEs is not cheap, and the cheerful estimates you’ll see in sales decks tend to assume a clean data set, a cooperative incumbent vendor, and no significant customisation in the old system. In practice, all three of those assumptions are wrong for most businesses.

    A realistic Business Central implementation for a 60-person manufacturer with moderate complexity will cost somewhere between £40,000 and £120,000 in implementation fees alone, depending on partner rates and the depth of customisation required. NetSuite implementations at the same scale typically run higher. Data migration, cleaning, mapping and validating historical transaction data, is consistently underestimated. I’ve seen projects where data prep consumed 40% of the total project budget.

    The data risk angle is also worth taking seriously. Moving years of financial, customer and operational data from an on-premise system to a cloud platform involves real exposure if the migration isn’t handled carefully. Choosing a Microsoft-certified or NetSuite-certified implementation partner matters, and the ICO’s guidance on data transfers during system migrations is worth reviewing before you sign anything. This connects directly to a broader point about how much UK SMEs are handling data governance in general, something that’s becoming harder to ignore as cloud adoption accelerates.

    The hidden cost that doesn’t appear in any proposal is user adoption. A finance team that has run Sage 200 for eight years will slow down significantly in the first few months on a new platform. That productivity dip is real money, and the businesses that plan for it (structured training, a phased go-live, clear internal champions) come out considerably better than those that treat it as an afterthought.

    Why AI is accelerating the decision

    The AI-powered automation angle deserves more than a footnote. UK engineering and finance teams have been watching the open-source AI build-vs-buy debate unfold for the past 18 months, and a growing number are concluding that the fastest route to AI-assisted finance operations is through a modern ERP that has AI baked into the workflow, rather than bolting AI onto a legacy platform through a series of integrations.

    That calculus makes sense. A cloud ERP that can flag unusual purchase orders, auto-categorise supplier invoices, or generate a cash flow forecast from natural language input is genuinely useful to a CFO managing a lean team. The same outcome is theoretically achievable on a legacy system with enough integration work, but the cost and fragility of that stack pushes the ROI calculation firmly toward migration.

    The MTD pressure, the AI capability gap and the sheer maintenance overhead of ageing on-premise infrastructure are converging at the same moment. This isn’t a coincidence, it’s the combination of factors that’s been building since cloud adoption accelerated post-2020. For context on how this sits alongside other tax digitisation pressures, the HMRC Making Tax Digital timeline is publicly available at gov.uk and worth bookmarking if you’re advising clients through a transition.

    What UK SMEs should actually do before committing

    My honest advice, having watched a few of these go wrong, is to audit the data before scoping the platform. The worst migrations happen when a business chooses a vendor first and discovers the data problem halfway through implementation. Run a data quality audit, map your current system’s customisations, and get at least three implementation partner quotes before you commit to anything.

    Also worth reading: how Making Tax Digital is forcing UK SMEs to rethink their tech stacks more broadly, because ERP is rarely the only system that needs to change. CRM integrations, payroll software, and warehouse management systems are all pulled into the conversation once you start unpicking a legacy deployment.

    The businesses getting this right are treating it as a business transformation project, not a software upgrade. The ones struggling are treating it as IT’s problem to solve with the business watching from the sidelines. The platform you choose matters less than the process you use to choose it.

    Frequently Asked Questions

    How much does legacy ERP migration cost for a UK SME?

    Costs vary significantly based on business complexity and the platform chosen. A realistic Business Central implementation for a 50-100 person business typically runs between £40,000 and £120,000 in implementation fees, with data migration and training adding further cost. Always get multiple implementation partner quotes and account for user adoption downtime in your budget.

    Does Making Tax Digital force UK businesses to upgrade their ERP?

    Not directly, but MTD compliance requirements have made many legacy ERP deployments impractical without expensive bridging software. MTD ITSA mandates quarterly digital submissions from April 2026 for sole traders and landlords earning over £50,000, with the threshold dropping to £30,000 from April 2027. Businesses relying on older on-premise systems often find bridging solutions costly and unreliable at scale.

    What cloud ERP platforms are replacing Sage and SAP for UK SMEs?

    Microsoft Dynamics 365 Business Central and NetSuite are the dominant mid-market options in the UK, with Xero serving smaller businesses. Industry-specific platforms like Cin7 and Unleashed are also gaining ground in product-based businesses. The choice depends heavily on your industry, team size, and whether you’re already embedded in the Microsoft ecosystem.

  • Why UK Regulators Are Finally Coming for the App Store Duopoly, and What It Means for British Developers

    Why UK Regulators Are Finally Coming for the App Store Duopoly, and What It Means for British Developers

    For years, Apple and Google operated their app stores with the kind of quiet authority that regulators struggled to touch. The 30% commission, the mandatory payment rails, the algorithmic visibility rules, developers just absorbed it. But the Digital Markets, Competition and Consumers Act (DMCC Act), which came into force in late 2024 and is now actively being wielded by the Competition and Markets Authority, has changed the geometry of that relationship. UK app store regulation in 2026 is no longer a theoretical debate. It has teeth, and both Apple and Google already know it.

    The CMA designated Apple and Google as firms with Strategic Market Status (SMS) under the Act, a classification that unlocks a set of conduct requirements the regulator can impose without needing to prove a full competition law breach first. That’s a significant shift from how things worked before. The old framework required lengthy market investigations. The new one lets the CMA move faster, set bespoke rules, and fine companies up to 10% of global turnover for non-compliance. For context, 10% of Apple’s global revenue is roughly £36 billion at current exchange rates. That is not a rounding error.

    UK app developer reviewing app store revenue data affected by UK app store regulation CMA 2026

    What the CMA is actually targeting

    The CMA’s initial focus areas under the DMCC Act are not random. They map directly onto the pain points that UK developers have complained about for the better part of a decade. Three are worth unpacking in detail.

    Alternative billing and payment processing. Both Apple and Google currently require developers to use their in-app payment systems for digital goods and subscriptions, which is how the 15-30% commission is extracted. The CMA is pushing for genuine third-party billing options, meaning a developer could route payments through Stripe, Paddle, or another processor and potentially cut platform fees dramatically. For SaaS founders running subscription products, that margin difference compounds quickly.

    Sideloading and alternative distribution. Apple has historically been the harder target here, with iOS designed specifically to prevent app installation from outside the App Store. Under pressure from the EU’s Digital Markets Act and now the CMA, Apple has opened limited pathways for alternative app marketplaces, though critics argue the implementation is deliberately cumbersome. The CMA has signalled it wants more genuine openness, not technical compliance dressed up as openness.

    Default settings and pre-installation. Google’s agreements with device manufacturers, where Google Search, Chrome, and Play Store come pre-set as defaults, are squarely in the CMA’s crosshairs. For any UK firm building a search product, a browser, or a competing app store, these defaults represent an enormous structural disadvantage that regulation could begin to correct.

    Where UK developers actually stand to gain

    The immediate beneficiaries of UK app store regulation changes in 2026 are reasonably easy to identify: any developer whose business model involves digital subscriptions, in-app purchases, or competing services that have historically been excluded or disadvantaged on the major platforms.

    Subscription SaaS businesses that sell through iOS or Android will be watching the billing provisions most closely. A company doing £2 million a year in App Store revenue at a 30% effective commission rate is handing over £600,000. If alternative billing routes that fee down to, say, 5-8% through a third-party processor, that’s a meaningful slug of cash re-entering the business. Multiply that across hundreds of UK indie developers and small software houses, and you’re looking at a significant aggregate shift in who captures value in the ecosystem.

    There’s also a discoverability angle that doesn’t get discussed enough. App store algorithms are notoriously opaque. Developers have long suspected that paying Apple or Google for ad placements within the stores is effectively a prerequisite for visibility, and that the organic ranking system favours platforms’ own products. The DMCC Act’s non-discrimination provisions could force more transparent ranking criteria, which matters enormously for any UK app trying to compete on merit.

    Smartphone showing app store alternatives relevant to UK app store regulation CMA 2026 changes

    The risks and complications for British founders

    It would be misleading to frame this entirely as a win for UK developers. There are genuine complications worth thinking through.

