an employee pastes documents into a public chatbot on a private account
Shadow AI: what it is and how to control it without a ban
Shadow AI is the use by employees of artificial intelligence tools that the organisation has not approved and does not oversee — most often public chatbots on private accounts. Data, knowledge and decisions then end up beyond the organisation’s reach, while responsibility for the consequences stays with it
What shadow AI is
The term echoes shadow IT, i.e. software used without the IT department’s knowledge. The literature describes shadow AI as the unsanctioned use of AI tools outside the organisation’s oversight. Its most common forms:
a team shares an account in an AI tool with no contract with the provider
an AI feature switched on in software the organisation already uses, with no assessment of where the data goes
in a public office or company, whole units work with AI without procedures — “institutional” shadow AI, where it is not an individual who fails but the absence of an organisational decision
Scale
civil servants use generative AI tools at work
NASK 2026 · 6,093 civil servantscivil servants want training; 70% see internal guidelines as a condition for successful AI deployment
NASK 2026employees use unapproved AI tools; 75% of them share sensitive information
Cybernews, August 2025 · 1,003 US employeesRisks
Personal data
Disclosure to a provider with no legal basis or data processing agreement (GDPR Art. 28), breach of security requirements (Art. 32)
Trade secrets and professional secrecy
Information is no longer confidential and its legal protection weakens
Organisational knowledge
Know-how settles in chat histories on private accounts and leaves with the employee
AI Act compliance
The deployer of an AI system used at work is the organisation — without a tool register and training (Art. 4), compliance is hard to prove
ISO certification
An external service processes information outside the management system (ISO/IEC 27001, ISO/IEC 42001)
Common denominator
The organisation is liable in all five areas — not the employee who “used AI at their own risk”
Why a ban does not work
A ban is not the same as control
A ban with no company alternative does not remove the need — it hides it. Employees who have found that AI shortens their work move to private phones and accounts. The organisation then loses even the little visibility it had — it no longer sees what is being used, and its liability does not change
A company tool at least as convenient as a public chatbot, with data under organisational control, an AI gateway and a log. Usage returns to the organisation’s view
A ban does not change who is liable — the organisation is equally responsible for data pasted from a private phone. It only changes whether it can see it
Five steps without a ban
find out which AI tools employees really use: a no-blame survey, network traffic, AI features in existing software
adopt rules: approved tools, data that must not be entered, responsibility for outputs (AI use policy template)
give staff a company AI tool that is at least as convenient as a public chatbot, with data under the organisation’s control
route traffic to models through a single control point: model inventory, personal data masking, limits and a request log
train staff by role (Art. 4 AI Act): what is allowed, what is not and why
How much shadow AI is in your organisation
Three questions, an estimate based on NASK and Cybernews studies and the first step — no form
Check your own organisation
Please answer three questions — the estimate appears here immediately, nothing is sent anywhere. The figures come from the NASK 2026 and Cybernews 2025 studies
How SAIE does it
a single gateway to 100+ models: personal data masking, access policies, budgets and a WORM log of requests. Safe access instead of a ban
TWIN:DESKa company AI assistant with answers from the organisation’s documents and source citations; data stays in-house
AI trainingan Art. 4 AI Act literacy programme for public administration and companies
Sources
- NASK, “AI w e-administracji publicznej — perspektywa urzędników i instytucji” (AI in public e-administration), 2026
- Cybernews, “59% of employees use unapproved AI tools at work”, 30 September 2025
- M. Silic, D. Silic, K. Kind-Trüller, From Shadow IT to Shadow AI — Threats, Risks and Opportunities for Organizations, Strategic Change, 2025
- Regulation (EU) 2024/1689 (AI Act), Art. 3, 4 · Regulation (EU) 2016/679 (GDPR), Art. 28, 32
For information only, not legal advice. As of 3.10.2026
Questions about shadow AI
What is shadow AI?
The use of AI tools that the organisation has not approved and does not oversee, most often public chatbots on employees’ private accounts
Is using ChatGPT at work safe?
It depends on the version and the contract. On a private account the organisation has no contract with the provider, no say over data retention and no access to chat history. A tool approved by the organisation, with a contract, data controls and logging, is safe
Is it enough to block public chatbots?
A block with no company alternative moves usage to private devices. It is more effective to approve a safe tool and route traffic through an AI gateway
Who is liable when an employee pastes client data into a chatbot?
Towards the client and the supervisory authority — the organisation: it is the data controller under GDPR and the deployer under the AI Act. An employee’s statement that they use AI “at their own risk” transfers nothing
Where should a public office start?
With an inventory and a policy. Then a safe tool and training for staff — before a ban turns into a workaround
What else to explore
One gateway: controlled model access, data masking and a query log