UK Cyber Agency Warns Shadow AI Use Exposes Corporate Data
NCSC finds 71% of UK employees use unapproved AI tools, creating visibility gaps and compliance risks for organizations.
The UK's National Cyber Security Centre has issued a warning that employees using unauthorized AI tools are creating significant security blind spots for their organizations, exposing corporate and customer data to risks that security teams may not even know exist.
In a blog post published September 7, the NCSC highlighted research from Microsoft showing that 71% of UK employees have used AI tools their employers have not approved. The agency characterized this "shadow AI" phenomenon as widespread and likely to persist as workers adopt new services faster than organizations can evaluate and provide sanctioned alternatives.
The visibility problem
Shadow AI refers to artificial intelligence technology operating outside an organization's approved systems and processes—a subset of the broader shadow IT challenge. The NCSC emphasized that these unapproved tools create gaps in visibility that prevent security teams from understanding their full risk exposure.
"Many people are reaping the benefits of AI in the workplace and are rightly being supported to do so by their employers, but IT security teams should not assume they are seeing the full picture," said David Chismon, NCSC CTO for architecture.
When employees transfer sensitive information to consumer AI services, organizations lose visibility and control over that data. The information may be stored, retained, or used to improve the AI service itself—often without the organization's knowledge or consent.
Risks extend to AI agents
The NCSC also warned about vulnerabilities in AI agents, which can hold significant data access and privileges within corporate systems. If an attacker exploits a vulnerability in an AI agent, they could gain the same data, services, and privileges the agent legitimately possesses.
The agency noted that attackers are highly likely to target agents with looser security guardrails to exploit vulnerabilities or misconfigurations elsewhere in corporate IT infrastructure.
Employees who use shadow AI with company or customer data increase the risk of data breaches, intellectual property loss, and regulatory compliance failures, according to the NCSC.
Why it matters
The shadow AI problem reflects a fundamental mismatch between the pace of AI adoption and organizational security processes. As AI capabilities become embedded in everyday productivity tools, the traditional approach of blocking unauthorized services becomes impractical. Organizations that fail to address this gap face not only immediate security risks but also potential regulatory penalties and competitive disadvantages as employees work around inadequate approved tools.
A cultural approach to mitigation
The NCSC recommended that organizations focus on reducing shadow AI rather than attempting to eliminate it entirely. The agency emphasized that blocking connections to all possible AI tools is unrealistic.
Instead, the NCSC urged organizations to develop a positive cybersecurity culture where employees feel comfortable discussing the tools they want to use. Organizations should establish clear guidelines around what secure AI use looks like rather than imposing blanket prohibitions.
"Organizations can't hope to block connections to all possible AI tools, so they need to develop a positive cybersecurity culture with open dialogue about the tools staff might wish to use and to set clear guardrails around what secure use of AI looks like," Chismon said.
The agency also pointed to guidance on the careful adoption of agentic AI services that it published with international partners.
These details were first reported by Infosecurity Magazine.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call