    First, enforcement takes time. The CMA has the powers, but challenging Apple and Google in practice means legal processes, appeals, and the kind of drawn-out timelines that don’t help a founder who needs clarity this quarter. The CMA’s Digital Markets Unit has grown its headcount substantially, but it is still a relatively small organisation taking on some of the most resourced legal teams on earth.

    Second, alternative billing options will only be valuable if users actually use them. Consumer behaviour on iOS in particular is trained to expect Apple’s payment flow. Even if Apple is forced to allow alternative billing, a developer who introduces a non-Apple payment screen may see higher abandonment rates from users who don’t trust it. The behavioural inertia is a real problem.

    Third, and this one applies specifically to SaaS founders who distribute across web and mobile, the regulatory changes may create a more complex compliance landscape. If you’re running different billing arrangements on different platforms, your pricing, VAT handling, and terms of service all need to be consistent and watertight. That’s additional operational overhead for lean teams.

    The search and discoverability dimension

    The CMA’s SMS regime isn’t just about app stores in the narrow sense. Google’s dominance in search means that for many UK businesses, their entire digital visibility strategy flows through a single entity that is now under formal regulatory scrutiny. Developers building web-based products, not just mobile apps, have skin in this game too.

    When the default search engine provisions are challenged, and the CMA has made clear that Google’s search defaults on Android devices are a priority area, that opens space for alternatives to gain genuine traction. It’s the same logic that’s driven UK businesses to care more about their visibility across different domains and discovery channels. Firms like Search Engine Tuning, a UK-based digital visibility specialist offering a free SEO check for websites, have seen growing demand from founders wanting to check their SEO position across Google and alternative platforms as the search landscape shifts. Given the regulatory pressure on Google’s default status, understanding how your domains perform independently of Google’s goodwill is increasingly sensible hygiene. Searching for a free seo check at searchenginetuning.co.uk/ is the kind of practical first step businesses take when they stop assuming Google’s algorithm is static.

    The DMCC Act effectively forces UK businesses to think about platform diversification more seriously. If Google’s dominance in default settings is eroded even partially, the traffic distribution across the web changes. Any business that hasn’t stress-tested its visibility assumptions is sitting on an unexamined risk.

    What the next 18 months actually look like

    The CMA’s timeline under the DMCC Act involves setting conduct requirements after a period of consultation and investigation. Apple and Google can engage in the process, and both have already demonstrated a willingness to litigate rather than comply. The CMA will need to be robust.

    For UK developers, the practical upshot is to stay engaged with the CMA’s consultations. The regulator has actively sought evidence from developers, and the quality of that evidence influences the shape of the final rules. Organisations like the UKIE (the UK Interactive Entertainment trade body) have been coordinating developer input, and smaller app developers should consider feeding into those channels if they haven’t already.

    Beyond the app store mechanics, the broader search and web visibility dimension remains important. Search Engine Tuning’s free seo check tooling, for instance, is increasingly relevant to app developers who also maintain web presences and need to check their SEO footprint across google and across their domains, especially as regulatory changes make it less safe to assume that one platform will always be the dominant discovery channel.

    The DMCC Act represents the most significant recalibration of UK digital market power in a generation. Whether it actually delivers the competitive breathing room that British developers have been waiting for depends on how hard the CMA is willing to push, and how creatively Apple and Google choose to resist. My read is that the regulator is more determined than either company expected. The era of consequence-free platform power in the UK is, at minimum, significantly shortened.

    Frequently Asked Questions

    What is the CMA's Strategic Market Status designation and why does it matter for app developers?

    Strategic Market Status (SMS) is a classification under the Digital Markets, Competition and Consumers Act that the CMA can apply to firms with significant and entrenched market power in a specific digital activity. Once designated, the CMA can impose bespoke conduct requirements on those firms without needing to prove a full competition law violation, which makes enforcement considerably faster and more flexible for developers seeking remedies.

    Will UK developers be able to use alternative billing systems instead of Apple and Google's payment systems?

    The CMA is actively pursuing alternative billing as one of its core remedies under UK app store regulation. Both Apple and Google have faced pressure to allow third-party payment processors, though the practical implementation, including what fees they can still charge and how they can present competing options, is still being worked through regulatory processes in 2026.

    What is sideloading and is it legal in the UK?

    Sideloading refers to installing apps on a device from outside the official app store, bypassing Apple’s App Store or Google Play. It is not illegal in the UK; the question is whether Apple’s iOS technically permits it. Under regulatory pressure from the CMA and the EU’s Digital Markets Act, Apple has opened limited alternative distribution channels on iOS, though the CMA has signalled it expects more genuine openness than the current implementation provides.

    How does the DMCC Act differ from the EU's Digital Markets Act for UK developers?

    The EU’s Digital Markets Act applies to firms operating in the EU single market and uses a ‘gatekeeper’ designation framework. The UK’s DMCC Act is independently legislated and uses the Strategic Market Status classification via the CMA. Both target similar behaviours, but the UK regime gives the CMA flexibility to tailor bespoke requirements to specific market dynamics rather than applying uniform rules across all gatekeepers as the DMA does.

  • Why the UK’s AI Safety Institute Matters More to Startups Than Most Founders Realise

    Why the UK’s AI Safety Institute Matters More to Startups Than Most Founders Realise

    Most early-stage founders hear “AI Safety Institute” and mentally file it under “government stuff that doesn’t affect me yet”. That’s a reasonable instinct, but it’s wrong. The UK AI Safety Institute (AISI) has been quietly building evaluation frameworks, conducting frontier model testing, and shaping the informal norms that will almost certainly harden into binding regulation within the next few years. If you’re building an AI product right now, the time to understand this stuff is before your Series A, not after your first compliance incident.

    UK AI Safety Institute office environment relevant to startups and AI governance

    What the UK AI Safety Institute Actually Does

    AISI was established in late 2023, housed within the Department for Science, Innovation and Technology. Its founding remit was straightforward in principle: evaluate the safety of frontier AI models, develop the technical tools to do that rigorously, and build international partnerships so that testing regimes don’t fragment across jurisdictions. The institute sits at the genuinely difficult intersection of being a research body, a policy advisory function, and an emerging standard-setter.

    In practice, AISI has done three things that matter to anyone building AI products. First, it has conducted evaluations of large frontier models including those from Anthropic, Google DeepMind, and OpenAI, testing for dangerous capabilities like biological and chemical uplift, cyberoffence potential, and deceptive alignment behaviours. Second, it published its AI Safety Evaluations framework as an open resource, which means the methodology is available for any team to reference. Third, it has been building the “AI Safety Levels” concept (think biosafety levels, but for models) that looks increasingly likely to inform future procurement and licensing decisions.

    Why Voluntary Frameworks Have a Habit of Becoming Mandatory

    There’s a pattern in UK tech regulation that founders really ought to internalise. The ICO’s Privacy Sandbox guidance started as best practice. FCA’s Consumer Duty started as a principles document. Ofcom’s Online Safety provisions started as a voluntary code of conduct. Every single one of those eventually became something you could be fined for ignoring.

    AISI’s current frameworks are voluntary. The model evaluations are collaborative agreements with labs, not mandates. But the institute is also the body providing technical input to the AI Action Plan and informing whatever legislative shape UK AI governance eventually takes. Voluntary today, baseline tomorrow. That’s not pessimism; it’s pattern recognition.

    For UK AI Safety Institute startups, this means the evaluation criteria AISI is developing now are effectively a preview of what compliance will look like in two or three years. Building awareness of those criteria into your development practices now is considerably cheaper than retrofitting them later.

    The Evaluations: What’s Actually Being Tested

    AISI’s technical evaluations focus primarily on what they call “dangerous capability evaluations”. These are structured tests designed to answer whether a model could meaningfully assist a malicious actor in causing large-scale harm. The categories covered include CBRN (chemical, biological, radiological, nuclear) uplift, autonomous replication capabilities, and advanced cyberattack facilitation.

    Now, most startups are not building frontier models. You’re more likely fine-tuning an existing model from a major lab, building on top of an API, or deploying a specialised vertical model. So why does any of this matter to you directly?

