On 7 September 2026, the National Cyber Security Centre published guidance on a problem that almost every UK business already has and almost none of them have written down. The subject is “shadow AI” - artificial intelligence tools that employees use for work without their employer having approved them - and the number the NCSC leads with is not a marginal one. Citing published research, the agency notes that nearly three-quarters of employees, 71%, reported using AI tools that had not been approved by their organisation. Not experimented with once. Used.
For a UK SME reading this on 8 September 2026, the useful way to interpret that figure is not as a statistic about other companies. It is a base rate. If you employ fourteen people and you have never issued an AI usage policy, the arithmetic suggests roughly ten of them have pasted something into a consumer AI service that belongs to your business or to your customers. A quotation. A client email thread they wanted rewritten more diplomatically. A spreadsheet of order values they wanted summarised. A CV they wanted screened. A block of code with a database connection string still in it. None of those people were being reckless. They were doing the job faster, using a tool that is free, instant, and sitting in the same browser as everything else they use.
That is precisely why the NCSC’s guidance is worth more attention than the average security advisory. It does not tell organisations to ban AI. It says the opposite. The agency’s position is that shadow AI is unlikely to disappear completely, that the realistic goal is to reduce risk rather than to assume it can be eliminated, and that the practical response is to give staff approved, secure alternatives that actually meet the business need they were solving in the first place. It is a governance document dressed as a security one, and for the roughly five and a half million businesses in the UK that have no CIO to write such things, it is effectively a free policy brief.
What the NCSC actually published
The guidance, written by a senior cloud researcher at the NCSC and published on the agency’s blog, frames shadow AI as a species of a much older problem: shadow IT. Shadow IT is the file-sharing account somebody opened because the approved one was slow, the personal messaging group the warehouse team runs because the official channel is clunky, the spreadsheet that quietly became a production system. Security teams have understood that phenomenon for two decades. What has changed is the speed at which the newest version of it arrived, and the sensitivity of what gets handed over when an employee uses it.
The NCSC sets out three main risks, and they are worth separating carefully because they call for different responses. The first is the exposure of sensitive company or customer information. When an employee pastes material into a consumer AI service, that material leaves the organisation’s boundary. The second is the loss of visibility and control over data once it has been shared. Unless specific privacy controls are in place, data submitted to an unapproved consumer tool may be stored, retained, or used to improve the service - all of it happening outside the organisation’s established security and governance arrangements. The third is the most technical and the least discussed: AI tools, and particularly AI agents, are complex software that can carry exploitable vulnerabilities. Every unapproved tool an employee adopts is a new piece of software in the estate, with its own attack surface, that nobody has reviewed.
Those three risks compound rather than sit alongside each other. Exposure without visibility means an organisation cannot answer the most basic question a regulator, an insurer or a client will ask after an incident: what left, when, and where did it go. And an AI tool with a vulnerability in it is a far more attractive target when it has been fed three months of a company’s commercial correspondence. The NCSC’s guidance links out to its own material on cyber security culture principles and on adopting agentic AI, which is a fair indication of where the agency thinks the answer lies: in how organisations behave, not only in what they block.
If a customer asked you today which AI services your staff have used their work email address to sign up for, could you answer? For most small and medium UK businesses the honest answer is no - and that is the actual finding buried inside the 71% figure. The exposure is not hypothetical future risk; it is data that has already been shared, with services nobody catalogued, under terms nobody read. Under UK GDPR you remain the data controller for personal data your staff hand to a third-party service, whether or not you approved that service. “We did not know they were using it” has never been a defence, and it is a particularly weak one when the research says you should have expected roughly seven staff in ten to be doing it.
How the story arrived at 7 September 2026
Shadow AI did not appear with the NCSC’s blog post. The guidance is a formalisation of something that had been building in UK workplaces for well over two years, and reading it as a sudden warning misses what it is actually doing - putting a national security agency’s name to a behaviour pattern that had become normal without ever becoming approved.
Where unapproved AI actually shows up in a UK SME
The mental image of shadow AI is an employee typing a confidential document into a chatbot. That happens, but it is not where most of the exposure sits, and organisations that police only the obvious case will miss the majority of it. The ranking below reflects what we see across UK SME estates when we go looking - it is an assessment of where unapproved AI use concentrates, not a published survey. It is ordered by how commonly each pattern turns up, and every one of these is a route by which company or customer data leaves the boundary without a decision being taken.
Read that list against the NCSC’s three risks and the picture sharpens. The top two categories are almost pure data exposure: the material being handed over is, by definition, the organisation’s own correspondence and documents. The middle categories - extensions, in-app assistants, transcription bots - are where loss of visibility bites hardest, because the employee often does not perceive them as an AI tool at all and would not name them if asked. And the bottom category, small today but growing, is where the vulnerability surface argument lands: an autonomous agent with standing access to a mailbox or a file store is not a website you paste text into. It is software with credentials, acting on its own, inside your estate.
