Shadow AI: NCSC Warns UK Firms as Nine-in-Ten Report Unapproved Tool Use
New data from Turbotic and a fresh NCSC alert confirm that ungoverned AI use has become the default in UK workplaces - not the exception. For consulting and business services firms handling client data, the liability question is no longer theoretical.

The numbers landed within hours of each other on 9 September, and they tell the same uncomfortable story. A Turbotic survey of more than 1,000 UK senior decision-makers found that 88% believe unapproved AI tools are already running inside their organisations, with over half (51%) specifically afraid that staff are feeding sensitive company data into those tools. The same morning, IT Security Guru reported that the NCSC had weighed in directly, citing Microsoft research showing 71% of UK employees have used AI tools their employer has not approved.
For professional and business services firms, the sector where client confidentiality is quite literally the product, this is a utilisation problem dressed up as a technology story.
The Spread Is Not What Anyone Expected
The Turbotic data, published on Consultancy.uk, identifies IT departments as the worst offenders for unauthorised AI use at 36%. That is the department nominally responsible for controlling this. Customer service follows at 30%, then marketing at 28% and sales at 27%. As ResultSense noted in its analysis of the findings, that spread suggests the behaviour tracks wherever there is repetitive drafting and lookup work, which in a consulting or agency context means practically everywhere.
The compliance exposure stacks up accordingly. Among the senior AI decision-makers surveyed, 38% cite regulatory or compliance breaches as a primary concern, 36% flag AI being used with no management oversight whatsoever, and 35% worry about unreliable AI-generated outputs influencing business decisions. These are not junior employees experimenting; these are the people signing off AI budgets.
The most revealing figure is smaller. More than a quarter of those same respondents, people with direct responsibility for AI deployment, had never encountered the term "shadow AI" before the survey asked them about it. Awareness is trailing the practice inside the very group meant to be governing it.
What the NCSC Is Actually Saying
The NCSC's intervention, reported by IT Security Guru on 9 September, frames the problem as one of alternatives rather than prohibition. The agency's position is that simply banning AI is unlikely to solve the problem, and that businesses need to provide secure, approved alternatives, with clear policies, employee education and appropriate technical controls developing at the same pace as AI adoption. The NCSC also flagged that the challenge is particularly acute for SMEs without large in-house security teams, pointing to managed service providers as a practical route to identifying unapproved technology and establishing appropriate controls.
That creates a specific commercial opening. Governance consulting, AI policy design, and AI acceptable-use frameworks are all Class 35 business services, the very category showing strain in the UK trademark register right now. According to AIBD analysis of IPO (TMD) data, as of September 2026, Class 35 UK trademark filings reached 8,631 in Q3 2026, down 19.9% on the prior period. That contraction in new brand registrations in the business services class may partly reflect founders deferring formal branding until their governance proposition is clearer: the market is moving faster than the paperwork.
Pilots Are Already in Production. Governance Isn't.
Turbotic's research highlights a particular tension: 64% of UK businesses confirmed that most or all of their AI pilot projects had already progressed into day-to-day operations. The tools left the lab before the rulebook was written. SAP and Oxford Economics research from February 2026 put the proportion of UK businesses with employees regularly using unapproved AI at 68%, while only 7% of UK businesses have an enterprise-wide AI strategy in place.
So the pilots scaled. The governance didn't.
For consultancies selling AI transformation programmes, this is a genuine wedge. The British Chambers of Commerce finding, that only 10% of UK firms using AI rely on bespoke or proprietary systems, with the vast majority on off-the-shelf, generic tools, means the surface area for data leakage is enormous and almost entirely unmonitored. Only 29% of companies regularly audit AI usage across teams, and just 36% have formal AI governance frameworks.
Theodore Bergqvist, CEO and co-founder of Turbotic, put it plainly: organisations need to treat visibility, governance and trust as part of deployment, not something bolted on afterwards, and that responsibility sits with leadership rather than staff.
The Consulting Play
MCA projections have the UK consulting sector growing at 5.7% in 2026, driven primarily by AI strategy, implementation, and governance mandates. Shadow AI governance is one of the few areas where mid-market advisory firms can compete with the Big Four on pure speed. A three-week AI policy sprint requires no global alliance structure, just someone who has actually read the NCSC guidance and can translate it into an acceptable-use policy a line manager will follow.
The sector most exposed to shadow AI data leaks, professional services, where client information is the core raw material, is also the sector best positioned to sell the fix. The firms that move first on their own internal governance will have a credible case study before the end of the financial year. Those that don't will eventually feature in someone else's pitch deck as a cautionary tale.