The UK National Cyber Security Centre's latest note on shadow AI is blunt: employees are adopting AI tools faster than corporate policy can keep up, and the resulting risk looks a lot like classic shadow IT—only harder to see and quicker to spread.
NCSC defines shadow AI as AI technology that sits outside an organisation's approved systems and processes. Citing recent research, it reports that nearly three-quarters of employees (71%) said they used AI tools not approved by their employer. When policy cannot meet the job, people route around it.
The cyber consequences are familiar and still undercounted. Sensitive company or customer data may leave the perimeter into consumer services. Organisations lose visibility and control over retention and secondary use. Agentic tools add another layer: a vulnerable agent can expose the same data, services, and privileges the agent was granted.
NCSC is not telling staff to stop using AI. It is telling them to think carefully before sharing work data with a familiar consumer app, and telling employers to treat shadow AI the way mature security teams treat shadow IT: reduce risk rather than pretend elimination is realistic.
Their practical stack is culture first—open communication so people surface what they are already using—then secure, approved alternatives that actually meet the need, plus careful adoption of agentic AI rather than a rush to autonomous agents. You cannot manage what you do not know is running.
For desk and ops leaders, that means inventory of unsanctioned tools, a sanctioned path that is easy enough to prefer, and explicit guardrails before agentic workflows get write access to ticketing, identity, or production systems.