Nearly three quarters of employees have used an AI tool their employer never approved. That figure, 71%, comes from a study cited by the UK's National Cyber Security Centre in a blog post published on 7 September, and the agency's point is not that people should stop. It is that a security team cannot defend a tool it does not know is running.
The NCSC calls the problem shadow AI: AI technology in use that sits outside an organisation's approved systems and processes. It is a variant of the older shadow IT question with a sharper edge, because what staff paste into an unapproved AI service is usually the work itself.
Policy moved slower than the tools
Simon B, a senior cloud researcher at the NCSC, frames the cause as a gap rather than a discipline problem. Workplace AI adoption has outrun the policies meant to govern it, so staff who need the capability reach for whatever they already use at home. The agency expects that to continue as the tools get cheaper and easier to reach, and while approved alternatives lag behind what people actually need to do their jobs. The 71% study is referenced but not named in the post, so read it as an order of magnitude rather than a precise measurement.
Data leaves through the prompt box
The first two risks the NCSC sets out are about information rather than intrusion. Feeding company or customer data into an unapproved service raises the likelihood of a breach, of intellectual property loss and of a regulatory failure. The subtler one is loss of control: information handed to a consumer AI service may be stored, retained or used to improve that service, outside the governance arrangements the organisation believes it has, unless specific privacy controls are in place. Nobody files an incident report about that, because nothing visibly breaks.
The agent inherits your permissions
The third risk is the one that turns a governance headache into an intrusion path. AI agents are complex pieces of software and can carry critical vulnerabilities. If an attacker exploits one, the NCSC says, they get the same data, services and privileges the agent legitimately holds. The agency also expects attackers to favour agents with looser guardrails as a route into the wider corporate estate. That shape is already turning up in real work: we covered an exercise in which AI agents ran an intrusion end to end in under ten hours, and infostealers harvesting paid AI account sessions off user machines.
Culture beats a blocklist
The NCSC's remedy is deliberately not a ban. It asks organisations to build a security culture where people can say what they are using without expecting trouble, on the reasoning that a team which understands why staff reach for shadow AI can offer secure alternatives instead of pushing the habit further underground. Alongside that it points to its own cyber security culture principles and to guidance written with international partners on adopting agentic AI carefully. The goal it sets is reducing the risk, not eliminating a practice that is not going away. The post is on the NCSC's blog.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.