Home Technology NCSC warns UK businesses over growing risks of ‘Shadow AI’

NCSC warns UK businesses over growing risks of ‘Shadow AI’

NCSC warns UK businesses over growing risks of 'Shadow AI'

The UK’s cyber security agency says businesses need better visibility and clearer rules as employees increasingly use AI tools outside approved systems.

The UK’s National Cyber Security Centre (NCSC) has warned businesses about the security risks created when employees use artificial intelligence tools that have not been approved by their organisation.

The practice, known as “shadow AI”, is becoming more common as workers turn to consumer AI services for everyday tasks.

In new guidance published on September 7, the NCSC said organisations’ policies and guidance have not always kept pace with the rapid growth of AI in the workplace. When approved systems do not meet employees’ needs, staff can turn to other services without informing their employer.

The NCSC said this can make security risks harder to identify and manage.

What is shadow AI?

Shadow AI is the use of AI technology that is not covered by an organisation’s approved systems and processes.

It is a form of the older “shadow IT” problem, where employees use software or online services without going through their company’s normal approval process.

The NCSC says shadow IT is rarely driven by malicious behaviour. Employees often turn to unofficial tools because they are trying to complete their work and find that approved systems are too limited, unavailable or slow to access.

The same problem is now appearing with AI.

Research cited by the NCSC found that 71% of UK employees had used AI tools that were not approved by their employer. Microsoft’s research, published in October 2025, also found that 51% of those employees continued to use unapproved AI tools every week.

Why businesses are concerned

The main issue is not simply that an employee has used an AI chatbot.

The bigger concern is what information is being entered into the service and what access an AI system has to company data.

The NCSC warns that employees who put sensitive company or customer information into an unapproved AI service can reduce their organisation’s control over that information.

Depending on the service and its privacy settings, information submitted to an AI system may be stored, retained or used to improve the service outside the company’s normal security arrangements.

That can create risks involving confidential information, intellectual property and regulatory requirements.

For a business, the problem can be difficult to spot if the security team does not know which tools employees are using.

As the NCSC puts it, “You cannot manage what you do not know.”

AI agents create another security challenge

The NCSC is also drawing attention to AI agents.

Unlike a basic chatbot, an AI agent can carry out tasks and interact with other systems. That can make the consequences of a security weakness more serious.

The NCSC warns that AI agents can contain vulnerabilities and, if successfully exploited, an attacker could gain access to the same data, services and permissions available to the agent.

That means businesses need to consider not only what an AI system can produce, but also what systems it can access.

The agency has separately published guidance on adopting agentic AI safely, including the use of safeguards, sandboxing and active oversight.

The NCSC does not recommend simply banning AI

One of the more important points in the new guidance is that the NCSC is not telling businesses to stop employees using AI.

Instead, it says organisations should understand why staff are turning to unapproved tools and make sure secure alternatives are available.

The agency says shadow AI is unlikely to disappear completely. Trying to eliminate it altogether could also miss the reason employees are using these services in the first place.

If an approved tool cannot perform a task, or getting permission to use a new service takes too long, employees may simply find another option.

That makes visibility and practical policies important parts of the response.

What businesses should do

The NCSC recommends several steps for organisations dealing with shadow AI.

First, businesses need to understand what AI tools are actually being used across the organisation.

That includes looking beyond officially approved software and considering services employees may have adopted themselves.

Businesses should also create a positive cyber security culture. Staff need to feel able to raise questions about AI tools rather than hiding their use.

Clear guidance is important as well.

Employees should know which AI services they can use, what information they can enter and when they need to ask for approval.

The NCSC also recommends securely integrating AI systems into the workplace rather than treating them as something that can simply be blocked.

Why blanket bans can be difficult

For many businesses, banning consumer AI tools may seem like the simplest solution.

But the NCSC’s guidance points to a different problem: employees are already using AI because it helps them complete tasks more quickly.

Microsoft’s UK research found that workers use consumer AI assistants for activities including drafting workplace communications, preparing reports and presentations, and finance-related tasks.

If businesses remove those tools without providing suitable alternatives, employees may continue using AI without telling their IT or security teams.

That can leave the company with less visibility rather than more.

Shadow AI is becoming a business issue

The warning comes as AI moves further into ordinary business operations.

Companies are using AI for customer service, coding, administration, research, analysis and other tasks. At the same time, employees can access new AI services with little technical knowledge or support from their employer.

That creates a difficult balance for business leaders.

Restricting AI too heavily can slow adoption and productivity. Allowing employees to use any service without controls can create security and compliance risks.

The NCSC’s approach is to focus on managing that gap rather than pretending it can be removed.

For businesses, that means knowing what AI is being used, understanding what information is being shared and making secure options easy for employees to access.

The message from the UK’s cyber security agency is straightforward: AI use is already part of the workplace, so organisations need to manage it rather than assume they can simply stop it.

This article is based on guidance from the UK’s National Cyber Security Centre, along with research published by Microsoft and related NCSC guidance on shadow IT and agentic AI.

LEAVE A REPLY

Please enter your comment!
Please enter your name here