Shadow AI — Your Employees Are Using AI Without Your Knowledge and That's Your Problem
RETURN_TO_BLOG
Updated: AI & Security 16 min

Shadow AI — Your Employees Are Using AI Without Your Knowledge and That's Your Problem

Paweł Wiszniewski
Paweł Wiszniewski
SEO & GEO Specialist · AI Engineer

Shadow AI refers to the use of AI tools by employees without the knowledge, consent, or oversight of the organisation. This is not a marginal phenomenon: according to 2026 Gartner data, 68% of employees use unsanctioned AI tools, with engineers and developers reaching 79%. Employees aren't doing this maliciously — they do it because AI genuinely helps them, and the approved tool catalogue is empty or outdated. The problem is that they paste contracts, customer data, source code, strategies, and national ID numbers into public chatbots — and nobody in the company knows about it. This is simultaneously an IP leak, a GDPR violation, and an AI Act breach in a single action. The solution isn't a ban — it's an AI policy that channels this energy in a safe direction.

68% of employees use unsanctioned AI tools without IT's knowledge. They paste contracts, customer data, source code, and strategies into public chatbots — and the company has no idea. Shadow AI isn't a technology problem, it's a governance problem. I explain how to detect what your team is actually using, how to write an AI policy that actually works, and why an outright ban is the worst possible solution.

A few months ago, a client — a financial services firm — asked me for a security audit ahead of an AI deployment. I started with the question I always ask first: "How many people in your company already use AI?". The answer: "Nobody. We're waiting for your deployment." The next day I ran an anonymous survey among the employees. 71% admitted they regularly use ChatGPT, Claude, or Copilot at work. Several were pasting contract clauses from client agreements into them.

This is not an exception. It's the rule.

The Scale of the Problem — Numbers That Should Wake You Up

/// SHADOW AI: SCALE OF THE PROBLEM IN 2026

68%
OF EMPLOYEES USE SHADOW AI
without IT knowledge (Gartner 2026)
30%
OF FIRMS HAVE FULL VISIBILITY
into which AI tools their team uses
+$670K
EXTRA BREACH COST
when Shadow AI was the root cause
52%
OF FIRMS HAD COMPLIANCE ISSUES
due to unsanctioned AI tools

These data points aren't scare tactics — they're a photograph of the real state of organisations in 2026. The key takeaway: having no AI policy doesn't mean having no AI in the company. It means AI without control.

What are employees pasting into unsanctioned tools? Research shows: - 29% of Shadow AI incidents involve IP leaks: code, algorithms, product blueprints - 51% of employees admitted to pasting confidential work data into AI without authorisation - Client contracts, personal data, negotiation emails, strategic plans

Note: cloud models process this data on their servers. OpenAI and Anthropic with Enterprise accounts (API) have Zero Data Retention — data isn't used for training. With the free ChatGPT — it may be. And that's the heart of the problem.

What a Breach Costs — Real Incidents and Numbers

Shadow AI has stopped being a theoretical risk. According to the Verizon DBIR 2026 report, the share of employees regularly using AI on corporate devices jumped from 15% (2025) to 45% (2026) — in a single year. At the same time, only 23% of employees use AI tools the organisation actually provides and governs; 56% reach for unsanctioned ones.

The most famous example is Samsung. In 2023, engineers pasted fragments of internal source code and meeting transcripts into ChatGPT to speed up their work. The result: confidential data left the company, and Samsung imposed a complete ban on generative AI on work devices. It's the classic scenario: good intentions, no policy, an irreversible leak.

The 2026 numbers show the financial scale: - +$670,000 — how much Shadow AI adds on average to the cost of a single data breach - $4.2M — the average total cost of a Shadow AI-related breach - 20% of organisations reported a breach caused directly by Shadow AI - only 37% of companies had any detection or AI governance policy in place at the time of the incident

Verizon DBIR 2026 analysed 858,440 DLP events involving uploads to generative AI tools. In first place — by a large margin — was source code, followed by images and structured data. Personally identifiable information (PII) appeared in about 65% of Shadow AI incidents, intellectual property in around 40%.

The conclusion is brutal: it's not a question of "if" but "when and at what cost". Gartner predicts that by 2030 more than 40% of enterprises will experience a security or compliance incident linked to unauthorised Shadow AI.

6 Shadow AI Risks — From Critical to Serious

/// 6 SHADOW AI RISKS — FROM MOST SEVERE

IP Leak
Code, blueprints, contracts, strategy pasted into a public chatbot
GDPR Breach
Customer data, IDs, emails processed without a DPA with the provider
AI Act
No AI literacy, no policy — breach of Art. 4 since Feb 2025
Hallucinations in production
Decisions based on AI-generated content without verification
Vendor lock-in
Data and processes built on an unapproved platform
No audit trail
No log records what the company sent to external models

IP and trade secret leakage is risk number one. One employee, one copy-paste of an NDA contract into the free ChatGPT — and confidential commercial terms potentially feed the training data of a public model. That can't be undone.

