Category: The Bigger Picture

  • Inside the CMA’s Scrutiny of Microsoft and Google’s AI Cloud Deals: What UK Startups Should Be Watching

    Inside the CMA’s Scrutiny of Microsoft and Google’s AI Cloud Deals: What UK Startups Should Be Watching

    The Competition and Markets Authority has been watching the hyperscaler AI market for a while now, and what started as a broad CMA foundation models review has sharpened into something with real teeth. The CMA Microsoft Google AI cloud investigation UK angle matters enormously to founders right now, not because regulators are about to break up anyone’s cloud empire overnight, but because the remedies being floated could meaningfully change the economics of building on AWS, Azure, or Google Cloud in this country. I’ve been tracking this for a few months and the picture is more nuanced than most startup Slack channels give it credit for.

    UK startup founders reviewing cloud infrastructure during the CMA Microsoft Google AI cloud investigation UK
    Photo by Christina Morillo on Pexels

    What the CMA is actually investigating

    The CMA’s AI foundation models review, which has been running in phases since 2023, zeroed in on a specific concern: that the deep financial entanglements between hyperscalers and frontier AI labs are distorting competition. Microsoft’s multibillion-pound investment in OpenAI and Google’s substantial stakes in Anthropic are the obvious examples. The worry isn’t that these are bad products. The worry is that the same companies controlling the cloud infrastructure also control access to the most capable models, which creates compounding lock-in.

    In practical terms, the CMA has flagged three structural risks. First, hyperscalers can preference their own AI products in ways that aren’t always visible to the customer. Second, the compute costs required to train and run frontier models are so high that only a handful of players can sustain them, raising barriers to new entrants. Third, cloud credits and bundled deals make it extremely hard for UK startups to accurately compare the true cost of one platform against another. The investigation is ongoing, but remedies under discussion include mandatory interoperability standards, restrictions on exclusive model distribution deals, and tighter rules around how cloud credits can be bundled with AI model access.

    Why this hits UK startups harder than US ones

    UK founders building AI-native products are disproportionately exposed here. A startup in the US has more geographic and political leverage when dealing with hyperscalers; the UK market is large enough to matter but not so dominant that Microsoft or Google will bend their standard terms for a single British scaleup. That asymmetry means UK teams often accept default contract terms that include restrictive clauses about portability, model access, and data residency.

    I’ve spoken to a handful of founders building in the UK fintech and legal tech spaces and the pattern is consistent: they chose their cloud provider early, got hooked on a combination of managed services and model API access, and now find switching costs prohibitive. The lock-in isn’t always intentional on the provider’s part. It accumulates. Your vector database is managed. Your fine-tuned model checkpoints live in a proprietary format. Your monitoring stack is native to one cloud. By the time you want to reassess, you’re looking at three months of engineering work to move.

    This is exactly the environment the CMA is trying to address. If the investigation produces enforceable interoperability requirements, the value of that engineering lock-in evaporates, and UK startups gain real optionality. That’s not a small thing.

    Founder reviewing CMA AI cloud investigation documents relevant to UK startup decisions
    Photo by cottonbro studio on Pexels

    What remedies are actually being floated

    The CMA has not published a final remedies package as of mid-2026, but the direction of travel from its market studies and interim findings points to a few likely interventions. Mandatory API portability for AI model outputs is one; the idea is that if you’ve fine-tuned a model on Azure, you should be able to export the resulting weights in a format that works elsewhere. Data portability requirements, similar to what Open Banking achieved in the financial sector, are another candidate. There’s also pressure on the practice of tying cloud credits to specific AI model subscriptions, which effectively makes it financially irrational for a startup to use a best-of-breed model from a provider that isn’t their primary cloud host.

    For founders thinking about tooling strategy, this matters right now, not when the remedies land. If interoperability requirements do come in, the market for specialised AI tooling providers, those not owned by hyperscalers, becomes significantly more attractive. Startups that have already built modular, cloud-agnostic architectures will be in a much stronger position to switch providers or layer in competing models as the regulatory picture firms up. Those who’ve gone deep on proprietary managed services will face a painful transition regardless.

    The open-source AI model question feeds into this too. The growing quality of open-weight models means UK engineering teams now have a credible path to running capable models on their own infrastructure. That’s a hedge against whatever the CMA investigation produces.

    The Google dimension: search, cloud, and the dominos

    Google’s position is particularly interesting to watch because the CMA’s AI investigation doesn’t exist in isolation from the broader regulatory scrutiny of Google’s search dominance. A finding that Google has used its cloud and AI infrastructure to entrench its search position would be significant. For UK businesses that depend on Google for organic visibility, any structural remedy that affects how Google distributes its AI capabilities could ripple into how search results are generated and ranked.

    Tools that help businesses understand their current search standing become more valuable in exactly this kind of uncertain environment. Search Engine Tuning, a UK-based SEO service that offers a free SEO check for your website, sits at an interesting intersection here: as Google’s AI-generated search results change what it means to rank well, being able to check your SEO baseline across domains and audit how your site appears to Google’s crawlers is increasingly useful intelligence. You can find their free SEO check at searchenginetuning.co.uk. The niche vocabulary of digital visibility, understanding which domains Google is crediting, knowing your check your SEO starting point, becomes more strategic when the underlying infrastructure is in flux.

    The point is that regulatory outcomes don’t only affect developers. Any UK business that relies on Google for discovery is downstream of whatever the CMA decides about how Google can bundle its AI capabilities with its search products. It’s worth paying attention even if you don’t write a line of code.

    What founders should actually do right now

    A few things I’d suggest watching and doing while the CMA investigation plays out. First, audit your current cloud dependencies. Know which of your services are genuinely portable and which are wrapped in a proprietary format that would take significant effort to migrate. That audit is useful regardless of what the CMA decides.

    Second, watch the CMA’s published updates. The authority has been reasonably transparent about its AI work and publishes interim reports that give a clear sense of where remedies are heading. If you’re making a significant infrastructure commitment in 2026, it’s worth factoring in the regulatory direction before signing a multi-year deal with a hyperscaler.

    Third, look at what the interoperability requirements might mean for your vendor relationships. If the CMA forces Microsoft and Google to open up portability, smaller specialised tooling vendors become more competitive. Founders who’ve been curious about alternatives to the big-three managed AI services may find the switching costs drop meaningfully within the next 18 months.

    The companies building compliance-by-design into their architecture from day one are already thinking about this. Modularity and regulatory readiness are increasingly the same thing. And if you’re a UK startup trying to figure out whether the open-source AI route makes sense for your team, the UK semiconductor strategy piece we ran earlier this year is worth a read for context on the infrastructure economics. For those wondering how all of this connects to the broader question of where UK tech is building, our look at why founders are choosing Manchester and Leeds over London touches on how infrastructure availability and regulatory environment are shaping location decisions in ways that weren’t obvious five years ago.

    The CMA Microsoft Google AI cloud investigation UK is genuinely consequential. Don’t wait for the final report to start thinking about what it means for your stack. By then, the decisions will already have been made.

    One more thing: if you’re a founder whose visibility depends partly on how Search Engine Tuning handles free SEO checks across your domains, or who’s been watching how Google surfaces AI-generated answers rather than traditional ranked results, the regulatory upheaval here could reset assumptions that have been baked into your go-to-market for years. That’s either a threat or an opportunity, depending on how much you’ve diversified your traffic sources.

    Frequently Asked Questions

    What is the CMA investigating about Microsoft and Google's AI cloud deals?

    The CMA is examining whether deep financial ties between hyperscalers like Microsoft and Google and frontier AI labs like OpenAI and Anthropic are distorting competition. Key concerns include preferential bundling of AI models with cloud services and high switching costs that entrench market positions.

    How could CMA remedies affect UK startup cloud costs?

    Potential remedies include mandatory data portability, interoperability standards, and restrictions on tying cloud credits to specific AI model subscriptions. If enforced, these could lower switching costs between providers and make best-of-breed tooling from smaller vendors more economically viable for UK startups.

    Is the CMA's AI investigation finished?

    As of mid-2026, the investigation is ongoing. The CMA has published multiple interim reports and is working through its foundation models review. Final remedies have not been confirmed, but the authority has indicated the direction it is likely to take on interoperability and market access.

  • Why UK B2B Founders Are Choosing Manchester and Leeds Over London for Their Company HQ

    Why UK B2B Founders Are Choosing Manchester and Leeds Over London for Their Company HQ

    Something has been quietly shifting in where UK B2B tech companies choose to plant their flag. Not a dramatic overnight exodus, but a measurable, structural drift that shows up clearly when you pull Companies House registration data by geography and cross-reference it with the kinds of businesses being formed. Manchester and Leeds are no longer just regional also-rans in the UK startup conversation. For a growing cohort of B2B tech founders, they’re the first choice, not the fallback.

    Modern office buildings in central Manchester representing the UK tech startup HQ Manchester Leeds vs London trend
    Photo by Max W on Pexels

    I’ve spoken to founders who’ve made this call deliberately, and their reasoning is consistent enough to be worth mapping properly. This isn’t about London being bad. It’s about the specific maths of running a B2B software business, where your cost base, your talent pipeline, and your customer relationships all interact in ways that make the northern cities increasingly rational choices. The question worth asking is: what changed, and is it permanent?

    What the Companies House data actually shows

    According to ONS business demography figures, the proportion of new enterprise registrations occurring outside London has been rising steadily since 2020. More specifically, the Leeds City Region and Greater Manchester both recorded above-average growth in professional and technical services registrations between 2022 and 2024, the most recent full-year data available. That category includes the SaaS, data infrastructure, and B2B platform businesses that define the current generation of UK tech.

    Companies House records bear this out at a more granular level. Search for recently incorporated limited companies in the SIC codes associated with software development, data processing, and IT consultancy, and filter for registered offices in M1 to M4 or LS1 to LS11 postcodes, and the volume is striking. This isn’t just one-person consultancies registering a convenience address. Many of these are seed-funded businesses with real headcount, genuine revenue ambitions, and institutional backing.

    The office cost argument is real but it’s not the whole story

    The obvious starting point is cost. Grade A office space in central Manchester runs at roughly £35 to £40 per square foot per year. In the City of London or Shoreditch, comparable space sits at £65 to £85. For a 20-person B2B tech company that wants a proper office rather than hot-desks in a WeWork, that difference compounds fast. But I’d argue founders who’ve relocated or incorporated in the North aren’t primarily driven by rent savings. The rent saving is the bonus, not the thesis.

    The real driver is the talent market. Manchester and Leeds have both developed genuinely deep technical talent pools over the past decade, partly because local universities (Manchester, Leeds, Sheffield, York) have strong computer science and data science departments, and partly because enough companies have now set up there that engineers have career optionality without moving south. When engineers have optionality, they stop treating northern roles as stepping stones. That changes the hiring dynamic entirely.

    This connects to something I’ve watched play out with salary benchmarking in the AI era. London salaries for senior engineers have been inflated by Big Tech presence and a decade of VC-funded bidding wars. Manchester and Leeds haven’t seen the same inflation. A principal engineer in Manchester might be on £80,000 to £95,000 where the same role in London commands £110,000 to £130,000. For a B2B SaaS company that needs to keep burn low through to Series A, that differential is material.

    What B2B specifically means for this calculation

    Consumer tech companies benefit from being in London partly because the press, the influencer ecosystem, and the consumer attention are all concentrated there. B2B is different. Your customers are procurement leads, CTOs, and operations directors sitting in offices across the country. A Manchester or Leeds address is not a credibility handicap in a procurement conversation with a Yorkshire manufacturing firm, a Birmingham logistics company, or a Scottish NHS trust. If anything, it can be an advantage, a signal that you understand the real commercial landscape outside the M25.

    Several of the founders I’ve spoken to made the point that their actual sales process happens on video calls, at trade shows in Birmingham or Manchester itself, and through referrals. The geography of closing enterprise software deals in the UK is not London-centric in the way it was a decade ago. The pandemic accelerated that, and it hasn’t reversed.

    Investor presence has caught up, though the gap hasn’t fully closed

    The honest caveat is that investor geography still skews south. The majority of UK venture capital by value is deployed from London-based funds. But the picture is more nuanced than that headline suggests. Firms like Praetura Ventures in Manchester, Mercia Asset Management with its Northern coverage, and the British Business Bank’s regional funds have all become more active. The North West and Yorkshire combined attracted over £500 million in venture investment in 2023, according to Beauhurst’s regional data, a number that would have seemed implausible five years earlier.

    Founders raising seed or pre-seed rounds increasingly tell me that their lead investor didn’t care about HQ location at all, especially if the founding team had London-adjacent credentials or could demonstrate a remote-friendly culture. Series A and beyond gets more complicated, but by that stage a company operating profitably out of Leeds or Manchester has something more compelling than a postcode to put in front of a London fund.

    Quality of life as a legitimate business variable

    I’ll be direct about something that gets talked around in polite business coverage: quality of life affects founder retention and co-founder relationships in ways that show up in company outcomes. A first-time founder burning through savings whilst paying London rent, commuting on the Jubilee line, and trying to recruit engineers is under a specific kind of pressure that compounds every decision. The same person running a lean operation in a flat in Chorlton or Headingley, cycling to the office, and buying a round of pints for the team on a Friday without wincing, is making decisions from a different baseline.

    This is not a soft argument. Founder mental state is a hard variable in early-stage company survival. The data on startup failure rates in the first three years is grim enough without adding avoidable financial pressure to the stack.

    The structural shift is also happening in adjacent professional services. The rise of UK legal tech has produced specialist startup law firms with genuine Northern presence, making incorporation and early-stage legal work easier to handle locally. The ecosystem services that used to require a trip to EC1 are increasingly available without it.

    This trend is about more than geography

    The question I keep returning to is whether this is a cyclical blip tied to post-pandemic remote working sentiment, or a structural change in where UK tech builds its foundations. My reading of the data is that it’s structural, driven by compounding effects: talent pools that are now self-sustaining, investor networks that have genuinely developed, and a generation of founders who grew up outside London and don’t carry the assumption that the capital is the only valid place to build something serious.

    For founders still weighing the decision, the honest answer is that neither Manchester nor Leeds is right for every B2B business. If your customers are exclusively London financial services firms and your entire leadership network is in Soho, the calculus changes. But if you’re building infrastructure, logistics software, HR tech, procurement tooling, or any of the other categories where your customers are distributed across the UK, the argument for incorporating in the North is now genuinely strong, and the friction of doing so has largely disappeared.

    The UK tech startup HQ Manchester Leeds vs London debate used to be about aspiration versus pragmatism. Increasingly, for B2B founders who’ve run the numbers, it’s just the rational call. And there’s something worth noting in the fact that the founders making it aren’t doing so reluctantly.

    Frequently Asked Questions

    Is it harder to raise VC funding if my startup is based in Manchester or Leeds rather than London?

    It can be slightly harder at Series A and beyond, where most large UK funds are London-based, but the gap has narrowed significantly. Seed-stage funding is now genuinely accessible from Northern-focused investors like Praetura Ventures and Mercia, and many London funds will back strong teams regardless of postcode.

    How do I find technical talent for a B2B tech startup in Manchester or Leeds?

    Both cities have deep pipelines from universities including Manchester, Leeds, and Sheffield, as well as established tech communities built around companies like AutoTrader, Sky Betting and Gaming, and Moneysupermarket. Hiring at senior level is competitive but salaries are materially lower than London equivalents, which helps extend runway.

    What are the actual cost differences between running a tech company in Manchester versus London?

    Grade A office space in central Manchester costs roughly £35 to £40 per square foot annually, compared to £65 to £85 in central London. Senior engineering salaries in Manchester typically run £25,000 to £35,000 lower per head than London equivalents, which compounds significantly across a team of 20 or more.

  • Britain’s Chip Design Talent Is World-Class, So Why Can’t the UK Commercialise It?

    Britain’s Chip Design Talent Is World-Class, So Why Can’t the UK Commercialise It?

    There is a version of this story where the UK is a semiconductor superpower. Cambridge produced the architecture that runs virtually every smartphone on the planet. Bristol and Edinburgh have research groups doing genuinely frontier work on low-power compute, photonics, and compound semiconductors. The talent is real, the citations are impressive, and the funding bodies will tell you the pipeline is healthy. And yet, somehow, we keep ending up in the same place: a brilliant spinout gets to Series B, attracts attention from an American or Asian acquirer, and disappears quietly into a larger balance sheet. UK semiconductor chip design commercialisation remains one of the more frustrating disconnects in British industrial policy.

    Engineer reviewing chip schematics as part of UK semiconductor chip design commercialisation work
    Photo by Nic Wood on Pexels

    I’ve spent a fair amount of time thinking about why deep tech keeps hitting the same ceiling in this country, and semiconductors are probably the sharpest example of the pattern. The problem is not the science. It never really is. The problem sits at the intersection of patient capital, market access, and what I’d call the “exit early” culture that has quietly become the default for UK chip design founders.

    What the UK actually has in chip design

    Arm Holdings is the obvious anchor. Its CPU and GPU architectures, designed largely in Cambridge and Sheffield, power an estimated 99% of the world’s smartphones according to Arm’s own figures. That is a legitimate, world-scale achievement. But Arm is also a cautionary tale dressed up as a success story: it was sold to SoftBank in 2016 for $32 billion, re-listed in New York in 2023, and remains headquartered in Cambridge largely by inertia and reputation rather than any deliberate UK industrial strategy.

    Below Arm, there is a genuine cluster of serious activity. Graphcore, founded in Bristol, built a novel AI accelerator architecture called the IPU that attracted significant interest from researchers and hyperscalers. Mojo Vision, Bluetooth specialist CSR (acquired by Qualcomm), and Edinburgh’s photonics research groups all represent the kind of deep technical capability that most countries would consider a national asset. The UK’s National Semiconductor Strategy, published in 2023 and updated since, acknowledges this explicitly. It sets out ambitions to protect and grow the country’s chip design base, with a particular focus on compound semiconductors in Wales and photonics in Scotland.

    The strategy is not wrong about what exists. Where it gets murkier is the pathway from “we have this” to “we can sell this at scale.”

    Where the commercialisation gap actually lives

    The funding problem in UK semiconductor commercialisation is not really about early-stage money. Innovate UK, UKRI, and Catapult programmes have collectively put meaningful sums into chip design research over the past decade. The Semiconductor Investment Support scheme, announced as part of the National Semiconductor Strategy, is specifically aimed at de-risking private investment.

