On September 7, 2026, the National Cyber Security Centre (NCSC), the UK agency responsible for cybersecurity, issued a warning about 'shadow AI', or hidden AI. The term refers to the use of artificial intelligence (AI) tools not approved by the organization.
The stakes go beyond IT: an employee can paste a contract, a human resources (HR) file, a financial report, or customer data into an external tool without any official trace. For internal audit, compliance, data protection, and the ISO/IEC 27001 standard, the risk becomes very concrete. In Libreville, an HR manager or a management controller may already be concerned.
Recent articles
Copyright: Washington supports OpenAI, open risk
Google brings YouTube closer to messaging: opportunity and risk
How to use artificial intelligence in finance?
Certificate
Professional Certificate in Digitalization and Digital Tools for SMEs — Digitalization of SMEs
What is it, concretely?
Shadow AI is the digital equivalent of a critical file circulating outside of procedure. Work progresses, sometimes faster, but the organization no longer knows where the information is going. Previously, 'shadow IT' mainly concerned software, storage accounts, or applications used without authorization. With AI, the risk changes scale: the tool can summarize, analyze, rephrase, or retain sensitive elements according to its own usage conditions.
The NCSC does not present a technical test or the launch of a product. It publishes a cybersecurity alert and recommends not to assume that these uses will disappear. Its position is pragmatic: understand needs, provide visibility, propose approved solutions, and develop a positive security culture. The figure of 71%, as well as the 51% of British employees who would use these tools weekly, comes from a Microsoft publication. This is data published by a technology company, not an independent regulatory statistic.
Concrete case: what to do and what not to do
Questions to Ask Before Acting
- When employees are already using AI without official validation, who bears operational and legal responsibility in our organization?
- What does this alert change for internal audit, compliance, and data governance?
- Do we have an inventory of AI tools used by teams, including personal accounts and browser extensions?
- What categories of data are prohibited in unapproved AI tools: clients, HR, health, payroll, contracts, trade secrets?
- Is there a quick procedure to request authorization for a new AI tool?
- Are AI vendors evaluated as subcontractors or critical service providers?
- Can internal audit provide evidence: AI policy, register, training, validations, incidents, and action plans?

