The UK’s National Cyber Security Centre has urged organisations to tackle the growing use of ‘shadow AI’, warning that employees’ use of unauthorised artificial intelligence tools is creating hidden cyber security risks.
In a new blog, the NCSC said many organisations are focusing on external AI threats while overlooking the risks posed by staff adopting AI tools without the knowledge or approval of IT and security teams. While such tools can improve productivity, their unsanctioned use can expose sensitive data, create compliance issues and increase organisations’ cyber risk.
The agency said employees often turn to unauthorised AI applications because approved alternatives do not meet their needs or because existing policies are unclear or overly restrictive. As a result, simply banning AI tools is unlikely to be effective.
Instead, the NCSC recommends that organisations develop realistic AI policies that support innovation while reducing risk. It also encourages security teams to understand why employees are using unauthorised tools and to provide secure, approved alternatives where appropriate.
According to the NCSC, organisations cannot manage risks they are unaware of. Improving visibility of AI use across the business should therefore be a priority, enabling security teams to identify where sensitive information may be exposed and where additional governance is required.
Printed Copy:
Would you also like to receive CIR Magazine in print?
Data Use:
We will also send you our free daily email newsletters and other relevant communications, which you can opt out of at any time. Thank you.










YOU MIGHT ALSO LIKE