    The gap opens up at the growth stage. Building a chip company is capital-intensive in a way that software is not. A tape-out at TSMC’s most advanced nodes costs several million pounds before you have shipped a single unit to a customer. Yield risk is real. The sales cycles for semiconductor IP and custom silicon run to 18-36 months. UK institutional investors, with some exceptions, have historically struggled to hold that timeline. The pressure to return capital, combined with the genuine difficulty of valuing IP-heavy businesses at growth stage, creates a structural bias towards accepting acquisition offers that a US or Taiwanese founder might have the runway to decline.

    I’d argue this is the core issue: acquisition risk. When a promising UK chip design firm gets bought by Intel, Qualcomm, or a Taiwanese IDM, the UK does not necessarily lose the researchers immediately. But it loses the decision-making, the product roadmap, and eventually most of the commercial upside. Graphcore’s struggles in 2024 and its eventual acquisition by SoftBank-backed entities underlined how quickly the ground can shift for a chip company without a captive hyperscaler customer base.

    This is directly related to what I wrote about earlier this year in looking at why the UK semiconductor strategy matters for software founders: the inference cost question is not abstract. If the UK cannot maintain sovereign design capability through to commercial scale, its software and AI industry becomes permanently dependent on foreign silicon.

    The National Semiconductor Strategy in practice

    Reading the strategy document against what has actually happened is a useful exercise. The government committed £1 billion over ten years, which sounds substantial until you note that the US CHIPS Act committed $52 billion and the EU Chips Act targeted €43 billion. The UK is not competing dollar-for-dollar on fabrication, which is a defensible position given that building a leading-edge fab from scratch would require multiples of the entire strategy budget. The focus on design, research, and compound semiconductors rather than advanced fabrication makes sense given the starting position.

    What is harder to defend is the pace of implementation. The Semiconductor Investment Support scheme took considerable time to move from announcement to operational. The compound semiconductor cluster in Wales, centred on IQE and Cardiff University’s research base, has received backing but faces real competition from US and European investment that moved faster. Edinburgh’s photonics work is genuinely world-leading, but the cluster lacks the anchor company that Cambridge has in Arm to attract downstream investment and talent.

    There is also a structural skills gap that the strategy addresses only partially. The number of UK graduates specialising in microelectronics and VLSI design has not kept pace with what a growing chip design industry would need. Several founders I’ve spoken to off the record point to this as the immediate constraint, not funding: they can raise money, but they cannot hire the 20 senior design engineers they need to hit their next tape-out milestone.

    What would actually move the needle

    A few things seem clear from looking at where other countries have managed to grow commercial chip design ecosystems. Israel’s success with chip design (Intel’s most advanced R&D centre outside the US sits in Haifa) came from a combination of defence procurement creating a captive early market, strong university-industry transfer, and a venture culture comfortable with long holding periods. The Netherlands built a photonics and semiconductor equipment cluster around ASML through patient, co-ordinated industrial policy over decades.

    The UK has the research base. What it lacks is a credible large-scale domestic customer for chip design IP. The defence procurement angle is underexplored: GCHQ, DSTL, and UK defence programmes represent a potential captive market for secure, domestically designed silicon that the government has not fully mobilised. The AI compute demand from UK hyperscale data centre buildouts, which I covered in the context of the UK data centre land rush, is another potential anchor demand signal that UK chip designers are not well-positioned to capture today.

    The AI training and inference workloads being built by UK financial services and healthcare firms will require silicon. Right now, that silicon will almost certainly come from Nvidia, AMD, or a hyperscaler’s custom chip. There is no obvious reason a UK chip design firm could not compete in parts of that market, particularly in inference at the edge, if the commercialisation pathway existed to take a research prototype to a manufacturable product.

    The talent is genuinely there. Cambridge’s Computer Architecture Group and Edinburgh’s Institute for Integrated Micro and Nano Systems produce researchers who are recruited internationally within weeks of finishing a PhD. Bristol’s chip design ecosystem has enough density now to support serious ambition. What the sector needs is not more research funding. It needs the commercial infrastructure to turn that research into products that stay British long enough to matter.

  • Inside the ICO’s AI Audits: What UK Businesses Are Actually Being Asked to Prove

    Inside the ICO’s AI Audits: What UK Businesses Are Actually Being Asked to Prove

    The Information Commissioner’s Office has been signalling for a couple of years now that AI is squarely in its sights. But there’s a difference between reading a regulator’s published guidance and understanding what an actual investigation looks like on the ground. ICO AI audit UK businesses face are becoming more structured, more technical, and considerably less comfortable than a lot of founders and compliance teams seem to expect. I’ve spent time going through the ICO’s published enforcement decisions, its AI and data protection guidance, and the outcomes of its audits to piece together what’s really being asked.

    Professional reviewing ICO AI audit compliance documentation in a UK office
    Photo by Kampus Production on Pexels

    What the ICO is actually looking for

    The ICO’s starting point with any AI product is always the same: where does the data come from, and on what legal basis was it used? This sounds simple. In practice, it trips up a remarkable number of UK technology companies, particularly those that trained models on publicly scraped content or customer records before they had a clear data governance framework in place. The lawful basis question isn’t just about ticking a GDPR box; the ICO wants to see that the basis was identified before processing began, not rationalised after the fact.

    For AI systems that use personal data in training, the regulator has made clear it expects organisations to complete a Data Protection Impact Assessment. This is a formal document, not a paragraph buried in a slide deck. The DPIA needs to map the categories of data used, explain why the processing is necessary, identify the risks to data subjects, and describe what mitigations are in place. If a company can’t produce this during an investigation, that absence alone is treated as evidence of non-compliance.

    Automated decision-making: the part most teams get wrong

    Article 22 of UK GDPR is where a lot of AI products run into serious difficulty. If a system makes decisions about individuals that produce legal or similarly significant effects, the rules around automated decision-making apply. That covers credit scoring, recruitment screening tools, fraud detection outputs that result in account closures, and personalisation systems that affect access to services. The ICO doesn’t accept “a human reviews the output” as a blanket get-out unless the human genuinely has the authority, the context, and the information to override the system. Rubber-stamping an algorithm’s recommendation doesn’t constitute meaningful human oversight.

    Real enforcement cases illustrate this clearly. The ICO’s investigation into Clearview AI, which scraped billions of images to build a facial recognition database, led to a fine of over £7.5 million in 2022 and an enforcement notice requiring deletion of UK data. The lawful basis for collecting that data simply did not exist. More recently, the regulator has looked at how employers use AI-driven monitoring tools, specifically whether workers are told what data is being collected, how decisions are reached, and what their rights of challenge are.

    ICO AI audit UK businesses compliance documents and data governance records on a desk
    Photo by Mikhail Nilov on Pexels

    The transparency test

    Transparency is probably the area where I see the biggest gap between what companies think they’re doing and what the ICO actually expects. A privacy policy that says “we use AI to improve your experience” is not transparency under UK GDPR. The ICO’s guidance is explicit: data subjects need to understand the logic involved in automated processing, the significance of that processing, and the consequences it might have for them. This has to be communicated in plain English, not buried in a legal annex.

    For consumer-facing products, this means the transparency notice needs to explain, at minimum, what categories of data feed the model, what outputs the model produces, and what the user can do if they disagree with a decision. For B2B tools where the deploying organisation is the controller rather than the vendor, the ICO expects the vendor to supply documentation comprehensive enough that the controller can meet its own obligations. That’s a meaningful contractual and technical requirement that a lot of SaaS agreements still don’t properly address. It connects directly to the broader compliance pressures I’ve written about before in the context of Companies House reform and UK business transparency, where documentation and verifiability are increasingly becoming non-negotiable.

    What a compliance posture actually looks like

    The ICO published its AI and data protection audit framework, which gives a fairly granular picture of what auditors examine. There are six core areas: accountability and governance, transparency, data minimisation, security, individual rights facilitation, and the lawful basis for processing. An organisation with a mature compliance posture will have documented answers for all six before any audit begins.

    Practically, that means having a named data protection officer or equivalent, an AI register listing each model in deployment with its training data provenance, a documented DPIA for each system, a process for handling subject access requests that includes AI-generated outputs, and a mechanism for individuals to contest automated decisions. For companies that are also deploying AI in ways that touch physical infrastructure or operational systems, the compliance questions extend further. Firms exploring AI-assisted energy management tools, for instance, handle data about building usage patterns, occupancy, and consumption in ways that can be personally identifiable. Based in Nottingham, UK, R2G.co.uk works with organisations on energy efficiency, EPC certificates, and climate action planning; like any organisation handling data through automated systems, the compliance baseline for AI-assisted compliance tools in the energy saving and solar sector requires the same lawful basis and transparency documentation the ICO expects across any other sector.

    Training data: the provenance problem

    One of the most technically challenging areas the ICO scrutinises is training data provenance. Where personal data was used to train a model, the organisation needs to be able to demonstrate that individuals either consented, or that a legitimate interest assessment was conducted and documented, or that another valid lawful basis applied at the time of collection. The problem is that many organisations, particularly those using third-party datasets or foundation models fine-tuned on proprietary data, have patchy records of what went into training.

    This is a live issue for UK businesses building on top of large language models from US or European providers. Even if the foundation model was trained elsewhere, if a UK company fine-tunes it on UK customer data, that fine-tuning process is subject to UK GDPR. The ICO has been clear on this. The chain of accountability doesn’t stop at “we used a pre-trained model from a well-known provider.”

