The NCSC says you can't block every AI tool. It's right, and that changes what protection has to look like.
The NCSC says you can't block every AI tool. It's right, and that changes what protection has to look like.
On Monday the UK's National Cyber Security Centre published a blog on the hidden risks of shadow AI. One line in it deserves a slow read. The NCSC says shadow AI is unlikely to disappear and that organizations should aim to reduce the risk rather than assume it can be eliminated. Its CTO for architecture, David Chismon, went further in comments reported by Infosecurity Magazine, saying organizations can't hope to block connections to all possible AI tools.
That's a national security agency telling security leaders to stop chasing an allowlist they'll never finish. Most CISOs already knew it. Hearing it said out loud is useful, because it reframes the question. If you can't control where employees take your data, the protection has to travel with the data itself.
How widespread is shadow AI in the workplace?
The NCSC cites Microsoft research from a Censuswide survey of 2,003 UK employees. According to Microsoft, 71% had used consumer AI tools their employer hadn't approved and 51% still do so every week. Asked why, 41% said it's what they use in their personal life and 28% said their company doesn't provide a work-approved option.
Look at what people are doing with those tools. Microsoft found 49% used them to draft and respond to workplace communications, 40% to draft reports and presentations and 22% to carry out finance-related tasks. Those are the emails, decks and spreadsheets where sensitive data actually lives. Only 32% of respondents said they were concerned about the privacy of company or customer data they'd pasted in.
None of this is malicious. Someone has a deadline and a chatbot they trust. The NCSC's point is that the gap opens when security policy fails to meet a business need, so staff route around it. You've probably watched that happen in your own organization. You've probably also felt the awkward position it puts you in. Say no and become the blocker. Say yes and wonder which customer record just left through a browser tab.
Why can't security teams block their way out of shadow AI?
Blocking works on a fixed list of destinations. Shadow AI is the opposite of a fixed list. New assistants, plugins and browser extensions appear weekly. Each one is another URL to catalog and another rule for someone on your team to write and maintain.
Legacy DLP was designed for a world where data moved through predictable channels, so it protects by enumerating those channels. Every new AI tool is a channel it hasn't heard of yet. Meanwhile the rules it does have generate noise. At Infosecurity Europe in June, a Filigran survey of 168 security leaders found chasing false positives and low-priority alerts was the single largest drain on team time, named by 26% of respondents.
So the team is stretched in two directions. It's writing rules for tools it can't keep up with while clearing alerts from the rules it already has. Neither task protects the data. Both consume the people you'd rather have working on strategy.
What does autonomous data security do differently?
It starts from the data rather than the destination. If the system understands what a piece of information is and how it's being used, it doesn't need to know in advance which AI tool it's headed for.
This is where MIND sits. MIND classifies data by content and context, using multi-layer AI rather than regex alone. It recognizes a contract, a payroll report, a medical record or a block of source code for what it is. That recognition follows the data whether it's sitting in a SaaS folder or being pasted into a chat window.
Prevention then happens in real time, on the endpoint and in the browser. There's no network SSL inspection and no latency tax. When someone copies sensitive text from Slack and pastes it into a GenAI tool, MIND sees the action for what it is and can stop it before the data leaves.
“I was blown away by the fact that I could actually, in real time, stop someone from copying, pasting sensitive information from Slack into ChatGPT.”
Al Faiella
Senior Director of Security Engineering, ThoughtSpot
The response doesn't have to be a hard block. MIND's controls adapt to risk severity, so the everyday user gets a speed bump or a coaching message that explains what they were about to share, while a block is reserved for activity that's actually dangerous. That matches the NCSC's own advice to build a positive security culture and set clear guardrails around what safe AI use looks like. People learn in the moment. The team stops being the department of no.
How does it run without adding headcount?
The part that makes this autonomous rather than merely automated is what happens behind the policy. MIND's AI DLP Agents build the custom classifiers your team would otherwise construct by hand, writes and refines policies from observed behavior and plain-language instructions, summarizes each incident so an analyst can act on it in minutes and takes remediation action where it's allowed to.
The effect shows up in the queue. OpenWeb reports spending 80% less effort managing its DLP program than before. Guild's VP of Information Security, Julie Chickillo, described the value in staffing terms.
“I didn't need to hire three to four people just to manage MIND.”
Julie Chickillo
VP of Information Security, Guild
Matching patterns against a blocklist was never the job. The job is minding what your data is and where it's going, so your people can use the AI tools they've already chosen without you having to guess which one they'll pick next.
What should you do this week?
The NCSC's advice is to reduce the risk rather than pretend it can be removed. Start by finding out how much of your sensitive data is already reaching AI tools, then put a control in place that reasons about content instead of counting destinations.
MIND connects to your SaaS and deploys to endpoints in minutes, with insights the same day. Book a demo and watch a paste into a GenAI tool get caught in real time, in your environment. That's DLP at AI Speed.











