The UK’s National Cyber Security Centre has issued new advice on shadow AI: the use of artificial-intelligence tools outside an organisation’s approved systems and processes. Published on 7 September, the briefing treats the issue as a practical security and governance problem, not simply a question of whether employees should be allowed to use AI at work.
The core concern is visibility. When staff move company or customer information into an unapproved service, an organisation may not know where that data is being processed, retained or used. The NCSC says this can increase exposure to data breaches, intellectual-property loss and regulatory failures. It also warns that AI agents with access to data, services or privileges can create additional attack paths if a vulnerability is exploited.
That does not make the new guidance a blanket call to stop using AI. The NCSC explicitly says it is not recommending that people abandon the technology. Instead, its argument is that organisations need to understand why people reach for unapproved tools and make secure options usable enough to compete with them.
Why shadow AI is a workplace problem
The term is an extension of shadow IT: devices or services used for work but not covered by an organisation’s asset management or security processes. In the AI context, that might mean a consumer chatbot used to summarize a meeting, draft a customer response or turn notes into a presentation.
The appeal is understandable. In a 2025 survey of 2,003 UK employees commissioned by Microsoft and conducted by Censuswide, 71% said they had used unapproved consumer AI tools at work, while 51% said they did so every week. The study found that familiarity with consumer tools and the absence of a work-approved alternative were among the reasons people gave. Those figures are not a universal measure of workplace AI use, but they help explain why a policy document alone is unlikely to eliminate the behavior.
The NCSC’s guidance is therefore notable for its emphasis on the gap between security policy and the way work actually gets done. Its older shadow-IT guidance makes the same point: unofficial tools are often adopted because sanctioned processes are slow, unavailable or poorly suited to a task. Treating every instance as deliberate misconduct can make the visibility problem worse, because staff become less likely to disclose what they use.
What the NCSC says the risks are
The new briefing identifies three broad exposures. First, sensitive information entered into an unapproved service can leave established governance arrangements. Second, the organisation loses visibility and control over how that information is stored or handled. Third, more capable AI systems can widen an attacker’s opportunity: an agent compromised through a vulnerability may be able to reach the same data and services it was allowed to use.
That last point deserves a distinction. Shadow AI concerns unauthorised use and unknown services; agent security concerns what a deliberately deployed system is permitted to do. The issues overlap when an unapproved agent connects to files, email or business software. For teams already working on that second problem, Unhyd’s guide to permission-first AI agent security explains why separate identities, narrow permissions and meaningful approval boundaries matter once a system can take actions rather than only generate text.
A useful response is not just a stricter ban
The NCSC recommends a positive cyber-security culture, open communication and approved AI systems that meet employees’ needs. That approach has a practical implication: a company should make it easy to ask for an approved tool, report an existing workaround and describe the task the workaround solves. The agency’s board guidance on cyber-security culture similarly says staff are more likely to surface problems when they can communicate without fear of reprisals.
For leaders, the immediate question is not whether every AI service can be catalogued perfectly. It is whether the organisation has a usable route from a genuine employee need to a reviewed, supported option. Start by identifying common AI tasks, separating low-risk drafting from uses involving sensitive data or system access, and providing an approved path for each. Then review where staff still work around that path.
For higher-autonomy tools, the controls need to go further. The NCSC’s August guidance on agentic AI recommends safeguards, sandboxing, monitoring and a way to stop a system when necessary. NIST’s Generative AI Risk Management Framework profile likewise identifies acceptable-use policies, data protection, monitoring and incident response as governance tools.
The broader lesson is straightforward: shadow AI is a signal as much as a security gap. It can show where workers see a useful capability that their organisation has not yet made safe, accessible or easy to use. The NCSC’s new warning does not reduce that tension to a simple compliance exercise. It asks organisations to manage the risk without losing sight of the work that prompted people to seek AI help in the first place.