The meeting transcription line deserves singling out. A note-taking bot invited into a call is frequently the single largest uncontrolled data transfer in a small business, because it does not capture a paragraph - it captures the entire commercial conversation, including the parts nobody would have written down. It joins as a participant, it is invited by whoever booked the meeting, and it is very often somebody else’s account rather than yours. Under UK GDPR, the personal data of everyone on that call is being processed by a service you have no contract with.
The number that should set your agenda
There is a temptation to treat 71% as an interesting figure about the state of work. It is more useful as a planning assumption. If you accept it as your organisation’s starting position - that roughly seven in ten of your staff have already used an AI tool you never approved - then a series of questions follow that have nothing to do with technology and everything to do with governance. Which services? Signed up with which email addresses? Under whose terms? Retaining data for how long? Used to improve whose model? For the overwhelming majority of UK SMEs, all five answers are currently unknown, and they are unknown for a reason that is entirely rational: nobody was ever tasked with knowing.
What makes the figure actionable rather than alarming is the NCSC’s framing of what to do about it. The agency does not treat 71% as a compliance failure by 71% of employees. It treats it as evidence of unmet business need. People reach for unapproved tools when the approved ones do not exist, are too slow, or were never explained. That reframing matters enormously for a small business, because it changes the response from an enforcement exercise - which is expensive, unpopular and largely unenforceable - into a provisioning exercise, which is neither.
Where UK SMEs stand today
The assessment below is our reading of the typical position of a UK business of between ten and two hundred and fifty staff, measured against what the NCSC’s guidance implies an organisation ought to be able to demonstrate. High denotes a significant gap that is likely to matter in an incident or an audit; mid a partial or inconsistent position; low an area where most businesses are broadly adequate.
Two things stand out in that grid. The first is that the top four gaps are all governance artefacts rather than technical controls - a policy, an inventory, a provisioning decision, a classification scheme. None of them requires new software. The second is the last row: most UK SMEs, particularly those that have been through Cyber Essentials, have adequate account hygiene. That is genuinely good news, because managed identities are the mechanism by which shadow AI signup becomes visible in the first place. A business that already controls its identities is closer to controlling its AI exposure than it thinks.
What proportionate governance costs
The reason shadow AI policy gets deferred in small businesses is rarely disagreement about whether it matters. It is the absence of anyone whose job it is. The indicative ranges below reflect UK market rates in September 2026 for the work involved, expressed as a first-year figure covering the initial assessment and the ongoing oversight. They are illustrative bands rather than quotations, and they assume the business is starting from no formal position at all.
| Business size | Typical AI services in use | Indicative first-year governance cost | What that buys |
|---|---|---|---|
| 1–9 staff | 3–8 | £900 – £2,400 | Discovery of what is in use, a short written policy, one approved tool provisioned properly, staff briefing |
| 10–49 staff | 8–20 | £2,400 – £7,500 | The above, plus data classification, tenant-level controls, extension visibility and a quarterly review |
| 50–99 staff | 15–40 | £7,500 – £18,000 | Departmental needs assessment, approved tooling across functions, supplier due diligence, DPIA support |
| 100–249 staff | 30–80 | £18,000 – £45,000 | Full estate discovery, agent access review, board-level reporting, integration with the wider risk register |
Set those figures against the alternative. The costs of getting this wrong are not principally regulatory fines, which for a small business are rare. They are commercial: the client who asks in a tender whether their data has been processed by AI services and receives no credible answer; the professional indemnity renewal that now includes AI questions; the contract clause that prohibits sharing client material with third-party services, signed in good faith and breached daily by a member of staff who has never seen the contract. The first-year governance figure is almost always smaller than the cost of one lost account.
Two postures, one guidance document
The NCSC’s advice can be implemented in two quite different spirits, and the difference determines whether it works. One treats the 71% as a discipline problem. The other treats it as a demand signal. The agency is unambiguous about which it recommends.
Reactive posture
What most UK SMEs do today
- AI use is addressed only after an incident, a client question, or a headline
- The instinctive response is a blanket ban circulated by email and never enforced
- No inventory exists, so nobody can say which services hold company data
- Staff conceal the tools they rely on, because admitting to them invites a reprimand
- Approved alternatives are absent or so restricted that the unapproved tool remains faster
- AI agents are granted mailbox and file access by individual staff, with no review
- The business cannot answer a tender question about AI data handling
- Shadow AI keeps growing, but silently - the risk is now invisible as well as unmanaged
Proactive posture
Where a Virtual CIO takes you
- AI use is a standing item on the risk register, reviewed on a fixed cycle
- Policy states what may be shared and with which services, in language staff can apply
- A live inventory records every approved AI service, its terms and its retention position
- Open communication is the control - staff surface new tools rather than hiding them
- Approved tools are provisioned because the underlying business need was understood first
- Agent access to mailboxes and file stores is reviewed and granted deliberately
- Tender and insurance questions on AI have documented, defensible answers ready
- Residual shadow AI is expected, monitored and shrinking - not assumed to be zero
Note what the proactive column does not contain: a prohibition. The NCSC’s explicit position is that banning AI outright is not the recommendation, and the reason is practical rather than permissive. A ban that staff cannot comply with while doing their jobs does not stop the behaviour; it stops the reporting of the behaviour. The organisation loses the one thing it had - the ability to find out.
