What 2026’s UK cyber incidents can teach us about shadow AI

Discover what major UK cyber incidents in 2026 reveal about shadow AI risks, from data exposure and access controls to AI governance and secure adoption.

Earlier this year, we considered how AI can expose weaknesses already inside an organisation.

Unapproved or uncontrolled AI didn’t cause the cyber incidents reported across the UK in 2026. But they exposed many of the same problems, including poor control over data, unclear responsibilities, and a lack of visibility across organisations.

These are exactly the kinds of issues that unmanaged AI use can make more obvious, and potentially more serious.

Manchester Airports Group (MAG)

In August, MAG confirmed that attackers had accessed data linked to around 8.7 million customers across Manchester, London Stansted, and East Midlands airports.

That included email addresses, phone numbers, vehicle registrations, and postcodes.

Department for Education (DfE)

DfE also confirmed a security incident affecting its Customer Help Portal and Turing Scheme portal, with around 607,000 records reported stolen.

Companies House

In March, Companies House took WebFiling offline after finding that an authenticated user could potentially access or change parts of another company’s record by following a specific sequence of actions.

The issue had been introduced during an earlier system update.

The NHS

We’re still seeing the fallout from older incidents too.

NHS organisations continued to uncover patient records affected by the 2024 Synnovis ransomware attack, including disclosures involving patients at Bedfordshire Hospitals and Mid and South Essex NHS Foundation Trusts.

So, what’s the link?

The incidents all involve the things security teams deal with every day: data, identities, applications, access, and third parties.

That’s also where shadow AI can create problems. It can make existing weaknesses easier to find, exploit, or overlook.

AI threats from both sides

Businesses are connecting AI to everyday work, while attackers are using it for things like reconnaissance, social engineering, vulnerability research, and analysing stolen data.

Security teams already need to know where sensitive information lives, who can access it, which third parties handle it, and what happens when that access goes wrong.

Shadow AI can make that harder by introducing new applications, data flows, and permissions that sit outside the usual controls.

Agents take things a step further because they can be permitted to act.

Instead of someone manually uploading a file, an AI agent could potentially read emails, search documents, or interact with business applications on their behalf.

Knowing an AI tool exists isn’t enough. Security teams also need to understand which identity it uses, what permissions it has, and what information it can access.

The National Cyber Security Centre (NCSC) found that 71% of employees had used AI tools their employer had not approved.

That means some AI activity could be happening outside the logging, data controls, contractual safeguards, and identity governance organisations expect to have in place

How AI could change cyber incidents

MAG + AI

Let's take Manchester Airports Group. The incident involved customer data linked to parking, lounge, and fast-track bookings, as well as airport Wi-Fi registrations.

That’s the kind of data employees might use in everyday AI tools.

  • Customer service might use AI to sort enquiries.

  • Marketing might use AI to organise customer data.

  • An AI browser extension could access data shown in support systems.

Each case raises questions about where that data is stored, how long it’s kept, and who else may have access to it.

DfE + AI

The DfE incident highlights a different risk. Names, job titles, email addresses, and phone numbers collected at scale can all be exploited for phishing, impersonation, and reconnaissance.

The NCSC says attackers are already using AI to analyse stolen data and improve social engineering. So, security teams need to consider how quickly an attacker could use AI to turn information into a weapon.

Blocking AI doesn’t remove the need

People use AI to work through documents, analyse information, and write code. If the approved tool can’t do the job, they may turn to personal accounts, phones, or home computers instead.

If employees are using AI to summarise meetings, for example, that shows there’s a need for the capability. Removing the tool without offering a safe alternative is likely to push the same workflow elsewhere.

Security decisions should focus on the task and the data involved. Define what can be processed safely, provide an approved route where possible, and apply tighter controls when the information or access requires them.

Approved AI can still create risk

AI can still create challenges if access is broader than it needs to be.

If someone still has permissions from an old role, project, or temporary exception, an AI assistant working on their behalf may be able to use those permissions too.

That’s why securing AI involves reviewing identities, devices, data, permissions, and access to important systems.

Here are a few key questions to get you started:

  1. Who or what is carrying out the activity, and which identity is being used?

  2. What information is being accessed, and how sensitive is it?

  3. Is the data being uploaded directly, or accessed through a connector, plug-in, API, or agent?

  4. Can the AI only read information, or can it also create, change, send, or delete something?

  5. Is there enough logging to understand what happened afterwards?

Focus on the cases where AI changes what can access information, how quickly that information can be processed, and what can happen to it afterwards.

Are you ready to use AI securely?

The cyber incidents reported across the UK in 2026 show what can happen when data, access and connected systems aren’t properly understood or controlled.

What they can’t tell you is where similar risks may exist in your own organisation. Our Secure AI Readiness Assessment will provide that evidence.

It covers everything from data oversharing and agent governance, through to threat monitoring and wider information governance.

We’ll help you understand where AI could increase your existing exposure, what needs attention first and where adoption can move ahead safely.

Throughout Cyber Security Month this October, we’ll be exploring secure AI adoption in more detail.

Stay tuned

Meet our authors

Written by

Nasstar

Content Team

The Nasstar content team is a group of passionate technology writers, industry experts, and digital strategists.

Reviewed by

Justin Barker

Head of Modern Work & Cyber Security

Justin Barker joined Nasstar in 2024, bringing with him over 25 years of experience across the IT, cloud, and cyber security sectors.

What cyber incidents can teach us about shadow AI | Nasstar