The State of Dual CX · Q1 2026
We audited 100 UK brands. None were ready.
A field audit of how the UK's best-known brands behave when a customer's AI agent shows up, calling, filling forms, asking for policy, negotiating an outcome. Not a single one had declared scope, declared authority, or a designed fallback for the moment AI enters the conversation.
Licensed CC BY 4.0
Headline findings
0/100
brands with a published AI-interaction policy
73%
with no fallback path when an AI agent reached them
100
UK brands audited across retail, finance, and public sector
17
verification flows an AI agent passed undetected
Methodology
What we tested and how.
We selected 100 UK-facing brands across 17 sectors, weighted toward brands with the highest consumer contact volume. For each brand we conducted three assessments: a policy audit (what has the brand published about AI in customer service?), a surface audit (what does the brand's AI-facing infrastructure actually expose?), and a field test (what happens when an AI agent, acting on a real customer's behalf, attempts a real interaction?).
The policy audit examined public-facing statements, terms and conditions, help centre content, developer documentation, and regulator filings, for any declaration of scope, authority, fallback, or data-sharing policy applicable to AI-driven interactions.
The surface audit tested for machine-readable declaration surfaces: robots-style manifests, well-known JSON endpoints, structured data on service pages, or explicit endpoints for agent-to-agent negotiation. None were found.
The field test used consenting real-customer data and a compliant voice/chat AI agent to attempt a common service task, a return, a complaint, a tariff query, or a benefits enquiry, through the brand's public contact channels. Interactions were audited for verification behaviour, containment behaviour, escalation behaviour, and outcome.
Sectors covered
Findings
Four patterns held across every sector.
None declared scope
Zero of the 100 audited brands had a public statement defining what an AI agent may or may not do on their service surface. The absence was uniform across regulated and non-regulated sectors alike.
None declared authority
No brand exposed a declaration of the authority its own AI can commit to, or the authority it will accept from an incoming AI agent. Interactions therefore default to whatever the customer-facing surface happens to say, which is rarely tested against agentic input.
73% had no fallback path
The majority had no defined escalation for the moment an AI agent contacts them. Where a fallback existed, it was typically an unadvertised human queue rather than a designed pathway.
17 verification flows passed
In field-tested interactions, an AI agent presenting the customer's declared details passed 17 distinct verification flows undetected, including multi-step KYC on regulated services. Verification designed for humans is not verification designed for agents.
What we recommend
Publish the declarations before you ship the agent.
The gap the audit measured is not a technology gap, the technology to declare, verify, and escalate is off-the-shelf. It's a design and governance gap. Brands are shipping AI on their side of the conversation without a shared expectation of what the other side will do.
The Service Handshake standard closes that gap. We recommend every audited sector adopts a declaration schema at the brand level before deploying further AI-facing surfaces. Six declaration elements. One JSON schema. Vendor-independent.
For the operators who requested it: the audit dataset is open on GitHub under CC BY 4.0, including the field-test transcripts (with consenting customer PII redacted), the policy inventory, and the surface audit scripts. Reproduce it against your own sector. Contribute back what you find.