NCSC Warns Shadow AI Is Creating New Security Blind Spots for UK Businesses
Brief
The UK’s National Cyber Security Centre (NCSC) has warned organisations about the security risks posed by “shadow AI”, as employees continue to turn to artificial intelligence tools that have not been approved by their employers.
In guidance published this week, the NCSC described shadow AI as the use of AI technology outside an organisation’s approved systems and processes, warning that security policies and governance have struggled to keep pace with the rapid adoption of AI in the workplace.
The scale of the issue could already be significant. Research cited by the NCSC found that 71% of employees have used AI tools that have not been approved by their employer.
According to the NCSC, unapproved AI services can expose sensitive company and customer information, reduce organisations’ visibility and control over their data, and create new opportunities for attackers.
