Header image

UK's NCSC warns of security risks from unapproved AI tools

Employees using artificial intelligence tools not approved by their employers pose significant security risks, potentially exposing corporate data and creating blind spots for IT security teams, the UK's National Cyber Security Centre (NCSC) has warned. This phenomenon, known as shadow AI, is likely to persist as employees adopt new services faster than organizations can assess and approve them, according to Infosecurity Magazine.

The NCSC highlighted that 71% of UK employees have used unapproved AI tools, leading to visibility gaps and increased risks of data breaches, intellectual property loss, and regulatory non-compliance. When employees transfer sensitive information to consumer AI services, this data may be stored, retained, or used to improve the service, reducing organizational control. 

AI agents themselves can carry critical vulnerabilities, which attackers could exploit to gain access to data, services, and privileges. The NCSC advises organizations to focus on reducing, rather than eliminating, shadow AI by fostering a positive cybersecurity culture that encourages open dialogue about AI tool usage and establishes clear guidelines for secure AI implementation. This approach is crucial as blocking all potential AI tools is impractical.

Source: Infosecurity Magazine

Kelley Damore
Kelley Damore Chief Content Officer CyberRisk Alliance

Kelley Damore is Chief Content Officer at CyberRisk Alliance, where she leads content strategy across the company’s digital brands, research, communities and live events serving CISOs and security practitioners. At CyberRisk Alliance, she is focused on delivering 365-day engagement, trusted journalism and actionable insights to help security leaders navigate an increasingly complex threat landscape.

Kelley Damore
Kelley Damore Chief Content Officer CyberRisk Alliance

Kelley Damore is Chief Content Officer at CyberRisk Alliance, where she leads content strategy across the company’s digital brands, research, communities and live events serving CISOs and security practitioners. At CyberRisk Alliance, she is focused on delivering 365-day engagement, trusted journalism and actionable insights to help security leaders navigate an increasingly complex threat landscape.

Upcoming Events

No events found.