Seven in ten UK staff are using AI tools their employer never approved
AI for Business

Seven in ten UK staff are using AI tools their employer never approved

The NCSC has written up shadow AI, and the useful part is what it does not recommend. You will not block your way out of this one. The firms that have approved an AI tool have a related problem, and it comes down to permissions.

14 September 20265 min read

The National Cyber Security Centre published a post on 7 September about shadow AI, written by Simon B, a senior cloud researcher there. The definition is short: shadow AI is "the use of AI technology which isn't captured in an organisation's approved systems and processes". It is a form of shadow IT, which is the older and more familiar problem of staff using tools the business never chose.

The number it cites is the reason to read it. Microsoft UK research found that nearly three quarters of employees, 71 percent, reported using AI tools that have not been approved by their employer. Whatever your policy says, the working assumption should be that this is already happening in your business.

What actually goes wrong

The NCSC lists two things. The first is losing control of information. Staff who put sensitive or proprietary material into a consumer AI service reduce the organisation's visibility over it, because that information "may be stored, retained or used to improve the service" outside whatever security and governance arrangements you have. A draft quote for a client, a supplier contract, a spreadsheet of staff details: once it has gone into a personal account on somebody's own browser tab, you have no record it happened and no way to pull it back.

The second risk is newer. The NCSC points out that AI agents are complex software, complex software has vulnerabilities, and an attacker who exploits one gains "access to the same data, services, and privileges that the agent has legitimate access to". An agent is only as contained as the permissions somebody gave it. Nobody connecting a free AI tool to their work email thinks of it as installing software with access to the business, which is roughly what has happened.

Blocking is not the answer, and the NCSC says so

This is where the guidance earns its place. The NCSC's position is to reduce shadow AI rather than try to eliminate it, by building a culture where staff say openly what tools they want, and setting clear guardrails for what secure use looks like. The reasoning is practical. There are too many AI tools to block, most of them are just websites, and a member of staff who has found something that saves two hours a day will use it on their phone once you take it off the laptop. A policy that drives the practice underground leaves you the same risk with less visibility.

The approved route has a gap of its own

The week's other AI story belongs here. Syskit surveyed 327 IT and security decision makers at US and UK organisations with more than 500 employees for its State of Microsoft 365 Governance Report 2026, reported on 11 September. Of those surveyed, 76 percent had deployed or piloted an enterprise AI tool such as Copilot. Only 43 percent had completed a thorough permissions review before doing it.

The rest of that survey explains why the review matters. It found 41 percent leave SharePoint sites accessible to all staff, 35 percent have files belonging to former employees still reachable by current ones, and 33 percent have files shared with "Everyone". Only 4 percent said they could produce a complete access report within an hour. Toni Frankola, Syskit's chief executive, summed it up: "Reviewing permissions is unglamorous work, but it has become the deciding factor in whether an AI rollout is safe."

Those are large organisations rather than firms of twelve people, so read the percentages as a direction of travel and not as your own numbers. The mechanism is identical at any size though. Copilot answers questions using whatever the person asking is already allowed to open. If a folder was shared with everyone in 2021 and nobody remembers doing it, Copilot will find it and quote from it, and the first sign will be an answer containing something the person asking should never have seen.

What to do this month

Ask, with no consequences attached, which AI tools people are already using and what for. You will get a more useful answer than any audit produces. Then write one page: what may go into an AI tool, what may not, and which tool the business will pay for so there is a sanctioned option worth using. Then, before turning Copilot on, or now if it is already on, look at what your Microsoft 365 tenant actually shares. Sites open to everyone, old files from people who left, anything shared with "Everyone". That is the unglamorous work, and it decides whether the approved tool is any safer than the shadow one.

What this means for your business

Shadow AI is not a discipline problem, and treating it as one makes it invisible rather than rare. The NCSC's advice is to ask staff what they are using, set clear rules about what data may go into these tools, and provide a sanctioned option good enough that people actually use it. The second half matters just as much: an approved AI assistant inherits the permissions already sitting in your Microsoft 365 tenant, so working out who can open what has become a security job rather than housekeeping. If Copilot is on your list for this autumn, do the permissions review before the rollout rather than after the first awkward answer.

#WEARECOBALT

Ready when you are.

Tell us what's slowing your business down. We'll tell you exactly how we'd fix it — plainly, with no obligation.