Back Infosecurity-Magazine NCSC Warns Shadow AI Creates New Security Risks
The UK's National Cyber Security Centre (NCSC) has warned that employees using unapproved AI tools can expose corporate data and create security risks that organizations may struggle to detect and manage.
The NCSC blog post , published on September 7, said shadow AI was likely to persist as employees adopted new services faster than organizations could assess them and provide approved alternatives.
The agency cited Microsoft research that found 71% of UK employees had used AI tools not approved by their employer. The NCSC said the research suggested shadow AI use was widespread.
Unapproved AI Tools Create Visibility Gaps
Shadow AI refers to AI technology that falls outside an organization's approved systems and processes and is a form of shadow IT.
"Many people are reaping the benefits of AI in the workplace and are rightly being supported to do so by their employers, but IT security teams should not assume they are seeing the full picture," said David Chismon, NCSC CTO for architecture.
The NCSC said employees who give shadow AI access to company or customer data likely increase the risk of data breaches, intellectual property loss and failure to meet regulatory requirements.
The blog post said the problem could emerge when existing cybersecurity policies failed to meet business needs, encouraging staff to adopt new services before their employer had assessed them.
The NCSC also warned that AI agents could carry critical vulnerabilities, and that an attacker exploiting one could gain the same data, services and privileges the agent legitimately held.
It explained that attackers were highly likely to use agents with looser guardrails to exploit vulnerabilities or misconfigurations elsewhere in corporate IT.
Organizations Urged to Reduce Shadow AI Risks
Employees who transfer sensitive information to consumer AI services are likely reduce their organization's visibility and control over it, the NCSC said, because that information may be stored, retained or used to improve the service.
The agency warned that organizations should focus on reducing rather than eliminating shadow AI, as with shadow IT more broadly. It recommended adopting a positive cybersecurity culture so employees felt able to security issues openly.
"Organizations can't hope to block connections to all possible AI tools, so they need to develop a positive cybersecurity culture with open dialogue the tools staff might wish to use and to set clear guardrails around what secure use of AI looks like," Chismon said.
The NCSC also pointed to guidance on the careful adoption of agentic AI services, published with international partners.
Infosecurity Europe: OWASP Introduces Agentic AI Security Maturity Framework News 5 June 2026
Infosecurity Europe: OWASP Introduces Agentic AI Security Maturity Framework
Securing Perimeter Products Must Be a Priority, Says NCSC News 4 March 2024
Securing Perimeter Products Must Be a Priority, Says NCSC
Cost of Insider Incidents Surges 20% to Nearly $20m News 24 February 2026
Cost of Insider Incidents Surges 20% to Nearly $20m
Microsoft Copilot Deployments Delayed Over Security Concerns News 23 July 2026
Microsoft Copilot Deployments Delayed Over Security Concerns
AI Agents Are Here. Security Must Be an Accelerator for AI Transformation Opinion 20 May 2026
AI Agents Are Here. Security Must Be an Accelerator for AI Transformation
What’s Hot on Infosecurity Magazine?
FBI Probes Possible Breach of 153 Million Driver’s Licenses
US and Canadian Court Records Breached Following Thomson Reuters Incident
Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone
CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation
FulcrumSec Claims Responsibility for Manchester Airport Group Breach
65% of Enterprises Have Seen AI Agents Act Out of Scope
CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation
Attackers Steal METR API Key and Burn $600,000 in AI Credits
New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation
Hiring for the AI Era: A New Challenge for CISOs
How Industry Coalitions Are Rallying to Secure Open Source Software for the AI Era
65% of Enterprises Have Seen AI Agents Act Out of Scope
Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Predicting and Prioritizing Cyber Attacks Using Threat Intelligence
Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do
Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
