In April 2026, Cyber Essentials had its biggest update in years. Most of the coverage focused on multi-factor authentication and stricter cloud rules — all important. But one consequence slipped under the radar for a lot of businesses, and it matters enormously if your team has started using AI: your AI tools are now in scope for Cyber Essentials.
What actually changed
The updated scheme — version 3.3, live from 27 April 2026 — made three changes that matter here:
- Cloud services can’t be excluded. Any cloud or SaaS service accessed with business credentials that stores or processes your data is now formally in scope. The old habit of quietly leaving certain tools off the assessment is gone.
- MFA is mandatory. If a cloud service supports multi-factor authentication and you haven’t switched it on, that’s an automatic fail — no remediation within that assessment.
- Stricter scoping and patching. A new “Danzell” question set expects a proper inventory of your cloud services, and high-risk or critical updates must be applied within 14 days.
Why that puts AI in the frame
Here’s the bit that catches people out: AI tools are cloud services. Microsoft 365 Copilot, ChatGPT, Gemini, the AI features built into your CRM — if your staff sign in with business accounts and feed them company data, they are cloud services under the new rules. Which means they need MFA, they need to be in your inventory, and they can’t be left off the form.
For most organisations the challenge isn’t the tools they chose — it’s the ones they didn’t. Staff have quietly adopted AI on their own initiative: the “shadow AI” that leadership often can’t see. Under the old scheme that was a data risk. Under v3.3 it’s a compliance one too, because you can’t certify tools you don’t know you’re using.
What to do about it
The good news is that getting this right is straightforward, and it’s mostly good practice you’d want anyway:
- Inventory your AI and cloud tools — including the shadow AI — so you know exactly what’s in scope.
- Enforce MFA everywhere, ideally through Microsoft Entra Conditional Access, so nothing fails you on the MFA question.
- Stop AI oversharing with sensitivity labelling and data loss prevention, so tools like Copilot can’t surface data they shouldn’t.
- Put a simple AI usage policy in place so staff know what they can and can’t feed into AI.
- Then certify — with your AI tools properly accounted for, rather than discovered by an assessor.
We’ve written this up in more detail on our new AI & Cyber Essentials page, and it brings together two things we do every day: Cyber Essentials certification and AI security. We’re Cyber Essentials Plus certified ourselves, so if you’re adopting AI and want to stay certified, get in touch — we’ll map what you’re really using and get it in scope.
Source: NCSC and IASME Cyber Essentials v3.3 requirements (in force from 27 April 2026) and public guidance on the April 2026 update. This article is general guidance and reflects the scheme at the time of writing; confirm the specifics for your organisation as part of your assessment.