GDPR violation is certain if an employee processes personal data through a tool without a DPA (Data Processing Agreement) with the provider. Free ChatGPT has no DPA. ChatGPT Enterprise — does. The legal difference is fundamental, but the employee doesn't see it.

EU AI Act Article 4 (AI literacy) has applied since February 2025. The company is obligated to ensure employees have "a sufficient level of AI knowledge". Shadow AI without a policy is prima facie evidence that you haven't done this.

Regulated Industries — Where Shadow AI Hurts Most

Not every company has the same risk profile. In regulated industries, one careless prompt can mean an administrative fine, loss of licence, or litigation.

Finance and insurance. Transactional, scoring, and personal data under GDPR and supervisory requirements. An employee pasting a client's account history into a public chatbot breaches both banking secrecy and GDPR at once. Here the standard is a hard ban on consumer tools and a complete audit trail.

Healthcare. The scale is alarming — a February 2026 Healthcare Brew survey found that 57% of healthcare professionals have encountered or used unauthorised AI tools. Clinicians use ChatGPT, Claude, and Gemini to draft notes, generate diagnostic hypotheses, and synthesise treatment plans — often pasting patient data. This is special-category data (GDPR Article 9), whose leak is one of the most serious violations possible.

Legal and advisory. Attorney-client privilege, NDA-covered documents, litigation materials. A single copy-paste of a draft contract into a free tool can breach professional privilege and expose the firm to disciplinary liability.

In these industries, the minimum is: company Enterprise accounts with a DPA and Zero Data Retention, a hard ban on pasting client data into consumer tools, and an audit log recording who sent what and when.

Why a Ban Doesn't Work

Many managers see Shadow AI and think: "We'll block ChatGPT on company WiFi". That's a mistake that makes things worse.

First: the employee switches to mobile data and continues using it — only now you can't even see the network traffic. Second: you block productivity without eliminating risk. Third: you build a culture of circumventing security controls.

The data confirms: organisations that ban AI without offering an alternative have a higher rate of Shadow AI than those that implemented an approved tool catalogue. The employee will use AI — the only question is which one and with what level of control.

Shadow AI Management Model in Three Steps

Step 1: Detect — What Your Team Is Actually Using

Don't ask IT. Run an anonymous employee survey — honesty is higher and the results more useful. Questions: - Which AI tools do you use at work (ChatGPT, Copilot, Gemini, Claude, other)? - What tasks do you use them for? - What AI tools do you feel are missing from your work?

Technically: review DNS and network proxy logs for traffic to AI domains (openai.com, claude.ai, gemini.google.com, perplexity.ai). This gives you a picture without the survey. You can also check installed browser extensions through MDM (Mobile Device Management).

Step 2: Classify — Safe vs Risky

Not all Shadow AI carries equal risk. An employee using Copilot in Word to improve the style of an internal email is a different risk to an employee pasting contracts into free ChatGPT.

ScenarioRiskAction
Copilot (M365 Enterprise) — company dataLow — Microsoft has DPAApprove, document
ChatGPT Plus (personal account) — general questionsLow–Medium — no DPATolerate subject to data classification
ChatGPT Free — customer dataHIGH — possible training useBan this combination (not the tool)
Perplexity/Claude without DPA — personal dataHIGH — GDPR violationBan this combination
Own API with PII masking — any dataLow — data masked before transmissionPromote as the pattern

Key insight: you don't ban the tool — you ban the combination of tool and data category.

Step 3: AI Policy — A Document That Actually Works

An effective AI policy is not a regulatory document written by a lawyer that employees ignore. It's a one-page document that answers three questions:

  1. 1.Which AI tools can be used and under what conditions? (approved catalogue)
  2. 2.What data must never be pasted anywhere? (data classification: public / confidential / secret)
  3. 3.How to submit a new tool for approval? (simple process, not a bureaucratic wall)

Policy content template:

ElementExample content
Approved toolsMicrosoft Copilot (M365 Enterprise), ChatGPT Enterprise (company account), Claude API through company system
Data NEVER in AICustomer personal data (GDPR), social security numbers, tax IDs, financial data, trade secrets, full contract texts with NDAs
Data possible with careAnonymised excerpts, general questions, own texts without PII
Submitting new toolsEmail to IT/security, decision within 5 business days
Policy reviewQuarterly — because AI changes faster than most policies

The policy must be alive — updated quarterly, because in AI, 3 months is an era.

Technical Safeguards — The Engineering Layer

Policy without technology is just paper. The technical layer I recommend:

1. DLP (Data Loss Prevention) — tools like Microsoft Purview, Nightfall AI can scan traffic for PII patterns (social security numbers, tax IDs, card numbers) before they reach external APIs. Doesn't block — it warns or logs.

2. AI Gateway / Proxy — all requests to external models pass through a company proxy that: - Logs what and who is sending (audit trail) - Applies PII redaction rules before transmission - Enforces use of company Enterprise accounts (not personal ones)

3. Internal RAG + chatbot — building an internal tool that answers employee questions from the company knowledge base eliminates the need to paste documents into external chatbots. Employees have the need — give them a safe tool.

