Britain needs to prepare for AI workers

British companies should prepare for AI agents with bounded authority. UAE ambitions and Singapore’s governance framework point towards practical decisions about ownership, permissions, spending and recovery.

7 min read
Read with AI

Open in

ChatGPT Claude Perplexity

This page

Copied to clipboard
A realistic editorial photograph inside a modest British engineering wholesaler’s dispatch area on an autumn morning. Two staff members, seen from behind with no identifiable faces, examine a tablet b

British companies should prepare to delegate bounded work to AI, with named owners and enforceable limits. Buying assistants without deciding what they may do is an incomplete strategy. The UAE’s target for agentic government and Singapore’s agent governance framework make that preparation concrete. Neither proves Britain is behind on adoption. Both challenge British leaders to treat delegated authority, operational responsibility and staff training as part of the investment.

The overseas signal is a change in responsibility

The significant detail in the UAE announcement is the assignment of responsibility. Its framework calls for implementation teams headed by each minister or entity leader, alongside targets and assessment indicators. The programme connects technology deployment to leadership and workforce development. The Cabinet’s implementation framework describes an organisational project.

Singapore offers a different starting point. Its agentic AI framework organises the problem around bounding risks, human accountability, technical controls and user responsibility. The supplied document identifies version 1.5 as published on 20 May 2026 and updated on 5 June 2026.

British businesses should borrow the management questions from these initiatives without copying a national percentage target. Which process can accept delegated decisions? Who owns its failures? What evidence would justify expanding its authority?

For a small company, that discussion belongs with the owner and the person responsible for the affected process. It should happen before a supplier connects an agent to customer records, purchasing or production systems.

How a bounded AI worker should operate
An agent handles a narrow task under limited permissions, with human approval for consequential actions and a tested way to stop and recover.

An AI worker needs a bounded job

“AI worker” is a useful management metaphor if it makes authority explicit. Here, it means software authorised to complete a defined task across business systems. It does not imply human judgement, employee status or independent accountability.

The distinction matters because an agent can change the environment it operates in. Singapore’s framework explicitly discusses actions such as updating a customer database or making a payment, while insisting that humans remain accountable. Its explanation of agent capabilities and risks supports a more demanding procurement conversation than whether a chatbot gives convincing answers.

Consider a hypothetical British engineering wholesaler. An assistant might draft a response to a delayed order. An agent could be proposed to check stock, select an alternative and update the order.

Those steps carry different consequences. Reading stock availability, changing a delivery promise and committing money should each have their own permission. The business should decide those boundaries before testing the workflow.

A sensible first deployment would let the agent prepare a proposed change while an authorised employee approves the customer commitment. Greater autonomy should follow evidence from completed work.

Give each agent an owner and a stop mechanism

My recommended operating model is an identifiable agent, restricted access to the systems it needs, and a human owner who can suspend it. A machine identity is the account or credential through which the software acts. The design should make its actions attributable and its access revocable.

The following is a proposed responsibility map, not a claim that every platform supplies these controls automatically.

| Responsibility | What the business should require | Accountable owner |

| --- | --- | --- |

| Identity and access | An identifiable execution identity with only the necessary permissions | IT lead or contracted administrator |

| Business authority | Written limits on records, transactions and commitments the agent may change | Process owner |

| Financial limits | Separate controls for technology consumption and business expenditure | Budget holder |

| Approval points | Human authorisation before specified consequential actions | Named operational approver |

| Evidence | Records connecting the trigger, permitted action, approval and outcome | Operations and security leads |

| Intervention | A tested way to stop execution, revoke access and reconcile unfinished work | Service owner |

These requirements reflect the emphasis on bounded permissions and meaningful oversight in Singapore’s framework. Their implementation needs testing.

An approval button alone proves little. The approver needs enough context to judge the proposed action, time to intervene and a clear account of what has already happened.

Buy accountable delivery across suppliers

British procurement should compare Google, AWS and Microsoft proposals alongside credible open-source approaches and UK service providers. The supplied evidence supports specific Microsoft controls but does not establish equivalent capabilities or prices across those alternatives. A supplier ranking would therefore be unjustified.

