Skip to main content

The Ghost AI Problem: The Hidden Security Risk Lurking in UK Businesses

How many AI tools currently have access to your business data?

For most organisations, that’s becoming an increasingly difficult question to answer.

As businesses adopt AI assistants, automations and integrations at pace, attention is often focused on the risks of the technology itself. But for cybersecurity experts, a more immediate challenge is emerging: organisations losing track of the AI tools they’ve already deployed.

Projects end. Employees leave. Teams change.

But the integrations remain.

According to Bradley Collis, Cybersecurity Solutions Architect at Planet IT, part of TalkTalk Business, it’s not unusual to find AI tools still connected to business systems long after they’ve stopped being actively managed.

“The employee who set it up may have left months ago, but the tool is still quietly accessing business data.”

This is what we might call the Ghost AI problem: AI tools, agents and automations that continue accessing company systems long after they’ve been implemented, often without a clear owner, review process or ongoing oversight.

Businesses Are Worried About AI. But Are They Worried About the Right Things?#

Search behaviour suggests organisations are increasingly trying to understand the risks associated with AI adoption:

  • Searches for “Shadow AI” have increased 85% year on year

  • Searches for “What is Shadow AI?” have increased 191%

  • Searches for “Shadow AI meaning” have increased 1,000%

  • Searches for “AI governance” have increased 48% year on year

  • Searches for “AI governance certification” have increased 85% year on year

Source: UK Google search volume data, September 2025 to August 2026.

That growing interest reflects a challenge many organisations are already facing. According to Bradley:

“

“AI is now built into everyday business applications like Microsoft 365 Copilot, CRMs, and customer service platforms. But the bigger challenge is Shadow AI: employees using public AI tools or unapproved apps without IT oversight. Sensitive data like customer records, contracts, and financial documents are being pasted into these systems.”

Bradley Collis

Bradley Collis

Security Solutions Architect, Planet IT

Company logo

As adoption accelerates, governance is struggling to keep pace. The growth in searches for “AI governance certification” suggests organisations aren’t just becoming more aware of the risks. They’re also looking for ways to formalise their response.

Search interest in AI safety also spiked sharply in February 2026, driven by a wave of AI-related news, including new legislation, government action and the publication of the International AI Safety Report.

But much of that attention focused on consumer-facing risks such as deepfakes, chatbot safety and online harm.

The Ghost AI problem wasn’t part of that conversation.

While public attention was focused on AI’s most visible risks, a quieter governance challenge was sitting inside businesses: forgotten AI tools with standing access to company systems and data.

But there’s an important distinction.

The search data suggests businesses are becoming more aware of Shadow AI.

Bradley is increasingly concerned about Ghost AI.

Shadow AI vs Ghost AI#

The two terms sound similar, but they describe different problems.

Shadow AI is AI that enters the business without approval.

Ghost AI is AI that stays in the business without ownership.

A tool may have been legitimately approved and deployed months ago. The project ends, the employee leaves and the business moves on, but the integration remains.

Often, nobody is checking what it can access or whether it should still be there.

The Permission Problem#

When evaluating AI tools, many organisations focus on whether they trust the provider.

According to Bradley, a more important question is often overlooked:

What permissions does the tool actually have?

“Businesses focus on whether they trust the AI brand, but overlook what permissions the tool has once connected. A simple automation tool is often given permission to read every mailbox, access the entire CRM, or modify financial records simply because administrator access was easier to configure.”

Many AI tools end up with significantly more access than they need.

“That creates massive exposure from one compromised token or rogue instruction. An AI agent should only ever have the exact, minimum access needed for its specific task.”

The issue isn’t simply whether a business trusts the software. It’s whether the software has been given unnecessary access to sensitive systems and data.

The Hidden Risk Already Inside Your Business#

The biggest risk often emerges long after deployment.

Businesses roll out new tools to automate processes, improve productivity or connect systems. Over time, ownership becomes unclear.

Employees leave.

Projects end.

Teams change.

But the integrations remain.

“

“We frequently find abandoned AI integrations and automations connected to mailboxes and CRMs via long-lasting access tokens with no named owner, no review date, and no revocation process.”

Bradley Collis

Bradley Collis

Security Solutions Architect, Planet IT

Company logo

In many cases, organisations don’t realise these connections still exist.

“The employee who set it up may have left months ago, but the tool is still quietly accessing business data.”

These forgotten systems can continue accessing inboxes, customer records, documents and critical business platforms long after they’ve stopped providing value.

“The biggest threat to SMEs usually isn’t a complex nation-state attack. It’s a forgotten, unmonitored tool with excessive permissions.”

Ultimately, Ghost AI is a visibility problem. Businesses cannot secure systems they don’t know they have.

AI Doesn’t Remove Governance Problems. It Amplifies Them#

Many organisations are starting their AI journey through trusted platforms such as Microsoft 365 Copilot.

While this provides significant governance advantages, it doesn’t remove the need for strong controls.

“For businesses already using Microsoft 365, we recommend keeping trials within that managed ecosystem using Copilot or Copilot Studio. This leverages existing identity controls, MFA, and data loss prevention via Microsoft Entra and Purview.”

However, underlying permissions remain critical.

“Copilot still respects existing file permissions. If your internal SharePoint or Teams permissions are poorly managed, Copilot will expose that data to the wrong people. A permission review and a named human supervisor are essential before launching any trial.”

AI often amplifies existing governance problems rather than creating entirely new ones.

The Ghost AI Checklist#

Ask yourself:

  • Do you know every AI tool being used across the organisation?

  • Does every AI tool have a named owner?

  • Are permissions reviewed regularly?

  • Are former employees’ integrations and access tokens removed?

  • Can you identify every AI tool connected to your email, CRM or document systems?

  • Have any AI automations been left running without an active owner?

  • Have SharePoint, Teams and CRM permissions been reviewed before deploying AI assistants?

  • Do you have an AI governance policy in place?

If the answer to any of these questions is no, your business may have a Ghost AI problem.

The Bottom Line#

In February 2026, AI safety dominated headlines. New laws, government intervention and a landmark global report all landed within weeks of each other.

Businesses and the public paid close attention.

But almost none of that conversation was about the risks inside their own organisations.

The focus was on chatbots, deepfakes and consumer harm. Meanwhile, inside businesses, a quieter risk continued unnoticed: forgotten AI tools with standing access to inboxes, CRMs and company data, often with no owner, no review process and no one watching.

The rise in Shadow AI searches suggests businesses are becoming more aware of the risks associated with unapproved AI use. That’s a positive step.

But awareness of the visible risks isn’t the same as visibility over the risks already inside the business.

Ghost AI isn’t a futuristic threat. It’s a present-day governance challenge that many organisations may already be facing without realising it.

The businesses that get ahead of it won’t be the ones waiting for the next news cycle. They’ll be the ones asking a far simpler question today:

What AI tools do we actually have, who owns them, and what can they access?

Because as AI adoption accelerates, it’s often not the tools making headlines that pose the greatest risk.

It’s the ones nobody has checked on in months.

TalkTalk Business offers a dedicated Security Readiness Audit to help SMEs identify and secure these AI blind spots before they lead to a breach.

Article footer image