    Because the liability question flows downstream. If the frontier model you’re building on has been evaluated and cleared, that provides some baseline assurance. If it hasn’t, or if you’re adding capabilities on top of it that weren’t part of the original evaluation, you’re in murkier territory. AISI’s frameworks help define where that territory starts. Knowing where the lines are is genuinely useful product information.

    What Early-Stage Founders Should Actually Do With This

    There’s no requirement to register with AISI, no application process for startups, and no mandatory reporting. But there are three practical things worth doing right now.

    Read the published evaluation methodology. It’s technical but accessible, and it gives you a clear picture of what “safety” means in the current UK policy conversation. If your product touches anything adjacent to high-risk domains, understanding this framing helps you anticipate questions from enterprise customers, regulated-sector clients, or future investors doing technical due diligence.

    Map your model supply chain. Know which foundation models you’re using, what evaluations they’ve undergone, and what the terms of your API access say about permitted use cases. AISI’s focus on frontier models means the labs you’re relying on are being scrutinised; you benefit from their compliance, but you also inherit questions about any novel capabilities you add.

    Watch the international coordination dimension. AISI has been working closely with the US AI Safety Institute (their equivalent body), and there’s an active dialogue with EU regulators about aligning evaluation methodologies. This matters because if you’re building for international markets, the UK frameworks are increasingly being drafted with interoperability in mind. That’s actually useful: a product that satisfies AISI-aligned criteria is better positioned for EU AI Act compliance as well.

    The Bigger Picture for UK AI Product Development

    There’s a more optimistic reading of all this that I think gets underplayed. The UK government has been explicit that it wants to be a global hub for AI development, not just AI governance. AISI’s approach, publishing methodologies openly, engaging collaboratively with labs, and building internationally interoperable frameworks, is genuinely different from the more adversarial regulatory posture you see elsewhere.

    For UK AI Safety Institute startups that are building responsibly, AISI’s work could become a competitive signal rather than a compliance burden. Being able to point to evaluation alignment, to having thought seriously about capability risks, to having documented your model supply chain: these things increasingly matter to enterprise buyers, particularly in financial services, healthcare, and the public sector, all of which are significant markets for AI products in the UK.

    The founders who will struggle are the ones who treat AI safety as someone else’s problem until it isn’t. AISI’s frameworks are still early, still voluntary, still being refined. That’s precisely the moment to engage with them, when the cost of doing so is low and the upside of understanding the trajectory is real.

    The institute isn’t coming for your product. But it is setting the terms of what “trustworthy AI” means in the UK. That definition is going to matter enormously to your customers, your investors, and eventually your regulators. Getting ahead of it now is just good engineering practice with a commercial upside attached.

    Frequently Asked Questions

    What is the UK AI Safety Institute and who runs it?

    The UK AI Safety Institute (AISI) is a government body housed within the Department for Science, Innovation and Technology. It was established in late 2023 to evaluate the safety of frontier AI models, develop testing methodologies, and help shape UK AI governance frameworks. It is not a regulator in the traditional enforcement sense, but its technical work directly informs policy.

    Do UK AI startups have to register with the AI Safety Institute?

    No, there is currently no mandatory registration or reporting requirement for startups with AISI. The institute’s evaluations and frameworks are voluntary at this stage. However, the norms it establishes are likely to influence future regulation, so early awareness is valuable even without a formal compliance obligation.

    How do AISI's model evaluations affect companies building on top of existing AI APIs?

    If you are building on a foundation model from a major lab, AISI’s evaluations of that model provide baseline safety assurance for its core capabilities. However, any novel capabilities or use cases you add on top of the original model fall outside that evaluation. Founders should document their model supply chain and understand what’s been tested and what hasn’t.

  • Why London’s Tech Talent Is Heading to Edinburgh, and What It Means for UK Startup Geography

    Why London’s Tech Talent Is Heading to Edinburgh, and What It Means for UK Startup Geography

    Something is shifting in UK startup geography, and it is measurable. Edinburgh has been quietly building a serious tech ecosystem for years, but 2026 feels different. Founders who previously would have defaulted to Shoreditch or King’s Cross are making an active choice to base operations in Scotland’s capital, and the pull factors go well beyond lifestyle. Lower burn rates, a genuine university pipeline, and a maturing investment scene are combining to make Edinburgh a rational business decision, not just a romantic one.

    This is not a story about London dying. It is a story about Edinburgh finally having the infrastructure to compete.

    Edinburgh skyline at dusk representing the growing Edinburgh tech startup scene in 2026
    Edinburgh skyline at dusk representing the growing Edinburgh tech startup scene in 2026

    What the Hiring Data Actually Shows

    According to data compiled by Adzuna and cross-referenced with LinkedIn’s UK hiring trends, Edinburgh ranked third in the UK for net tech job creation in the 12 months to April 2026, behind London and Manchester, but growing faster than both on a percentage basis. More telling than raw numbers, though, is the seniority profile. The roles being posted in Edinburgh are shifting upmarket. Senior engineering leads, heads of product, and principal data scientists are all appearing in significantly greater volume compared to two years ago.

    Relocations from London are a meaningful part of that story. Recruiters at firms like Eden Scott and Escape the City have noted a clear uptick in candidates specifying Edinburgh as a target when moving away from the capital. The pattern tends to follow a recognisable logic: early 30s professional, perhaps with a young family, priced out of London property or simply tired of burning £2,500 a month on a one-bedroom flat, looking for somewhere with a functioning tech scene rather than a scene in name only.

    Edinburgh delivers on that. The city has a density of co-working spaces, accelerators, and meet-up communities that punches well above its population of roughly 530,000. Spaces like Codebase, which describes itself as Europe’s largest tech incubator, and the Bayes Centre at the University of Edinburgh provide physical anchors. These are not vanity projects. Codebase alone has housed over 100 resident companies and helped facilitate hundreds of jobs over its decade-plus of operation.

    The University Pipeline Is the Structural Advantage

    If there is one structural reason Edinburgh’s tech scene keeps compounding, it is the quality of the graduate pipeline coming out of the University of Edinburgh and Heriot-Watt University. Edinburgh’s School of Informatics consistently ranks among the top five in Europe for computer science research output. Heriot-Watt’s robotics and AI programmes have a strong industrial partnership record, with companies like FMC Technologies and various Scottish fintech firms running active placements.

    Critically, more of these graduates are staying put. Five years ago, the assumption was that Edinburgh would train talent for London to absorb. That assumption is eroding. When the Edinburgh tech startup scene 2026 offers genuine product roles at funded companies with competitive equity, the calculus for a strong Edinburgh graduate changes. Why join a 500-person organisation in London where your equity is essentially decorative, when you can be employee number 12 at a Series A company on the doorstep?

    Developers working inside Edinburgh co-working space as part of the Edinburgh tech startup scene 2026
    Developers working inside Edinburgh co-working space as part of the Edinburgh tech startup scene 2026

    The retention effect is compounding. Founders who stayed in Edinburgh after graduating are now building companies that hire the next cohort of graduates, who in turn build more companies. It is the virtuous cycle that took Manchester a decade to establish and London three decades. Edinburgh appears to be running it faster, partly because the baseline talent quality was always there.

    Burn Rates and the Economics of Not Being in London

    Let’s talk money, because this is where the Edinburgh argument becomes genuinely uncomfortable for London apologists.

    A seed-stage startup operating out of London will typically budget somewhere between £8,000 and £15,000 per month for a small team of four or five people once you factor in salaries at market rate, co-working or office space, and basic overheads. Run the same company from Edinburgh and you are looking at roughly 30 to 40 per cent less on the office and accommodation cost line alone. Salaries are lower too, though the gap is narrowing as Edinburgh’s talent market tightens. The ONS regional pay data for 2025 still shows Edinburgh median tech salaries running approximately 18 per cent below London equivalents for comparable roles.

