The National Cyber Security Centre published new guidance this week on “shadow AI”, staff using AI tools their employer never approved, and its central message will land awkwardly for any business whose entire strategy so far has been a line in the staff handbook saying “don’t use ChatGPT”. The NCSC’s position is blunt: prohibition doesn’t work, and pretending it does just pushes the risk further out of sight.
This isn’t the agency simply confirming a problem exists. Surveys earlier this year already established that most UK staff use unapproved AI tools regularly, and that senior leaders often use them more than the people they manage. What’s new is that the UK’s own cyber security authority has now gone on record with specific, practical advice on what to do about it, rather than leaving businesses to guess.
Why banning doesn’t work
The NCSC’s reasoning is straightforward: staff don’t adopt unauthorised tools out of malice, they do it because an approved alternative is missing, slow, or doesn’t do what they need. Block one tool and, without addressing the underlying need, employees move to another one, often with less visibility than before. The guidance frames the realistic goal as reducing risk, not eliminating shadow AI entirely, because a workforce determined to route around a blanket ban usually finds a way.
There’s also a trust dimension. Organisations with open communication about security are less likely to see staff hide their tool use, according to the guidance, while heavy-handed enforcement just teaches people to be quieter about what they’re already doing. For a small business, that’s the difference between knowing roughly what AI tools are touching your customer data and having no idea at all.
What the NCSC recommends instead
Four things, in order. First, understand why staff are reaching for unapproved tools in the first place, usually a genuine gap between what the business provides and what the job requires. Second, open a real conversation about it rather than issuing a policy nobody reads: make it safe for someone to say “I’ve been using this because it saves me an hour a day” without fear of being disciplined. Third, once you understand the actual need, provide a sanctioned tool that meets it, rather than leaving staff to keep improvising. Fourth, build some visibility into what’s being used, because you can’t manage risk in tools you don’t know exist.
What this looks like without a security team
None of this requires an IT department. A five-minute team conversation or anonymous form asking “what AI tools do you currently use for work, approved or not” will surface most of the picture in one go for most small businesses. From there, the practical move is picking one or two approved tools that genuinely cover what staff are already doing informally, rather than a long list nobody adopts. A service like BuildApps can help an SME work out which AI tools are actually worth standardising on for their specific work, so the “approved alternative” step doesn’t stall through indecision. And because shadow AI usage is itself a form of exposure, particularly where customer or financial data ends up pasted into a tool with unclear data handling, ongoing monitoring services such as KeepSafe are worth considering if you want early warning when something in your wider AI or IT footprint goes wrong.
The takeaway
The NCSC has effectively told UK employers that the ban-and-hope approach to shadow AI was never going to work, and to stop treating it as a discipline problem. Run a quick, blame-free audit of what your team is already using this month, pick a sanctioned tool that actually meets the need you find, and keep an eye on what’s touching your data. That’s a more realistic path to reducing risk than any policy document gathering dust in a drawer.