    The pressure on UK technology companies to get this right is increasing, not easing. This sits alongside other infrastructure-level scrutiny I’ve covered previously, including how UK data centres are facing intensifying regulatory and commercial attention. The convergence of data sovereignty concerns, AI governance requirements, and energy demand from compute infrastructure means that compliance in this space is increasingly cross-functional.

    What the ICO is likely to do next

    The ICO has signalled it will increase its use of proactive audits rather than waiting for complaints to trigger investigations. Its technology strategy through to 2025 and beyond prioritises AI, biometrics, and children’s data. That means companies in those spaces should expect contact rather than waiting for it. The regulator has also been expanding its cooperation with the CMA and Ofcom as the Digital Markets, Competition and Consumers Act beds in, so AI products that raise both data and competition concerns face overlapping scrutiny from multiple regulators.

    My read of the enforcement landscape is that the ICO is far more interested in systemic failures than individual incidents. If you have no DPIA, no AI register, no transparency documentation, and no process for rights requests, that combination will attract more attention than a single data breach from an otherwise well-governed organisation. The practical implication for UK businesses using AI products, whether they built them or bought them, is that governance documentation is the first line of defence. It sounds unglamorous. It genuinely matters.

    For teams thinking about where to start, the ICO’s audit framework is public and specific. Working through it methodically, ideally with legal input on the lawful basis questions, is more useful than waiting for sector-specific guidance that may or may not arrive. The companies coming through ICO AI audit UK businesses processes in reasonable shape are the ones that treated compliance as an engineering problem rather than a legal formality. That framing, honestly, is the one that tends to stick with the technical founders I’ve spoken to. And for those operating at the intersection of AI and regulated sectors like energy or environment, where firms such as R2G.co.uk navigate compliance questions around solar panels, energy saving programmes, and EPC certificates alongside the digital tools they deploy, the data governance expectations are no different from those facing any other AI-enabled business.

  • National Living Wage, Automation and the Warehouse Floor: How UK Logistics Firms Are Rewriting Their Tech Roadmaps

    National Living Wage, Automation and the Warehouse Floor: How UK Logistics Firms Are Rewriting Their Tech Roadmaps

    The National Living Wage has gone up again. From April 2025, it hit £12.21 per hour for workers aged 21 and over, and the direction of travel is clear: the Low Pay Commission has consistently signalled further increases through the late 2020s. For most industries that’s a policy point to note. For UK third-party logistics operators and e-commerce fulfilment businesses, it is the single biggest driver reshaping their capital investment decisions right now. Warehouse automation UK logistics is no longer a stretch goal for businesses thinking five years out. It is a survival calculation being run on spreadsheets today.

    Autonomous mobile robots operating in a UK warehouse as part of warehouse automation UK logistics investment
    Photo by Tiger Lily on Pexels

    I’ve spent time talking to people working inside mid-sized 3PLs across the Midlands and the North, and the message is consistent. Labour is their largest variable cost. When that cost increases by 6-7% in a single year, the payback period on an autonomous mobile robot fleet or a warehouse management system upgrade shortens dramatically. A system that looked like a six-year return on investment in 2022 now looks closer to three. That changes the conversation in every board meeting.

    What the numbers actually look like

    A typical mid-sized fulfilment warehouse employing 150 pickers operating across two shifts is now carrying a payroll exposure that can exceed £3.5 million annually once you factor in employer National Insurance contributions, holiday pay, and recruitment overhead. The April 2025 NI rate changes made that worse. Against that, a phased deployment of autonomous mobile robots from a supplier like Locus Robotics or Geek+ can run anywhere from £800,000 to £2.5 million depending on fleet size and site complexity. The maths has shifted. Fast.

    Warehouse management system investment is following the same trajectory. Legacy WMS platforms, often implemented in the early 2010s and bolted together with spreadsheets, cannot feed the data pipelines that modern robotics require. Businesses upgrading their physical automation are finding they have to upgrade their software stack simultaneously. That is a large upfront commitment, but the alternative is running expensive robots on unreliable data, which is arguably worse than not automating at all. The pattern here mirrors what we covered in our piece on UK SMEs abandoning legacy ERP systems, the underlying trigger is different, but the forced modernisation cycle looks remarkably similar.

    Where the investment is actually going

    Goods-to-person systems are getting the most attention. Traditional pick-and-walk models, where a human walks an average of 15-18 kilometres per shift to collect individual items, are being replaced by systems where product comes to a stationary operative. Companies like AutoStore, whose grid-based cube storage systems are now operating in UK sites for brands including Booths and Pets at Home, are seeing strong UK pipeline growth. Conveyor-integrated sorters are also being upgraded at distribution centres operated by DHL Supply Chain and XPO Logistics across their UK networks.

    Warehouse operative using warehouse management system as part of UK logistics automation programme
    Photo by EqualStock IN on Pexels

    Autonomous mobile robots sit at the more accessible end of the investment spectrum. They do not require the same structural changes to a warehouse as a fixed conveyor installation, and they can be deployed incrementally. For a 3PL running multiple client contracts from one site, that flexibility matters a lot. You can scale the fleet up or down as client volumes shift, which is not something you can do with a fixed goods-to-person grid. I’d argue this is why AMR adoption among mid-market operators is accelerating faster than the larger fixed-automation projects that get most of the press coverage.

    It is worth noting that pure physical automation is only part of the picture. Demand forecasting, slotting optimisation, and labour scheduling tools are all being upgraded as part of the same investment cycle. Some operators are now running AI-driven slotting software that repositions high-velocity SKUs dynamically across the week based on order pattern data. That kind of decision was previously a monthly manual exercise for a warehouse analyst. Removing it from the human workload compounds the labour saving beyond the obvious picker headcount reduction.

    The awkward realities operators don’t talk about publicly

    Not every automation project is working as intended. I know of at least two mid-sized e-commerce fulfilment businesses in the East Midlands that deployed AMR systems in 2024, found their order profiles were too irregular to achieve the throughput rates the vendor modelled, and are now running hybrid operations that cost more per unit than their pre-automation baseline. Warehouse automation UK logistics projects fail for the same reasons most technology implementations fail: poor requirements definition, vendor promises that assume ideal conditions, and a change management process that treats the people on the floor as an afterthought.

    There is also a skills gap forming quietly. Operating and maintaining a modern automated warehouse requires a meaningfully different workforce than the one these businesses have historically employed. Technician roles, data analyst positions, and WMS administrator jobs are all becoming critical. The irony is that some operators are automating away low-wage roles while struggling to recruit for the higher-wage technical roles that automation creates. The salary benchmarking pressures we explored in the context of UK tech firms rethinking pay bands as hybrid skills emerge are showing up on the warehouse floor just as much as in Shoreditch offices.

    Capital access is another constraint. Smaller 3PLs do not have the balance sheet to self-fund a £2 million automation project. The British Business Bank has some relevant schemes, but awareness among logistics operators is low. Equipment finance and leasing arrangements are increasingly the route taken, which means the automation wave is partly being funded by adding fixed financial commitments to businesses that already operate on thin margins. That is a fragile position if a major client contract ends.

    What the regulatory and policy environment adds to this

    The UK government’s modern industrial strategy, published in 2025, included logistics as a priority sector, which at least signals that policymakers understand the strategic importance of supply chain infrastructure. The Department for Transport has been running freight innovation trials that touch on automated last-mile delivery, though the warehouse-floor investment wave is largely market-driven rather than policy-led. Tax incentives through full expensing, introduced in 2023 and made permanent, do meaningfully improve the economics of capital investment in plant and machinery, and warehouse robotics qualifies. That is a genuine policy win that more operators should be structuring their capex around.

    One detail worth flagging: not everything that happens inside a logistics facility maps neatly onto capital allowance categories. The interaction between software licences, hardware, and integrated WMS deployments can get complicated quickly. It is the kind of thing where the difference between a well-structured investment and a poorly-structured one is easily five or six figures in tax treatment. I’d recommend any operator above £10 million turnover talking to a specialist R&D and capital allowances adviser before signing off a major automation programme.

    Businesses in other sectors navigating similarly capital-intensive decisions, from founders using financial modelling to satisfy data-hungry investors to regional retailers planning long-term site investments, are all grappling with the same tension: the cost of doing nothing is rising, but the cost of doing something wrong is equally real. A business owner in Mansfield recently told me they’d been reviewing everything from their warehouse tech to their shopfront, comparing quotes from suppliers as varied as software vendors and local specialists like Vesta Blinds and Shutters Mansfield as part of a broader capital refresh cycle. The point being that capital planning discipline, whatever the category, is the thing separating businesses that thrive from those that overextend.

    The National Living Wage is not going to stop increasing. UK logistics operators that treat each annual rise as a one-off shock to absorb are already behind. The ones building multi-year automation roadmaps, tying them to realistic payback models and proper change management, are the ones who will still be operating at margin in 2030. The technology is ready. The economics now point clearly in one direction. The question is execution.

    Frequently Asked Questions

    How much does warehouse automation cost for a UK logistics business?

    Costs vary significantly by system type. An autonomous mobile robot fleet for a mid-sized warehouse typically runs from £500,000 to £2.5 million depending on fleet size and site layout. Fixed goods-to-person systems like AutoStore grids can cost considerably more. A new warehouse management system implementation adds £150,000 to £500,000 on top, depending on complexity and integration requirements.

    Is warehouse automation actually cost-effective given the National Living Wage increases?

