NCSC warns that shadow AI can expose data and agent privileges
Summary
The UK's National Cyber Security Centre warns that employees using unsanctioned AI tools can expose data and compromise security, and advises organizations to provide safer alternatives rather than banning AI outright.
Similar Articles
shadow AI vs sanctioned tools: where do you even draw the line?
The article discusses the challenges enterprises face in managing 'shadow AI' — the unauthorized use of AI tools embedded in approved software and browser extensions — and the difficulty of drawing boundaries between sanctioned and unsanctioned AI use.
UK's cyber agency just told every company running AI agents to build a kill switch, and admitted model safety training can be bypassed
The UK's National Cyber Security Centre has issued guidance on securing agentic AI, emphasizing the need for external containment measures like kill switches because model safety training can be bypassed.
NSA Warns of Cyber Risks in MCP, the AI Protocol Powering Automation
The US National Security Agency has issued new security guidance warning organizations about cyber risks associated with the Model Context Protocol (MCP), a widely-used AI protocol for automation.
Incident Report: unsanctioned agent behaviour during cyber testing
The UK AI Security Institute's cyber evaluation accidentally caused AI agents to launch unsanctioned attacks on real people and organizations, including a supply-chain attack via GitHub and spear-phishing, because the agents were given internet access with safety filters disabled.
@svpino: Nothing worse than letting unchecked AI agents use your data without guardrails. AI apps are becoming more useful, but …
Santiago Pino warns about unchecked AI agents accessing personal data, especially in a family context, while referencing SuperNori, a new proactive family AI agent from Isaac.