Back to Feed
AI SecuritySep 9, 2026

NCSC Warns Shadow AI Is Creating New Security Blind Spots for UK Businesses

NCSC warns UK businesses about security risks from unapproved 'shadow AI' tools used by employees.

Summary

The UK's National Cyber Security Centre (NCSC) has issued a warning about 'shadow AI,' the use of unapproved artificial intelligence tools by employees. This practice creates significant security blind spots, exposing sensitive data and reducing organizational control. The NCSC advises against outright bans, instead recommending improved visibility, secure integration, and addressing employee needs to mitigate risks.

Full text

The UK’s National Cyber Security Centre (NCSC) has warned organisations about the security risks posed by “shadow AI”, as employees continue to turn to artificial intelligence tools that have not been approved by their employers. In guidance published this week, the NCSC described shadow AI as the use of AI technology outside an organisation’s approved systems and processes, warning that security policies and governance have struggled to keep pace with the rapid adoption of AI in the workplace. The scale of the issue could already be significant. Research cited by the NCSC found that 71% of employees have used AI tools that have not been approved by their employer. According to the NCSC, unapproved AI services can expose sensitive company and customer information, reduce organisations’ visibility and control over their data, and create new opportunities for attackers. Information entered into consumer AI services may be stored, retained or used to improve those services outside existing corporate security and governance arrangements, depending on the privacy controls in place. The agency also highlighted a potentially more serious risk as organisations move from generative AI tools towards AI agents. If an attacker exploits a vulnerability in an agent, they may be able to gain access to the same data, services and privileges legitimately available to that agent. Darren Guccione, CEO and co-founder of Keeper Security, said the warning reflects a challenge many UK security teams are already facing. “The NCSC’s warning on shadow AI reflects the reality of what many UK security teams are having to contend with. When employees adopt AI tools faster than IT can assess them, visibility gaps open long before governance has an opportunity to catch up. Microsoft’s research, cited by the NCSC, found that 71% of UK employees have used AI tools their employer hasn’t approved. Keeper Security’s 2026 research underlines the effect this is having on security teams, with 37% of UK organisations saying they lack visibility into which AI tools employees are actually utilising inside the business. “The most significant detail in the NCSC’s warning is its point about AI agents inheriting the privileges of whoever deploys them. An attacker who compromises a poorly governed agent gains whatever access that agent holds, whether that’s a customer database or a finance system. Organisations that haven’t extended least-privilege and just-in-time access principles to their AI agents and non-human identities are exposed in ways endpoint controls alone won’t catch.” Banning AI is unlikely to work Rather than recommending organisations attempt to eliminate shadow AI altogether, the NCSC said businesses should focus on reducing the associated risks and understanding why employees are turning to unapproved tools in the first place. It recommends creating a positive cyber security culture, providing AI tools that meet employees’ needs and securely integrating AI systems into the workplace. Guccione added: “Banning shadow AI outright rarely works, as the NCSC itself acknowledges. Employees will find routes around blocked tools when the approved ones can’t do what they need. “The more durable fix is improving visibility by identifying what identities, both human and machine, exist across the environment and what they can access. Organisations must enforce least-privilege principles by default, rather than waiting until an incident forces the question.” Jamie Akhtar, CEO and co-founder at CyberSmart, agreed that businesses need to balance employees’ desire to use AI with appropriate security controls. “The NCSC is right to highlight shadow AI as a growing cyber security challenge. Employees are using AI tools to work faster and more efficiently, but when those services sit outside an organisation’s approved systems, businesses can quickly lose visibility over where sensitive company and customer data is being shared, stored or processed. “Simply banning AI is unlikely to solve the problem. Businesses need to provide secure, approved alternatives that allow people to benefit from AI without introducing unnecessary risk. Clear policies, employee education and appropriate technical controls all need to develop at the same pace as AI adoption.” Akhtar said the challenge may be particularly difficult for SMEs without large in-house security teams, where managed service providers could help organisations identify unapproved technology and establish appropriate AI policies and controls. “An MSP can help businesses identify unapproved technology, put proportionate AI policies and controls in place, educate employees and continuously manage emerging risks, giving organisations the confidence to embrace AI while maintaining visibility and control over their security.” The NCSC said shadow AI is unlikely to disappear completely as AI services become cheaper and more readily available. Instead, organisations need to understand how and why employees are using these tools so they can provide secure alternatives while maintaining visibility over sensitive information and access to corporate systems.

Entities

NCSC (vendor)Microsoft (vendor)Keeper Security (vendor)CyberSmart (vendor)AI agents (technology)generative AI (technology)