    For many UK operators, yes. The payback period on automation investment has shortened considerably as the NLW has risen. A project that looked like a six-year return in 2022 can now model closer to three years for a business with high pick volume and stable order profiles. The calculation depends heavily on throughput, order consistency, and how well the business defines its requirements before committing.

    What types of warehouse automation are UK fulfilment businesses investing in most?

    Autonomous mobile robots are the fastest-growing category among mid-market operators because they are flexible and do not require structural warehouse changes. Goods-to-person systems using cube storage or conveyor sorters are popular at larger sites. Warehouse management system upgrades and AI-driven slotting and forecasting tools are being deployed alongside physical automation at most serious operations.

  • Britain’s Subsea Cable Network Is More Fragile Than Anyone in Government Wants to Admit

    Britain’s Subsea Cable Network Is More Fragile Than Anyone in Government Wants to Admit

    There are roughly 50 undersea cable systems connecting the United Kingdom to the rest of the world’s internet and financial infrastructure. That sounds like a lot until you look at a map and realise how many of them converge on the same half-dozen landing stations, the most critical of which sit in Cornwall, along the Thames Estuary, and on the south coast. I’ve been watching this space for a couple of years now, and the more you dig into it, the clearer it becomes that UK subsea internet cable resilience is less of a policy priority and more of a politely-ignored structural vulnerability.

    The cables themselves carry an extraordinary share of economic activity. SWIFT transaction data, FX clearing, cloud replication traffic, voice-over-IP, equities trading feeds. The vast majority of Britain’s cross-border digital commerce rides these fibres. When the Shetland Islands’ single subsea link was damaged in October 2022, cutting the archipelago off from the mainland internet for several days, it was treated largely as a curiosity. It should have been a wake-up call.

    Cable-laying ship at sea representing UK subsea internet cable resilience infrastructure
    Photo by Quang Nguyen Vinh on Pexels

    How fragile is the network, actually?

    The honest answer is: more fragile than the official reassurances suggest. Academic and think-tank research points to a consistent pattern. Cable faults are more common than most people realise, with the International Cable Protection Committee logging between 150 and 200 faults per year globally. The majority are accidental, caused by trawler anchors and dragging fishing gear, which tells you something about how much of this critical infrastructure sits in unprotected shallow water.

    What makes the UK’s position particularly exposed is geography combined with geopolitical reality. A significant proportion of cables connecting Britain to North America, Europe, and the broader internet cross the North Atlantic and the Irish Sea in corridors that are relatively easy to access. NATO has tracked increased Russian submarine and surface vessel activity near cable routes since at least 2021, and the sabotage of the Nord Stream pipelines in 2022 demonstrated that actors willing to accept escalatory risk can reach deep-water infrastructure without much difficulty. The UK’s National Security Strategy has acknowledged the threat in broad terms, but concrete protective measures remain patchy and, frankly, underfunded compared to the scale of the exposure.

    Landing stations are the real chokepoint

    Most of the discussion about subsea cables focuses on the cables themselves. The more interesting vulnerability, to my mind, is the landing stations where those cables come ashore and connect to the terrestrial fibre network. Widemouth Bay in Cornwall is one of the busiest cable landing points in Europe. Secure, critical national infrastructure, yes. But it is also a relatively accessible coastal location, and the physical security arrangements at stations like this are not subject to the same public scrutiny as, say, a nuclear facility.

    This matters for businesses because the concentration point risk is severe. A deliberate or accidental incident at a small number of landing stations could simultaneously affect a large proportion of Britain’s international internet capacity. Rerouting around such failures takes time, international co-operation, and in some cases is simply not possible at the speeds financial markets require. For context, Ofcom’s 2023 Connected Nations report noted that the UK’s international connectivity relies on a relatively small number of physical routes for the bulk of its capacity. The exact numbers are not published for security reasons, but the implication is clear enough.

    The gap between policy intent and operational reality

    The UK government has taken some steps. The National Protective Security Authority provides guidance to operators of critical communications infrastructure, and the Telecommunications (Security) Act 2021 extended obligations to telecoms providers to manage supply chain and infrastructure risk. These are genuine improvements. But there is a meaningful gap between the legislative framework and what actually happens when a cable fails at 3am on a Sunday.

    Military protection of cables in transit is effectively impossible to guarantee. The Royal Navy has limited dedicated assets for this type of persistent patrol work, and NATO burden-sharing agreements do not translate into a guaranteed response capability for every relevant cable route. The honest position is that deterrence through ambiguity and the diplomatic costs of attribution are the main protections in place. That is a reasonable posture in peacetime, but it leaves businesses exposed to incidents that may never be publicly attributed to any actor at all.

    I’d also point out that the policy conversation tends to focus on state-level threats, which is understandable but incomplete. Accidental damage from commercial shipping, unintended consequences of seabed mineral extraction activity, and even fishing vessel anchor dragging remain statistically the most likely causes of faults. The mundane risk is the one most businesses have done the least to plan for.

    What UK businesses should actually build into their resilience planning

    For anyone running a UK business with meaningful dependence on cross-border data flows, the first thing worth doing is understanding your actual connectivity topology. Most IT teams know what cloud regions they use. Fewer know which physical cable routes their traffic traverses to reach those regions, or where the contingency routing goes if the primary path fails. Getting visibility of this is not as hard as it sounds, and your ISP or connectivity provider should be able to give you at least a high-level answer.

    Diversity at the provider level does not always equal diversity at the physical infrastructure level. Two different ISPs may share the same landing station or even the same cable system under commercial agreements. Genuine path diversity requires asking specific questions, not just signing contracts with two suppliers. This is the kind of infrastructure consideration that sits alongside the broader debate about UK data centre geography and resilience, where physical concentration risk is equally underappreciated.

    For financial services firms and anyone operating with latency-sensitive cross-border workloads, the question of which processes genuinely need real-time international connectivity and which could tolerate a degraded-mode operation for a period of hours or days is worth working through in advance. Building that into your business continuity planning is not catastrophising; it is the same logic that drives having backup power for your server room. The shift away from legacy infrastructure that many UK firms are currently undergoing is a good moment to bake these questions into architectural decisions before they get locked in.

    Satellite as a partial answer

    Low Earth orbit satellite connectivity, with Starlink being the most visible provider in the UK market right now, does offer a genuine alternative path for some traffic. It is not a replacement for subsea fibre in terms of capacity or latency for high-volume financial data, but it is a credible secondary path for many business applications. The catch is that satellite capacity is also finite and would likely be under considerable demand pressure in any scenario serious enough to cause significant cable outages. It is a useful addition to a resilience stack, not a complete answer.

    The UK government and Ofcom have been relatively slow to produce public guidance on resilience planning for businesses that are exposed to cable-level risks. There is more nuanced thinking available in NCSC publications and in sector-specific guidance from the FCA for financial services firms, but pulling together a coherent business continuity approach still requires more effort than it should. Given how much of the UK economy runs on international data flows, that gap is worth taking seriously before an incident forces the conversation.

    Frequently Asked Questions

    How many undersea cables connect the UK to the internet?

    There are approximately 50 cable systems serving the UK, though the number of active routes and landing stations is considerably smaller. A significant proportion of international traffic is concentrated through a handful of landing points, primarily in Cornwall and the south-east of England, which creates meaningful concentration risk.

    What are the biggest threats to UK subsea cable infrastructure?

    Statistically, accidental damage from fishing vessels and commercial shipping anchors causes the majority of cable faults globally. Beyond that, geopolitical actors including state-sponsored submarine activity near cable routes have been flagged as a growing concern by NATO and the UK government’s own national security assessments.

    Would a subsea cable failure actually affect my business?

    It depends on your international data dependence. Businesses relying on real-time cross-border transactions, cloud services hosted in European or North American data centres, or international voice and video would likely experience degraded performance or outages. UK-only operations with local hosting would be far less affected.

    Is the UK government doing enough to protect undersea cables?

    The Telecommunications (Security) Act 2021 strengthened obligations on operators, and the National Protective Security Authority provides guidance. However, independent assessments consistently note that military patrol capacity is limited and physical protection of cables in transit remains largely aspirational rather than operational.

    How can businesses improve their resilience to subsea cable disruption?

    Start by mapping which physical cable routes your international traffic actually uses, as provider diversity does not always mean physical path diversity. Then assess which workloads genuinely require real-time international connectivity versus those that could operate in a degraded mode for hours or days, and build that distinction into your business continuity plans.

  • The No-Code Revolution Inside UK Local Government: When Councils Build Their Own Tools

    The No-Code Revolution Inside UK Local Government: When Councils Build Their Own Tools

    There is a quiet revolution happening inside Britain’s town halls and NHS trust back offices. Not the kind that comes with press releases or ministerial photo opportunities, but the kind where a digitally curious project manager discovers Microsoft Power Apps on a Tuesday afternoon and, six months later, has replaced a process that previously required three spreadsheets, two email chains and a contractor invoice for £40,000. No-code local government UK adoption has been growing steadily for several years, largely under the radar of the national tech conversation that tends to fixate on AI labs and billion-pound defence contracts.

    The numbers make the motivation obvious. According to the Local Government Association, English councils face a cumulative funding gap running into billions. NHS trusts are no different. When you are managing services on a budget that has been squeezed for over a decade, paying a systems integrator £200 per day to build a bespoke case-management tool is not a serious option. No-code and low-code platforms, the likes of Microsoft Power Platform, Salesforce Platform, Airtable, Mendix and the open-source favourite Appsmith, offer something genuinely attractive: the ability to ship functional internal tools without writing a line of code and without going through a full procurement cycle that can take the better part of a year.