Instead, compare proposals against the same operational task and acceptance conditions.

| Candidate or delivery route | What the proposal must demonstrate | Decision condition |

| --- | --- | --- |

| Google proposal | Permission boundaries, approval handling, action records and recovery in the intended workflow | Select only after those controls work with the company’s actual systems |

| AWS proposal | The same controls, plus a clear allocation of integration and ongoing operating work | Select only if the retained technical responsibilities are affordable |

| Microsoft Copilot Studio | How documented controls are configured and tested for this deployment | Assess configuration and dependencies rather than assuming product features settle responsibility |

| UK managed service provider | Monitoring scope, response hours, intervention authority, subcontractors and exit support | Select when the contract covers the operational work the business needs to outsource |

| Open-source or self-hosted approach | Maintainer support, licence suitability, permissions, monitoring and recovery ownership | Select only with a named team able to maintain the complete service |

Microsoft’s security and governance documentation describes data policies, usage visibility and agent identity controls for organisations that onboard its Agent 365 service. That is evidence of available mechanisms under stated conditions, not proof that a particular deployment is safe.

For UK managed service providers and cyber firms, my commercial thesis is straightforward. Managing agent access, exceptions and recovery could become a useful service to sell. The credible offering would specify who responds when an agent changes the wrong record, rather than promising an undefined “digital workforce”.

Budget for completed work and its exceptions

The buying metric I would use is cost per successfully completed business task, with a stated quality threshold. Message counts and demonstrations are insufficient acceptance criteria.

For a British small business seeking quotations, the cost schedule should include setup, connections to existing systems, usage charges, monitoring, human review, support, maintenance and exit. Request GBP figures, billing commitments and explicit VAT treatment. The evidence here does not support a comparable supplier price table.

The financial model also needs to recognise that human checking consumes time. If an employee must reconstruct every decision before approving it, the proposed workflow may offer little operational benefit.

Test that question against the existing process. Record successful completions, exceptions, review effort and recovery work. Keep the existing approach where the agent cannot demonstrate a worthwhile improvement.

The strongest objection is that targets are not results

The strongest counterargument is sound. A government announcement does not establish productivity gains, and a governance framework does not prove that agents can reliably run a business process. The supplied evidence contains no comparable UK adoption dataset that would justify declaring a national lag.

It would also be a mistake to turn the UAE’s public-sector target into a benchmark for British companies. An engineering wholesaler and a federal ministry have different resources, responsibilities and consequences of failure.

That weakens the race narrative. It does not weaken the case for preparation.

A company can define ownership, access boundaries and acceptance tests without granting broad autonomy or signing a large contract. Singapore’s framework itself recognises the tension between meaningful human oversight and the impracticality of watching every agent workflow continuously. Its executive summary makes risk management part of adoption.

The defensible response is bounded experimentation, with permission to stop when the economics or reliability fail.

Editorial analysis

Britain should measure readiness through the work its organisations can safely delegate. A useful test is whether a business can identify an agent’s owner, limit its authority, inspect its actions and recover from its mistakes.

The UAE announcement puts leadership and training alongside an ambitious deployment target. Singapore supplies a framework for controlling delegated action. British leaders can act on those ideas without accepting every claim made for autonomous AI.

Start with a process whose outcome can be checked and whose failures can be contained. Give the agent a narrow remit, a human owner and a tested stop mechanism. Expand the remit only when operational evidence earns it.

FAQ

Does the UAE target mean half of government jobs will disappear?

No. The announcement concerns transitioning 50% of federal services and operations to agentic AI within two years, not eliminating half of government employment. It also describes a programme to train 80,000 federal employees. The original announcement does not substantiate a job-loss forecast.

What separates an AI assistant from an AI worker?

In this article, the distinction is delegated authority to act on business systems. An assistant may propose an answer, while an agent may execute a permitted action. Singapore’s framework describes agents as taking actions and interacting with systems on behalf of humans.

Should a small British business outsource agent management?

Outsourcing is sensible when the business cannot provide the monitoring, maintenance and incident response its proposed workflow requires. Ask the provider to specify those duties, its intervention authority and its exit arrangements. Retain a named business owner who decides what the agent is allowed to do.

What should a first pilot prove?

It should prove that the agent completes a defined task at an acceptable cost and quality, stays within its permissions and stops or escalates correctly. Include failures and recovery in the test. This is consistent with Microsoft’s guidance on staged rollout, restricted access and human oversight.

Sources

UAE target for agentic federal services and operations. Source: UAE Cabinet announcement, 18 May 2026
The announced target is 50% within two years, representing a policy ambition rather than measured adoption or a workforce reduction.