Regulation

AI-generated text

UK NCSC: firms must set clear rules, technical limits and leadership on workplace AI use

The UK National Cyber Security Centre (NCSC) warned in a September 2026 post that workplace adoption of AI has outpaced many companies' internal policies, creating data protection and operational risks.

UK NCSC: firms must set clear rules, technical limits and leadership on workplace AI use

In a professional post published in September 2026, the UK National Cyber Security Centre (NCSC) warned that workplace adoption of artificial intelligence (AI) has in many places outpaced internal company policies and procedures. The NCSC says secure use requires clear rules, appropriate technical safeguards and executive decisions.

Task and data determine risk

The NCSC emphasizes that different tasks carry different risks: rephrasing a public product description is not equivalent to analysing a customer contract or automatically modifying data in a business system. Companies therefore need to define which tasks may be performed with AI, what types of data may be used, and what level of privileges are allowed. Developing these definitions requires collaboration between IT, business units, data protection specialists and leadership.

Senior management must appoint responsible parties, provide the resources needed for protection, and decide which risks are acceptable.

Corporate data sent to external AI providers: shadow AI and data-handling concerns

The NCSC notes that employees often use external AI applications outside approved corporate systems — commonly called shadow AI. Using an external service is not automatically a data leak, but risks arise if confidential information is sent without approval or under inadequate data-handling and access terms.

Organisations should clarify in advance what data a service retains, how long it stores data, what purposes it may use submitted information for, and who can access it. Contractual terms and subscription details must be checked for each specific service; the fact that an application is paid-for does not guarantee it meets a company’s security requirements.

Privileges, prompt injection and related risks

A further risk is that an AI may follow deceptive instructions embedded in a processed document or web page instead of the user’s explicit request. Such techniques, for example hidden directives in an offer that bias comparisons, are called indirect prompt injection attacks.

Consequences can be severe if the AI has access to other corporate systems and can perform operations in them. The Open Web Application Security Project (OWASP) recommends applying least-privilege access and requiring human approval for risky operations. For instance, an assistant that prepares email drafts need not have permission to send messages autonomously.

These measures can reduce the impact of an attack but do not by themselves eliminate prompt injection risk.

AI can help both attacks and defences

The NCSC also warns that generative AI can speed up creation of deceptive messages, so detecting phishing is no longer reliably based on grammar or spelling errors alone. For example, when a partner requests payments to a new bank account, it is advisable to verify the change using the partner’s previously known contact details.

At the same time, AI can assist defenders: it can support vulnerability discovery (which can serve both attackers and defenders), analyse log data, triage alerts and prepare investigations. The NCSC cautions that machine analysis can be wrong, so results require appropriate professional review.

Recommended first steps

A safer approach begins with an inventory of which AI applications employees use, for what tasks, and what data or corporate systems those applications can access. Based on this inventory, organisations should build internal rules and workflows that are practicable in daily operations.

A usable guidance document should clearly state, for example:

  • which applications are approved;
  • what data may be uploaded to external services;
  • who approves new solutions;
  • which operations require human oversight;
  • whom to notify in case of inadvertent uploads or suspicious behaviour.

The NCSC also recommends training tied to employees’ everyday tasks (such as contract summarisation or drafting client emails), implementing appropriate permission settings, technical restrictions and enforceable internal procedures.

Unapproved tool usage often stems from missing functionality in approved tools or burdensome approval processes; therefore organisations should provide practical, approved alternatives for daily work.

Advisory and testing services

The article notes that ProMan Consulting’s experts provide AI information-security consulting, supporting organisations from inventorying AI tools and assessing their risks to designing data handling, access and operational rules. The firm’s information-security consulting and vulnerability assessments help identify technical and process weaknesses.

Overall, the NCSC’s position is that safe workplace use of AI requires considered governance, technical controls and executive commitment, with particular attention to data usage and application privileges.