HomeinterviewsKnowBe4 Study: Shadow AI and Employee Pressure Emerge as Top Cyber Risks...

KnowBe4 Study: Shadow AI and Employee Pressure Emerge as Top Cyber Risks for UK Businesses

Artificial intelligence is reshaping workplace productivity, but it’s also creating new cybersecurity headaches. According to new UK research from KnowBe4, organizations are increasingly concerned that employees are using unauthorized AI tools, sharing sensitive information with generative AI platforms, and making security mistakes under pressure.

The company’s latest report, “From Agentic Risk to Human Wins,” surveyed 80 cybersecurity decision-makers and 300 employees across UK organizations with at least 250 employees. The findings reveal a widening gap between AI adoption and cybersecurity readiness, with both human behavior and emerging AI risks contributing to a rapidly evolving threat landscape.

Perhaps the biggest takeaway: 58% of UK decision-makers identify employees using unapproved software and AI tools as their top human-related cyber risk, while 55% of employees admit to using unapproved applications. Even more concerning, one in ten employees knowingly entered sensitive information into AI tools despite understanding the associated risks.

The findings suggest that shadow AI—the use of AI applications outside approved corporate policies—is quickly becoming as significant a security concern as shadow IT has been over the past decade.

Shadow AI Is Moving Into the Mainstream

Organizations have spent years trying to control unauthorized software installations and cloud applications. Now, generative AI is creating a new version of that challenge.

Employees are increasingly turning to public AI assistants to summarize documents, draft emails, analyze data, and improve productivity. However, when those tools are used outside approved governance frameworks, they can expose confidential business information, intellectual property, customer data, and regulated content.

KnowBe4’s research indicates many organizations recognize the risk but are still struggling to manage it effectively.

Nearly half (49%) of cybersecurity decision-makers identified the safe use of AI tools and AI agents as one of their top organizational concerns. Meanwhile, 46% said their organizations have established objectives for improving AI governance over the next year.

Despite those ambitions, only 16% believe their organizations are currently effective at managing the safe use of AI tools and autonomous AI agents.

That disconnect highlights a familiar challenge: AI adoption is moving faster than organizational policies, employee education, and security controls.

Confidence Gap Persists Between Leaders and Employees

The study also uncovered a notable perception gap between cybersecurity leaders and employees.

Decision-makers generally believe employees are better prepared to recognize cyber threats than employees believe themselves.

The difference is particularly visible when it comes to deepfake attacks.

  • 81% of decision-makers believe employees can identify deepfake video or audio impersonation.
  • Only 66% of employees feel confident they could detect one.

Phishing remains the area where confidence is strongest.

Almost all decision-makers (98%) believe employees can recognize phishing emails, while 95% of employees agree they have that capability.

That high confidence likely reflects years of sustained phishing awareness training across organizations, where phishing reporting rates remain one of the most commonly tracked security metrics.

Employees Still See Traditional Threats as the Biggest Risk

While executives increasingly focus on AI governance, employees remain more concerned about familiar cyber threats.

Among employees surveyed:

  • 56% identified phishing or impersonation emails as the biggest human-related cybersecurity risk.

Cybersecurity leaders ranked risks differently:

  • 46% cited employees sharing sensitive information with AI platforms.
  • 43% pointed to AI agents acting autonomously without sufficient human oversight.
  • 40% ranked phishing as a primary concern.

The contrasting perspectives illustrate how cybersecurity priorities are shifting.

Traditional attacks such as phishing continue to dominate employees’ day-to-day experiences, while leadership teams are increasingly preparing for the governance challenges introduced by AI-powered systems.

Pressure and Fatigue Increase Human Error

Technology is only part of the equation.

The report also identifies workload and employee stress as significant contributors to cybersecurity risk.

Among decision-makers:

  • 38% believe heavy workloads and time pressure will contribute to employee security mistakes during the coming year.

Employees largely agree.

Nearly 47% admitted that deadlines, multitasking, or distraction can cause them to make security mistakes even when they know the correct course of action.

Meanwhile, 93% of cybersecurity leaders believe employees generally understand safe security practices but may behave differently under pressure.

The findings reinforce a growing industry consensus that cybersecurity failures often result less from knowledge gaps than from behavioral and workplace pressures.

As organizations encourage greater AI adoption to improve productivity, balancing efficiency with security awareness may become an increasingly important leadership challenge.

Regulation Is Driving Stronger AI Governance

The research also highlights the growing influence of regulation on cybersecurity strategy.

According to the survey:

  • 84% of decision-makers said regulatory reporting requirements are the primary factor influencing how quickly cyber incidents are escalated.
  • 85% expect the UK’s proposed Cyber Security and Resilience Bill to significantly influence how organizations manage human-related cyber risk.

Third-party risk is another major concern.

Nearly 39% of respondents identified suppliers and external partners as one of the largest sources of human-related cyber risk—a focus that aligns closely with the proposed legislation’s emphasis on strengthening supply chain security.

Why It Matters

AI adoption is transforming workplace productivity, but it is also fundamentally changing enterprise cybersecurity.

Organizations are no longer protecting only employees and traditional endpoints. They must now secure AI assistants, autonomous agents, cloud applications, and increasingly complex digital workflows—all while ensuring employees understand how to use these technologies responsibly.

KnowBe4’s findings suggest that technology alone won’t solve the problem.

Building a strong security culture will require continuous employee education, clear AI governance policies, behavioral support, and security controls that acknowledge how people actually work under pressure.

For HR leaders, CISOs, and IT teams, the message is increasingly clear: successful AI adoption depends as much on workforce behavior as it does on technical safeguards. As shadow AI becomes more common and autonomous AI systems take on larger operational roles, organizations that invest equally in people, policy, and technology will be better positioned to manage the next generation of cyber risk.

Join thousands of HR leaders who rely on HRTechEdge for the latest in workforce technology, AI-driven HR solutions, and strategic insights

Business Wire, a Berkshire Hathaway company, is the global leader in press release distribution and regulatory disclosure. Public relations, investor relations, public policy and marketing professionals rely on Business Wire for secure and accurate distribution of market-moving news and multimedia. Founded in 1961, Business Wire is a trusted source for news organizations, journalists, investment professionals and regulatory authorities, delivering news directly into editorial systems and leading online news sources via its multi-patented NX network. Business Wire’s global newsrooms are available to meet the needs of communications professionals and news media worldwide.