UK firms left in the dark over what workers are sharing with AI
Security teams can’t keep track of what workers are sharing with AI applications, regardless of whether they’re approved or unauthorized
Enterprises across the UK are contending with “critical blind spots” over what workers are sharing with AI applications, according to new research.
A survey from SailPoint found more than two-thirds (67%) of organizations can’t account for the information staff are sharing with AI platforms and large language models (LLMs).
Worse still, the study noted that 35% of respondents admitted to sharing data through external tools, rather than approved internal applications, which is creating an array of risks for enterprises.
The rise of ‘shadow AI’ has become a recurring pain point for organizations over the last two years. Workers using unauthorized applications risk exposing sensitive company data, research shows – and there’s no sign of the trend slowing down.
Research from Gartner in November 2025 predicts that 40% of enterprises will suffer a data breach due to shadow AI by 2030.
SailPoint noted that the growing shadow AI trend comes in spite of the fact many enterprises are investing heavily in data management and AI capabilities for staff.
More than four-in-five respondents (82%) said they have invested in additional staff and skills training to help workers better manage AI applications, while 41% have brought on dedicated AI and analytics personnel.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Notably, nearly half (45%) of IT leaders said they still lack visibility on where information is being shared, and how.
Agentic AI poses new governance challenges
Mark McClain, CEO and Founder at SailPoint, said the findings show AI can often represent a catch-22 for organizations. While these tools are helping staff, they’re now creating additional risk surfaces for security teams.
“AI tools can enhance productivity, but they also create serious risk when they operate outside an organization’s visibility and governance,” he said.
“When sensitive information is entered into unapproved models, it can be exposed, mishandled, or even amplified through errors and hallucinations.”
McClain warned that with the rise of agentic AI, poor data management practices could be further amplified and put businesses at greater risk.
SailPoint noted that the need for greater visibility and oversight is now a priority for many enterprises on account of growing risks. In a previous study from SailPoint, four-in-five organizations (80%) revealed that AI agents had performed “unintended actions” such as accessing or sharing inappropriate data.
UK businesses are adding as many as 10,000 agents and machine identities each month, the company noted, meaning security teams could quickly become overwhelmed.
"As use of AI systems becomes more widespread, the situation is only going to get more out of control if organizations fail to put the right guardrails in place – compounded by other tools flying under the radar,” McClain commented.
“Organizations need to stop workarounds and regain control. That takes a combination of skills and awareness, but it also fundamentally boils down to a challenge around identity”
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
What to expect at Dreamforce 2026Opinion Salesforce will be pinning its hopes on the Claudeforce launch resonating with customers
-
Atlassian introduces 'always-on' capabilities for agentic development workflowsNews Customers can now adopt and scale governed agentic workflows right across the AI software development lifecycle
-
‘We can assume that all threat actors are using AI in some capacity’: Cyber researchers warn hackers are ramping up automated attacksNews Google Threat Intelligence Group has issued a warning over the increased threats posed by hackers using agentic AI tools
-
'You cannot manage what you do not know': The NCSC is calling for a crackdown on shadow AINews Organizations are urged to identify shadow AI use and tighten up security procedures
-
Trust your AI agents? New research shows ‘memory poisoning’ can dupe them into ‘remembering’ fake information – and it’s a huge security riskNews Memory poisoning allows hidden text on a webpage to be treated as fact and used to make harmful decisions
-
Anthropic’s Mythos AI tried to dupe devs in social engineering attack, collaborated with other agentsInter-agent collaboration is a serious cause for concern, says security expert
-
Anthropic joins OpenAI in admitting loss of control in cybersecurity testsThe company found Claude AI had escaped containment three times and targeted other organizations
-
'It delivers world-class performance at 50 percent of the cost of leading models': Microsoft unveils cut-price AI for security with latest in-house model launchNews Pairing the MAI security model with GPT-5.4 gives benchmark leading results at half the cost, according to the tech giant
-
An ‘unprecedented cyber incident’: How OpenAI models breached Hugging Face – and why it could herald a ‘new phase of AI-powered cyber crime’News The incident should serve as a stark warning on the dangers of AI agents, according to cyber experts
-
The case for the channel in an AI-driven security marketIndustry Insights AI won't replace channel partners; SMB cybersecurity still relies on trust