UK NCSC warns shadow AI exposes data; 71% of staff use unapproved AI tools

Codeblix_Ltd · reddit · 2026-09-08

The UK's National Cyber Security Centre warns that employees using AI tools outside approved systems can expose company or customer data and erode organizational visibility and control. Research it cites finds 71% of employees use AI tools their employer has not approved.

NCSC also flags a new agentic risk: if an AI agent has a vulnerability or bad configuration, an attacker may inherit the same data, services, and privileges the agent can access.

The recommended approach is less 'ban AI' and more 'make the approved path usable': understand why people turn to shadow AI, offer safer alternatives, and reduce risk rather than assume it will disappear.

Original post →

More from Safety

Safety channel →