UK cybersecurity agency urges firms to tackle risks of “shadow AI”
It could be their next security headache.

Shadow AI emerges as cybersecurity risk. Image by Cybernews
- The NCSC warns unapproved AI tools can expose company and customer data.
- Shadow AI can create openings for hackers if tools have serious security flaws.
- The agency says firms should approve AI services before employees share data with them.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The use of “shadow AI” in the workplace can lead to data breaches and other security incidents for businesses and organizations, thus creating serious consequences for employers.
According to the National Cyber Security Centre (NCSC), the UK’s cybersecurity agency, keeping unapproved AI tools away from the workplace is key to managing the security challenges they pose.
Over the past few years, employees' use of AI technology has grown significantly to boost their productivity. However, deploying AI tools such as chatbots or coding assistants without the approval of upper management, also known as “shadow AI,” might pose risks to the company.
For starters, sensitive information may be exposed when unauthorized AI tools are exposed to company or customer data. This increases the risk of data breaches, loss of intellectual property, or failure to meet legal requirements.
When sensitive or proprietary information is shared with shadow AI, organizations will lose control over that data unless specific privacy controls are in place.
Furthermore, shadow AI introduces new opportunities for hackers because these tools can have critical security vulnerabilities. If attackers successfully exploit a vulnerability, they can gain access to the same data, services, and privileges that the agent has legitimate access to, the NCSC warns.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
The agency is not recommending that businesses and organizations stop using AI. Instead, they should carefully consider which apps and services they use before sharing their data.
“It may feel natural to stick with using the same AI service that you are familiar with from your personal life, but using systems that are not corporately approved can present real problems for your employer,” the NCSC explains in a blog.
It’s important for organizations to establish policies managing the use of AI and to adopt a “positive cybersecurity culture.” This should facilitate open communication about cybersecurity issues, making staff less likely to resort to using shadow AI.
Nevertheless, the NCSC warns that the use of shadow AI will likely never disappear entirely. But there’s one thing to keep in mind:
“You cannot manage what you do not know. By raising awareness of the risks of shadow AI use within your organization and understanding the needs of employees, you can help them get the benefits of new technologies while using them securely.”
In June 2026, European Data Protection Supervisor (EDPS) Wojciech Wiewiórowski said that using unauthorized AI tools can create “blind spots” for regulators, leading to a lack of legal compliance and, in turn, a so-called “transparency black hole.”
“Once data is entered into an unapproved system, it becomes virtually impossible to track or monitor where that information goes, how it is used, or who trains their models on it,” Wiewiórowski explained.