RiverSafe’s Censuswide survey of 200 senior security leaders at large UK retailers reported AI-related incidents, unapproved tools and incomplete security reviews. The UK Government’s Cyber Security Breaches Survey and NCSC secure-AI guidance show how boards can convert that warning into access, supplier, monitoring and incident controls.
Coles and Woolworths have described limited facial-recognition testing while emphasising that no deployment decision has been made. OAIC guidance and the Bunnings tribunal outcome show that necessity, proportionality, notice and documented privacy assessment must come before rollout.