The UK’s National Cyber Security Centre has urged organisations to tackle the growing use of shadow AI, warning that employees’ use of unauthorised artificial intelligence tools is creating hidden cyber security risks.
In a new blog, the NCSC said many organisations are focusing on external AI threats while overlooking the risks posed by staff adopting AI tools without the knowledge or approval of IT and security teams. While such tools can improve productivity, their unsanctioned use can expose sensitive data, create compliance issues and increase organisations’ cyber risk.
Employees often turn to unauthorised AI applications because approved alternatives do not meet their needs or because existing policies are unclear or overly restrictive. As a result, simply banning AI tools is unlikely to be effective.
Instead, the NCSC recommends that organisations develop realistic AI policies that support innovation while reducing risk. It also encourages security teams to understand why employees are using unauthorised tools and to provide secure, approved alternatives where appropriate.
The agency recently urged organisations deploying autonomous AI agents to put robust safeguards in place, warning that systems can carry out unintended or malicious activity when they do not behave as expected, highlighting the need for an emergency shutdown capability.
Printed Copy:
Would you also like to receive CIR Magazine in print?
Data Use:
We will also send you our free daily email newsletters and other relevant communications, which you can opt out of at any time. Thank you.










YOU MIGHT ALSO LIKE