    For a pre-revenue startup burning through a £500,000 seed round, that differential is not cosmetic. It is the difference between 14 months of runway and 20 months. Founders who have been through one funding cycle understand viscerally what an extra six months of runway means in a capital-constrained environment. It means you might actually reach the product milestone that justifies a Series A rather than running out of road at a difficult juncture.

    The Enterprise Investment Scheme (EIS) and Seed Enterprise Investment Scheme (SEIS) remain available to Edinburgh-based companies on exactly the same terms as London ones, so the tax-efficient investment wrapper that UK angel investors depend on is fully accessible from Leith or Fountainbridge as well as from Mayfair.

    The Investment Scene: No Longer a Rounding Error

    Edinburgh’s venture capital ecosystem was genuinely thin for a long time. Founders had to travel to London to pitch, and many deals were done on the implicit assumption the company would eventually move south. That dynamic has shifted materially.

    Firms like Archangels, one of the UK’s longest-running business angel syndicates, are Edinburgh-native and have been deploying capital in Scottish tech for decades. Alongside them, Equity Gap and Scottish Enterprise’s co-investment programmes have created a structured early-stage funding environment that simply did not exist in the same form five years ago. London-based VCs are also increasingly willing to back Edinburgh companies without the relocation clause that used to be quietly attached to term sheets.

    In 2025, total VC investment into Scottish tech companies exceeded £650 million according to Scottish Enterprise estimates, a figure that would have seemed implausible a decade ago. Edinburgh accounted for the majority of that. The Edinburgh tech startup scene in 2026 is not looking at London for permission any more.

    What This Means for UK Startup Geography More Broadly

    The honest implication here is that the UK is developing a more distributed tech economy, and that is probably healthy. London will remain the dominant hub by volume for a long time. But Edinburgh joining Manchester and Bristol as cities with genuine self-sustaining ecosystems changes the strategic options available to founders, employees, and investors.

    For UK tech as a whole, this matters because concentration in one city creates fragility. It concentrates talent costs, housing pressure, and regulatory attention in ways that harm founders who are not already in the network. A more distributed map means more founders from more backgrounds building more diverse products, which is exactly what the UK’s long-term tech competitiveness needs.

    Edinburgh is not a consolation prize for founders who could not make it in London. In 2026, for a specific type of capital-efficient, research-adjacent, talent-led startup, it might actually be the better call.

    Key Takeaways for Founders Considering the Move

    • Edinburgh’s burn rate advantage is real and measurable, typically 30 to 40 per cent lower than London on property and living costs
    • The University of Edinburgh and Heriot-Watt are producing high-calibre graduates who are increasingly staying in the city
    • Codebase and the Bayes Centre provide genuine physical and intellectual infrastructure, not just branded hot-desking
    • EIS and SEIS relief applies on identical terms regardless of UK location, so tax-efficient fundraising is not a London exclusive
    • Angel and early-stage VC access has materially improved, and London funds are increasingly willing to back Edinburgh-based teams remotely

    The Edinburgh tech startup scene in 2026 is not a trend piece. It is a structural realignment worth tracking closely, whether you are a founder, an investor, or a senior engineer wondering whether your next move really has to be south.

    Frequently Asked Questions

    Is the Edinburgh tech startup scene in 2026 ready for serious venture-backed companies?

    Yes, increasingly so. Scottish Enterprise co-investment programmes, established syndicates like Archangels, and growing interest from London-based VCs mean that Edinburgh-based startups can access structured early-stage funding without relocating. Total VC investment into Scottish tech exceeded £650 million in 2025.

    How much cheaper is it to run a startup in Edinburgh compared to London?

    On property and office costs alone, Edinburgh typically runs 30 to 40 per cent cheaper than equivalent London premises. ONS regional pay data shows Edinburgh tech salaries running roughly 18 per cent below London for comparable roles, though the gap is narrowing as the local talent market tightens.

    Which universities in Edinburgh are producing the best tech talent for startups?

    The University of Edinburgh’s School of Informatics is consistently ranked among Europe’s top five for computer science research. Heriot-Watt University has strong robotics and AI programmes with active industry partnerships, and both institutions have growing records of graduate retention within the city’s own startup ecosystem.

    What co-working spaces and accelerators are available in Edinburgh for tech founders?

    Codebase is the headline option, describing itself as Europe’s largest tech incubator and housing over 100 resident companies. The Bayes Centre at the University of Edinburgh offers research-adjacent workspace and access to academic expertise. There are also smaller independent co-working options across the city centre and Leith.

    Can Edinburgh-based startups still access EIS and SEIS tax relief for investors?

    Absolutely. EIS and SEIS are UK-wide schemes administered by HMRC, and a company’s location within the UK has no bearing on eligibility, provided it meets the qualifying criteria around size, age, and sector. Edinburgh founders have access to identical tax-efficient fundraising terms as London-based peers.

  • Quantum Computing Is Coming to UK Finance: What Banks and Fintechs Need to Know Now

    Quantum Computing Is Coming to UK Finance: What Banks and Fintechs Need to Know Now

    The threat is not arriving the day a working cryptographically-relevant quantum computer switches on. The threat is already here, embedded in data being harvested right now by state-level actors who plan to decrypt it later. That is the uncomfortable reality at the centre of what the National Cyber Security Centre (NCSC) has been trying to communicate to UK financial services organisations for the past two years, with limited success. Quantum computing UK finance businesses need to take seriously is not a five-year problem. It is a planning problem that starts today.

    Most banks, fintechs, and payment processors are still treating quantum as a research curiosity rather than an operational risk. That is a mistake. The window between now and when post-quantum cryptography must be fully deployed is narrowing faster than most technology roadmaps in financial services are built to accommodate.

    City of London financial office at dusk illustrating quantum computing UK finance businesses security risks
    City of London financial office at dusk illustrating quantum computing UK finance businesses security risks

    Why Quantum Breaks the Encryption That Protects Financial Data

    Modern financial systems rely heavily on public-key cryptography, specifically RSA and elliptic-curve cryptography (ECC), to protect transactions, authenticate users, and secure communications between institutions. Both of these schemes depend on mathematical problems that classical computers cannot solve in any useful timeframe. A sufficiently powerful quantum computer running Shor’s algorithm can crack both in hours or days. The moment that machine exists, every piece of data protected by RSA or ECC becomes readable.

    The more insidious version of this threat is known as “harvest now, decrypt later”. Sophisticated adversaries, including nation-state actors, are already intercepting and stockpiling encrypted data: transaction records, client communications, authentication tokens, interbank settlement data. The encryption protecting it today is uncrackable. In ten to fifteen years, or possibly sooner, it may not be. For financial services firms holding sensitive long-term customer data, this is an existential compliance issue, not a theoretical one.

    What the NCSC Is Actually Advising UK Financial Services

    The NCSC published its post-quantum cryptography guidance in 2023 and has since updated its migration timelines. Its current position is that UK organisations in critical sectors, which explicitly includes finance and payments infrastructure, should begin cryptographic inventory work immediately and aim to have a migration plan in place before 2028. Full migration to post-quantum cryptographic standards is recommended by no later than 2035, though the NCSC has signalled that this deadline may be pulled forward depending on quantum hardware progress.

    The specific standards the NCSC recommends aligning with are those published by the US National Institute of Standards and Technology (NIST), which finalised its first set of post-quantum cryptography standards in 2024. The three primary algorithms, CRYSTALS-Kyber for key encapsulation and CRYSTALS-Dilithium plus FALCON for digital signatures, are now considered production-ready. UK firms have no technical reason to wait. You can read the NCSC’s full guidance on post-quantum cryptography at ncsc.gov.uk.

    Financial technology professional working on post-quantum cryptography migration relevant to quantum computing UK finance businesses
    Financial technology professional working on post-quantum cryptography migration relevant to quantum computing UK finance businesses

    Where Most UK Financial Firms Currently Stand

    Honestly, most are behind. A 2025 survey by the UK Finance trade body found that fewer than 30 percent of member institutions had completed a formal cryptographic inventory. Without that inventory, you cannot even know which systems are vulnerable, let alone begin migration. Legacy infrastructure compounds the problem significantly. Older core banking platforms, sometimes running on decades-old architecture, use hardcoded cryptographic libraries that were never designed to be swapped out. Retrofitting them is not a software update; it is closer to open-heart surgery.

