NCSC warns against threat of shadow AI

Published: 07/09/2026
| Last Updated: 09/09/2026
| NCSC

The National Cyber Security Centre (NCSC) has issued a warning about staff using unauthorised artificial intelligence (AI) tools, a practice termed shadow AI. This widespread behaviour likely exposes sensitive corporate and personal information, creating significant security risks that organisations may not know about or be able to control.

The NCSC highlighted research showing that 71% of workers admit to using workplace AI applications not sanctioned by their employers. Such widespread adoption occurs when institutional security policies lag behind technological developments, driving staff towards consumer platforms that may retain, store, or train models on corporate and personal data outside corporate visibility and compliance controls. This creates further opportunities for external threat actors to target vulnerabilities within complex AI agents, potentially exploiting looser guardrails to access internal information technology (IT) networks and enterprise data.

Rather than supporting a ban on AI adoption, the NCSC advised organisations to focus on practical risk reduction. It recommends fostering an open security culture, assessing staff operational requirements to deliver safe, sanctioned alternatives, and following official frameworks to integrate agentic systems securely into enterprise workflows.

In related news, the Financial Times (£) reports on growing fears within the government that US technology companies are beginning to adopt the protectionist policies advocated by the Trump administration. This follows Anthropic's decision to exclude the UK's AI Security Institute (AISI) from early access to test its latest AI model.  

Meanwhile, an article in The Wall Street Journal (£) outlines the concerns of an Anthropic researcher who recently quit his role, fearing that competition is driving AI companies to create models that risk spiralling out of human control. 

In a separate announcement, Paul Christiano, a US government technology adviser who has agreed to join OpenAI's non-profit board on the Safety and Security Committee, has warned in a Substack article that neither OpenAI nor the AI industry is "on track to reduce this risk to an acceptable level." He goes on to say that there is now a "meaningful risk that rapid acceleration in AI capabilities leads to catastrophic and irreversible loss of control in the very near term." He is joining the company's Safety Committee to help reduce this risk. 

£ - These articles require a subscription. 


Training Announcement: Freevacy offers a range of independently recognised professional AI governance qualifications and AI Literacy short courses that enable specialist teams to implement robust oversight, benchmark AI governance maturity, and establish a responsible-by-design approach across the entire AI lifecycle. Find out more.

Read Full Story
Shadow AI

Image credit phloxii on Shutterstock

What is this page?

You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.

The Privacy Newsfeed monitors over 300 global publications, of which more than 3,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.