NCSC highlights security concerns around unapproved workplace AI use
The UK National Cyber Security Centre (NCSC) has warned that employees using unapproved artificial intelligence services for work could expose organisations to data loss, reduced oversight and new att...
The UK National Cyber Security Centre (NCSC) has warned that employees using unapproved artificial intelligence services for work could expose organisations to data loss, reduced oversight and new attack paths.
The practice, often called “shadow AI,” refers to AI tools operating outside an employer’s authorised technology, security and governance processes. It is part of the broader issue of shadow IT, where staff adopt services without formal approval because existing tools or policies do not meet their needs.
The NCSC said workplace interest in AI has accelerated as tools become cheaper and easier to access. While such services can support productivity, decision-making and cost savings, internal controls have not always kept pace. The agency cited research in which 71% of employees said they had used AI tools not approved by their employer.
Data and access risks
A primary concern is that workers may submit company, customer or proprietary information to consumer-facing AI platforms. Depending on the provider’s terms and configuration, submitted content may be retained, processed outside corporate controls, or potentially used to improve the service. That can create exposure to data breaches, intellectual-property loss and compliance issues.
Unmanaged AI also limits an organisation’s ability to determine where sensitive information has gone, how it is handled and who can access it. The NCSC noted that AI agents add another consideration: if an agent has access to internal data, systems or privileges, an attacker who compromises it could potentially inherit those permissions.
Misconfigured or insufficiently protected agents may also give threat actors another route into wider corporate environments, the agency said.
Focus on secure adoption
Rather than calling for a blanket ban on AI, the NCSC recommends reducing the risks associated with unapproved use. It urged organisations to foster a culture in which employees can discuss their technology needs and security concerns openly, helping security teams understand why unofficial services are being used.
- Provide approved AI tools that address legitimate business requirements.
- Explain what information may and may not be entered into AI services.
- Assess privacy, data handling, access controls and supplier security before deployment.
- Introduce agentic AI gradually and review permissions, configurations and monitoring arrangements.
The NCSC said complete elimination of shadow AI is unlikely. Greater visibility, usable approved alternatives and clear guidance can help organisations retain the benefits of AI while limiting avoidable cyber risk.