The score above is an assessment, not a measurement, and it is deliberately low for a reason that is easy to miss: the businesses scoring 29 are not badly run. They are businesses whose identity controls, backups and patching are in reasonable order - frequently better than average - but which have never been asked to govern a category of tool that arrived without a purchase order. Readiness here is almost entirely a documentation and provisioning question. It is one of the few risk areas where a substantial improvement is available in weeks rather than budget cycles.
Before buying anything, ask each team a single non-judgemental question: “What is the most tedious part of your week, and have you found anything that helps with it?” That phrasing consistently produces a more complete list of tools than a security questionnaire does, because it asks about the work rather than about compliance. It is also the practical expression of what the NCSC recommends - a positive culture with open communication, in which staff who feel able to discuss why they use a tool are less likely to hide it. The answers tell you which approved alternatives are actually worth provisioning, which is the part of the guidance that costs money if you get it wrong.
At a glance
| Detail | Position |
|---|---|
| What was published | NCSC guidance on the hidden risks of shadow AI |
| Date of publication | 7 September 2026 |
| Author | A senior cloud researcher at the NCSC |
| Definition of shadow AI | AI tools used by staff that have not been approved by their employer - a form of shadow IT |
| Headline research figure | 71% of employees reported using AI tools their employer had not approved |
| Risk one | Exposure of sensitive company or customer information |
| Risk two | Loss of organisational visibility and control once data is shared with consumer AI services |
| Risk three | New attack opportunities - AI agents are complex software that can carry exploitable vulnerabilities |
| Data handling concern | Data may be stored, retained or used to improve the service unless specific privacy controls are in place |
| NCSC position on banning AI | Not recommended - provide approved, secure alternatives that meet real business needs instead |
| Stated objective | Reduce risk; shadow AI is unlikely to disappear completely |
| Recommended cultural control | A positive cyber security culture with open communication, so staff do not conceal tool use |
| Related NCSC material | Cyber security culture principles; guidance on adopting agentic AI |
| Who is accountable in a UK SME | The data controller - the business - regardless of whether the tool was approved |
| Cloudswitched service mapping | Virtual CIO, supported by IT Support, Cyber Essentials and Cloud Backup |
The wider pattern in 2026
This story does not sit on its own. It is the governance counterpart to a series of developments we have covered over the past fortnight, and read together they describe a single trend: UK organisations are being asked to account for data flows they never consciously created. The Swansea University research on consent showed that most UK websites are still mishandling cookie consent under GDPR, which is the same failure mode as shadow AI - data leaving the organisation through a mechanism nobody audited. The ASCII smuggling technique used against Microsoft 365 users is a direct illustration of the NCSC’s third risk, since it turns an AI assistant’s own text handling into the attack path. Legislative attention is moving in parallel, as the debate over AI kill-switch provisions in UK law shows. And the underlying dependency questions remain unchanged: the SMS blaster fraud conviction and the continuing arguments about accountability for UK business broadband faults both turn on the same point - that responsibility does not follow convenience, and the organisation carrying the risk is rarely the one that introduced it.
Do you know which AI services hold your business data?
Cloudswitched’s Virtual CIO service gives UK SMEs the governance function they do not have on the payroll - discovery of the AI tools already in use, an acceptable-use policy written in language your staff will actually apply, and approved alternatives provisioned against the business needs that drove people to shadow AI in the first place. It is the NCSC’s recommendation, implemented rather than filed.
Talk to us about a Virtual CIOFrequently asked questions
The governance gap is the whole story
What makes the NCSC’s 7 September guidance unusual is how little of it is about technology. There is no product to buy, no patch to apply, no configuration to change. The three risks it names - data exposure, loss of visibility, and vulnerable AI software - are all downstream of a single organisational condition: nobody decided anything. Tools arrived, staff adopted them because they were useful, and no function existed to ask which data those tools were receiving or on what terms. In a large enterprise that function has a name and a salary. In the overwhelming majority of UK SMEs it does not exist at all, which is why a figure as high as 71% can be true without anybody having behaved badly.
The practical consequence is that this is a solvable problem, and cheaply, provided it is treated as governance rather than enforcement. Discovery, a short policy, a decision about which approved tools to provision, and a review cycle will move most small businesses from the position described in the assessment above to a defensible one inside a quarter. What will not work is the instinctive response - a prohibition that removes the organisation’s remaining visibility without removing the behaviour. The NCSC has said so plainly, and it is the single most useful sentence in the guidance for any UK business owner deciding what to do on the strength of it.
Put a CIO’s judgement behind your AI decisions
Most UK SMEs do not need an AI strategy. They need someone accountable for asking which tools hold company data, whether the terms are acceptable, and what should be provisioned properly instead. That is what Cloudswitched’s Virtual CIO service provides - senior IT governance on a retained basis, working alongside your IT Support, Cyber Essentials and Cloud Backup arrangements, so decisions like this one get made deliberately rather than by default.
Talk to us about a Virtual CIO


