Why three-quarters of British businesses using AI are more productive, almost none of them are richer for it, and what that has in common with cybersecurity’s skills problem
Three-quarters of UK businesses using AI report genuine gains in workforce productivity. According to the same research, from the Department for Science, Innovation and Technology, only 12% report an increase in revenue they can attribute to it. Seventyseven per cent say revenue hasn’t moved at all.
Most people read that gap one of two ways: either AI doesn’t really work as advertised, or businesses are too slow or too sceptical to capitalise on it properly. I don’t think either is right. This is a well-documented pattern in economic history, and it’s worth understanding properly before anyone decides the technology has failed.
We’ve seen this movie before
In 1987, the economist Robert Solow looked at decades of computers flooding into offices and factories and delivered one of the most quoted lines in economics: you can see the computer age everywhere but in the productivity statistics. Aggregate productivity data simply refused to show the gains everyone could see happening at the desk level. It took roughly a decade, until the mid-to-late 1990s, for that investment to show up as measurable economic output.
MIT’s Erik Brynjolfsson has spent much of his career explaining why, through what he and colleagues call the productivity J-curve. Transformative technology doesn’t lift output the moment it arrives. It depresses measured productivity first, while organisations spend time and money on the unglamorous, invisible work of reorganising around it, and only pays off once that reorganisation is largely complete. The economic historian Paul David told a similar story about electricity: factories that simply bolted an electric motor onto their existing steam-era layout saw almost nothing. The productivity boom only arrived once factories were redesigned from scratch around the fact that individual machines, not one central drive shaft, could now each have their own motor. The technology was never the bottleneck. The layout was.
AI in 2026 looks a great deal like computers in 1987 and factories in 1900. Torsten Slok, chief economist at Apollo, has made the same observation about today’s data: AI is everywhere except in the incoming macroeconomic figures. History would predict exactly this gap between adoption and conversion. It isn’t evidence the technology has failed.
The conversion mechanism
If productivity gains are real and revenue gains are rare, the question worth asking is what the small number of organisations converting one into the other are doing differently from everyone else.
My honest answer is that AI, on its own, is a time machine rather than a money machine. It reliably hands time back to the people using it. What happens to that time afterwards is a business decision, not a technology outcome, and most organisations are currently making that decision by accident rather than on purpose. PwC’s most recent global CEO survey of more than 4,400 leaders found that 56% of AIadopting companies saw neither a revenue increase nor a cost decrease from it. Just 12% saw a genuine improvement on both fronts, and that group had something specific in common: they had embedded AI extensively across operations rather than in a single pilot function, and they had built responsible-AI and governance frameworks around it rather than deploying first and figuring out oversight later.
There’s a sharper illustration in research from INSEAD and Harvard Business School that followed more than 500 high-growth startups through a three-month accelerator. The firms shown, through structured workshops, how to identify and act on new AI use cases ended up completing more tasks, becoming markedly more likely to land paying customers, and generating close to double the revenue of firms that had access to the same AI tools but not the same structured process for redirecting the time those tools freed up. The tools were identical. The redirection wasn’t.
That’s the difference between a business that treats AI as a productivity feature bolted onto existing processes, and one that treats the hours it frees up as raw material for something new: a faster sales cycle, a product nobody had time to build before, a service level competitors can’t match. The first group gets a quieter Friday afternoon. The second gets a P&L that looks different in twelve months.
I don’t want to overstate this, though. The economist Daron Acemoglu, who has been among the more sceptical voices on AI’s near-term economic impact, estimates that only around 5% of workplace tasks are likely to be profitably automated within the next decade, with a fairly modest effect on overall productivity. He’s probably right that this transformation will be slower and patchier than AI’s most enthusiastic advocates claim. If anything, that reinforces the point rather than undermining it: the businesses redesigning deliberately now are the ones who’ll be furthest up the curve whenever it does bend upward.
The same pattern, a different department
I see a near-identical shape in cybersecurity, which is instructive precisely because it’s a completely different discipline with completely different metrics.
ISC2’s 2025 Cybersecurity Workforce Study, the largest of its kind with more than 16,000 respondents, found that 88% of security professionals have experienced at least one significant negative consequence from a skills shortage in the past year. What’s changed is the diagnosis. For the first time, professionals are pointing at the absence of specific skills rather than a simple shortage of headcount as the bigger problem. Cloud security captures this well: hiring managers name it as the single technical skill they most want when recruiting, yet practitioners themselves rank it only second in importance for their own development, just behind AI and machine learning. Two groups, looking at the same discipline, optimising for slightly different things.
Just as with AI adoption, the instinctive response to a skills gap is to add more people, and just as with AI, that instinct usually misses where the value actually gets created. The organisations managing this well aren’t simply hiring harder. They’re investing in the specific, current capabilities of the team they already have: paid time for professional development, structured cross-training between security and adjacent technical functions, deliberate skill-building around whichever technologies, cloud infrastructure and AI systems alike, are changing fastest. It’s the same lesson as the productivity-to-revenue gap. Effort and activity aren’t the same thing as outcome, and the gap between them only closes when organisations redesign how the work gets done, rather than simply doing more of what they were already doing.
What to measure instead
If you lead technology or security anywhere, and you’re currently celebrating an efficiency metric, a percentage of tasks automated, hours saved per employee, tickets closed faster, ask the harder followup question before anyone else does. Where did that saved time actually go? Did it get redirected into something that grows the business or strengthens its defences, or did it simply get absorbed into the same processes running slightly faster than before?
The productivity is very likely real. Whether it turns into anything a shareholder, a board or an attacker will ever notice depends entirely on what happens next, and that part was never going to be automated for you.
Arik Fletcher is a fractional vCTO, vCISO and vCIO working with organisations across financial services, healthcare, manufacturing and hospitality
Sources: UK Department for Science, Innovation and Technology, AI Adoption Research, published January 2026 (3,500 UK business interviews); Robert Solow, New York Times Book Review, 1987; Erik Brynjolfsson and colleagues, MIT, research on the productivity Jcurve; Paul David, historical research on electrification and factory productivity; PwC, 29th Global CEO Survey; INSEAD/Harvard Business School accelerator research on AI use-case discovery, March 2026; Daron Acemoglu, published estimates on AI’s near-term productivity impact, 2024; ISC2, 2025 Cybersecurity Workforce Study, December 2025, and ISC2 Cloud Security Research Deep Dive, April 2026.

