
An employee receives a long email from a customer. Instead of writing a reply themselves, they paste the message into ChatGPT and type: "Summarize this request and draft a professional reply." Two minutes later, the task is done.
Convenient? Absolutely.
But what happens if that email contained names, phone numbers, contract details, internal prices, or other confidential data? Does the company even know which AI system was used? What terms apply there? Is there a contract with the provider? And was the employee even allowed to send this information to that service in the first place?
This is exactly where Shadow AI begins.
Shadow AI is becoming a problem for companies much like Shadow IT once was: employees use applications, services, and AI tools that IT, privacy, or management never reviewed or officially approved.
The problem here isn't ChatGPT itself. The problem is uncontrolled AI use.
What does Shadow AI mean?
Shadow AI refers to the use of artificial intelligence within a company without that use being officially approved, documented, or controlled.
Typical examples are employees who:
- use a personal ChatGPT account,
- edit texts through Claude or Gemini,
- upload documents to unknown AI services,
- have source code reviewed by a public coding assistant,
- have meeting notes summarized by an AI,
- use AI-powered translation or writing tools,
- install browser extensions that use AI,
- connect their own AI agents or automations,
- feed company data into public AI services.
Microsoft now uses the term for unsanctioned AI applications as well, and offers features that let companies detect network traffic to generative AI services that haven't been approved.
Shadow AI is effectively the next generation of Shadow IT. The key difference: with unknown software, IT might not have known where data was stored. With generative AI, employees can now actively enter information, documents, source code, or entire datasets into external systems.
Why do employees secretly use ChatGPT?
Some companies' first reaction is: "Then let's just ban ChatGPT." That sounds simple, but it often doesn't solve the actual problem.
Most employees don't use AI to harm their employer. They use it because it lets them work faster. An employee might want to:
- understand a complicated spreadsheet formula,
- phrase an email better,
- summarize a report,
- structure a presentation,
- find a bug in some code,
- translate a longer text,
- write documentation,
- brainstorm ideas for a project.
Expectations around productivity shift dramatically as a result. When employees know a task takes ten minutes with AI instead of an hour, there's a strong incentive to use a tool that can do that.
If no official system exists for this, some employees simply use the tool they already know from their private life. That's exactly why Shadow AI shouldn't be treated purely as an employee problem. It's often also a sign that actual needs and company strategy are out of sync.
Why Shadow AI can become dangerous for companies
Not every ChatGPT request is automatically a security incident. The prompt "Write a friendly invitation to our summer party." is in a completely different risk category than: "Analyze this spreadsheet containing all customer names, revenue figures, contract numbers, and email addresses."
The core problem with Shadow AI is that the company may not even be aware of this difference.
1. Confidential company data can leave the company
Employees work daily with information that isn't meant to be public: internal documentation, cost calculations, quotes, contracts, access credentials, network structures, source code, customer data, HR data, business strategy, unreleased product information.
Anyone who enters such content into an unvetted external AI service may be passing it on to yet another provider. What happens to that data afterward depends on the specific vendor, product, contract, account, and chosen settings.
That's why, before approving any AI service for company use, it's worth checking: What data is processed? Where is it processed? How long is it retained? What contract terms apply? What security features are available?
2. Personal data and GDPR
Shadow AI becomes especially problematic when personal data is involved. An employee might paste a customer complaint into ChatGPT: "Mr. Miller, customer number 47382, complained about his invoice. Here's his full email. Draft a reply."
This may process personal data outside the business process it was originally intended for.
The GDPR doesn't ban generative AI outright. What matters is which personal data is processed, for which purpose, on what legal basis, by whom, and under which safeguards. Germany's federal data protection authority (BfDI) also points out that the relevant question under data protection law is always the processing of personal data.
So the statement "ChatGPT is GDPR-compliant" isn't very useful on its own. The better question is: "Is our specific use of this AI service, with this data and this purpose, properly organized from a data-protection standpoint?"
3. Trade secrets can be put at risk
It's not just personal data that matters. Company know-how has value too. A developer might use a prompt like: "Here's the configuration of our production infrastructure. Find security issues."
