"Many people are reaping the benefits of AI in the workplace and are rightly being supported to do so by their employers, but IT security teams should not assume they are seeing the full picture," said David Chismon, NCSC CTO for architecture.
Widespread, often hidden use: Microsoft research finds 71% of UK employees
The UK's National Cyber Security Centre (NCSC) published a blog post on 7 September warning that employees are increasingly using AI tools outside of approved corporate systems — a practice the agency characterizes as "shadow AI." The NCSC cited Microsoft research showing that 71% of UK employees had used AI tools not approved by their employer, and the agency said that finding suggested shadow AI use was widespread.
Visibility gaps when employees use unapproved AI tools
The NCSC said unapproved AI tools create visibility and control gaps for organizations. When staff transfer company or customer data to consumer AI services, that information may be stored, retained or used to improve the service — actions that can reduce an organization’s ability to see or control where sensitive information lives. The agency warned these gaps can increase the risk of data breaches, intellectual property loss and failure to meet regulatory requirements.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadAgentic AI and the risk of shared privileges
The NCSC highlighted an additional technical risk from agentic AI services. It explained that AI agents can carry critical vulnerabilities and that an attacker who exploited one of those vulnerabilities could gain the same data, services and privileges the agent legitimately held. The agency also warned that attackers were highly likely to use agents with looser guardrails to exploit vulnerabilities or misconfigurations elsewhere in corporate IT.
Why shadow AI persists: business needs outrun policy
According to the NCSC, shadow AI is likely to persist because employees often adopt new services faster than organizations can assess them and provide approved alternatives. The problem commonly appears when existing cybersecurity policies fail to meet business needs, creating an incentive for staff to use unassessed tools before their employer has completed an evaluation. The agency advised that organizations cannot realistically block connections to all possible AI tools and therefore must take other approaches.
How technologists, enterprises, and employees should respond
- Technologists and security teams: the NCSC urged them to avoid assuming they have full visibility over staff activity and to recognise that AI agents can carry vulnerabilities allowing attackers to inherit agent privileges. The agency recommends focusing on practical steps to reduce shadow AI risk rather than attempting total elimination.
- Enterprise procurement and leadership: the agency said organizations should work to provide assessed, approved alternatives so staff are less incentivized to adopt external services. Clear guardrails around what constitutes secure use of AI were recommended as part of that response.
- End users and employees: the NCSC recommended fostering a positive cybersecurity culture so staff feel able to discuss the tools they want to use. Open dialogue, combined with clear rules on secure AI use, was presented as a means to reduce risky transfers of sensitive information to consumer services.
NCSC guidance and international coordination
The NCSC emphasised a pragmatic posture: reduce, rather than eliminate, shadow AI. It recommended developing a positive cybersecurity culture with open dialogue about the tools staff might wish to use and setting clear guardrails around secure AI practices. The post also pointed to guidance the agency published with international partners on the careful adoption of agentic AI services.
The agency’s message is straightforward and consequential: shadow AI is already widespread, it creates hard-to-see data flows and new technical attack surfaces, and organizations that simply block connections will not close those gaps. The practical test will be whether organizations can match the pace of staff adoption with assessed, approved tools and clear guardrails that restore visibility and control — or whether the visibility gaps the NCSC identified will continue to widen.
Source: NCSC Warns Shadow AI Creates New Security Risks — Infosecurity Magazine




