Every AI tool is a way in

Chris Duffy, Managing Director and Chief AI Officer, IgniteAI Solutions

Staff adopted AI before most small firms wrote a rule about it. Chris Duffy on why shadow AI, agents and poisoned documents belong on the threat register, and why governance is the control that makes adoption safe.
In signals, one of the first habits drilled into you is that every device on the net is a way in. A radio that was never logged, a laptop that joined the network because it was quicker than asking: each one is a gap in the picture you are defending. I carried that habit through 23 years in the British Army, and it’s the lens I bring to AI in smaller businesses, because most of them have plenty of devices on the net that were never logged.
The adoption already happened
The UK’s National Cyber Security Centre put this in writing on 7 September 2026, in a blog post titled “The hidden risks of shadow AI”. Its explanation is the sentence every board should read: where security policy can’t meet the business need, employees will adopt AI services before the organisation has had time to assess them and offer an approved alternative.
The figure NCSC cites comes from Microsoft-commissioned Censuswide research of 2,003 UK employees in October 2025. 71% said they had used unapproved consumer AI tools at work, 51% said they still did so every week, and only 32% said they were concerned about the privacy of the company or customer data they were putting in. That survey is nearly a year old, so treat those numbers as a floor.
On the ground it looks ordinary. Someone pastes a client contract into a free chatbot for a summary before a meeting, or uploads a spreadsheet of customer names to tidy the formatting. None of them think of it as a security event, because from where they sit it’s just getting the job done faster.
Three threats, in rising order of seriousness
The first is exposure. Data sent to a consumer service may be retained or used to improve it, outside anything you control, and NCSC names that loss of visibility as one of its three risks. UK GDPR applies in full to any AI system that touches personal data, so the business stays accountable for that customer spreadsheet whichever tool it went into.
The second is agents. The tools have moved on from answering questions to doing things: reading an inbox, opening shared drives, sending on someone’s behalf. That’s where most of the productivity sits, and where the risk changes shape. NCSC’s own wording is plain: if an attacker successfully exploits a vulnerability, they can gain access to the same data, services and privileges the agent has legitimate access to. An agent connected to the managing director’s inbox holds the managing director’s inbox. Give a tool that access without anyone deciding it should have it, and you have issued a set of keys you never logged.
The third is prompt injection, and it’s the one that takes the most explaining to a board. OWASP ranks prompt injection first in its 2025 Top 10 for large language model applications, and the variant that matters most here is the indirect one: instructions hidden inside content the model reads, such as a web page, an attached document or an email. A supplier invoice can carry text a person is unlikely to notice, telling an assistant to forward last month’s correspondence somewhere else. If the assistant has the permissions to act, it can act.
Put the two together and an agent with inbox access, reading email from outside the business, is an open channel between your data and anyone who can send you a message.
I sat with the senior team of a UK equipment business who wanted exactly this: an assistant to triage the directors’ email, because that’s where their day goes. In the same meeting they asked what happens if someone emails it instructions, and they were already worried about customer details ending up on personal WhatsApp accounts. They were right on both counts.
Why banning it fails
The instinct in most boardrooms is to block the tools. In my experience that makes things worse, because the need is still there and people go round the block on personal phones and home accounts, where you have even less sight of it. NCSC reaches the same place: it says the goal is to reduce the risk rather than assume it can be eliminated, and that it is not recommending individuals stop using AI.
I’d go a step further. Shadow AI is the most useful diagnostic a small business owns. If people are smuggling tools in, that’s where the pain is. Every unapproved tool is somebody showing you which part of their job is too slow, and most firms throw that intelligence away by treating it purely as a discipline problem.
Governance as the control
So the control I’d put in place is governance, written down and short enough that people read it. For a firm without a security team, it comes down to four things.
Find out what’s already in use, in a way that gets no one into trouble. An amnesty works better than an audit, because you need honest answers more than names. At an environmental consultancy I’m working with, that’s the first workstream: a shadow AI amnesty across the team, an approved tools list, and file permissions mapped before Copilot goes near them, so it can only see what each person could already see.
Decide what data can never go near a public AI tool, and say it in plain English: client contracts, personal data, pricing, anything under a non-disclosure agreement. One page people remember beats forty they don’t.
Give people an approved tool for the jobs they’re doing with free ones, on business terms covering data retention and training, so the fast route and the safe route become the same.
Treat every agent like a new starter. Grant it the least access that does the job, record what it’s connected to, and assume anything it reads from outside could be carrying instructions, so a person approves anything that leaves the building, whether that’s an email, a payment or a file.
That record is already a legal requirement in one Gulf jurisdiction. In September 2023 the Dubai International Financial Centre added Regulation 10 to its data protection rules, covering personal data processed by autonomous and semi-autonomous systems, AI included. It requires a register of AI processing activities and creates an Autonomous Systems Officer, a role much like a data protection officer, and DIFC describes it as the first regulation of its kind in the region. It’s a useful template wherever you trade.
All of that fits a small firm’s budget. What it needs is an owner, and a board willing to approve the safe route quickly enough that people stop reaching for the other one.
The gate
The businesses I see moving fastest with AI are the ones that did this work first, because once the rules exist, the answer to “can I use this?” comes back quickly, and it’s usually yes. Governance is the gate that removes the barriers to adoption.
Chris Duffy is Managing Director and Chief AI Officer of IgniteAI Solutions. He served 23 years in the British Army, including in signals, led a significant defence AI programme, holds SC clearance, and works with UK and Gulf SMEs on AI adoption and governance.
Sources
1. National Cyber Security Centre, “The hidden risks of shadow AI”, Simon B, Senior Cloud Researcher, 7 September 2026. https://www.ncsc.gov.uk/blogs/the-hidden-risks-of-shadow-ai
2. Microsoft UK Stories, “Rise in ‘Shadow AI’ tools raising security concerns for UK”, 13 October 2025. Research conducted by Censuswide in October 2025 among 2,003 UK employees aged 18 and over. https://ukstories.microsoft.com/features/rise-in-shadow-ai-tools-raising-security-concerns-for-uk/
3. OWASP GenAI Security Project, “LLM01:2025 Prompt Injection”, OWASP Top 10 for LLM Applications 2025. https://genai.owasp.org/llmrisk/llm01-prompt-injection/
4. Information Commissioner’s Office, “Guidance on AI and data protection”. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/
5. Dubai International Financial Centre, “DIFC enacts amended data protection regulations”, 7 September 2023. https://www.difc.com/whats-on/news/difc-enacts-amended-data-protection-regulations
6. Dubai International Financial Centre, “Regulation 10 on Personal Data Processed Through Autonomous and Semi-Autonomous Systems”, guidance, 27 August 2024. https://assets.difc.com/v1/media/edge/images/dubaiintern0078-difcexperie96c5-production-3253/media/project/difcexperiences/difc/difcwebsite/documents/registrars-and-commissioners/guidance-and-handbooks/lawful-processing/dp_regulation_10.pdf

Hot Topics

Related Articles