CyberzSOC

Publication detail
← Back to advisories & guidance

The hidden risks of shadow AI ↗ source

September 7, 2026 NCSC Guidance

Summary

Understanding why staff use unapproved AI tools is key to managing the security challenges they can create. Over the past few years, the use of artificial intelligence (AI) has grown rapidly in many workplaces with employees increasingly exploring how such tools can be incorporated into their jobs. AI can help people complete tasks more quickly, improve decision-making, save costs and increase productivity. However, organisations’ policies and guidance, which should reflect and manage the risks associated with using these new technologies, have not always developed at the same pace. Rather than preventing them from using AI, this can mean employees turn to using AI tools that have not been approved by their organisation, introducing new cyber security risks that can be hard to identify. Shadow AI describes the use of AI technology which isn’t captured in an organisation’s approved systems and processes.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.