The short answer: Shadow AI is the use of AI tools at work that your organisation has not approved, assessed or may not even know about.
An employee using a personal ChatGPT account to summarise a customer document.
Someone uploading a spreadsheet to an AI tool because they want help analysing it.
A manager pasting an employment contract into an AI assistant.
A salesperson installing an AI meeting recorder without asking anyone.
None of those people is necessarily trying to bypass security.
They are trying to get their job done.
And that is precisely why Shadow AI could become one of the most important cyber security problems facing UK businesses.
The National Cyber Security Centre has now specifically warned organisations about the issue, describing Shadow AI as AI technology being used outside an organisation’s approved systems and processes.
This matters because businesses are rapidly moving from asking:
“Should we allow AI?”
to needing to answer:
“Where is AI already being used in our business?”
Those are very different questions.
Shadow AI is essentially the AI version of Shadow IT.
It happens when employees use artificial intelligence applications, assistants, browser extensions, meeting tools, automation platforms or other AI-enabled services without them being formally approved by the organisation.
That might include:
The important point is that the technology itself is not necessarily the problem.
The lack of visibility is.
If a business knows which AI systems are being used, what information they can access and what those systems are allowed to do, it can assess and manage the risk.
If nobody knows they exist, that becomes considerably harder.
Because AI adoption is moving faster than corporate governance.
Employees do not normally wait for an AI strategy.
They find something useful and start using it.
The NCSC highlighted research suggesting that 71% of employees reported using AI tools that had not been approved by their employer. (National Cyber Security Centre)
That should change the conversation for business leaders.
The question is no longer whether your employees are interested in AI.
You should probably assume they are.
The better questions are:
Which tools are they using?
What information are they putting into them?
What have those tools been given access to?
Imagine an employee has a difficult spreadsheet.
They upload it to an AI service and ask:
“Can you analyse this and tell me which customers are most profitable?”
Perfectly reasonable request.
But what was in the spreadsheet?
Customer names?
Email addresses?
Financial information?
Pricing?
Contracts?
Commercially sensitive information?
Personal data?
Where has that information now gone?
How long will it be retained?
Can it be used to improve the service?
Which country is processing it?
Who else could access it?
Has the organisation agreed to those terms?
This is where a simple productivity shortcut can become a data governance problem.
The NCSC specifically warns that transferring sensitive or proprietary information into consumer AI services can reduce an organisation’s visibility and control over that information. (National Cyber Security Centre)
The first generation of workplace AI mostly answered questions.
The next generation can do things.
This is agentic AI.
AI agents can potentially access information, remember context, use tools, interact with other systems and perform actions towards a goal.
The NCSC describes this as an important step beyond traditional generative AI because agents can make decisions and take actions with reduced human intervention. (National Cyber Security Centre)
That changes the risk.
Giving an AI assistant access to your diary is one thing.
Giving an AI agent access to your:
Microsoft 365 environment,
email,
CRM,
SharePoint,
financial systems,
customer information,
cloud applications,
or internal workflows
is something very different.
Now the question isn’t simply:
“What information can the AI see?”
It becomes:
“What can the AI actually do?”
This is probably the simplest way for business leaders to think about the issue.
If you employed somebody tomorrow, you would hopefully consider:
What systems should they access?
What information should they see?
What are they allowed to change?
What permissions do they need?
How will their activity be monitored?
What happens when they leave?
An AI agent deserves similar questions.
Possibly more.
Because unlike an employee, an automated system may perform actions extremely quickly and at considerable scale.
The NCSC’s latest guidance on agentic AI recommends controlling the environment in which agents operate, maintaining logs and audit trails, providing appropriate human oversight and retaining the ability to stop an agent if necessary. (National Cyber Security Centre)
That is not science fiction.
It is access control.
And access control has always been fundamental to cyber security.
There is an obvious response to all this:
“We’ll just tell everyone not to use AI.”
That sounds safe.
It may actually make the problem worse.
If employees believe AI genuinely helps them work faster, some will continue using it.
They just won’t tell you.
Now you have exactly the situation you were trying to prevent.
Shadow AI.
The NCSC isn’t recommending that organisations simply stop people using AI either. Its advice focuses on understanding why employees are using these services, providing appropriate alternatives and creating a culture where people can discuss their requirements openly. (National Cyber Security Centre)
That is a far more realistic approach.
AI is going into businesses.
That argument is effectively over.
Trying to prevent every employee from ever using an AI service is likely to become about as practical as trying to prevent them using Google.
The businesses that handle this well will not necessarily be those with the strictest AI policies.
They will be the businesses with the clearest ones.
Employees need to know:
What AI can I use?
What information can I put into it?
What information must never be entered?
Which business systems can AI access?
Who approves a new AI tool?
What should I do if I’m unsure?
That is governance people can actually follow.
A 47-page AI policy sitting in SharePoint that nobody has read is not governance.
Do not start by writing a policy.
Start by discovering reality.
Ask departments what tools they currently use.
Marketing may be using completely different AI services from finance, HR or sales.
You may discover considerably more AI adoption than you expected.
That is useful information.
Employees should not have to guess.
Create a simple register showing which AI services are approved for business use.
For each system, establish:
Who owns it?
What is it used for?
What data can it access?
What data can employees enter?
Does it connect to other company systems?
When was it last reviewed?
The NCSC’s secure AI guidance emphasises understanding what data organisations hold, where it is stored and who can access it. (National Cyber Security Centre)
Most employees do not need a lecture about large language models.
