A Cybersecurity Agency Just Told Companies to Stop Fighting Their Own Employees
The UK's National Cyber Security Centre says 71% of workers use unapproved AI tools at work — and urges employers to adapt, not crack down.
The Admission
On September 7, 2026, the UK's National Cyber Security Centre published guidance on what it calls "shadow AI" — AI tools employees use for work without formal approval. The opening stat is striking: 71% of employees reported using unapproved AI tools at work.
The more striking part: instead of recommending bans or lockdowns, the NCSC told employers to accept that this is happening and work with it.
This is a national cybersecurity authority effectively acknowledging that employees are quietly rebuilding the software stack at work, at scale, because official tools aren't keeping up. And rather than treating this as a problem to eliminate, the guidance frames it as a reality to manage.
What Shadow AI Actually Looks Like
The NCSC defines shadow AI explicitly: AI tools staff use without employer approval. It's the AI-era successor to shadow IT, but with higher stakes.
The scenarios are easy to picture. A finance analyst pasting sensitive data into a consumer AI tool because the ERP's reporting module is too clunky. A customer support lead wiring a cheap AI summariser into ticket workflows because the official CRM doesn't have those features yet. A procurement team running contract analysis through an unapproved tool because the legal department's approved software takes three days to process what takes the free tool three minutes.
The guidance acknowledges that shadow AI is "unlikely to disappear completely." That phrasing matters — it's an admission that the behaviour is too widespread and too useful to stamp out. The goal shifts from elimination to risk reduction.
The Cultural Argument
Here's where it gets interesting. The NCSC doesn't just recommend technical controls. It urges organisations to build what it calls a "positive cyber security culture" with open communication.
The logic: staff who feel able to discuss which tools they're using and why are less likely to conceal shadow AI use. Psychological safety becomes a security control. The ability to say "I'm using this tool because our approved software doesn't do what I need" without fear of being shut down becomes part of the defense.
That's an unusual stance for a security authority. It treats workplace culture not as an HR concern but as infrastructure — something that affects whether threats stay visible or go underground.
What This Says About Approved Software
If 71% of employees are supplementing or bypassing approved tools, that's a verdict on internal software. It means the official stack isn't solving the right problems, or isn't solving them fast enough, or isn't usable enough for people to choose it when they have alternatives.
The NCSC's recommendation is to provide approved, secure alternatives that genuinely meet the business needs employees are solving. Not "tools that check compliance boxes" — tools people actually want to use.
That's a high bar. Consumer AI tools and indie products are designed for immediate utility. They're built to feel fast, responsive, and adaptable. Enterprise software, by contrast, often moves slowly, requires multiple approval layers for new features, and prioritises control over experience.
The shadow AI problem exposes that gap. Employees aren't choosing unapproved tools to be reckless — they're choosing them because those tools let them do their jobs better.
The Governance Problem Nobody Planned For
Most AI governance frameworks focus on top-down decisions: procurement policies, model risk management, vendor assessments. The assumption is that enterprises choose their AI tools, implement them through IT, and employees use what they're given.
Shadow AI breaks that model. It's a parallel adoption wave happening entirely outside formal governance, driven by frontline workers rather than CIOs or procurement committees.
This isn't a niche problem. A separate analysis of shadow AI in enterprise environments describes it as a diverse ecosystem of tools, largely invisible to IT, being wired into everyday business processes by people who were never part of the AI decision-making process.
The NCSC guidance treats this not as a temporary phase but as a permanent feature. Employees are now a creative layer of the tech stack — not just users of centrally chosen systems, but active architects of how work gets done.
The Uncomfortable Question
The shadow AI story raises an uncomfortable question for B2B vendors and IT leaders: if employees keep reaching for outside tools despite official alternatives, what does that say about the tools being provided?
The NCSC's practical advice isn't "block everything you don't control." It's "give people tools they actually want to use, and make it safe to tell you what they're doing."
That's a harder problem to solve than writing a policy. It requires building software that competes on experience, not just compliance. It requires creating environments where people feel comfortable saying "this isn't working" instead of quietly finding workarounds. And it requires accepting that some level of improvisation and adaptation by employees is going to happen, no matter how tightly controlled the official stack appears to be.
The interesting part isn't that employees are bending the rules. It's that a government security agency looked at the situation and decided the smarter response is to bend with them.
Technology decisions, clearly explained.
Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.
