NCSC warns of growing cyber risks from ‘shadow AI’

The UK’s National Cyber Security Centre has urged organisations to tackle the growing use of ‘shadow AI’, warning that employees’ use of unauthorised artificial intelligence tools is creating hidden cyber security risks.

In a new blog, the NCSC said many organisations are focusing on external AI threats while overlooking the risks posed by staff adopting AI tools without the knowledge or approval of IT and security teams. While such tools can improve productivity, their unsanctioned use can expose sensitive data, create compliance issues and increase organisations’ cyber risk.

The agency said employees often turn to unauthorised AI applications because approved alternatives do not meet their needs or because existing policies are unclear or overly restrictive. As a result, simply banning AI tools is unlikely to be effective.

Instead, the NCSC recommends that organisations develop realistic AI policies that support innovation while reducing risk. It also encourages security teams to understand why employees are using unauthorised tools and to provide secure, approved alternatives where appropriate.

According to the NCSC, organisations cannot manage risks they are unaware of. Improving visibility of AI use across the business should therefore be a priority, enabling security teams to identify where sensitive information may be exposed and where additional governance is required.



Share Story:

YOU MIGHT ALSO LIKE


Resilience Rooted in Reality
In this podcast, CIR speaks to CLDigital’s Tejas Katwala about why organisations must move beyond checklist compliance to build living, data driven resilience. He explains how rethinking governance, risk and compliance, breaking down silos and focusing on value streams can create sustainable, real time resilience that is rooted in the way businesses actually operate today.

Building cyber resilience in a complex threat landscape
Cyber threats are evolving faster than ever. This episode explores how organisations can strengthen defences, embed resilience, and navigate regulatory and human challenges in an increasingly complex digital environment.