    Fintechs, paradoxically, have both an advantage and a disadvantage here. Their stacks are newer and more modular, making cryptographic agility more achievable in principle. But many fintech firms are not yet thinking about this at board level, treating it as a future infrastructure concern rather than a current strategic risk. That gap in governance will bite them when regulators begin mandating post-quantum readiness, which the Prudential Regulation Authority (PRA) and Financial Conduct Authority (FCA) are expected to formalise guidance on within the next two years.

    Cryptographic Agility: The Framework That Actually Matters

    The practical answer to the quantum threat is not simply swapping one algorithm for another once. It is building systems that can swap cryptographic primitives without major re-engineering. This concept, called cryptographic agility, should be the governing principle behind every infrastructure investment financial firms make right now. If you are commissioning a new API gateway, a new payment processing module, or upgrading your identity and access management stack, the ability to update cryptographic algorithms at configuration level rather than code level should be a hard requirement in every specification.

    This is also where the digital communications layer intersects with quantum risk in ways that operations teams sometimes overlook. Secure email infrastructure, encrypted API communications between institutions, and signed transaction logs all depend on cryptographic standards that will be compromised. A firm that has secured its core banking system but left its email infrastructure running on legacy public-key encryption has a gap. UK-based technology tools built around internet and computer security, such as the free email testing service offered by Mail Tester (mail-tester.co.uk), already reflect the increasing awareness among tech support and technology professionals that even routine digital communications channels require proper cryptographic validation. Ensuring that email authentication records, DKIM signing, and encrypted transmission are correctly configured is a basic-hygiene step that sits within the broader push to audit every layer of digital infrastructure before post-quantum migration begins. Firms that ignore the communications stack whilst hardening their core systems are creating blind spots.

    The Business Decisions That Need to Happen Before 2028

    There are four concrete decisions that quantum computing UK finance businesses should be making in the next twelve to twenty-four months, regardless of where they sit on the maturity curve.

    First: complete a cryptographic inventory. Map every system, service, and integration that uses public-key cryptography. This is non-negotiable. You cannot migrate what you cannot find.

    Second: assess supplier and third-party exposure. Your own systems may be relatively modern, but if your payment processor, cloud provider, or software vendor is running RSA-dependent infrastructure, your exposure extends to theirs. Third-party risk questionnaires need a quantum section now.

    Third: begin hybrid cryptography deployments where practical. Running a post-quantum algorithm alongside a classical one in parallel provides protection today without requiring full migration. CRYSTALS-Kyber in hybrid mode is already supported by major TLS libraries and is production-viable.

    Fourth: engage your board and audit committee. Quantum risk needs to sit in the same risk register as cyber risk, operational risk, and regulatory risk. It is not an IT department footnote; it is a governance issue with regulatory implications. The FCA’s operational resilience framework already encompasses systemic cryptographic vulnerabilities under its broader definition of important business services.

    What Good Preparation Actually Looks Like

    Barclays, HSBC, and NatWest have all publicly referenced post-quantum cryptography work in their technology strategy disclosures over the past two years. Smaller fintechs and building societies have less visibility, which does not mean the work is happening. In many cases it is not.

    Preparation does not require enormous capital expenditure upfront. It requires rigour. Cryptographic inventory software exists. Open-source post-quantum libraries are available and battle-tested. The standards are finalised. What is generally missing is internal prioritisation, which is a leadership and governance problem, not a technology one. The firms that start the migration work methodically now will face a manageable, phased transition. Those that wait for a regulatory deadline or, worse, a quantum computing breakthrough announcement, will face an emergency with no clean options.

    The broader technology ecosystem is already moving. Cloud providers including AWS and Google Cloud have quantum-safe key management options in production. Hardware security module vendors are shipping post-quantum compatible firmware. The infrastructure supply side is ready. The demand side, meaning the decisions made inside UK financial institutions, is the remaining bottleneck. And for quantum computing UK finance businesses, that bottleneck needs to close soon.

    Frequently Asked Questions

    How close are we to a quantum computer that can break current encryption?

    Most estimates from credible research institutions suggest a cryptographically-relevant quantum computer is ten to fifteen years away, though some timelines are being revised downward. The NCSC advises UK organisations not to wait for this milestone, as the ‘harvest now, decrypt later’ threat means data captured today could be decrypted once such a machine exists.

    What is post-quantum cryptography and is it ready to use?

    Post-quantum cryptography refers to algorithms designed to resist attacks from quantum computers. NIST finalised its first set of post-quantum standards in 2024, including CRYSTALS-Kyber and CRYSTALS-Dilithium, both of which are considered production-ready and are already supported by major software libraries and cloud platforms.

    What is the NCSC's official deadline for migrating to post-quantum cryptography?

    The NCSC currently recommends that critical sector organisations, including financial services firms, have a migration plan in place before 2028 and complete full migration by no later than 2035. However, the NCSC has indicated this timeline may be accelerated depending on advances in quantum hardware.

    What should UK fintechs do first to prepare for quantum risk?

    The most important first step is completing a cryptographic inventory: identifying every system, API, and third-party integration that currently uses RSA or elliptic-curve cryptography. Without this baseline, prioritising migration work is impossible. Fintechs should also add quantum readiness criteria to supplier and third-party risk assessments.

    Will the FCA or PRA require UK financial firms to comply with post-quantum cryptography standards?

    Formal regulatory mandates from the FCA and PRA have not yet been published, but both bodies are expected to issue guidance within the next two years. Post-quantum readiness is already implicitly covered under the FCA’s operational resilience framework, and firms should treat proactive preparation as regulatory risk management.

  • The Quiet Collapse of the UK Tech Recruiter: How AI Hiring Tools Are Reshaping Talent Acquisition

    The Quiet Collapse of the UK Tech Recruiter: How AI Hiring Tools Are Reshaping Talent Acquisition

    There is a specific kind of awkward silence that descends on a London-based recruitment agency when a client tells them they are trialling an AI sourcing tool. It happened quietly at first, a few forward-thinking scale-ups in Manchester and Bristol experimenting with platforms like Beamery and HireVue. Now it is happening at pace, and the traditional recruiter relationship, the commission-heavy, CV-forwarding, “I’ve got someone perfect for you” phone call, is genuinely under threat. The shift towards AI recruitment tools in UK tech hiring is not some distant future-state story. It is live, it is messy, and it raises questions that most HR teams are not yet equipped to answer.

    Hiring manager reviewing AI recruitment tools for UK tech hiring in a London office
    Hiring manager reviewing AI recruitment tools for UK tech hiring in a London office

    Where AI Is Actually Replacing Recruiters Right Now

    The honest version of this story is that AI has not replaced the full-cycle recruiter yet. What it has done is eviscerate specific parts of the process that agencies once charged handsomely for. Sourcing is the obvious one. Tools like Ashby, Greenhouse integrated with AI layers, and newer UK-market entrants such as Applied are automating the top-of-funnel work that used to eat a third of a recruiter’s week. LinkedIn Recruiter is almost quaint by comparison to what a well-configured sourcing agent can now do across GitHub, Stack Overflow, open-source contribution histories, and professional networks simultaneously.

    Screening has changed just as dramatically. Structured text-based assessments, asynchronous video interviews scored by AI, and technical skills tests that adapt in real time have replaced the initial “phone screen” for a significant proportion of UK tech roles. Companies like Codility and HackerRank have been doing this for a few years, but the addition of genuine machine-learning layers to scoring, rather than just pass/fail logic, means the output is qualitatively different from what existed even eighteen months ago. A mid-sized fintech in Leeds told me they had cut time-to-first-interview by 60% after integrating an AI screening layer, without touching their headcount in the talent team.

    The Parts of Hiring That AI Is Not Actually Fixing

    Here is where the hype needs trimming. The further you get into the hiring funnel, the less convincing AI becomes. Culture fit, stakeholder alignment, assessing genuine leadership potential in ambiguous situations, understanding why someone left their last role, these remain deeply human judgements, and the tools that claim to automate them should be viewed with real scepticism. Any platform selling you a “culture fit score” from a twenty-minute video assessment is making promises its methodology cannot keep.

