Someone in your business has probably tried an AI chatbot for work. Maybe they used it to tidy an email, summarise a report or write a spreadsheet formula. That isn't the problem. The problem is when they do it from a personal account, on a tool nobody has looked at, with customer or company information pasted in.

The National Cyber Security Centre (NCSC) calls this shadow AI. In a blog published on 7 September 2026, it describes shadow AI as AI use that sits outside an organisation's approved systems and processes, a form of what's often called shadow IT.

What the risks are

The NCSC sets out three.

  • Sensitive information getting out. Giving AI tools access to company or customer data can raise the chance of a data breach, the loss of intellectual property and the breaking of regulations.
  • Losing visibility and control. What staff type into a consumer AI service may be kept and used to improve that service, outside your own governance, unless privacy controls are in place.
  • New openings for attackers. AI agents can contain serious vulnerabilities, and an attacker who exploits one could reach the data, services and permissions the agent has.

How common is it?

I can't tell you how many of your staff use unapproved AI tools, and nobody can without asking. That's the first step below.

Some context comes from the government's Cyber Security Breaches Survey, published on 30 April 2026. Around a third of businesses (31%) were using AI, in the process of adopting it or actively considering it. Of that group, around a quarter (24%) reported having cyber security practices or processes in place to manage the risks from AI.

The survey counts business use of AI in general, not staff using unapproved tools. But it does suggest that many businesses are moving into AI without a plan for its risks.

Don't just ban it

The tempting response is a ban. The NCSC doesn't expect that to work. It says shadow AI is unlikely to disappear completely, and that "the goal should be to reduce risk rather than assume it can be eliminated".

If you block these tools without giving people something else, they're likely to carry on out of sight. The NCSC's advice is to build a culture where people talk openly about security, find out why staff are using these tools, and give them a secure alternative.

Six steps

  1. Ask what people use, and why. Have a no-blame conversation, or send a two-question survey: which AI tools do you use, and what for? You'll learn what the business needs as well as what the risk is.
  2. Decide what must never go in. Customer personal data, passwords, contracts under negotiation, unpublished financial results, anything covered by a confidentiality agreement. Put the list on one page.
  3. Give people an approved option. Choose a business version of a tool. Read what its terms say about keeping your inputs and using them to improve the service, and switch off what you can.
  4. Write a short policy. One page, in plain English: what's approved, what's off limits and who to ask. Include AI features that arrive inside software you already pay for.
  5. Protect the accounts. Sign in with work accounts, not personal ones, and turn on multi-factor authentication. When someone leaves, you can then remove their access.
  6. Review it every few months. Tools and their terms change quickly, so put a date in the diary.

If someone proposes AI that acts on its own, such as an agent that can send emails or change files, treat that as a separate decision. The NCSC's blog Thinking carefully before adopting agentic AI, published on 15 May 2026, recommends starting with small, tightly limited pilots and keeping people clearly accountable.

One more thing

If personal data is involved, you also have data protection duties. I'm not a lawyer, so check the data protection guidance on the ICO website, or speak to your adviser.

I can help with the practical side: finding out what's in use, choosing an approved tool, writing the one-page policy and setting up accounts so access can be removed. That's part of what I do as a part-time IT director. To talk it through, get in touch.

Sources

All articles