Shadow AI
Shadow AI is the use of AI tools inside an organisation without approval, oversight or a contract — typically a personal account on a public chat service, used with work documents. It is not an edge case: in most organisations it is the default state at the point where anyone first asks the question. Obligations attach to actual use rather than approved use, which is why it matters legally and not only culturally.
Why prohibition alone reliably fails
Because a ban does not remove the reason the tool was used. The work still has to be done, and the instruction to stop using a public chat service changes where it happens rather than whether it happens. The observable result is not less use but less visible use, through personal devices and personal accounts.
The sequence that works is inverted: first an approved path that solves the task at least as well, then the rule. A policy without an approved alternative is a written explanation of why the shadow use will continue.
What is actually at stake
Three things, in ascending order of cost. Confidentiality: a free consumer account carries no processor agreement, so there is no lawful basis for putting personal data or client material into it. Evidence: nobody can say what was pasted where, which makes an incident impossible to scope. And correctness: output nobody reviewed enters documents that go to customers.
The second is the one that turns a small problem into a large one. An incident whose extent cannot be established has to be treated as the worst case it could have been.
How to surface it without driving it further underground
Ask without a sanction attached, and say so credibly in advance. An inventory conducted as an amnesty produces a usable list; one conducted as an investigation produces a short list and a long tail nobody mentions.
The useful question is not "do you use AI" — which invites a defensive answer — but "which part of your work is slowest, and what have you tried". The tools surface on their own, along with the reason, which is the part you actually need in order to offer a replacement.
What it is not to be confused with
Shadow IT
The older phenomenon and the same mechanism: departments procure what they need when the official route is slow. Shadow AI differs in what leaves the building — not a subscription, but the content of documents, one paste at a time.
An approved tool used wrongly
Different problem, different fix. Misuse of an approved tool is a training and configuration question. Shadow use is a procurement and speed question: the approved route was too slow or did not exist.
Frequently asked
How widespread is it really?+
Every honest inventory we have seen finds more than expected, and the pattern is consistent: the tools are concentrated in the functions with the most text work — sales, HR, legal, support. The number matters less than the composition, because it tells you which approved alternative to provide first.
Is it a GDPR breach by itself?+
Using a tool is not a breach; putting personal data into a service with no processor agreement and no lawful basis is. Because a free consumer account carries neither, the two collapse in practice. The narrower question worth asking is what categories of data actually went in — that determines whether you have a notification duty.
What should the policy actually say?+
Five things, on two pages: which tools are approved, by name; which data may go in and which explicitly may not; who reviews output before it leaves the building; how a new tool gets approved; and whom to tell when something looks wrong. Anything longer does not get read, and a policy nobody reads is indistinguishable from no policy.
Does the EU AI Act apply to shadow use?+
Yes, and this is the point most often missed. Obligations attach to actual deployment, not to what management approved. If staff are using a system that interacts with customers, Article 50 transparency applies regardless of whether anyone signed off on it.
Related terms
The inventory that has to come first
Ask what is actually in use, with no sanction attached and that said credibly in advance. The list will be longer than expected, and it is the only honest starting point for everything downstream.
Request a test