allclouds.pl
Knowledge

Shadow AI: what it is and how to control it without a ban

Shadow AI is the use by employees of artificial intelligence tools that the organisation has not approved and does not oversee — most often public chatbots on private accounts. Data, knowledge and decisions then end up beyond the organisation’s reach, while responsibility for the consequences stays with it

46%civil servants (NASK)
59%employees
5steps
3.10.2026legal status
01 / 09

What shadow AI is

The term echoes shadow IT, i.e. software used without the IT department’s knowledge. The literature describes shadow AI as the unsanctioned use of AI tools outside the organisation’s oversight. Its most common forms:

Private account

an employee pastes documents into a public chatbot on a private account

Shared account

a team shares an account in an AI tool with no contract with the provider

AI feature in software

an AI feature switched on in software the organisation already uses, with no assessment of where the data goes

Institutional shadow AI

in a public office or company, whole units work with AI without procedures — “institutional” shadow AI, where it is not an individual who fails but the absence of an organisational decision

02 / 09

Scale

Two studies · 2025–2026
46%

civil servants use generative AI tools at work

NASK 2026 · 6,093 civil servants
87%

civil servants want training; 70% see internal guidelines as a condition for successful AI deployment

NASK 2026
59%

employees use unapproved AI tools; 75% of them share sensitive information

Cybernews, August 2025 · 1,003 US employees
In a public office of 100 people, around 46 use AI — most without a company toolFull sources in section 08
03 / 09

Risks

Personal data

Disclosure to a provider with no legal basis or data processing agreement (GDPR Art. 28), breach of security requirements (Art. 32)

LiableThe organisation as controller

Trade secrets and professional secrecy

Information is no longer confidential and its legal protection weakens

LiableThe organisation and, under criminal law, the person who disclosed it

Organisational knowledge

Know-how settles in chat histories on private accounts and leaves with the employee

LiableThe organisation loses an asset

AI Act compliance

The deployer of an AI system used at work is the organisation — without a tool register and training (Art. 4), compliance is hard to prove

LiableThe organisation

ISO certification

An external service processes information outside the management system (ISO/IEC 27001, ISO/IEC 42001)

LiableThe organisation — risk of a nonconformity at audit

Common denominator

The organisation is liable in all five areas — not the employee who “used AI at their own risk”

That is whya ban does not remove liability — section 04
04 / 09

Why a ban does not work

OFTEN CONFUSED

A ban is not the same as control

A ban

A ban with no company alternative does not remove the need — it hides it. Employees who have found that AI shortens their work move to private phones and accounts. The organisation then loses even the little visibility it had — it no longer sees what is being used, and its liability does not change

vs
A safe alternative

A company tool at least as convenient as a public chatbot, with data under organisational control, an AI gateway and a log. Usage returns to the organisation’s view

0

A ban does not change who is liable — the organisation is equally responsible for data pasted from a private phone. It only changes whether it can see it

05 / 09

Five steps without a ban

1Inventory

find out which AI tools employees really use: a no-blame survey, network traffic, AI features in existing software

2Policy

adopt rules: approved tools, data that must not be entered, responsibility for outputs (AI use policy template)

3A safe tool

give staff a company AI tool that is at least as convenient as a public chatbot, with data under the organisation’s control

4AI gateway

route traffic to models through a single control point: model inventory, personal data masking, limits and a request log

5Training

train staff by role (Art. 4 AI Act): what is allowed, what is not and why

06 / 09

How much shadow AI is in your organisation

Three questions, an estimate based on NASK and Cybernews studies and the first step — no form

Tool · estimate

Check your own organisation

Instant result · no e-mail
1 · How many people work with documents and e-mail
2 · Is there a company AI tool
3 · Is there an AI use policy
?

Please answer three questions — the estimate appears here immediately, nothing is sent anywhere. The figures come from the NASK 2026 and Cybernews 2025 studies

An estimate, not a measurement — the exact number comes from an inventory (a no-blame survey + network traffic)
08 / 09

Sources

For information only, not legal advice. As of 3.10.2026

FAQ

Questions about shadow AI

What is shadow AI?

The use of AI tools that the organisation has not approved and does not oversee, most often public chatbots on employees’ private accounts

Is using ChatGPT at work safe?

It depends on the version and the contract. On a private account the organisation has no contract with the provider, no say over data retention and no access to chat history. A tool approved by the organisation, with a contract, data controls and logging, is safe

Is it enough to block public chatbots?

A block with no company alternative moves usage to private devices. It is more effective to approve a safe tool and route traffic through an AI gateway

Who is liable when an employee pastes client data into a chatbot?

Towards the client and the supervisory authority — the organisation: it is the data controller under GDPR and the deployer under the AI Act. An employee’s statement that they use AI “at their own risk” transfers nothing

Where should a public office start?

With an inventory and a policy. Then a safe tool and training for staff — before a ban turns into a workaround

All questions →

https://www.allclouds.pl/en/wiedza/shadow-ai/