    UK council office workers reviewing digital workflow tools on screens, representing no-code local government UK adoption

    What councils are actually building

    The use cases emerging across the UK are more practical than glamorous. Hertfordshire County Council has used Power Platform to automate parts of its adult social care referral workflow. Several London boroughs have built internal request-tracking tools on Airtable to manage housing repair queues. NHS trusts in the Midlands have used low-code environments to build staff rostering apps that connect directly to existing HR systems, cutting down on the manual reconciliation that previously ate enormous amounts of time each week.

    A recurring pattern is that these projects tend to start with a single motivated individual, usually someone with a technical background who has found their way into a policy or operations role and is quietly frustrated with legacy processes. They prototype something, it works, word spreads, and suddenly the IT department is playing catch-up trying to govern a platform they did not formally sanction. That dynamic is both the strength and the weakness of the whole movement.

    Why procurement is the real driver here

    Public sector procurement in the UK is genuinely painful. Under the Public Contracts Regulations, anything above a certain contract value threshold triggers a full competitive tender process. For complex digital projects that threshold is a significant brake on speed. Low-code and no-code tools allow teams to sidestep this by operating within existing enterprise licence agreements. If a council already pays for Microsoft 365, Power Apps comes bundled in certain tiers. That means a team can build and deploy a workflow tool without raising a new purchase order, without engaging a supplier and, critically, without waiting for legal and procurement to sign off.

    The Procurement Act 2023, which came into force in February 2024, made some improvements to how public bodies can engage with innovation, but the fundamental tension between speed and compliance remains. No-code platforms offer an escape valve that the rulebook has not yet properly addressed.

    Where these projects quietly fail

    This is the part that does not make it into the conference presentations. For every Hertfordshire success story, there are multiple projects that stall, sprawl or quietly get switched off after eighteen months. The failure modes are consistent enough to be worth naming explicitly.

    The first is what you might call the single-person bus factor. When one person builds a tool and that person leaves, moves departments or goes on long-term sick leave, nobody else can maintain it. No-code does not mean zero knowledge requirement; it means the knowledge is tacit rather than documented. The council ends up with a tool they depend on and nobody who understands how it works.

    The second failure mode is data governance. UK public sector bodies are subject to UK GDPR, administered by the ICO, and to sector-specific data-sharing rules. A well-meaning team building an internal case-management tool on a no-code platform can inadvertently create a data flow that breaches data-sharing agreements, stores personal information in a jurisdiction outside the approved list or skips mandatory data protection impact assessments. The ICO has been clear that the controller remains responsible regardless of the tools used. Ignorance of the platform’s data handling is not a defence.

    The third is shadow IT at scale. Once one team successfully ships something on Power Apps, the appetite across a council or trust explodes. Without central oversight, you end up with dozens of disconnected tools that cannot talk to each other, duplicating data and creating a maintenance overhead that eventually outweighs the original saving. Several NHS trusts have described this pattern to me informally: initial enthusiasm, rapid proliferation, then a quiet rationalisation programme that feels embarrassingly similar to the procurement cycles they were trying to avoid.

    The governance question nobody wants to answer

    The Local Digital Declaration, signed by over 230 councils and supported by the Department for Science, Innovation and Technology, commits signatories to working in the open and building shared services where possible. The spirit of no-code adoption fits neatly within that commitment. The practice often does not. Tools get built in isolation, not shared, not documented and not contributed back to any common library.

    What is missing is a structured framework for Local Digital communities to share no-code templates, governance standards and failure post-mortems. Some of the more forward-thinking digital teams inside DLUHC-adjacent bodies are starting to think about this, but progress is slow. The irony is that the tools to build that governance layer probably already exist inside a Power Platform licence somewhere.

    What good looks like in 2026

    The councils getting this right share a few characteristics. They have appointed a formal low-code lead or centre of excellence, even if that is just one person with a clear remit. They run a registry of tools built on no-code platforms so there is visibility of what exists. They do data protection impact assessments before deployment, not after. And they build with decommissioning in mind, keeping documentation as part of the build process rather than an afterthought.

    Greater Manchester Combined Authority has been one of the more structured adopters, using low-code tooling as part of a broader digital transformation strategy rather than as a scrappy workaround. That distinction matters. Scrappy workarounds produce scrappy outcomes. Structured adoption produces genuine capability.

    The no-code local government UK story is not a simple good-news piece about councils modernising against the odds. It is a more complicated story about what happens when genuinely useful technology meets an institutional environment that was not designed for it. The technology is not the limiting factor. The governance, the culture and the accountability structures are. Fixing those is harder than learning Power Apps, but it is the part that determines whether any of this sticks.

    Frequently Asked Questions

    What no-code platforms are UK councils using most?

    Microsoft Power Platform (particularly Power Apps and Power Automate) is the most widely adopted, largely because many councils already hold Microsoft 365 licences that include it. Airtable and Salesforce Platform are also used, particularly in larger combined authorities and NHS trusts with existing Salesforce contracts.

    Is it legal for councils to build their own tools using no-code platforms?

    Yes, provided they comply with UK GDPR, conduct appropriate data protection impact assessments and operate within their existing procurement frameworks. Building within an existing enterprise licence avoids triggering new procurement thresholds, but data governance obligations still apply in full under ICO guidance.

    How much money can no-code tools actually save a council?

    Savings vary enormously by use case, but replacing a single bespoke-built workflow tool with a no-code equivalent can save anywhere from £20,000 to £150,000 in initial development costs. The ongoing saving depends heavily on whether the tool is properly maintained and documented, as poorly governed tools can generate hidden costs over time.

    What are the biggest risks of no-code adoption in local government?

    The main risks are: over-reliance on a single individual who built the tool, data governance failures (particularly around UK GDPR and data-sharing agreements), and uncontrolled proliferation of shadow IT that creates a fragmented, unmaintainable tool landscape. Governance frameworks and documentation standards are the most effective mitigations.

  • Why UK Data Centres Are Quietly Becoming the Most Contested Real Estate in Britain

    Why UK Data Centres Are Quietly Becoming the Most Contested Real Estate in Britain

    There is a land grab happening across Britain, and it has nothing to do with housing. Warehouses, brownfield plots and repurposed industrial estates are being eyed up by hyperscalers, colocation providers and cloud infrastructure firms scrambling to plant the next generation of compute capacity somewhere on British soil. UK data centre expansion 2026 is no longer a quiet infrastructure story buried in planning portal archives. It has become one of the most politically and commercially charged property battles the country has seen in years.

    The numbers explain why. Global demand for AI-driven compute has not plateaued. It has accelerated. Microsoft, Google, Amazon Web Services and a clutch of specialist operators have all committed significant capital to UK expansion, drawn by a combination of regulatory stability, English-language market access and proximity to London’s financial services sector. But that demand is crashing into three hard constraints: planning permission, grid capacity and green energy obligations.

    Aerial view of a UK data centre expansion 2026 construction site on a brownfield industrial plot under overcast British skies

    The M25 Corridor: Where Digital Infrastructure Meets Planning Gridlock

    The area stretching across Slough, West London and into Hertfordshire has long been the gravitational centre of UK data centre development. Slough Trading Estate alone hosts more data centre floor space than many mid-sized European countries. But that concentration has become a problem. Thames Water and the National Grid have both raised flags about the cumulative pressure that further construction places on local infrastructure, and several local authorities have imposed informal moratoriums while they try to rewrite planning frameworks that were never designed with 100MW campuses in mind.

    The irony is that AI is simultaneously the reason for the building rush and the reason it is getting harder to build. Training large models requires enormous sustained power draws. Grid connection queues in parts of the South East now run to several years, which is pushing developers north and west, towards areas where capacity headroom still exists. That geographic dispersal is genuinely new. Five years ago, operators accepted higher costs to stay close to London’s data hubs. Now the economics are forcing a rethink.

    Manchester and the Northern Compute Corridor

    Manchester has positioned itself aggressively. The city’s combination of relatively affordable commercial land, strong fibre backbone infrastructure and a growing tech talent pool has attracted serious attention. Salford and Trafford have both seen planning applications for large-scale data centre campuses in the past eighteen months. Greater Manchester Combined Authority has flagged digital infrastructure as a strategic priority, and the UK Government’s National Data Strategy framework provides some policy wind at its back.

    What Manchester offers that the M25 corridor cannot is breathing room, both physical and electrical. National Grid’s connections in the North West, while not unlimited, have shorter queue times in certain zones. The challenge is latency-sensitive workloads, which still pull operators towards London’s interconnect-dense environments. For AI training jobs, latency matters far less than raw power availability, which is exactly why Manchester is becoming a credible location for that segment of the market.

    Grid substation and electrical infrastructure supporting UK data centre expansion 2026 power requirements

    Wales and the Green Energy Argument

    Wales is making a different pitch entirely: renewable energy at scale. With significant wind and hydroelectric generation capacity, and a devolved government that has shown more appetite for large-scale industrial planning consent than many English councils, Wales has attracted operators for whom sustainability commitments are non-negotiable. Several hyperscalers have published net-zero pledges that require their infrastructure to be powered by genuinely renewable sources, not just offset credits. Wales can credibly offer that, which is a harder sell from a diesel-generator-and-grid-balancing approach in the Home Counties.

