www.malwarebytes.com 1 Oct 2026, 14:05 UTC

Shadow AI Is Putting UK Workplace Data at Risk, Studies Warn

Shadow AI Is Putting UK Workplace Data at Risk, Studies Warn
CyberSIXT Evidence Panel Source marked as original reporting

SHADOW AI is defined as AI technology used at work that isn’t captured in an organisation’s approved systems and processes. The article emphasises that employees may turn to AI tools to get work done faster, such as summarising long email threads or drafting replies, often without their employer’s knowledge or approval.

It notes that the phenomenon isn’t limited to chatbots; it can include browser extensions, meeting-notes bots, stealthy AI features inside applications, or small self-built automations that send data to an AI service. The piece also highlights how AI features are increasingly embedded in search, email, and mobile devices, which can make unauthorised use feel unobtrusive.

The piece cites evidence to show the scale and risk of shadow AI. The UK National Cyber Security Centre defines shadow AI as “the use of AI technology which isn’t captured in an organisation’s approved systems and processes.” A 2025 Microsoft study found that 71% of UK employees had used AI tools at work without employer approval.

On the security and governance side, IBM’s 2025 Cost of a Data Breach report found one in five breaches were linked to shadow AI, and only 37% of organisations had policies to manage AI or detect shadow AI; those with substantial shadow AI faced roughly £670,000 more per breach.

Practical responses include obtaining approved tools, using work rather than personal accounts, clarifying data types allowed with AI, checking privacy settings, registering approved use cases, reviewing agents and plug-ins, and fostering open conversations about security so teams feel supported rather than policed.

View full article

Article by CyberSIXT