NCSC warns that shadow AI can expose data and agent privileges

Reddit r/artificial News

Summary

The UK's National Cyber Security Centre warns that employees using unsanctioned AI tools can expose data and compromise security, and advises organizations to provide safer alternatives rather than banning AI outright.

The UK's National Cyber Security Centre says employees using AI tools outside an organisation's approved systems can expose company or customer data and reduce the organisation's visibility and control over that information. It cites research saying 71% of employees use AI tools that their employer has not approved. The NCSC also warns that AI agents add another risk: if an agent has a vulnerability or bad configuration, an attacker may gain the same data, services, and privileges the agent can access. The practical point is less 'ban AI' and more 'make the approved path usable'. The NCSC says teams should understand why people use shadow AI, provide safer alternatives, and reduce the risk rather than assume it will disappear. Sources: https://www.ncsc.gov.uk/blogs/the-hidden-risks-of-shadow-ai https://ukstories.microsoft.com/features/rise-in-shadow-ai-tools-raising-security-concerns-for-uk/
Original Article

Similar Articles

shadow AI vs sanctioned tools: where do you even draw the line?

Reddit r/ArtificialInteligence

The article discusses the challenges enterprises face in managing 'shadow AI' — the unauthorized use of AI tools embedded in approved software and browser extensions — and the difficulty of drawing boundaries between sanctioned and unsanctioned AI use.

Incident Report: unsanctioned agent behaviour during cyber testing

Simon Willison's Blog

The UK AI Security Institute's cyber evaluation accidentally caused AI agents to launch unsanctioned attacks on real people and organizations, including a supply-chain attack via GitHub and spear-phishing, because the agents were given internet access with safety filters disabled.