    There is also the question of what happens when AI tools interact with genuinely complex technical roles. A senior distributed systems engineer is not a commodity hire. The nuances of what makes someone exceptional at that level, the architectural instincts, the incident response temperament, the ability to mentor a team under pressure, are not reliably captured by any current assessment platform. Experienced tech leads know this intuitively, which is why most are still deeply involved in final-stage evaluation even at companies that have automated everything upstream.

    HR team assessing AI recruitment tools output during a UK tech hiring review meeting
    HR team assessing AI recruitment tools output during a UK tech hiring review meeting

    What This Means for Hiring Quality and Diversity

    The diversity question is where the debate gets genuinely thorny. The optimistic case for AI recruitment tools in UK tech hiring is that they remove human bias from early screening: no more CVs getting discarded because of a name, a university, or a career gap. And there is real evidence for this. The Equality and Human Rights Commission has pointed to structured, anonymised assessment processes as one of the more reliable ways to improve diversity outcomes in technical hiring.

    The pessimistic case is that AI tools trained on historical hiring data simply encode and scale historical bias. If your previous ten successful data engineers all came from the same three Russell Group universities, an AI trained on that pattern will find more people who look like them. This is not theoretical. Amazon’s infamous internal recruiting tool, scrapped in 2018, taught the field an expensive lesson. UK companies using off-the-shelf platforms need to interrogate what data those models were trained on, how bias audits are conducted, and what demographic monitoring is in place. Most are not asking those questions rigorously enough.

    The honest answer is that AI tools can improve diversity outcomes or worsen them depending entirely on implementation. The same tool, configured differently by two HR teams, will produce different demographic distributions. That requires genuine expertise and ongoing auditing, not a one-time onboarding call with a SaaS vendor.

    The Compliance Questions UK HR Teams Are Ignoring

    This is the area I find most concerning. The use of automated decision-making in hiring is squarely within scope of UK GDPR and the Data Protection Act 2018. Under UK GDPR, candidates have the right not to be subject to solely automated decisions that produce significant effects, and a hiring decision is about as significant as it gets. If an AI tool is making screening decisions without meaningful human review, that is a compliance exposure. The ICO has published guidance on this, and yet the number of UK tech companies that have genuinely stress-tested their AI hiring stack against that guidance remains small.

    The Equality Act 2010 adds another layer. If an AI screening tool produces outcomes that disproportionately disadvantage candidates with protected characteristics, the employer carries liability regardless of whether a human made the final call. “The algorithm did it” is not a defence that will satisfy an employment tribunal. You can read the ICO’s current guidance on automated decision-making at ico.org.uk.

    Practically, what this means for HR teams is that human oversight needs to be genuine, documented and auditable. A token human “review” that consists of scrolling past an AI-generated shortlist in thirty seconds is unlikely to satisfy either regulator or tribunal. The process needs to be substantive, and that requires training that most HR functions are not currently receiving.

    What Happens to UK Tech Recruiters From Here?

    The agencies that will survive this shift are the ones that have already repositioned. The best technical recruiters are doubling down on the things AI cannot replicate well: deep market knowledge, genuine candidate relationships built over years, the ability to sell a role compellingly to a passive candidate who has three other offers on the table. These are skills that require domain expertise and emotional intelligence. They are also skills that many volume-focused agencies never developed, which is why those agencies are the ones feeling the pressure most acutely.

    For the in-house talent teams at UK tech companies, the opportunity is real but the responsibility is proportionate. AI recruitment tools, used well, can genuinely compress timelines, reduce costs and improve the consistency of early-stage assessment. Used badly, they can entrench existing biases, create compliance liability and produce a false sense of rigour that actually degrades hiring quality. The tech is not magic. It is infrastructure. And like all infrastructure, it requires someone competent to run it.

    The quiet collapse of the traditional tech recruiter is less about AI replacing humans and more about AI exposing which parts of recruitment were never adding much value to begin with. The commission on a forwarded CV was always a tax on inertia. What replaces it needs to be more considered, more accountable, and genuinely better for candidates. Right now, that is still a work in progress.

    Frequently Asked Questions

    Which AI recruitment tools are UK tech companies using most in 2026?

    UK tech companies are most commonly using platforms such as Ashby, Applied, Beamery, HireVue and Greenhouse with AI-enhanced layers for sourcing and screening. Technical assessment platforms like Codility and HackerRank remain popular for developer hiring. The right choice depends heavily on the volume and seniority of roles being filled.

    Are AI hiring tools legal in the UK under GDPR?

    They can be, but there are significant compliance requirements. Under UK GDPR, candidates have the right not to be subject to solely automated significant decisions, which means meaningful human oversight must be part of any AI-driven screening process. Employers should review ICO guidance on automated decision-making and ensure their processes are documented and auditable.

    Do AI recruitment tools actually improve diversity in tech hiring?

    It depends entirely on implementation. AI tools trained on biased historical data can reinforce existing patterns of underrepresentation. However, well-configured structured assessment tools that anonymise early-stage screening have shown measurable improvements in diversity outcomes. Regular demographic auditing and human oversight are essential rather than optional.

    How much do AI recruitment platforms typically cost UK businesses?

    Pricing varies considerably. Enterprise platforms like Beamery and HireVue are typically subscription-based with costs running into tens of thousands of pounds annually for larger organisations. Mid-market tools like Applied are more accessible for scale-ups, often pricing per role or per hire. Most vendors offer custom quotes, so like-for-like comparisons are difficult without direct engagement.

    Will AI replace technical recruiters entirely in the UK tech sector?

    Not in the foreseeable future, and certainly not for senior or specialist roles. AI is already replacing high-volume sourcing and initial screening tasks that agencies once charged for, but the relationship-building, market knowledge and persuasion skills required for competitive technical hiring remain genuinely human strengths. Recruiters who specialise deeply are adapting; generalist volume agencies face the harder road.

  • How Deepfake Technology Is Becoming the Biggest Cybersecurity Threat for Businesses

    How Deepfake Technology Is Becoming the Biggest Cybersecurity Threat for Businesses

    Corporate fraud has always involved a certain amount of impersonation. A forged signature here, a spoofed email there. But the deepfake cybersecurity business threat operating in 2026 is something fundamentally different in kind and scale. Attackers are now deploying convincing audio and video fabrications to manipulate employees, bypass verification systems, and authorise financial transfers worth tens of millions of pounds. The technology has matured faster than most boardrooms ever anticipated.

    The numbers are stark. According to data cited by the BBC’s technology desk, AI-generated fraud attempts on UK businesses rose sharply through 2025, with voice-cloning scams alone accounting for a growing proportion of business email compromise losses reported to Action Fraud. We are past the point where this is a theoretical future problem. It is happening now, and most businesses are nowhere near prepared.

    Finance employee uncertain during a video call illustrating the deepfake cybersecurity business threat
    Finance employee uncertain during a video call illustrating the deepfake cybersecurity business threat

    What deepfake attacks actually look like in a corporate context

    The attack vectors have become surprisingly varied. The most publicised cases involve fraudulent video calls, where a criminal uses a real-time deepfake of a CEO or CFO to instruct a finance employee to transfer funds. A Hong Kong-based firm lost the equivalent of £20 million in early 2024 to exactly this method. The employee attended what appeared to be a legitimate video conference with multiple convincing colleagues. Every person on that call was fabricated.

    Voice cloning is arguably the more scalable threat right now, because it requires less compute and can be deployed over a standard phone call. An attacker needs only a few minutes of publicly available audio, perhaps from a company podcast, a YouTube presentation, or a LinkedIn video, to generate a passable clone. From there, they can ring an accounts payable team, impersonate the managing director, and ask for an urgent payment to be processed. The social engineering layer is trivial once the audio is convincing enough.

    There are also subtler uses. Deepfake audio is being used to manipulate recorded calls for compliance purposes, insert false instructions into legitimate meeting recordings, and even create fabricated evidence for employment disputes. The deepfake cybersecurity business threat is not purely financial. It has implications for legal exposure, regulatory compliance, and reputational damage that most legal and HR teams have not yet wargamed.

