Context
The NCSC has published a blog post considering why staff use unapproved AI tools and how this is key to managing the security challenges this can create.
Key points to note and next actions
- Shadow AI is the use of AI tools that have not been approved or incorporated into an organisation’s official systems and processes. The NCSC states its use is widespread, with one study finding 71% of employees had used unapproved AI tools at work.
- AI offers significant benefits, including faster task completion, improved decision-making, potential cost savings and increased productivity. However, organisational policies and security controls have often failed to keep pace with rapid AI adoption.
- The NCSC notes that shadow AI creates cybersecurity risks, particularly through exposure of sensitive or proprietary information. There may be a loss of organisational control over data leading to regulatory breaches, and new vulnerabilities that attackers could exploit through AI agents.
- Organisations should therefore focus on reducing rather than eliminating shadow AI. They should promote an open cybersecurity culture and understand the risks where employees may use an unapproved AI tool. Secure, approved AI alternatives should be considered, with AI being integrated into the workplace alongside awareness of the associated risks, so that deployment can be managed safely.
