www.infosecurity-magazine.com 7 Sept 2026, 14:00 UTC

UK Cyber Agency Warns Unapproved AI Tools Put Corporate Data at Risk

THE UK National Cyber Security Centre (NCSC) has warned that employees using unapproved AI tools creates new security risks for organisations. In a blog post dated 7 September 2026, the NCSC highlighted “shadow AI”—tools outside approved systems—as a persistent issue as staff adopt services faster than formal assessments can keep pace.

Microsoft research cited by the NCSC showed that 71% of UK employees had used AI tools not approved by their employer, suggesting that shadow AI use is widespread and difficult for security teams to fully see.

Shadow AI creates visibility gaps and elevates risk in several ways. When staff grant access to corporate or customer data to consumer AI services, organisations lose visibility and control over how that data is stored or used, potentially increasing chances of data breaches, intellectual property loss and failure to meet regulatory requirements. The NCSC warned that attackers could exploit vulnerabilities or misconfigurations in other parts of corporate IT by targeting AI agents with looser guardrails.

The agency urged organisations to focus on reducing shadow AI rather than trying to eliminate it entirely, advocating a positive cybersecurity culture that encourages open dialogue and clear guardrails about secure AI use. It also pointed to guidance on careful adoption of agentic AI services produced with international partners.

View full article

Article by CyberSIXT