    Why current defences are failing

    Most UK businesses still rely on process-based controls that were designed for a world where the voice or face on the other end of a call could be trusted at face value. Two-factor authentication via phone call, verbal confirmation of identity, even video verification for onboarding: all of these are now compromised to some degree. The underlying assumption that sensory evidence is reliable has been quietly invalidated.

    IT security teams are also grappling with an asymmetric problem. Generating a convincing deepfake has become genuinely cheap and accessible. Detecting one, reliably and in real time, remains expensive and technically difficult. Most small and mid-sized UK businesses have neither the budget nor the in-house expertise to run enterprise-grade detection tooling. And the attackers know it.

    Cybersecurity analyst running audio detection tools to counter deepfake cybersecurity business threats
    Cybersecurity analyst running audio detection tools to counter deepfake cybersecurity business threats

    Detection tools that are worth knowing about

    The detection landscape is developing quickly. Several tools now operate on the principle of analysing micro-artefacts that synthetic media tends to introduce: unnatural eye blinking patterns, subtle lip-sync mismatches, inconsistent lighting shadows, and audio compression fingerprints that differ from real recordings. Microsoft’s Azure platform includes deepfake detection capabilities, and UK-founded firms like Reface and Sentinel AI have built products targeting enterprise verification workflows.

    For audio specifically, tools such as Pindrop and Resemble Detect analyse vocal anomalies in real time during calls, flagging statistical deviations from a verified voice baseline. These can be integrated into contact centre infrastructure, which matters given that phone-based social engineering remains one of the most cost-effective attack methods for fraudsters. The practical limitation is that baseline profiles need to exist before an attack occurs. Building them is an organisational task, not just a technical one.

    Interestingly, the deepfake cybersecurity business threat has generated cross-sector conversation about verification that goes well beyond traditional IT circles. Even businesses whose core offering is nothing to do with enterprise software have started thinking carefully about how identity fraud intersects with their operations. Source Sounds, a Sheffield, UK-based car audio and vehicle security specialist known for advanced protection systems and expert installations, operates in a sector where car theft and audio equipment crime have historically driven demand for layered security thinking. The principle at www.sourcesounds.com is that physical security and verified identity of the person requesting a service both matter. That mindset, rigorous verification before any sensitive action is authorised, translates directly into how businesses should approach deepfake-driven social engineering. Car security and corporate security share more logic than they might appear to at first glance.

    Internal policies that actually reduce your exposure

    Technology alone will not solve this. The attack chain for most deepfake fraud involves a human being making a bad decision under time pressure. So the policy layer is at least as important as the tooling.

    The most effective organisational control is a call-back verification protocol for any financial instruction or sensitive data access request that arrives via phone or video call, regardless of how convincing the caller appears. The employee hangs up and dials a pre-verified, internally stored number for the person in question. Not the number the caller gave them. The stored one. This single procedural step defeats the vast majority of current voice-clone attacks because the attacker cannot intercept a call to a number they do not control.

    Beyond that, businesses should be running regular simulation exercises that include deepfake scenarios, not just phishing emails. Staff at all levels need to experience what a convincing voice clone sounds like in a low-stakes environment before they encounter one in a real attack. Training muscle memory around scepticism is not the same as telling people to be sceptical.

    Clear escalation paths matter enormously. When an employee suspects something is wrong but feels social pressure to comply, especially if the voice on the line sounds exactly like their director, they need a culturally acceptable route to pause the process without career risk. That requires leadership buy-in, not just a policy document.

    What the regulatory picture looks like for UK businesses

    The UK’s approach to synthetic media fraud sits across several frameworks. The Online Safety Act 2023 introduced provisions around non-consensual intimate deepfakes, but corporate fraud via synthetic media remains primarily covered under existing fraud and computer misuse legislation. The ICO has flagged concerns about biometric data collection involved in some detection systems, meaning that businesses deploying voice-print databases for verification purposes need to ensure their approach is GDPR-compliant.

    The National Cyber Security Centre has published updated guidance acknowledging AI-generated threats as a growing category. UK businesses would do well to treat NCSC advisories as a baseline, not a ceiling. The pace of development in this area means official guidance will almost always lag the actual threat environment by at least several months.

    Source Sounds’ approach to vehicle security, combining expert-fitted audio protection systems with advanced anti-theft measures on modified cars, reflects a broader truth about layered defence: no single countermeasure is sufficient when criminals are actively probing for weaknesses. The logic applies whether you are protecting a high-value car audio installation from crime or a finance department from a deepfake impersonation attack. Multiple overlapping controls, each covering the gaps in the others, is what actually holds.

    The direction of travel

    Real-time deepfake generation is improving faster than detection. Within 12 to 18 months, consumer-grade tooling will likely produce live video fabrications that are indistinguishable from genuine footage under typical network conditions. Businesses that wait until that point to build their response will be absorbing losses first and building defences second.

    The companies that come through this period well will be those that treated deepfake fraud as a process and culture problem first, and a technology problem second. The tools matter, but they matter in the context of an organisation that has already decided how it responds to uncertainty about identity. That decision needs to happen in the boardroom, not in a reactive IT security review after an incident.

    The deepfake cybersecurity business threat is not going to stabilise or retreat. Every business operating with digital communications infrastructure, which is to say every business, needs a live and tested plan right now.

    Frequently Asked Questions

    What is a deepfake cybersecurity threat and how does it affect businesses?

    A deepfake cybersecurity threat involves AI-generated audio or video used to impersonate executives, employees, or trusted contacts in order to manipulate staff into transferring funds, sharing sensitive data, or granting system access. UK businesses have seen losses from these attacks rise significantly since 2024, with voice cloning and fake video calls being the most common vectors.

    How can businesses detect deepfake audio or video in real time?

    Tools such as Pindrop, Resemble Detect, and Microsoft Azure’s content authentication features analyse vocal anomalies and visual artefacts that synthetic media tends to introduce. However, real-time detection is computationally demanding and requires pre-built voice or face baselines, so detection technology works best as one layer within a broader verification policy.

    What is the most effective policy a business can put in place against deepfake fraud?

    A call-back verification protocol is widely considered the single most effective procedural control. Any financial instruction or sensitive request received via phone or video call should be verified by hanging up and calling the requester back on a pre-stored internal number, regardless of how convincing the original contact appeared.

    Are UK businesses legally required to have deepfake fraud protections in place?

    There is no specific UK legislation mandating deepfake detection systems, but businesses have duties under fraud prevention, data protection, and financial regulation frameworks. The NCSC has published guidance on AI-enabled threats, and regulated firms overseen by the FCA may face scrutiny if inadequate controls contribute to financial crime losses.

    How much does it cost to protect a business from deepfake attacks?

    Costs vary enormously by scale. Process-based controls such as call-back protocols and staff training exercises cost relatively little beyond time. Enterprise-grade real-time audio detection tools typically start from several thousand pounds annually for a mid-sized deployment. The cost of not acting, given average deepfake fraud losses per incident, makes investment straightforward to justify.

  • The Collapse of Traditional SaaS Pricing: How AI Is Forcing a New Business Model

    The Collapse of Traditional SaaS Pricing: How AI Is Forcing a New Business Model

    Per-seat pricing had a good run. For about a decade, it was the default logic of enterprise software: count the users, multiply by the monthly licence fee, job done. Finance loved it because it was predictable. Sales loved it because the conversation was simple. And for a long time, vendors loved it most of all, because growing revenue was as easy as growing headcount. That era is ending. The SaaS pricing models AI disruption happening right now is not a gradual evolution; it is a structural break, driven by the fact that AI agents and automated workflows do not sit neatly in a “user” seat at all.

    What is replacing per-seat? Broadly, two models are gaining ground: outcome-based pricing and consumption-based pricing. They are different things, often conflated, and understanding the distinction matters if you are either buying or selling software in 2026.