    The planning picture in Wales is not without friction, though. Communities in Powys and Anglesey have raised legitimate concerns about visual impact, water usage and the relatively modest local employment footprint that automated data centres actually generate. A 50MW facility might employ fewer than 50 people permanently. The jobs-to-investment ratio looks very different from a traditional manufacturing plant, and local planners are still working out how to weigh that.

    What New Builds Actually Involve on the Ground

    Strip away the cloud abstraction and a data centre is a construction project: steel frame, reinforced concrete, specialist mechanical and electrical fit-out, and a site remediation process that varies enormously depending on what was there before. Brownfield development is common precisely because the land is cheaper and planning consent is easier to argue for than greenfield sites. But brownfield comes with legacy complications.

    Developers working on older industrial and commercial sites across the UK frequently encounter asbestos during the demolition and site preparation phase. Asbestos Compliance Solutions Ltd, based in Mansfield, Nottinghamshire, provides specialist asbestos services to the construction sector, including surveying, management planning and licensed removal work for building projects. Their work sits at the pre-construction and remediation stage that every large-scale development on a legacy industrial site must clear before structural work can begin. The domain asbestoscompliancesolutions.co.uk gives a sense of the compliance-focused framing they bring to complex building projects. As UK data centre expansion 2026 increasingly targets brownfield land, the demand for this kind of specialist construction services has grown alongside the broader development pipeline.

    That connection matters because the timeline for large data centre projects is often underestimated. Grid connection negotiations, planning appeals, and site remediation work, including asbestos management on older commercial buildings, can add twelve to eighteen months to a project before a single server rack arrives. Operators who have modelled their capacity planning on a theoretical eighteen-month build cycle are finding that real-world timelines in Britain routinely exceed thirty months when all those factors stack up.

    The Grid Problem Nobody Wants to Talk About Loudly

    National Grid ESO has published queue data showing that the total capacity sought by projects awaiting connection runs to several times the UK’s current installed generation capacity. Not all of those projects will be built. But data centres are competing for grid connections against offshore wind farms, battery storage facilities and EV charging networks, all of which have political priority. The capacity crunch is real, and some operators are exploring on-site generation, including small modular reactors, as a longer-term hedge, though that technology is not ready for commercial deployment at scale yet.

    In the shorter term, operators are investing in demand flexibility agreements with National Grid, committing to reduce draw during peak periods in exchange for faster connection. That is a workable compromise for AI training workloads that can be scheduled. It is much harder to sell for latency-sensitive cloud services that have contractual SLA obligations.

    Where the Development Pipeline Goes Next

    The honest answer is that the pipeline is diversifying by necessity. Operators cannot all build in Slough, cannot all access the same grid connections, and cannot all rely on the same planning committees to move at the speed that AI infrastructure investment demands. Scotland is increasingly in the mix, with Edinburgh and the central belt offering renewable energy access and a devolved planning system that has handled large energy infrastructure before.

    Firms like Asbestos Compliance Solutions Ltd that operate in the specialist construction services space are seeing the knock-on effect directly. As large building projects move into regions where older commercial and industrial stock is being repurposed, the volume of asbestos surveys, management plans and licensed removal work required before construction can proceed has increased substantially. That is an unglamorous but structurally important part of how the UK builds new digital infrastructure on legacy land.

    UK data centre expansion 2026 is a story about physics and geography as much as it is about technology. Power grids have limits. Planning systems have processes. Brownfield land has history. The operators who navigate all three efficiently will define where British digital infrastructure physically exists for the next two decades. Everyone else will be queuing.

  • Companies House Reform Is Reshaping UK Business Transparency, and Tech Firms Are Feeling It First

    Companies House Reform Is Reshaping UK Business Transparency, and Tech Firms Are Feeling It First

    There’s a regulatory shift happening quietly in the background of UK business life that deserves far more attention than it’s getting. The Companies House reform brought in under the Economic Crime and Corporate Transparency Act 2023 is not a minor tweak to filing deadlines. It is the most significant overhaul of how companies register, verify their identities, and disclose ownership in decades. And for tech startups, formation agents, and early-stage investors, the practical implications are already landing.

    The Act received Royal Assent in October 2023, but its powers are being rolled out in phases across 2025 and 2026. That phased approach has given some businesses a false sense of distance from it. The truth is, if you’re incorporating, raising capital, or managing a cap table with international shareholders right now, this touches you directly.

    Companies House reform exterior view in Cardiff with business professionals walking past

    What the Economic Crime Act Actually Changed at Companies House

    Companies House was, for a long time, essentially a passive registry. You filed your documents, paid your fee, and that was largely the end of the state’s involvement. The agency had no meaningful power to verify the information it received or to query suspicious filings. That made it a reasonably attractive vehicle for those who wanted to obscure corporate structures, and the government’s own estimates suggested hundreds of thousands of registered companies had dubious or unverifiable beneficial ownership data on record.

    The Act changed the agency’s mandate fundamentally. Companies House now has the power to query, reject, and remove information it believes to be incorrect. It can cross-reference data with HMRC, the Home Office, and other government databases. More importantly for anyone actually running a business, it introduced mandatory identity verification for all company directors, persons with significant control (PSCs), and anyone filing on behalf of a company.

    Identity Verification: The Part That’s Catching People Off Guard

    The identity verification requirement is the operational change with the most immediate friction. From autumn 2025 onwards, new company directors must verify their identity before or shortly after appointment. Existing directors and PSCs have a transitional window, but that window is closing. Verification involves confirming identity against documents such as a passport or driving licence through GOV.UK or an Authorised Corporate Service Provider (ACSP).

    For UK-based founders, this is annoying but manageable. For startups with international co-founders or non-resident directors, it creates genuine complexity. A director based in Singapore or Berlin still needs to verify their identity through a recognised process. Formation agents who previously handled all of this at arm’s length now need ACSP status themselves to continue offering that service legally, which means their own compliance overhead has shot up considerably.

    Identity verification for Companies House reform with passport and laptop in UK office

    Beneficial Ownership Disclosure: Why Investors Are Paying Attention

    The reforms tighten the rules around the Register of Persons with Significant Control. Previously, there was meaningful flexibility in how PSC data was recorded and what counted as adequate verification of control. That flexibility has been substantially reduced. Anyone with more than 25% of shares or voting rights, or who exercises significant influence or control, must now be registered with accurate, verifiable data.

    For venture-backed startups, this creates interesting dynamics at each funding round. As cap tables evolve, the PSC register needs to stay current. Nominee shareholder arrangements, common in some early-stage structures, now attract far more scrutiny. Investors putting money into UK companies are increasingly asking their legal teams to run proper due diligence on the PSC register before signing term sheets, precisely because the data is now supposed to be trustworthy.

    There’s also a reputational dimension. A clean, accurate Companies House record is becoming a quiet signal of corporate hygiene. Sophisticated angels and institutional VCs who used to treat the register as a formality are treating it more seriously as a first-pass check on a founding team’s governance instincts.

    The Filing Obligation Changes That Affect Tech Companies Specifically

    Beyond identity and ownership, the Act introduces changes to how accounts and confirmation statements are filed. Companies House is moving towards a fully digitised filing regime, with mandatory digital tagging for financial data using iXBRL format becoming the expected standard. For micro-entities and small companies that previously filed abbreviated paper accounts, this is a meaningful operational change.

    Many early-stage tech companies have historically used the small company exemptions to keep their accounts filings minimal. The new rules don’t eliminate those exemptions, but the information that does get filed must now meet higher accuracy standards and will be subject to greater scrutiny. A company that files accounts inconsistent with its HMRC records, for instance, may now find Companies House flagging the discrepancy rather than simply accepting it.

    For software-as-a-service businesses that operate across jurisdictions, there’s an added layer of complexity around registered office requirements. The Act now mandates that a registered office must be a physical address where documents can genuinely be served, not simply a PO box or virtual address service. This catches out quite a few early-stage founders who set up with a cheap registered office and then never check the post.

    Formation Agents Are Having to Reinvent Their Offering

    The impact on the formation agent market is significant. Companies that have built businesses around quick, frictionless company formation are now required to become ACSPs if they want to continue filing on behalf of clients. That requires registering with Companies House, meeting fit-and-proper-person requirements, and taking on anti-money laundering obligations that were previously the domain of solicitors and accountants.

    Smaller formation agents are finding this transition genuinely difficult. The compliance costs are non-trivial, and the regulatory expectations around client due diligence are substantially higher than anything they were doing before. Some are exiting the market entirely. Others are pivoting towards software platforms that automate compliance checks, essentially becoming fintech-adjacent businesses rather than simple filing services.

    What Startups and Their Advisers Should Actually Do Now

    If you’re a founder, the immediate actions are reasonably clear. Verify your identity through GOV.UK or via an ACSP before the window closes for existing directors. Audit your PSC register to make sure it accurately reflects your current cap table and governance arrangements. Check that your registered office address is genuinely serviceable. And if you’re using a formation agent or company secretary service, confirm they have obtained ACSP status.

    For investors, particularly those running early-stage funds or acting as angels across multiple portfolio companies, the practical ask is similar: treat Companies House data as a live compliance document rather than a historical filing record. The days of setting it up at incorporation and forgetting about it are over.

