Jessica Entwistle
September 9 2026
The National Cyber Security Centre has published new guidance addressing the security risks created when employees use unapproved AI tools, a practice commonly referred to as shadow AI. The NCSC blog post emphasises that understanding why staff turn to these tools is essential to managing the risks they create. Employees often adopt AI services to improve productivity, solve problems faster or work around limitations in approved systems, but this can lead to sensitive data being shared with third-party platforms, create compliance gaps, and introduce unmanaged security risks into the organisation. The guidance encourages organisations to engage with staff to understand their needs, provide approved alternatives where possible, and establish clear policies that balance security with practical usability.
Shadow AI is not a theoretical risk but a widespread reality across UK businesses. Staff are using generative AI tools for drafting documents, analysing data, summarising meetings and automating tasks, often without considering where that data is being processed, stored or used for model training. For many organisations, this creates exposure in areas such as intellectual property protection, client confidentiality, regulatory compliance and data sovereignty. The NCSC's focus on understanding user behaviour rather than simply blocking tools reflects a more mature approach to governance. Organisations that take a purely restrictive stance risk driving AI use further underground, while those that provide approved, well-governed alternatives and clear guidance are more likely to maintain visibility and control over how AI is being used across the business. This is particularly relevant for UK organisations handling sensitive client data, operating in regulated sectors, or managing intellectual property that could be inadvertently exposed through unmanaged AI tool use.
UK organisations should review whether there is a clear and practical AI acceptable use policy in place, whether staff understand what tools are approved and why, and whether the organisation is providing realistic alternatives that meet genuine business needs. Consider whether there is visibility into which AI tools are being used across the organisation, whether data classification and handling policies account for AI-related risks, and whether training and awareness programmes address the specific risks of shadow AI. Organisations should also review whether there are technical controls in place to monitor or restrict access to unapproved AI services, whether procurement and vendor management processes account for AI tools, and whether there is clear ownership and accountability for AI governance across IT, security, legal, HR and business functions.
Source: NCSC UK