Briefings — Grocery Retail

AI in UK Grocery Retail

Four regulators hold a position on AI in or around this sector. None of them is aimed at its largest deployments — the facial recognition now reaching around two hundred stores, or the machine learning forecasting that already sits inside a statutory duty.

Why this briefing

In September 2025 a supermarket trialled live facial recognition in two stores. By July 2026 it was in more than fifty-five, with up to a hundred and fifty more announced before Christmas. Twice in that period the wrong person was stopped — in February at Elephant and Castle, in August at East Dulwich — and on both occasions the company's explanation was the same: human error, not the technology.

That explanation is correct, and it is the problem. Since 5 February 2026, section 80 of the Data (Use and Access) Act has permitted solely automated significant decisions provided four safeguards hold, which means the defence that a decision was not solely automated now rests entirely on whether the human review was doing something real. In a supermarket that review is a duty manager with a phone, in seconds, mid-shift.

Meanwhile the wider estate carries a second duty that almost nobody files under artificial intelligence. Paragraph 10 of the Groceries Supply Code of Practice requires a retailer to compensate a supplier for costs caused by its forecasting errors, unless the forecast was prepared with due care, after consultation, on a basis communicated to that supplier. Sainsbury's says machine learning forecasting is embedded across all food products.

Every regulator has a position. None of them is aimed here — five ICO priorities with retail not among them, zero mentions of technology, systems, data or AI across two 2026 Groceries Code Adjudicator publications, Sainsbury's facial recognition going from two stores to around two hundred, 18% of suppliers reporting significant costs from inaccurate retailer forecasting, the poorest fifth of households spending 15.2% of expenditure on food against 7.9% for the richest, and £285m and £131m of audited cyber incident costs at the Co-op and M&S
From the full briefing's regulatory and market data — sources listed in the document.

The human moment

A shopper is stopped at a self-checkout and told they have been identified. They are not a customer with a file and a reference number; they are a member of the public being judged in front of other people. A supplier harmed by a bad forecast has a regulator, a duty and a compensation route. The shopper has a data protection complaint, or a civil claim. There is no statutory grocery ombudsman, and the published price of getting it wrong so far is a £75 shopping voucher — set by the retailer, because no regulator has set one.

What's inside

Fifteen pages, written for an executive who knows grocery well and AI not at all:

  • A note on the numbers — what is included, what was excluded, and why
  • The market, and which households carry the consequence when a system is wrong
  • The pressure point — a record-low workforce, a record cost base, and supervision aimed elsewhere
  • Four regulators, read in full: the ICO, the FSA Science Council, the Groceries Code Adjudicator and the CMA
  • The estate on the operators' own record — forecasting, personalisation, colleague tooling, loss prevention
  • The threat side, and why it is a failure of human verification rather than fraud
  • Two duties nobody has connected to their AI estate — DUAA section 80 and GSCOP paragraph 10
  • Beyond the UK: what the EU AI Act does and does not do, and the deadline it has just moved
  • Eight things that are defensible today, three horizons, and eight numbers to report
  • An eight-workstream way in

The discipline behind it

Every figure carries a source. Nine bodies of evidence were found and deliberately excluded, and the exclusions are listed in the document — among them the whole class of vendor adoption percentages, a technology supplier's claim that its forecasting models are up to forty per cent more accurate with no baseline stated, and claims that electronic shelf labels are enabling surge pricing in British supermarkets, for which no UK primary evidence exists.

Four findings were corrected during verification before the briefing was written. One of them would have opened the international section with a prohibition that does not exist: the EU AI Act's ban on real-time remote biometric identification in public spaces applies to law enforcement only, not to supermarkets.

Who it's for

An AI lead or programme director inside a large grocer, a board member being asked to approve a rollout, or anyone on the supplier side who wants a plain, sourced account of what the systems on the other side of the table are now doing. It is written to work for all three.

Briefing details

Sector
Grocery retail
Regulator
ICO / GCA / CMA
Published
3 September 2026
Length
15 pages, free PDF

Frequently asked

Questions people ask before reading

Is this vendor material?

No. Every figure is checked against a regulator, published legislation, government statistics, named academic work, or an operator's own audited accounts. Nine bodies of evidence that could not be sourced to one of those were excluded, and the exclusions are listed in the briefing itself — including a technology supplier's claim that its forecasting models are up to 40 per cent more accurate, which has no stated baseline.

Is it free to download?

Yes. It downloads directly, with no form and no email address required.

How current is the research?

Verified against primary sources as at 2 September 2026, including the ICO's AI and biometrics strategy update of March 2026, the FSA Science Council's report of June 2026, the Groceries Code Adjudicator's April 2026 supplier survey and July 2026 priorities, and the 2026 annual reports of Sainsbury's, Tesco, Marks and Spencer and the Co-op.

Does it name retailers?

Yes, but only from regulator or government findings, published statistics, or the retailers' own disclosures, and then illustratively. No organisation named in the briefing has been engaged or approached in connection with it. Individuals are named only where they have spoken publicly about their own experience.

Is it only about facial recognition?

No. It covers the whole estate — machine learning forecasting, replenishment, personalisation, colleague tooling and loss prevention. Two duties run through it: section 80 of the Data (Use and Access) Act 2025 for decisions about customers, and paragraph 10 of the Groceries Supply Code of Practice for forecasts affecting suppliers.

What if I want to take this further?

The briefing ends with an eight-workstream action plan. The first three — readiness assessment, use case triage, and a regulatory position paper — form a natural first engagement of six to eight weeks.