The UK’s National Cyber Security Centre warned on September 7 that “shadow AI,” employees using AI tools their employer has not approved or assessed, has become a security risk organizations are struggling to see, let alone manage. The agency cited Microsoft research finding that 71% of UK employees have used AI tools not sanctioned by their company, adoption moving faster than most security teams can build a policy around.

The risk NCSC describes is not abstract. Sensitive information pasted into a consumer AI service can be stored outside the organization’s own security controls, with no way for the security team to know it left the building. Unapproved tools also bring their own vulnerabilities into the environment, an entry point that never appears on an asset inventory because it was never sanctioned to be there. Shadow AI, in NCSC’s framing, is shadow IT wearing a new label, and it inherits the same blind spot: what security teams cannot see, they cannot secure.

What stands out is what NCSC is not recommending. Rather than pushing blanket bans, the agency says teams should focus on reducing shadow AI use, not eliminating it, and should build a “positive cybersecurity culture” where staff feel able to disclose the tools they use instead of hiding them. That is a concession that prohibition already failed once, against shadow IT generally, for the reason it will fail again here: employees adopt tools faster than any approval process can evaluate them, and driving that underground only removes the visibility security teams need most.

The practical takeaway is to stand up an approved AI pathway fast enough that staff have a legitimate alternative, alongside monitoring AI traffic patterns rather than trying to block them outright. That sits alongside this publication’s coverage of AI agents crossing from tool to threat actor, and an argument against treating any AI environment as inherently safe.

Source: National Cyber Security Centre