Live National Cyber Helpline · 0300 123 2040
Assured Cyber Protection Cyber & insurance briefing

News

NCSC Shadow AI Warning, and a 964-Bug Patch Tuesday

By the Assured Cyber Protection team · Updated 2026 · Reviewed
NCSC Shadow AI Warning, and a 964-Bug Patch Tuesday
Photo: CERN data centre by Hugovanmeijeren (CC BY-SA 3.0), via Wikimedia Commons

Three things happened this week that change what a UK small business should be doing on Monday morning. One is a warning about software your staff have already installed, one is the biggest patch release Microsoft has ever shipped, and one is a Bill that will widen who counts as regulated. All three are worth twenty minutes.

The NCSC says 71% of UK employees have used AI tools their employer never approved

On 7 September the National Cyber Security Centre published guidance on shadow AI, the term for AI services staff adopt without going through IT. The headline number is borrowed from Microsoft research: 71 per cent of UK employees have used AI tools their employer had not approved.

The NCSC’s argument is that this is a visibility problem before it is a technology problem. Where employees paste company or customer data into a consumer AI service, that data may be stored, retained or used to improve the service, and the organisation loses control of it. The consequences the NCSC names are the ones that cost money: data breaches, loss of intellectual property, and failing regulatory requirements you have told an insurer you meet. It also flags AI agents specifically, on the basis that an attacker who exploits a vulnerable agent inherits every permission that agent legitimately holds, which in practice is often more than the person using it has.

The advice is the part most coverage skipped. The NCSC does not tell organisations to ban these tools. It says bans push usage further out of sight, and that the realistic goal is reducing shadow AI rather than eliminating it: publish clear guidance on what is and is not acceptable, provide approved alternatives quickly enough that people do not go looking, and build a culture where someone will tell you they used something rather than hide it.

For an SME this maps onto controls you may already have written down. If you hold Cyber Essentials, your asset and software list is supposed to reflect what is actually running, and an unapproved AI service handling customer data is a gap in it. Our cyber security checklist for UK SMBs covers where to start, and data leak protection covers the mechanics of stopping data walking out. The guidance is at the NCSC, via Infosecurity Magazine.

Microsoft’s September patch day was its largest ever, with two flaws already being exploited

On 8 September Microsoft shipped its September 2026 Patch Tuesday, and it is the biggest on record. Tenable counted 964 CVEs, 104 rated critical and 860 important. Other trackers put the number between 964 and 974 depending on whether externally reported and Chromium-based issues are counted, so treat the exact figure as a range and the scale as the point.

Two of them were already being exploited before the patch existed. CVE-2026-81963 is an elevation of privilege flaw in the Windows Update Stack, and CVE-2026-85880 is an elevation of privilege flaw in Windows Advanced Local Procedure Call. Both carry a CVSSv3 score of 7.8 and both are rated important rather than critical, which is exactly the trap: severity ratings describe the flaw, not whether someone is using it against you today. Elevation of privilege made up nearly 45 per cent of the month’s total and remote code execution around 27 per cent.

A release this size will not land cleanly everywhere, and the honest advice is not “patch everything tonight”. It is to make sure the two exploited flaws are covered first, on every Windows machine including the laptop in the back office nobody logs into, and then let the rest follow your normal ring. If you carry cyber cover, check the patching wording in your policy while you are at it, because a delay measured in months is the kind of thing that surfaces at claim stage. What cyber insurance actually covers walks through the exclusions that do the damage. The breakdown is at Tenable.

The Cyber Security and Resilience Bill has been reprinted after Lords committee

The Cyber Security and Resilience (Network and Information Systems) Bill reached Grand Committee in the House of Lords this month, with sittings running through the first half of September. A reprint of the Bill as amended in Grand Committee, HL Bill 49, was published on 7 September, and the parliamentary record was last updated on 8 September. Report stage comes next.

Two scope questions are doing most of the work in committee. The first is relevant managed service providers, a new statutory category and the single largest expansion of who falls inside the regime. The second is data centres, regulated as a category for the first time, with the thresholds left to secondary legislation. Peers have also been debating incident reporting timings, obligations to tell customers when something has happened, and where senior executive liability sits.

If you are a small business, the direct obligation probably still does not land on you. The indirect one does, and it is the one to plan for: if your IT is outsourced, your provider is the entity most likely to be brought into scope, and regulated providers pass their compliance costs and their contractual demands down. Expect requests for evidence of your own controls in contract renewals over the next couple of years rather than a letter from a regulator. We keep a plain-English summary at what the Cyber Security and Resilience Bill means for SMBs, and if you are weighing certification first, Cyber Essentials and the April 2026 MFA rule covers what has already changed. The Bill’s passage is tracked at UK Parliament.

The Threat Brief

A calm, plain-English security update. Once a week.

New scams, breach lessons, and cyber insurance changes that affect UK businesses, explained without the jargon. No alarmism, no vendor spin.

Unsubscribe anytime. We never share your address.