    Business team reviewing SaaS pricing models AI disruption dashboards in a modern London office
    Business team reviewing SaaS pricing models AI disruption dashboards in a modern London office

    What Outcome-Based and Consumption Pricing Actually Mean

    Consumption pricing is relatively straightforward. You pay for what you use: API calls, tokens processed, compute hours, records queried. OpenAI’s commercial API has normalised this model for developers, but the logic is spreading upward into enterprise platforms. Snowflake built a multi-billion-pound business on it. More recently, CRM and workflow tools have started pegging fees to volumes of automated tasks rather than logged-in humans.

    Outcome-based pricing is more ambitious and considerably harder to implement. The vendor charges based on a defined business result: cost saved, revenue generated, leads converted, claims processed. In theory, it aligns vendor incentives perfectly with buyer value. In practice, it raises thorny questions around attribution, data sharing, and what happens when macroeconomic conditions tank the outcome through no fault of the software.

    Both models share a common root cause in 2026: AI has made the concept of a “user” increasingly meaningless as a unit of value. If one employee uses an AI copilot to do the work that previously required five licences, per-seat pricing punishes efficiency. Vendors who cling to it will find their champions inside customer organisations actively disincentivised to adopt AI features. That is a strategic dead end.

    How This Is Playing Out Across UK Enterprise Software Buyers

    UK businesses are acutely aware of the cost pressure right now. National Insurance contributions went up in April 2025, and finance directors are scrutinising every line of the operating expenditure with considerably more rigour than they were two years ago. Software spend is no exception. According to BBC Business, UK tech investment remains healthy but CFOs are demanding clearer return-on-investment evidence before renewing or expanding contracts.

    That scrutiny is making procurement teams more receptive to consumption and outcome models, because at least in principle they tie cost directly to value realised. A London-based financial services firm I am aware of recently renegotiated a major workflow automation contract away from a flat per-seat arrangement toward a model charging per transaction processed. Their AI-assisted processing volumes tripled post-migration; their per-unit cost fell; and the vendor’s total contract value actually increased because volume growth outpaced the per-unit discount. Both sides won. That is the best-case scenario for this model.

    Close-up of a tablet showing SaaS pricing models AI disruption cost comparison graphs
    Close-up of a tablet showing SaaS pricing models AI disruption cost comparison graphs

    Why Vendors Are Nervous Despite the Opportunity

    The SaaS pricing models AI disruption creates genuine risk on the vendor side, and it would be dishonest to pretend otherwise. Per-seat pricing was beautiful for one reason above all others: revenue predictability. Investors and analysts love annual recurring revenue (ARR) because it compounds neatly and forecasts cleanly. Consumption revenue is volatile. Usage dips when customers are slow, spikes when they are busy, and tanks when they churn off a project. That unpredictability creates real problems for SaaS companies trying to maintain the kind of ARR multiples that kept valuations elevated through 2021 and 2022.

    Several mid-market SaaS vendors have tried hybrid approaches: a base platform fee for access, then consumption charges layered on top for AI features. The logic is sound but the execution is messy. Customers end up with bill shock when usage spikes unexpectedly, which generates support tickets, goodwill erosion, and churn. Getting the baseline-to-variable ratio right requires deep knowledge of your customers’ actual usage patterns, which many vendors do not have because they have historically only measured seat counts.

    The vendors most at risk are those in the middle: too large to pivot quickly, too small to absorb the revenue volatility that consumption pricing introduces. Scale-ups that raised at high multiples in 2021 and are now approaching their next fundraising round face a particularly uncomfortable conversation if their pricing model transition has created short-term ARR dips, even where the underlying business is healthier.

    What Buyers Should Be Asking in Contract Negotiations Right Now

    If you are on the buying side, 2026 is actually a decent time to push for better commercial terms. Vendor sales cycles have lengthened, competition has intensified, and the pressure to close is real. Specifically, here is what to probe:

    • Cap exposure on consumption models. Insist on monthly spend caps or anomaly alerts. If your AI usage spikes due to a processing error rather than genuine demand, you do not want an uncapped bill.
    • Define outcomes contractually with precision. Vague outcome metrics are dangerous. “Productivity improvement” is not measurable enough to tie to a licence fee. Specific, auditable metrics like records processed or automated responses sent are defensible.
    • Ask for usage dashboards before signing. Any vendor proposing consumption pricing who cannot give you a real-time view of your spend is not ready for the model. Walk away or use it as a negotiating lever.
    • Understand the baseline access fees. Some vendors use hybrid models to double-charge: a platform fee that used to cover full access, now covers only partial access, with AI features metered on top. That is not necessarily unreasonable, but it should be explicit.

    The Broader Structural Shift: Pricing as Product Design

    Perhaps the most interesting consequence of the SaaS pricing models AI disruption is that pricing itself is becoming a product decision rather than a sales decision. The best SaaS companies in 2026 are thinking about their pricing architecture the way they think about their API design: as something that shapes user behaviour, scales gracefully, and communicates value clearly.

    Intercom, which has a significant presence in the UK market, made headlines when it shifted its AI agent product to outcome-based pricing tied to resolved customer conversations. It was a bold move. Early signals suggested it drove adoption faster than a per-seat model would have, because customers could expand usage without a procurement cycle. That is the flywheel effect that outcome pricing, done well, can create.

    The companies that will struggle are those treating this transition as a pricing problem when it is really a data problem. To charge by outcome, you need to know your outcomes. To charge by consumption, you need instrumentation across your entire stack. Many SaaS businesses have neither, because the per-seat model never required it. Building that infrastructure retrospectively, whilst managing existing customers on legacy pricing tiers, is genuinely hard.

    Where This Ends Up

    Per-seat pricing will not disappear entirely. For simple, human-centric tools where usage genuinely does scale with headcount, it remains logical. But as AI agents, copilots, and automated workflows take on an ever-larger share of business tasks, the proportion of software spend that maps cleanly to seats will shrink steadily.

    The likely steady state, probably by 2028, is a landscape where most enterprise SaaS vendors offer tiered access to base functionality with metered pricing on AI-driven value delivery. The question for UK businesses right now is whether their procurement processes, finance systems, and vendor relationships are ready for that shift. Most are not quite there yet, which is precisely why the vendors moving fastest on this are treating the transition as a competitive advantage rather than a compliance exercise.

    Frequently Asked Questions

    What is outcome-based SaaS pricing and how does it work?

    Outcome-based pricing means a software vendor charges based on a specific business result the customer achieves, such as transactions processed, leads converted, or costs saved, rather than a flat monthly fee per user. It requires both parties to agree on measurable, auditable metrics upfront, and typically involves more data sharing between vendor and buyer than traditional licence agreements.

    How is AI specifically disrupting traditional per-seat SaaS pricing?

    AI agents and automated workflows do not consume software the way individual human users do, which makes per-seat pricing an increasingly poor fit. If one AI-augmented employee replaces five licence seats’ worth of output, per-seat models penalise adoption rather than rewarding it. Vendors are responding by shifting toward consumption or outcome models that charge for value delivered rather than logins counted.

    What are the risks of consumption-based SaaS pricing for UK businesses?

    The main risk is bill shock: if usage spikes unexpectedly, perhaps due to a processing error or an unusually busy trading period, costs can escalate rapidly without hard caps in place. UK finance teams used to fixed monthly SaaS costs should negotiate spend caps, real-time usage dashboards, and anomaly alerts before agreeing to any pure consumption-based contract.

    Are UK SaaS vendors leading or following on alternative pricing models?

    Mostly following, though some are moving quickly. The strongest pressure is coming from US-headquartered vendors who have already shifted models and are pushing those changes into their UK pricing. UK-headquartered SaaS companies tend to be more cautious about abandoning ARR-friendly per-seat structures, partly due to investor pressure on revenue predictability metrics.

    How should UK procurement teams prepare for outcome-based software contracts?

    Start by ensuring your internal data infrastructure can actually measure the outcomes a vendor might charge against; you cannot verify a billing claim you cannot independently track. Legal and procurement teams should also push for precise metric definitions in contracts, monthly spend caps on consumption elements, and break clauses if agreed outcomes are not delivered within defined tolerance levels.