The UK’s National Cyber Security Centre (NCSC) has issued a warning regarding the growing risks of ‘shadow AI’, the use of AI tools by employees outside of official IT governance.
Research has shown that up to 71 percent** of UK workers use unapproved AI tools, and the NCSC highlighted how unsanctioned tools create critical visibility gaps and infrastructure vulnerabilities through unmonitored AI agents.
The advisory stresses that blanket prohibitions are ineffective, urging organisations to focus on gaining network visibility, setting clear guardrails, and establishing proactive governance.
Darren Anstee, CTO for security at NETSCOUT, discusses how businesses can address the risks of shadow AI without stifling productivity:
“Employees are continuing to adopt AI tools to streamline daily tasks and boost productivity. However, unauthorised and unmonitored use can also bring risks around data and infrastructure security.
“The temptation for businesses is to enforce blanket bans on unauthorised AI tools, but this only drives AI usage further into the shadows. Businesses need to combine policy and education to enable the adoption of the new technologies that maximise business benefits. A streamlined approval pathway for new AI technologies is key, as complex, long-winded governance processes risk being bypassed.
“When it comes to the dangers of shadow AI, most organisations focus on the exposure of confidential data and intellectual property leaking. This occurs as employees share data with AI tools with the best of intentions, potentially using their own personal accounts, outside of data governance. Dependent on the configuration of the AI tools, these inputs can be absorbed into the corpus of information used for the next training cycle, so confidential data and/or intellectual property could be shared inadvertently with any other users of that same tool.
“Business should create clear, AI usage policies that define approved tools, establish data-handling guidelines, and classify AI applications into tiers: sanctioned, limited-use, and prohibited. They should also create an internal AI council to maintain oversight of the above, with accountability across their organisation.”





Leave a Comment