4. Training (AI literacy) — required by the AI Act, but also effective. An employee who understands the difference between free ChatGPT and Enterprise API makes a different decision. Not because they have to, but because they understand the risk.

AI Governance Tools — What to Actually Deploy

The market for Shadow AI control tools has matured. Below are the categories and examples — the right choice depends on company size and IT stack.

CategoryWhat it doesExamplesFor whom
Next-gen DLPScans and blocks uploads of PII/code to AIMicrosoft Purview, Nightfall AI, CyberhavenCompanies on M365/Google Workspace
AI Gateway / proxyBrokers requests to models, logs, redacts PIICloudflare AI Gateway, Portkey, LiteLLMTechnical teams, custom AI apps
CASB / SSEAccess control for SaaS and cloud AI appsNetskope, Zscaler, Palo AltoMid-size and large organisations
Enterprise AI with DPAA safe, approved tool for employeesChatGPT Enterprise, Copilot M365, Claude TeamEvery company — this is the foundation
Browser monitoringDetects data pasted into AI in the browserIsland, LayerXCompanies without their own proxy

Practical rule: start with the foundation (Enterprise with a DPA + a clear policy), then layer technical controls on top. The most expensive DLP tool won't help if the employee has no approved, convenient alternative — they'll route around it anyway.

30/60/90-Day Rollout Plan

/// AI GOVERNANCE ROLLOUT PLAN: 30 / 60 / 90 DAYS

DAYS 1–30
VISIBILITY
See the truth, not punish
  • Anonymous survey
  • DNS/proxy log analysis
  • Tool & data inventory
DAYS 31–60
FOUNDATION
Give a safe alternative
  • Enterprise catalogue + DPA
  • AI policy (1 page)
  • AI literacy training
DAYS 61–90
CONTROL
Sustain and measure
  • DLP / AI Gateway
  • Audit trail
  • Quarterly review

Days 1–30: visibility. Anonymous survey, DNS/proxy log analysis, a list of tools actually in use and the data categories flowing through them. The goal is to see the truth, not to punish — employee honesty here is worth more than formal compliance.

Days 31–60: foundation. An approved tool catalogue (Enterprise with a DPA), a one-page AI policy, data classification (public / confidential / secret), and the AI literacy training required by the AI Act. The goal is to give a safe, convenient alternative before you block anything.

Days 61–90: control. The technical layer (DLP/gateway), an audit trail, a process for submitting new tools, and the first quarterly review. The goal is to sustain, measure, and iterate — because the tool landscape will change faster than you expect.

My Approach to AI Deployment

When I build AI systems for companies, I start with the question: "What are your employees already using?". The answer always surprises me — both in scale and creativity. Instead of shutting that down, I design an architecture that channels this energy:

  • Internal RAG chatbot replaces pasting documents into ChatGPT
  • Company API with PII masking replaces personal accounts
  • AI policy with an approved catalogue replaces a blanket ban

Result: the company has control, employees have tools, and GDPR and the AI Act are complied with not on paper but in the architecture.

If you want to know what Shadow AI looks like in your organisation and what to do about it — I invite you to a Shadow AI Audit: anonymous survey + network traffic review + AI policy tailored to your company. A week-long sprint that gives you a complete picture and action plan.

FAQ — Shadow AI

/// RELATED_RECORDS

AI & Security

The EU AI Act in Practice — What Your Company Must Do in 2026 (No Panic, No Legalese)

The AI Act sounds scary, but 90% of SMB automation is "minimal risk" with no extra obligations. I explain the four risk tiers, the provider vs deployer distinction, what applies right now (AI literacy, chatbot transparency), when you fall into "high risk", and what a realistic compliance checklist looks like. With an up-to-date timeline after the May 2026 Digital Omnibus package.

13 min
AI & Security

AI Data Security — How Not to Hand Over Your Company's Secrets?

Free ChatGPT in the browser is not a safe — it's a risk. Learn the difference between Web UI, Enterprise API, and on-premise, how PII masking works, and why a professional AI architecture is fully GDPR-compliant without compromise.

15 min
AI & SEO

AI Browsers and Agent Experience (AX) — Can an Agent Actually Use Your Website?

Within twelve months we got Comet from Perplexity (free worldwide since October 2025), Claude for Chrome and ChatGPT Atlas — and in July 2026 OpenAI announced it is retiring Atlas and folding agentic browsing directly into ChatGPT. Browser brands come and go, but the capability stays: an agent that clicks, fills forms and completes tasks on your site on the user's behalf. Crawlers only needed readable HTML — an agent has to be able to ACT. What Agent Experience (AX) is, what most often blocks agents (captchas, modal walls, div-buttons, unlabeled forms) and how to test your own site with an agent in 30 minutes.

14 min
/// AUTHOR
Paweł Wiszniewski – AI & Web Engineer

Paweł Wiszniewski

SEO & GEO Specialist & AI Engineer

SEO/GEO specialist (10 years) and AI engineer (3 years). I build search visibility, AI systems and automations that reduce costs and improve operational efficiency.

Signal received?

Terminate
Silence

Initiate protocol. Establish connection. Let's build something loud.

> WAITING_FOR_INPUT...