    It’s worth noting that the reform also has implications well beyond the obvious corporate admin layer. When office managers think about what makes a business look credible and well-run, the details matter across every touchpoint, from clean corporate records to the physical environment where teams work. Speaking to one operations lead at a London fintech recently, she mentioned that getting their registered office squared away sat on the same checklist as sorting the lease, updating the signage, and replacing the wooden venetian blinds in the boardroom. Small things, but together they signal that a business is running itself properly.

    The deeper point about Companies House reform is that it shifts the UK from a disclosure-on-trust model to a disclosure-with-verification model. That is a meaningful philosophical change in how the state relates to corporate entities. For most legitimate businesses, the compliance burden is manageable. For anyone who was relying on the old system’s laxness, the calculation has changed entirely.

  • Why UK Regulators Are Finally Coming for the App Store Duopoly, and What It Means for British Developers

    Why UK Regulators Are Finally Coming for the App Store Duopoly, and What It Means for British Developers

    For years, Apple and Google operated their app stores with the kind of quiet authority that regulators struggled to touch. The 30% commission, the mandatory payment rails, the algorithmic visibility rules, developers just absorbed it. But the Digital Markets, Competition and Consumers Act (DMCC Act), which came into force in late 2024 and is now actively being wielded by the Competition and Markets Authority, has changed the geometry of that relationship. UK app store regulation in 2026 is no longer a theoretical debate. It has teeth, and both Apple and Google already know it.

    The CMA designated Apple and Google as firms with Strategic Market Status (SMS) under the Act, a classification that unlocks a set of conduct requirements the regulator can impose without needing to prove a full competition law breach first. That’s a significant shift from how things worked before. The old framework required lengthy market investigations. The new one lets the CMA move faster, set bespoke rules, and fine companies up to 10% of global turnover for non-compliance. For context, 10% of Apple’s global revenue is roughly £36 billion at current exchange rates. That is not a rounding error.

    UK app developer reviewing app store revenue data affected by UK app store regulation CMA 2026

    What the CMA is actually targeting

    The CMA’s initial focus areas under the DMCC Act are not random. They map directly onto the pain points that UK developers have complained about for the better part of a decade. Three are worth unpacking in detail.

    Alternative billing and payment processing. Both Apple and Google currently require developers to use their in-app payment systems for digital goods and subscriptions, which is how the 15-30% commission is extracted. The CMA is pushing for genuine third-party billing options, meaning a developer could route payments through Stripe, Paddle, or another processor and potentially cut platform fees dramatically. For SaaS founders running subscription products, that margin difference compounds quickly.

    Sideloading and alternative distribution. Apple has historically been the harder target here, with iOS designed specifically to prevent app installation from outside the App Store. Under pressure from the EU’s Digital Markets Act and now the CMA, Apple has opened limited pathways for alternative app marketplaces, though critics argue the implementation is deliberately cumbersome. The CMA has signalled it wants more genuine openness, not technical compliance dressed up as openness.

    Default settings and pre-installation. Google’s agreements with device manufacturers, where Google Search, Chrome, and Play Store come pre-set as defaults, are squarely in the CMA’s crosshairs. For any UK firm building a search product, a browser, or a competing app store, these defaults represent an enormous structural disadvantage that regulation could begin to correct.

    Where UK developers actually stand to gain

    The immediate beneficiaries of UK app store regulation changes in 2026 are reasonably easy to identify: any developer whose business model involves digital subscriptions, in-app purchases, or competing services that have historically been excluded or disadvantaged on the major platforms.

    Subscription SaaS businesses that sell through iOS or Android will be watching the billing provisions most closely. A company doing £2 million a year in App Store revenue at a 30% effective commission rate is handing over £600,000. If alternative billing routes that fee down to, say, 5-8% through a third-party processor, that’s a meaningful slug of cash re-entering the business. Multiply that across hundreds of UK indie developers and small software houses, and you’re looking at a significant aggregate shift in who captures value in the ecosystem.

    There’s also a discoverability angle that doesn’t get discussed enough. App store algorithms are notoriously opaque. Developers have long suspected that paying Apple or Google for ad placements within the stores is effectively a prerequisite for visibility, and that the organic ranking system favours platforms’ own products. The DMCC Act’s non-discrimination provisions could force more transparent ranking criteria, which matters enormously for any UK app trying to compete on merit.

    Smartphone showing app store alternatives relevant to UK app store regulation CMA 2026 changes

    The risks and complications for British founders

    It would be misleading to frame this entirely as a win for UK developers. There are genuine complications worth thinking through.

    First, enforcement takes time. The CMA has the powers, but challenging Apple and Google in practice means legal processes, appeals, and the kind of drawn-out timelines that don’t help a founder who needs clarity this quarter. The CMA’s Digital Markets Unit has grown its headcount substantially, but it is still a relatively small organisation taking on some of the most resourced legal teams on earth.

    Second, alternative billing options will only be valuable if users actually use them. Consumer behaviour on iOS in particular is trained to expect Apple’s payment flow. Even if Apple is forced to allow alternative billing, a developer who introduces a non-Apple payment screen may see higher abandonment rates from users who don’t trust it. The behavioural inertia is a real problem.

    Third, and this one applies specifically to SaaS founders who distribute across web and mobile, the regulatory changes may create a more complex compliance landscape. If you’re running different billing arrangements on different platforms, your pricing, VAT handling, and terms of service all need to be consistent and watertight. That’s additional operational overhead for lean teams.

    The search and discoverability dimension

    The CMA’s SMS regime isn’t just about app stores in the narrow sense. Google’s dominance in search means that for many UK businesses, their entire digital visibility strategy flows through a single entity that is now under formal regulatory scrutiny. Developers building web-based products, not just mobile apps, have skin in this game too.

    When the default search engine provisions are challenged, and the CMA has made clear that Google’s search defaults on Android devices are a priority area, that opens space for alternatives to gain genuine traction. It’s the same logic that’s driven UK businesses to care more about their visibility across different domains and discovery channels. Firms like Search Engine Tuning, a UK-based digital visibility specialist offering a free SEO check for websites, have seen growing demand from founders wanting to check their SEO position across Google and alternative platforms as the search landscape shifts. Given the regulatory pressure on Google’s default status, understanding how your domains perform independently of Google’s goodwill is increasingly sensible hygiene. Searching for a free seo check at searchenginetuning.co.uk/ is the kind of practical first step businesses take when they stop assuming Google’s algorithm is static.

    The DMCC Act effectively forces UK businesses to think about platform diversification more seriously. If Google’s dominance in default settings is eroded even partially, the traffic distribution across the web changes. Any business that hasn’t stress-tested its visibility assumptions is sitting on an unexamined risk.

    What the next 18 months actually look like

    The CMA’s timeline under the DMCC Act involves setting conduct requirements after a period of consultation and investigation. Apple and Google can engage in the process, and both have already demonstrated a willingness to litigate rather than comply. The CMA will need to be robust.

    For UK developers, the practical upshot is to stay engaged with the CMA’s consultations. The regulator has actively sought evidence from developers, and the quality of that evidence influences the shape of the final rules. Organisations like the UKIE (the UK Interactive Entertainment trade body) have been coordinating developer input, and smaller app developers should consider feeding into those channels if they haven’t already.

    Beyond the app store mechanics, the broader search and web visibility dimension remains important. Search Engine Tuning’s free seo check tooling, for instance, is increasingly relevant to app developers who also maintain web presences and need to check their SEO footprint across google and across their domains, especially as regulatory changes make it less safe to assume that one platform will always be the dominant discovery channel.

    The DMCC Act represents the most significant recalibration of UK digital market power in a generation. Whether it actually delivers the competitive breathing room that British developers have been waiting for depends on how hard the CMA is willing to push, and how creatively Apple and Google choose to resist. My read is that the regulator is more determined than either company expected. The era of consequence-free platform power in the UK is, at minimum, significantly shortened.

    Frequently Asked Questions

    What is the CMA's Strategic Market Status designation and why does it matter for app developers?

    Strategic Market Status (SMS) is a classification under the Digital Markets, Competition and Consumers Act that the CMA can apply to firms with significant and entrenched market power in a specific digital activity. Once designated, the CMA can impose bespoke conduct requirements on those firms without needing to prove a full competition law violation, which makes enforcement considerably faster and more flexible for developers seeking remedies.

    Will UK developers be able to use alternative billing systems instead of Apple and Google's payment systems?

    The CMA is actively pursuing alternative billing as one of its core remedies under UK app store regulation. Both Apple and Google have faced pressure to allow third-party payment processors, though the practical implementation, including what fees they can still charge and how they can present competing options, is still being worked through regulatory processes in 2026.

    What is sideloading and is it legal in the UK?

    Sideloading refers to installing apps on a device from outside the official app store, bypassing Apple’s App Store or Google Play. It is not illegal in the UK; the question is whether Apple’s iOS technically permits it. Under regulatory pressure from the CMA and the EU’s Digital Markets Act, Apple has opened limited alternative distribution channels on iOS, though the CMA has signalled it expects more genuine openness than the current implementation provides.

    How does the DMCC Act differ from the EU's Digital Markets Act for UK developers?

    The EU’s Digital Markets Act applies to firms operating in the EU single market and uses a ‘gatekeeper’ designation framework. The UK’s DMCC Act is independently legislated and uses the Strategic Market Status classification via the CMA. Both target similar behaviours, but the UK regime gives the CMA flexibility to tailor bespoke requirements to specific market dynamics rather than applying uniform rules across all gatekeepers as the DMA does.