Your policy is why they went around you

· · AI Security

Somebody in your business pasted something into an AI tool this week that you would rather they had not. A customer email, a supplier contract, a spreadsheet with names in it. They were not being reckless. They had a job to do, the tool made it faster, and nobody had given them a better option.

The National Cyber Security Centre has now put a name and a number to this, and its diagnosis is more uncomfortable than the usual warning.

What NCSC actually said

In a blog published on 7 September, NCSC set out the risks of shadow AI, which it defines as AI technology that is not captured in an organisation's approved systems and processes. It is shadow IT wearing new clothes: the same pattern as staff signing up for file-sharing accounts a decade ago, moving faster than anyone's policy.

The number is the eye-catching part. NCSC cites research finding that 71% of employees have used AI tools their employer has not approved, a figure Infosecurity Magazine attributes to Microsoft research on UK employees. Nearly three in four.

David Chismon, NCSC's chief technology officer for architecture, put the practical problem plainly:

"Many people are reaping the benefits of AI in the workplace and are rightly being supported to do so by their employers, but IT security teams should not assume they are seeing the full picture."

The risks NCSC names are the ones you would expect, stated without drama. Sensitive information gets exposed, raising the risk of data breaches, loss of intellectual property, and failure to meet regulatory requirements. Organisations lose visibility and control, because information sent to a consumer AI service may be stored, retained, or used to improve that service, outside your governance arrangements, unless specific privacy controls are in place. And AI agents are complex software with their own vulnerabilities, so an attacker exploiting one gains the same data, services, and privileges the agent legitimately holds.

The sentence worth rereading

Buried in the middle is the line that makes this filing worth writing:

"Where cyber security policies cannot meet business needs, organisations are likely to continue seeing their employees adopt new AI services before they have had time to assess them and provide approved alternatives."

Read that as a diagnosis rather than an observation, because that is how it is meant. Your staff are not going around the policy because they are careless. They are going around it because the policy does not let them do their job at the speed the job now demands, and no approved alternative exists.

That reframes the problem completely. A firmer ban, another all-staff email, a line in the handbook: these treat the symptom. If the underlying gap stays open, the behaviour continues, only further out of sight, which is the one outcome that makes everything worse. You cannot manage what you cannot see, and a stricter rule mostly buys you less visibility.

NCSC is explicit that it is not telling people to stop using AI. Its advice to individuals is to think carefully about which apps and services they use before sharing data, and it acknowledges the pull of using the same service you know from your personal life. Its advice to organisations is blunter: shadow AI is unlikely to disappear completely, so the goal should be to reduce risk rather than assume it can be eliminated.

We made a related argument in May, that a policy which only says "do not" is not a policy. NCSC has now supplied the reason it fails.

What to do this quarter

The order matters here. Most businesses start at the last step and wonder why it does not hold.

  • Find out what is actually being used, without punishing anyone. Ask the question in a way that gets a truthful answer: not "are you breaking the rules" but "what are you using, and what does it save you". You will get a list. That list is the requirement specification for everything below.
  • Give people a sanctioned option that is genuinely as good. This is the step that does the work. If the approved tool is slower, worse, or three approvals away, the shadow version wins and no amount of policy changes that. A business account on a mainstream AI service, with training data sharing turned off, is not expensive and removes most of the reason to go elsewhere.
  • Say clearly what must never go in, whatever the tool. People can follow a short list of categories far better than a general instruction to use good judgement. Customer personal data, anything under a confidentiality agreement, credentials, unpublished financials. Four categories beat four pages.
  • Check the privacy setting on the accounts you do approve. The distinction that matters commercially is whether your input trains the provider's model. Consumer tiers often do by default, business tiers often do not. This is a setting, and somebody should have looked at it.
  • Build the culture bit, because NCSC leads with it. Its first recommendation is a positive security culture: if people can raise a tool they want to use without expecting a telling-off, you find out about it while you can still influence the decision. Organisations that understand why people reach for shadow AI are better placed to offer secure alternatives.
  • Treat AI that acts, rather than answers, as a separate decision. An assistant that drafts an email is a different risk from an agent with access to your systems. NCSC points at its own guidance on adopting agentic AI, and we covered what that guidance requires when it landed.

One closing note on who this was written for. NCSC labels the piece for security professionals and large organisations, which is not most of our readers. The translation for a smaller business is that you have the same problem with fewer people and no security team, but you also have an advantage a large organisation does not: you can ask everyone what they are using, and get a real answer, in an afternoon.

How Steelwise can help

Working out what your staff are already using, what a sanctioned alternative would need to do, and where the line sits for your business is a short, practical piece of work. Get in touch if you would like a hand with it.

Further reading

← All filings