The AI might genuinely deliver an excellent analysis. But at the same time, the employee may have transmitted internal information about hostnames, IP addresses, architecture, firewall rules, APIs, databases, and user structures to an unapproved service.
What was meant to be a useful security review can end up creating a security risk of its own.
Shadow AI is far from just a ChatGPT problem
ChatGPT is simply the best-known example. Generative AI is now embedded in countless applications: office software, browser extensions, development environments, meeting assistants, CRM systems, translation tools, graphics software, project management tools, search engines, and SaaS applications in general.
That means a company can have Shadow AI without any employee consciously saying: "I'm using AI." A browser extension that improves writing may already be sending content to an external AI service. A meeting bot can process entire conversations. A coding assistant can analyze source code.
The key question, then, isn't just: "Who is using ChatGPT?" It's: "Which AI systems in our company are processing which information?"
4. AI output can be wrong
Another problem arises when employees adopt AI results without checking them. Generative AI can sound convincing and still be wrong. This affects technical configurations, legal texts, contract language, calculations, sources, software commands, and security measures, among other things.
This becomes especially dangerous when the AI use stays invisible. An employee produces a report with the help of an AI. Their manager knows nothing about it and assumes every figure, source, and statement was manually verified.
AI shouldn't only be regulated in terms of what data goes in. Companies also need rules for how the output is handled.
5. AI agents raise the risk further
A normal chatbot processes information and produces answers. Modern AI agents can go much further. Depending on the product and permissions granted, they can read files, research websites, use applications, analyze data, or call external tools.
That changes the risk profile. "Employee → AI → answer" can turn into "Employee → AI agent → company data → applications → actions."
The more permissions a system has, the more important access control, logging, and human approval become. You can read more about this development in the KI-Buster article ChatGPT Agent 2026: What Can the AI Agent Really Do? (Read article).
6. Prompt injection hits company AI too
Another danger arises when AI systems automatically process external documents, websites, or emails. Manipulated content can try to alter an AI agent's original instructions. This attack technique is called prompt injection.
It becomes especially critical for AI systems with access to email, files, databases, APIs, cloud services, and automations. An unknown private AI agent with access to company systems can therefore be considerably more problematic than an employee who occasionally has a general text drafted.
How these attacks work is explained in detail in the KI-Buster article Prompt Injection Explained: How Attackers Hijack AI Agents (Read article).
Shadow AI and the EU AI Act
In 2026, the topic also gains regulatory weight. The European AI Act entered into force on August 1, 2024, and has generally applied since August 2, 2026. Individual provisions have their own transition deadlines. Obligations around prohibited AI practices and AI literacy have already applied since February 2, 2025.
That doesn't mean every secret ChatGPT request automatically violates the AI Act. But it does mean companies can no longer permanently rely on: "We simply don't know what our employees are doing with AI."
Companies should be able to trace which AI systems are used for which purposes, what risks exist, and what knowledge employees need to use AI responsibly. What the AI Act specifically means for smaller businesses is explained in EU AI Act for Small Businesses: What SMEs Need to Know Now (Read article).
Shadow AI thus becomes a combination of IT security, data protection, compliance, employee training, and corporate governance.
Is banning ChatGPT entirely the solution?
An outright ban can certainly be necessary in particularly sensitive areas. As a general AI strategy, though, it's rarely enough. A ban doesn't answer the question: why do employees want to use these tools in the first place?
If a marketing team has to write twenty product texts every week and knows AI could help enormously, that need doesn't disappear because of a firewall rule.
A successful AI strategy should therefore pursue two goals at once: limiting risk and enabling productive use. That's the key difference between banning AI and AI governance.
How companies can tackle Shadow AI sensibly
1. First, find out where AI is already being used
Before writing any rules, a company should understand its actual current state. Useful questions: Which AI services are employees using? Which departments use them? For what tasks? What data is being entered? Are there private accounts in use? Are documents being uploaded? Do AI browser extensions exist? Do developers use external coding assistants? Are AI agents or APIs in use?
This shouldn't initially be about assigning blame. The information is needed to build a realistic company policy.
