Need urgent help?

Call our team on 0207 099 0740

Need urgent help?
0207 099 0740
Client Portal
view of earth from space which shows some areas with lights on as it is night time

2 October 2026

3 minutes read time

Shadow AI and AI governance: What UK businesses need to know

Author

As Chief Information Security Officer at CloudTech24, I lead security strategy, governance and operational delivery. I help our clients’ executive teams make informed decisions about cyber risk. My role involves understanding how a customer’s business actually works, where the real risks sit, and what it takes to reduce them in a way that lasts, using existing capabilities wherever possible.

My background spans hands-on technical delivery and board-level advisory to clients across fintech, financial services, legal and other regulated industries. I also own our ISO 27001 programme and the ISMS behind it. As AI moves into everyday business use, I also ensure that our usage of AI aligns to best practise through governance and policy, and advise leadership and customers on safe adoption, aligning toward emerging standards such as ISO 42001 and the EU AI Act.

Outside of work, I’m a proud dad to two brilliant daughters and a lifelong LEGO enthusiast – if we’ve had a video call, chances are you’ve seen a few of my builds in the background. I’m also a passionate gamer and PC builder, a hobby I picked up in the early 2000s with my dad, who first sparked my interest in computers. Fun fact: back in the day, I was Europe’s #1 ranked Battlefield 1942 player – proof that my competitive streak goes way back!

Read blogs in other categories

Shadow AI: the security risk your business can’t see

The use of AI in the workplace has increased dramatically and not always through a company-approved rollout!

Shadow AI refers to the use of AI tools or assistants at work without the knowledge, approval or oversight of an organisation’s IT or security team. It might be the use of a meeting note-taker, through browser tabs or a quick request on ChatGPT. IBM’s research found that shadow AI-linked incidents more than doubled, from 20% to 43% of AI-related breaches last year. This comes at a huge cost to businesses.

What is the difference between shadow AI and shadow IT?

Shadow IT is where an employee signs up for a file-sharing tool or creates a cloud account without telling anyone. It is risky but has been around for years and is fairly well understood.

Shadow AI involves a different and higher level of risk because an AI tool doesn’t just store your data, it processes it. If one of your team has shared a client contract or your pricing list with an AI tool, you will have no visibility as to where this information has gone, no audit trail and no contractual protection.

In addition, traditional security measures are unlikely to identify the moment a staff member copies client data into a chat window.

An escalating risk

AI agents don’t simply answer questions, they browse, execute code, send emails, call APIs etc. So, if your staff are using shadow AI, your business may not only be leaking sensitive data, the unapproved AI tool could also be accessing your systems.

The numbers you need to know

  • On average, it took companies 247 days to detect AI breaches, meaning organisations had more than eight months of unmonitored exposure.
  • 65% of shadow AI incidents compromised customer personal data and 40% exposed intellectual property.
  • 97% of organisations experiencing an AI breach lacked proper AI access controls, and 63% had no AI governance policy.

Is banning AI a realistic option?

Although it might be tempting to ban AI, in practice, this is likely to mean that AI usage simply moves onto personal devices and accounts, so organisational visibility becomes poorer, not better.

Your company aim should be to offer your team an approved AI tool or tools that work well, alongside clear AI governance.

AI governance guidelines

For most organisations, AI governance would include the following key essentials:

  1. An approved AI tools list. State which AI tools are permitted and ensure they are suitable for your business requirements.
  2. A short AI use policy. This should detail what company data can be input into an AI agent, what is strictly prohibited, and which outputs need human review before they reach a client.
  3. A named owner. Detail who is responsible if an AI-assisted process produces a wrong output.
  4. An AI register or risk log. Before you write any AI use policy, put together a list of what AI tools/agents are actually in use before writing any AI policies. You can’t govern what you can’t see.
  5. Staff awareness and training. Ensure your team are clear as to which AI tools are approved and what the AI Use Policy includes.
  6. Regular policy reviews. AI tooling is ever-changing so any policies/guidelines should be reviewed quarterly.

Finally

Don’t forget the importance of identity controls. Nearly 50% of AI usage is through personal accounts, so conditional access and SSO (Single Sign-On) matter as much as the policy itself.

How CloudTech24 can help

Shadow AI is familiar territory for CloudTech24. Our 24/7/365 in-house security team helps organisations discover unsanctioned tool usage, tighten access controls, apply data protection at the point sensitive information would reach an AI system, and build AI governance that people actually follow.
Get in touch for a no-obligation conversation, book a FREE discovery call.

Back to blog

Recent blogs from CT24

view of earth from space which shows some areas with lights on as it is night time

Shadow AI and AI governance: What UK businesses need to know

Shadow AI: the security risk your business can’t see The use of AI in the workplace has increased dramatically and not always through a company-approved rollout! Shadow AI refers to the use of AI tools or assistants at work without the knowledge, approval or oversight of an organisation’s IT or security team. It might be…

Read more

view of earth from space which shows some areas with lights on as it is night time

The steep rise in ‘ClickFix’ style phishing attacks  

What is ClickFix? ClickFix is a social engineering technique that the Security Operations team at CloudTech24 are seeing cybercriminals use to trick users into infecting their own devices. Typically, we find that a user is redirected to a fake verification page that impersonates a trusted service such as Cloudflare, Google reCAPTCHA, or a website security…

Read more

What is a virtual CISO (vCISO)?

Cybersecurity issues don’t pop up one at a time. They’re often frequent, urgent, and complex. When issues build up and the level of complexity increases to the point where your team needs an extra hand, having a vCISO can lighten the load. A vCISO (Virtual Chief Information Security Officer) is a security leader who serves…

Read more