Wednesday, September 9, 2026

News

UK Cybersecurity Agency Warns of Shadow AI Used Without Employers' Knowledge

PolicyPatryk Raba
UK Cybersecurity Agency Warns of Shadow AI Used Without Employers' Knowledge
Fot. cottonbro studio, Pexels (Pexels License)

The UK's National Cyber Security Centre warns that 71 percent of British employees use AI tools not approved by their employer, opening the door to data leaks and attacks. The agency advises against blocking AI outright, urging smarter management instead.

Contents
  1. Scale of the problem
  2. Three main risks
  3. A ban won't work
  4. What it means for Polish companies

The UK's National Cyber Security Centre (NCSC) has published a warning about "shadow AI" - employees using artificial intelligence tools that their company's security department has no idea about. According to data cited by the agency, this affects nearly three in four employees.

Scale of the problem

Shadow AI is a variant of the long-known shadow IT problem, meaning the use at work of software and services that haven't passed formal review by the security department. The difference is that AI tools - chatbots, coding assistants, text generators, or transcription tools - reach company computers and phones far faster than any other software ever has, because all it takes is a browser and a free account.

NCSC cites Microsoft data showing that 71 percent of employees in the UK have turned to AI tools not approved by their employer. The author of the agency's blog post stresses that many employees do this in good faith, wanting to work faster and more efficiently, not to bypass security measures.

Three main risks

The agency lists three specific categories of risk. The first is leaks of sensitive data and intellectual property - when an employee pastes a snippet of code, a contract, or client documentation into a public chatbot, that information can end up beyond the company's control, and in some cases be used to further train models.

The second category is loss of control over data flows - the company no longer knows where its information is physically stored or under which jurisdiction. The third, most technical, concerns vulnerabilities in the AI tools themselves. NCSC notes that security flaws in popular AI systems could give attackers access to the same resources and permissions available to the legitimate user of such a tool.

A ban won't work

A key element of NCSC's recommendations is moving away from a prohibition-based approach. The agency states outright that organizations cannot block access to every possible AI tool - the number of available chatbots, plugins, and assistants is growing faster than IT departments can catalog and block them.

Organizations can't rely on blocking access to every possible AI tool, so they need to build a positive cybersecurity culture, with open dialogue about the tools employees want to use, and clear rules for using AI safely - David Chismon, Director of Architecture, NCSC

Instead, NCSC recommends three actions. First, an open conversation with employees about which tools they actually need for their work, rather than a default ban. Second, quickly providing secure, approved alternatives before employees find a solution online themselves. Third, clear guidelines on what can be entered into AI tools and what should stay within company systems.

Many employees are getting value from AI at work, and rightly so, they're supported in this by employers, but IT security teams shouldn't assume they see the full picture - David Chismon, Director of Architecture, NCSC

What it means for Polish companies

Although the warning concerns the UK, the mechanism is identical in any organization where employees have internet access and an incentive to work faster. Polish companies face the same phenomenon, and the EU AI Act, now coming into force, additionally requires employers to know which AI systems are actually being used within their organization - a requirement that's hard to meet if a significant share of AI use happens off the security department's radar.

NCSC's recommendation to favor dialogue and quickly delivering legitimate alternatives over outright bans is also a practical pointer for companies still drafting their AI policies. Hard blocks most often push employees toward personal devices and accounts, which makes it even harder for a company to keep control over its data.

NCSC gave no timeline for further regulatory action or additional guidance, but said the topic of shadow AI would return in future agency publications as the number of tools available to employees without employer approval keeps growing.

Share: