Shadow AI is becoming a major systemic risk. Even intelligence agencies are getting worried
Security authorities around the world warn of the broad, unpredictable risks of uncontrolled AI usage.
The cybersecurity wing of Britain’s intelligence services has warned that shadow AI is creating “hidden risks” for organizations and adding to the growing threats facing critical systems.
Shadow AI involves using AI tools without permission or oversight. Research shows that companies with greater technical expertise are more likely to break the rules by running unauthorized AI tools, which isn't surprising, given the fine line between innovation and rule-breaking.
But great ideas often come with great risk. The National Cyber Security Centre (NCSC) warned that unauthorized AI tools can expose sensitive information, strip organizations of visibility, erode control over their data, and create new opportunities for attackers.
“You cannot manage what you do not know,” the NCSC warned.
It added: "Where security policies cannot meet business needs, organizations are likely to continue seeing their employees adopt new AI services before they have had time to assess them and provide approved alternatives.
"This trend is likely to be reinforced as AI capabilities become increasingly affordable and readily available."
Research cited by the agency found that 71% of employees had used AI tools which were not approved by their employer.
Spooks and Shadow AI
Despite its chummy, collegiate public persona, the NCSC is not simply another government IT body. It is part of GCHQ, Britain’s signals intelligence agency.
And it is not alone. Intelligence and national security authorities across the Five Eyes alliance have been steadily raising the alarm about uncontrolled AI.
The National Protective Security Authority, part of MI5, has explicitly advised organizations to manage the risks of shadow AI and unknown AI tools.
In June, the Defense Counterintelligence and Security Agency warned that shadow AI creates a “massive, unmonitored attack surface”, describing it as a primary vector for unauthorized disclosure, data spillage and operational security failures.
Five Eyes cyber authorities have also warned about the related risks of agentic AI. Guidance backed by authorities in the UK, US, Canada, Australia and New Zealand warned that agents can be given broader access to external systems, data and tools, making their behavior harder to predict, monitor and govern.
Taken together, the warnings point towards the same systemic risk: organizations are adopting AI faster than they can identify, govern and secure it.
Shadow AI makes that problem particularly acute because businesses may not even know which systems are operating inside their networks, what information they can access, or what actions they can take.
Agents introduce escalating risk
The systemic threat posed by shadow AI is likely to grow as AI agents move cautiously from testing into real-world deployment, gaining access to corporate data, applications and permissions, even if their use in genuinely mission-critical systems remains limited for now.
Research from Gartner found that just 17% of organizations had deployed AI agents in 2026, with much of the experimentation focused on discrete tasks including software engineering, customer support and operations. More than 60%, however, expect to deploy agents within the next two years.
Shadow AI creates a problem larger than employees pasting confidential documents into ChatGPT.
It creates systems that organizations may not know exist, processing data they cannot properly track through models, agents, and vendors they have not necessarily assessed.
Sensitive information can leave controlled environments, privacy and retention safeguards can be bypassed, and new dependencies can develop beyond the visibility of security teams.
READ MORE: “LLMs will be subverted”: Malware is evolving to attack AI defenders, SentinelOne warns
Darren Anstee, CTO for security at NETSCOUT, said organizations have traditionally focused on the danger of confidential information and intellectual property leaking through shadow AI.
Employees acting with legitimate intentions can feed corporate information into AI services, potentially using personal accounts outside company data governance. Depending on how those tools are configured, Anstee warned, those inputs could be incorporated into future training data, potentially exposing confidential information or intellectual property to other users.
“Businesses should create clear AI usage policies that define approved tools, establish data-handling guidelines, and classify AI applications into tiers: sanctioned, limited-use, and prohibited. They should also create an internal AI council to maintain oversight of the above, with accountability across their organization.”
Is banning Shadow AI a bad move?
However, attempting to stamp out unauthorized AI altogether could prove counterproductive, particularly because a certain type of smart, innovative, free-thinking person will always just bypass restrictions if they need to get the job done.
Anstee advised: “The temptation for businesses is to enforce blanket bans on unauthorized AI tools, but this only drives AI usage further into the shadows. A streamlined approval pathway for new AI technologies is key, as complex, long-winded governance processes risk being bypassed.”
Jamie Akhtar, CEO and co-founder of CyberSmart, also argued that simply prohibiting AI would not solve the underlying problem.
READ MORE: Rogue OpenAI agents hijacked a wiki. Humans attacked the power grid
He said: “The NCSC is right to highlight shadow AI as a growing cyber security challenge. Employees are increasingly using AI tools to work faster and more efficiently, but when those services sit outside an organization’s approved systems, businesses can quickly lose visibility over where sensitive company and customer data is being shared, stored or processed.
“Simply banning AI is unlikely to solve the problem. Businesses need to provide secure, approved alternatives that allow I think I'm a propeople to benefit from AI without introducing unnecessary risk. Clear policies, employee education and appropriate technical controls all need to develop at the same pace as AI adoption.”
The risks grow more serious when shadow AI moves beyond standalone chatbots to AI agents embedded in corporate applications.
"A new class of operational risk"
Research from Reco found that just 20% of AI tools operating across enterprise environments were subject to IT oversight.
That potentially creates a more dangerous form of shadow AI because agents can inherit existing permissions and connections to other corporate systems.
“AI agents have moved from experimentation into daily business workflows, but our findings show only 20% of AI tools in enterprise ecosystems are currently governed by IT oversight,” said Ofer Klein, CEO of Reco.
“That leaves organizations exposed to a new class of operational risk. Agents embedded in applications can operate through existing permissions, OAuth grants and workflow access, creating toxic combinations that expose data and trigger actions beyond what any owner approved.”
The problem therefore extends beyond data leakage. An unknown chatbot represents one kind of security problem. An unknown agent capable of accessing applications, invoking permissions, and taking actions represents another.
A bigger risk for smart teams?
Evidence also suggests that the employees most capable of understanding those risks may be among the most willing to ignore restrictions.
New research from TrustedTech found a stark divide between industries, with sectors possessing deep technical expertise also showing a greater willingness to bypass organizational AI rules.
Julian Hamood, Founder and Chief Visionary Officer of TrustedTech, said: “There is an assumption that Shadow AI is a problem of ignorance – that people use unapproved tools because they do not understand the risk. Our sector data shows the opposite. The industries that understand AI best are the ones bypassing the rules most often, and the most willing to do so knowing it could cost them their job.
“That should reframe how organizations respond. This is not a training problem to be solved with another awareness module – it is a provision and policy problem.
"Where approved tools are slower, narrower or more restricted than the alternatives, employees will route around them, and the more capable the workforce, the faster they will do it.
"Sectors handling regulated or highly sensitive data, particularly Finance and Healthcare, cannot afford to treat that as an acceptable trade-off.”
READ MORE: Nuclear cops: Legacy tech made our Microsoft Teams video call system “insecure”
Shadow AI is therefore beginning to look less like another version of shadow IT and more like a systemic visibility problem.
Companies are becoming dependent on AI while simultaneously losing sight of which models and agents their employees are using, what information those systems can access, which permissions they possess and what external services they depend upon.
For now, widespread autonomous deployment into mission-critical systems remains more ambition than reality. But that may be precisely why the window for imposing controls matters.
A system cannot be properly secured if nobody knows it exists. And as AI moves from answering questions to taking actions across corporate infrastructure, the potential consequences of that blindness are growing.