Jessica Entwistle
September 10 2026
The National Cyber Security Centre has published new guidance explaining why employees across UK organisations are turning to unapproved AI tools and what security risks that behaviour creates. The NCSC blog post, published on 7 September, explains that staff often adopt AI services outside approved channels because they find them faster, more accessible or better suited to their immediate needs than sanctioned alternatives. The guidance warns that this shadow AI use can lead to sensitive data being shared with third-party services, create compliance gaps, and make it harder for security teams to understand where organisational information is being processed or stored.
Shadow AI reflects a familiar tension between security policy and operational reality. When approved tools are slow, difficult to access or poorly suited to how people actually work, staff will find alternatives. This is particularly concerning because many generative AI platforms process data outside the organisation's control, often in jurisdictions with different data protection standards. This creates risks around confidentiality, intellectual property, regulatory compliance and data sovereignty. The challenge is not just technical but cultural: organisations need to provide AI tools that are secure, accessible and genuinely useful, while also explaining clearly why certain services should not be used and what the realistic alternatives are. The NCSC emphasises that organisations need to understand the underlying reasons for shadow AI adoption rather than simply blocking tools, and recommends providing clear, practical alternatives that meet genuine business needs.
Review whether your current AI governance is realistic and enforceable. If staff are using unapproved AI tools, the question is why, and whether your organisation is providing practical, secure alternatives that meet genuine operational needs. Consider reviewing what AI services are already in use across the business, whether your acceptable use policies reflect how people actually work, and whether security and IT teams have the visibility and tools needed to manage AI adoption safely. This includes understanding where data is being processed, what third-party services are being used, and whether staff understand the risks associated with sharing sensitive information with unapproved AI platforms. Clear communication, practical alternatives and realistic policy are more effective than blanket bans.
Source: NCSC UK