NCSC warns of growing cyber risks from ‘shadow AI’

The UK’s National Cyber Security Centre has urged organisations to tackle the growing use of shadow AI, warning that employees’ use of unauthorised artificial intelligence tools is creating hidden cyber security risks.

In a new blog, the NCSC said many organisations are focusing on external AI threats while overlooking the risks posed by staff adopting AI tools without the knowledge or approval of IT and security teams. While such tools can improve productivity, their unsanctioned use can expose sensitive data, create compliance issues and increase organisations’ cyber risk.

Employees often turn to unauthorised AI applications because approved alternatives do not meet their needs or because existing policies are unclear or overly restrictive. As a result, simply banning AI tools is unlikely to be effective.

Instead, the NCSC recommends that organisations develop realistic AI policies that support innovation while reducing risk. It also encourages security teams to understand why employees are using unauthorised tools and to provide secure, approved alternatives where appropriate.

The agency recently urged organisations deploying autonomous AI agents to put robust safeguards in place, warning that systems can carry out unintended or malicious activity when they do not behave as expected, highlighting the need for an emergency shutdown capability.



Share Story:

YOU MIGHT ALSO LIKE


Resilience Rooted in Reality
In this podcast, CIR speaks to CLDigital’s Tejas Katwala about why organisations must move beyond checklist compliance to build living, data driven resilience. He explains how rethinking governance, risk and compliance, breaking down silos and focusing on value streams can create sustainable, real time resilience that is rooted in the way businesses actually operate today.

Building cyber resilience in a complex threat landscape
Cyber threats are evolving faster than ever. This episode explores how organisations can strengthen defences, embed resilience, and navigate regulatory and human challenges in an increasingly complex digital environment.