Press "Enter" to skip to content

Critical Blind Spots for UK Organisations as Two Thirds Don’t Know What’s Being Shared with AI 

  • 67% of UK organisations unable to account for whether staff are sharing information through secure AI platforms, raising risk of sensitive data exposure 
  • This is despite 82% investing in additional staff or skills to manage AI and data 
  • A further 35% admit to data sharing through external tools, amplifying risk without proper visibility 

New research from SailPoint reveals the scale of risky data sharing practices in UK organisations as AI adoption accelerates. More than two thirds (67%) of UK organisations can’t account for whether staff are sharing information through their own secure AI platforms or gated large language models, highlighting critical blind spots which increase security risk.

The study of UK IT decision-makers points to a growing challenge for enterprises as employees increasingly turn to AI platforms like ChatGPT, Claude, Gemini, and others to enhance productivity. When used outside approved channels – often referred to as Shadow AI – employees may unknowingly upload confidential documents or sensitive data into unapproved models, raising the risk of exposure and weakening governance controls.

This is happening despite significant investment in AI and data management. More than four in five organisations (82%) say they have invested in additional staff or skills to manage AI and data, and 41% have hired dedicated AI or analytics management roles. Yet, nearly half (45%) of IT decision-makers say they still need more visibility into where information is being shared and how.

The need for oversight is becoming more urgent as autonomous technologies are rolled out across businesses. Four in five organisations (80%) report their AI agents have performed unintended actions, such as accessing or sharing inappropriate data. With more than one in ten (12%) UK companies adding as many as 10,000 AI agents and machine identities each month, security teams risk being overwhelmed without the right tools and processes in place.

SailPoint notes that real-time, automated insights into how tools are being used – such as monitoring document uploads and interaction frequency – can help organisations identify high-risk behaviour and bring AI usage back under control.

Blind spots also extend beyond AI. A third (35%) of UK organisations report employees sharing files via third-party, often unsanctioned, collaboration tools, further increasing security and compliance risk.

Mark McClain, CEO and Founder at SailPoint, commented:

“AI tools can enhance productivity, but they also create serious risk when they operate outside an organisation’s visibility and governance. When sensitive information is entered into unapproved models, it can be exposed, mishandled, or even amplified through errors and hallucinations. As use of AI systems becomes more widespread, the situation is only going to get more out of control if organisations fail to put the right guardrails in place – compounded by other tools flying under the radar.

“Organisations need to stop workarounds and regain control. That takes a combination of skills and awareness, but it also fundamentally boils down to a challenge around identity. Organisations need a real-time view of who, or what, is accessing what data, from which devices, and where it’s being shared. Technology can provide that critical context, giving organisations visibility to close security gaps and strengthen compliance. This means businesses can be confident that tools designed to boost productivity won’t set them back by introducing unnecessary risk.”

This research was conducted by Censuswide in January 2026, on behalf of SailPoint. 333 IT decision makers from the UK were surveyed from large organisations (7,500 employees or more in size) – and across multiple sectors.   

Please follow and like us:

Author

Be First to Comment

Leave a Reply

Technology Reseller Magazine & Site is Published by Kingswood Media 2024