They need clear boundaries.
For example:
Public information: generally acceptable.
Internal information: approved business AI tools only.
Confidential/customer/personal information: only where specifically authorised.
Passwords, authentication information and highly sensitive information: never enter into unapproved AI systems.
The exact rules will differ between organisations.
The important thing is that people understand them.
This becomes increasingly important as AI agents arrive.
An AI system should not automatically receive broad access simply because it makes implementation easier.
Use the same principle you should already use for people:
Give it the minimum access necessary to perform its job.
If an AI agent only needs access to one data source, why can it access ten?
If it only needs to read information, why can it modify it?
If it doesn’t need email, why can it send email?
The NCSC specifically advises organisations not to give agents unrestricted access to sensitive information or critical systems. (National Cyber Security Centre)
Someone inside the organisation needs ownership.
That does not necessarily mean creating a Chief AI Officer.
For most SMEs, that would be excessive.
But somebody should know:
which systems are approved,
what information they access,
who approved them,
what risks were considered,
and when they will be reviewed.
Without ownership, AI adoption becomes everybody’s responsibility.
Which usually means nobody’s responsibility.
The first is assuming Microsoft 365 security automatically solves the AI problem.
It doesn’t.
Your Microsoft environment might be well protected while an employee is copying information into an entirely separate consumer AI application.
The second is treating AI entirely as an IT problem.
It isn’t.
AI governance touches information security, data protection, HR, legal, compliance and operational risk.
The third is writing an AI policy without discovering what employees are already doing.
You end up governing the organisation you think exists rather than the one that actually exists.
The fourth is banning everything.
That encourages employees to hide useful tools rather than discuss them.
And the fifth is approving AI applications without considering what they connect to.
That becomes increasingly dangerous as AI moves from generating information to performing actions.
It doesn’t need to be complicated.
For most organisations, a sensible starting point is:
An AI Acceptable Use Policy.
An approved AI tools register.
Clear data classification rules.
A simple approval process for new AI services.
Appropriate Microsoft 365 permissions.
Multi-factor authentication.
Proper identity and access management.
Logging and monitoring.
Regular access reviews.
Staff awareness training.
An incident response process that includes AI-related incidents.
And somebody accountable for maintaining it.
That is considerably more useful than banning ChatGPT and hoping for the best.
There is another reason Shadow AI matters.
For years, businesses have thought about digital identities primarily as people.
Jason has an account.
Sarah has an account.
The finance team has accounts.
External suppliers have accounts.
Now businesses are beginning to introduce another category:
machines acting on behalf of people.
AI assistants.
Automation platforms.
AI agents.
Service accounts.
APIs.
Bots.
Those identities can potentially access exactly the same valuable information as employees.
That means businesses increasingly need to understand not only:
Who has access to our systems?
but:
What has access to our systems?
That distinction is going to become extremely important.
There is a temptation whenever new technology arrives to assume we need an entirely new security model.
Usually we don’t.
The fundamentals still work.
Know what you have.
Know who or what can access it.
Use strong authentication.
Limit privileges.
Protect sensitive information.
Patch systems.
Monitor activity.
Train people.
Maintain backups.
Prepare for incidents.
The technology may change.
The fundamentals don’t.
Ask your leadership team one question today:
“Which AI tools are currently being used inside our business?”
Do not ask IT.
Ask everyone.
Marketing.
Sales.
Finance.
Operations.
HR.
Management.
Then write the answers down.
If the answer surprises you, you have just discovered your first Shadow AI risk.
If nobody knows the answer, you have discovered something even more useful.
Because you cannot protect what you cannot see.
Shadow AI is the use of artificial intelligence tools or services within an organisation without formal approval, visibility or governance. It can include AI assistants, meeting tools, browser extensions, automation platforms and autonomous AI agents.
Not automatically. The risk depends on how the service is configured and what information employees enter or allow it to access. Problems arise when confidential, personal or commercially sensitive information is shared without appropriate controls.
Usually not as a blanket strategy. Blocking useful technology can encourage employees to use it without telling the organisation. A better approach is to provide approved tools, clear rules and appropriate technical controls.
Employees should avoid entering passwords, authentication information, sensitive customer information, personal data, confidential company information or intellectual property into unapproved AI systems.
An AI agent is an AI system capable of taking actions towards a goal rather than simply generating an answer. Depending on its configuration, an agent may interact with applications, data, email, files or other business systems.
They can be. The risk increases when an agent has broad access to sensitive information or business systems. Organisations should restrict permissions, monitor activity and maintain appropriate human oversight.
At minimum, it should explain which AI systems employees may use, what information can be entered, what is prohibited, how new AI services are approved and who employees should contact when unsure.
Responsibility will vary by organisation, but ownership should be clearly assigned. AI governance should normally involve leadership alongside IT, cyber security, data protection and other relevant business functions.
AI is moving quickly.
Your governance doesn’t need to move slowly.
You do not need to understand every AI model your employees might encounter.
But you should know which AI systems are being used inside your business, what information they can access and what they are allowed to do.
Start there.
People Protected. Full Stop.
Munio helps UK businesses understand their real cyber risk across Microsoft 365, users, devices, vulnerabilities, identity and the growing use of AI.
Our Cyber Resilience Review cuts through the dashboards and technical noise and shows you what actually matters, what needs fixing first and what good looks like.