2. Build a simple AI service catalog
A clear classification can already create a lot of clarity.
| Category | Example | Rule |
|---|---|---|
| Green | approved company AI | use permitted |
| Yellow | new AI service | must be reviewed first |
| Red | unknown public AI service | not permitted with sensitive data |
Employees understand a structure like this far faster than a 40-page compliance document.
3. Classify data
The question "Am I allowed to use ChatGPT?" is often too broad. A better question is: "Which data am I allowed to process with which AI?" For example:
- Public: already-published website content, general product information, public press releases
- Internal: internal work instructions, project information, internal communication
- Confidential: customer data, employee data, contracts, access credentials, trade secrets, unpublished source code, security configurations
For each class, you can then define which AI systems may be used.
4. Create an understandable AI policy
An AI policy shouldn't be a document written once and then forgotten. Employees need concrete answers. For example:
Allowed: "Turn these general bullet points into a friendlier phrasing."
Not allowed: "Here's an employee's complete personnel file. Summarize it."
Only with an approved company solution: "Analyze these internal contract documents."
That makes rules tangible.
Matching product · German-language edition
KI ohne Bauchschmerzen
50 AI prompt templates, 15 workflows, and a 21-day plan for rolling out AI in a company under control — including how to handle risk and pick the right tasks.
5. Offer a safe alternative
This is possibly the single most important point. Anyone who wants to reduce Shadow AI should give employees an official alternative. It doesn't need every conceivable feature. But it should cover the most common needs: drafting text, summarizing information, analyzing documents, coding, researching, translating, developing ideas.
If an approved tool works nearly as easily as the private alternative, the incentive to switch to unknown services drops.
6. Train employees instead of just handing out rules
A good training doesn't just explain: "This is forbidden." It explains: "Why can this become dangerous?"
After AI training, an employee should be able to answer, for example: What counts as personal data? What counts as confidential company information? Which AI services am I allowed to use? What data am I allowed to enter? How do I verify an AI's answer? When do I need human review? What is prompt injection? Who do I ask if I have questions?
NIST's AI Risk Management Framework likewise recommends clearly defining roles, responsibilities, skills, and training for people who use AI systems.
7. Add technical controls
Organizational rules alone may not be enough in larger environments. Depending on the infrastructure, companies can check which external AI services are in use through DNS and proxy analysis, secure web gateways, CASB solutions, endpoint security, browser management, SaaS discovery, and network monitoring.
Microsoft, for instance, offers shadow AI discovery that can surface unsanctioned generative AI applications on the network.
Caution is required here, though. Technical monitoring must not quietly turn into hidden employee surveillance. In Germany, technical systems designed to monitor employee behavior or performance can specifically trigger works-council co-determination rights under Section 87 of the Works Constitution Act (BetrVG).
Data protection, employee representation, and legal counsel where appropriate should therefore be involved early on.
Matching product · German-language edition
Cyberangriffe mit KI abwehren
A 576-page security package with cheat sheets on Zero Trust, SIEM, EDR/XDR, and threat hunting — useful for building structured technical controls against uncontrolled AI use.
8. Create a simple reporting path
Employees should know: "I found a new AI tool. Where can I ask whether I'm allowed to use it?" If approval takes six weeks and five forms, Shadow AI becomes more likely.
A simple process could look like: report the tool → describe the purpose → state the data class → IT/privacy reviews it → approval or alternative. That turns secret AI use into controlled innovation.
What belongs in a good AI policy?
At minimum, the following points should be regulated:
- Which AI services are approved?
- What data may be processed?
- What data must never be entered?
- Are private accounts allowed?
- May files be uploaded?
- How must AI results be verified?
- When must AI use be disclosed?
- Who approves new AI systems?
- What applies to source code?
- What applies to personal data?
- What applies to AI agents and automations?
- What permissions may AI systems be granted?
- How are security incidents reported?
- How are employees trained?
A good policy doesn't need to be complicated. It needs to be understandable and usable in daily work.
A real-world example
A sales employee receives a spreadsheet with 800 customers. She wants to know: "Which customers have ordered less in the past three months?"
Option A: Shadow AI
She uploads the entire file to a public AI service using her personal account. IT knows nothing about it.
