'You cannot manage what you do not know': The NCSC is calling for a crackdown on shadow AI
Organizations are urged to identify shadow AI use and tighten up security procedures
The widespread use of shadow AI is putting British businesses at risk, according to the UK’s National Cyber Security Centre (NCSC).
The use of unapproved AI tools is on the rise, with research from Microsoft late last year revealing that 71% of UK employees have used unapproved consumer AI tools at work, with more than half saying they do so every week.
While the NCSC said AI can help people complete tasks more quickly, improve decision-making, cut costs and increase productivity, organizations are falling short when it comes to policy and guidance.
In a new briefing document, the security agency said enterprises need to tighten up practices on this front and crack down on unapproved use.
"Rather than preventing them from using AI, this can mean employees turn to using AI tools that have not been approved by their organization, introducing new cybersecurity risks that can be hard to identify,” the document reads.
"Where cybersecurity policies cannot meet business needs, organizations are likely to continue seeing their employees adopt new AI services before they have had time to assess them and provide approved alternatives. This trend is likely to be reinforced as AI capabilities become increasingly affordable and readily available."
The rise of shadow AI
Some of the biggest concerns associated with shadow AI is the risk of data breaches, the loss of intellectual property, and failure to meet regulatory requirements.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
If employees transfer sensitive or proprietary information to consumer AI services, there's a strong chance that this information might be stored, retained, or used to improve the service – outside established security and governance arrangements – unless specific privacy controls are in place.
This can reduce the organization's visibility and control over that information.
Similarly, the use of shadow AI can also create a wealth of new opportunities for attackers, according to the NCSC. If hackers successfully exploit a vulnerability, they can gain access to the same data, services, and privileges that the agent has legitimate access to.
Attackers are highly likely to use agents with looser guardrails to exploit any vulnerabilities or misconfigurations in the wider corporate IT system.
"The NCSC is not recommending that individuals stop using AI – but when turning to these tools for assistance with a work task, think carefully about which apps and services you are using before you share data," said the NCSC.
"It may feel natural to stick with using the same AI service that you are familiar with from your personal life – but using systems that are not corporately approved can present real problems for your employer."
Stronger controls are needed
The NCSC said organizations need to introduce policies that reflect the real world, with the aim of reducing risk rather than assuming it can be eliminated.
This means adopting a positive cybersecurity culture and encouraging open communication about security issues. Once organizations understand why people are using shadow AI, it becomes much easier to identify risks, provide secure alternatives, and support innovation safely.
The guidance echoes analysis by Gartner last year that found nearly half of enterprises could face serious security or compliance-related incidents as a result of shadow AI by 2030.
"You cannot manage what you do not know," the NCSC guidance noted. "By raising awareness of the risks of shadow AI use within your organisation and understanding the needs of employees, you can help them get the benefits of new technologies while using them securely."
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Samsung backs Mistral in record-breaking €3 billion funding roundNews The French AI company breaks European records, but still trails American rivals with a €21bn valuation
-
Advania targets fresh growth with new UK chief executiveNews The seasoned technology veteran will lead the IT services provider into its next phase of growth and transformation
-
NCSC issues alert over 'zero-click' phishing campaign hitting enterprisesNews Ukrainian organizations were used to test new zero-click techniques employed by Russian hackers
-
NCSC issues warning over Russian intelligence-backed threat groupNews The advisory comes as the government cracks down on groups involved in “destructive cyber and hybrid operations”
-
UK’s Cyber Resilience Pledge gathers momentum as 60 firms sign up to bolster capabilitiesNews The voluntary pledge sees organizations tightening up their defences, particularly against supply-chain attacks
-
Hostile states behind three-quarters of UK critical infrastructure attacksNews NCSC CEO warns that with the rise of AI, the danger is only set to get worse
-
NCSC urges organizations to shore up supply chain security practicesNews With attackers increasingly compromising open source packages to spread malware, organizations need to be on their guard
-
UK firms left in the dark over what workers are sharing with AINews Security teams can’t keep track of what workers are sharing with AI applications, regardless of whether they’re approved or unauthorized
-
A ‘perfect storm’: NCSC chief issues warning over quantum threats, nation-state hackers, and the dangers of global ‘hacktivism’News NCSC CEO Richard Horne says nation-state attacks, AI and the looming quantum threat require stronger global collaboration
-
The NCSC says it’s time to switch to passkeysNews UK security organization calls for companies to step up and offer more secure ways to login