Skip to content
NCSC Warns Shadow AI Creates New Security Risks

NCSC Warns Shadow AI Creates New Security Risks

Infosecurity-Magazine September 7, 2026

The UK's National Cyber Security Centre (NCSC) has warned that employees using unapproved AI tools can expose corporate data and create security risks that organizations may struggle to detect and manage.

The NCSC blog post , published on September 7, said shadow AI was likely to persist as employees adopted new services faster than organizations could assess them and provide approved alternatives.

The agency cited Microsoft research that found 71% of UK employees had used AI tools not approved by their employer. The NCSC said the research suggested shadow AI use was widespread.

Unapproved AI Tools Create Visibility Gaps

Shadow AI refers to AI technology that falls outside an organization's approved systems and processes and is a form of shadow IT.

"Many people are reaping the benefits of AI in the workplace and are rightly being supported to do so by their employers, but IT security teams should not assume they are seeing the full picture," said David Chismon, NCSC CTO for architecture.

The NCSC said employees who give shadow AI access to company or customer data likely increase the risk of data breaches, intellectual property loss and failure to meet regulatory requirements.

The blog post said the problem could emerge when existing cybersecurity policies failed to meet business needs, encouraging staff to adopt new services before their employer had assessed them.

The NCSC also warned that AI agents could carry critical vulnerabilities, and that an attacker exploiting one could gain the same data, services and privileges the agent legitimately held.

It explained that attackers were highly likely to use agents with looser guardrails to exploit vulnerabilities or misconfigurations elsewhere in corporate IT.

Organizations Urged to Reduce Shadow AI Risks

Employees who transfer sensitive information to consumer AI services are likely reduce their organization's visibility and control over it, the NCSC said, because that information may be stored, retained or used to improve the service.

The agency warned that organizations should focus on reducing rather than eliminating shadow AI, as with shadow IT more broadly. It recommended adopting a positive cybersecurity culture so employees felt able to security issues openly.

"Organizations can't hope to block connections to all possible AI tools, so they need to develop a positive cybersecurity culture with open dialogue the tools staff might wish to use and to set clear guardrails around what secure use of AI looks like," Chismon said.

The NCSC also pointed to guidance on the careful adoption of agentic AI services, published with international partners.

Infosecurity Europe: OWASP Introduces Agentic AI Security Maturity Framework News 5 June 2026

Infosecurity Europe: OWASP Introduces Agentic AI Security Maturity Framework

Securing Perimeter Products Must Be a Priority, Says NCSC News 4 March 2024

Securing Perimeter Products Must Be a Priority, Says NCSC

Cost of Insider Incidents Surges 20% to Nearly $20m News 24 February 2026

Cost of Insider Incidents Surges 20% to Nearly $20m

Microsoft Copilot Deployments Delayed Over Security Concerns News 23 July 2026

Microsoft Copilot Deployments Delayed Over Security Concerns

AI Agents Are Here. Security Must Be an Accelerator for AI Transformation Opinion 20 May 2026

AI Agents Are Here. Security Must Be an Accelerator for AI Transformation

What’s Hot on Infosecurity Magazine?

FBI Probes Possible Breach of 153 Million Driver’s Licenses

US and Canadian Court Records Breached Following Thomson Reuters Incident

Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone

CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation

FulcrumSec Claims Responsibility for Manchester Airport Group Breach

65% of Enterprises Have Seen AI Agents Act Out of Scope

CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation

Attackers Steal METR API Key and Burn $600,000 in AI Credits

New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation

Hiring for the AI Era: A New Challenge for CISOs

How Industry Coalitions Are Rallying to Secure Open Source Software for the AI Era

65% of Enterprises Have Seen AI Agents Act Out of Scope

Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Predicting and Prioritizing Cyber Attacks Using Threat Intelligence

Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do

Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

Extracted Entities

Attack Types (1)

Ransomware Groups (1)