Option B: controlled AI use
The company provides a vetted AI solution. The employee knows, based on the company policy, which data is allowed to be processed there. Access, vendor, contract, permissions, and technical setup were reviewed beforehand.
The same AI function can therefore be either an uncontrolled risk or a productive business tool. The difference is governance.
Shadow AI is also an opportunity
Shadow AI sounds purely negative at first. But hidden AI use also gives companies valuable information — it shows where employees see potential for automation.
If ten employees regularly use AI to summarize quotes, there's clearly a useful use case there. If developers constantly use coding assistants, there's a real need. If marketing staff draft texts with AI, the same applies.
Instead of only asking "How do we block this?", it's worth also asking: "Why are our employees using this tool — and can we solve that need officially, and better?" That's exactly where productive AI projects can emerge.
Shadow AI checklist for companies
Check the following points:
- Do we know which AI services are used in the company?
- Is there a written AI policy?
- Are approved AI systems clearly named?
- Is sensitive and confidential data classified?
- Do employees know which data they must not enter?
- Is there a secure company solution available?
- Are employees trained in using AI?
- Is AI output checked for important decisions?
- Are AI agents and external integrations regulated?
- Are permissions granted following least privilege?
- Is there a simple process for new AI tools?
- Are data protection and information security involved?
- Is there a process for AI-related security incidents?
- Are policies updated regularly?
If you answer "no" to several of these, it's time to deal with Shadow AI — probably not eventually, but now.
Conclusion: Shadow AI won't disappear by looking away
Generative AI has arrived in everyday work. Every month, employees discover new ways to get their work done faster and more easily. Fully stopping this trend is unlikely to be realistic or economically sensible for most companies.
The real task, then, isn't to prevent AI altogether. Companies need to turn "Our employees secretly use some AI tools" into a controlled state: "Our employees know which AI they can safely use for which tasks."
This doesn't require a huge AI department. Clear rules, approved tools, data classification, training, technical safeguards, and a simple approval process can already make an enormous difference.
Shadow AI is ultimately a warning sign. It shows that employees already want to use AI — while the company's processes, governance, and security measures may not have caught up yet.
Whoever reads that signal correctly can turn a security problem into a competitive advantage.
Frequently asked questions about Shadow AI
What is Shadow AI in simple terms?
Shadow AI refers to AI applications that employees use at work without official approval or oversight from the company. This can include ChatGPT, other chatbots, coding assistants, browser extensions, or AI agents.
Is ChatGPT banned in companies?
Not generally. Whether ChatGPT may be used depends on the specific use case, the data being processed, company policy, contracts, and data protection requirements.
Why is Shadow AI dangerous?
Possible risks include uncontrolled disclosure of confidential data, privacy violations, incorrect AI output, unknown vendors, missing access controls, and unsafe AI agents.
Can employees enter customer data into ChatGPT?
This should not be answered in a blanket way. What matters is the specific service, the account or contract model used, the purpose and legal basis for processing, and the organizational and technical safeguards in place. Without proper company approval, employees should not submit sensitive or personal customer data to external AI services on their own.
How can companies prevent Shadow AI?
The most effective strategy combines clear rules, approved AI tools, employee training, data classification, simple approval processes, and appropriate technical controls.
Is it enough to block ChatGPT on the company network?
A technical block can prevent certain access, but it does not remove employees' underlying need. Private devices, mobile data, or other AI services can still be used. In the long run, a controlled AI strategy is usually more effective than blocking alone.
What does Shadow AI have to do with the EU AI Act?
The AI Act sets obligations for different roles and use cases involving AI. Since August 2, 2026 the framework generally applies, though individual provisions have different deadlines. Companies should be able to account for which AI systems they use and how employees handle them.
Sources & currency
Fact-checked as of: August 21, 2026. This article draws primarily on current primary sources and vendor documentation: the European Commission (EU AI Act application timeline), the NIST AI Risk Management Framework, Microsoft Learn (Shadow AI discovery), Germany's Federal Commissioner for Data Protection and Freedom of Information (BfDI), and Section 87 of the German Works Constitution Act (BetrVG).
Note: This article is for general information only and does not replace individual legal or data-protection advice.