Somewhere in your company, right now, someone is pasting a customer email into ChatGPT to draft a reply. Someone else is summarising a contract, translating a complaint or cleaning up a spreadsheet the same way. None of it went through IT, and nearly all of it is done with good intentions. This is shadow AI: AI used at work without the organisation's knowledge or approval. It's two things at once: a real privacy risk, and an unusually honest map of your automation opportunities.
Note: this is practical guidance, not legal advice. Whether a particular use of AI breaches the GDPR or the EU AI Act depends on the tool, its terms, the data and your agreements. Check your own situation with your privacy officer or counsel.
How common is shadow AI?
Very. In Microsoft and LinkedIn's 2024 Work Trend Index, a survey of 31,000 people in 31 countries, 75% of knowledge workers said they used generative AI at work, and 78% of those users brought their own AI tools to work. More than half (52%) were reluctant to admit using it for their most important tasks (Microsoft). MIT's 2025 study of AI in business also highlighted widespread use of unsanctioned tools like ChatGPT running alongside the official projects (Fortune).
If your company has no approved AI tools, that doesn't mean nobody uses AI. It means you don't know how they use it.
What can go wrong
The risk isn't that people use AI. It's what they put into it. In August 2024 the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) said it had received several data breach notifications caused by employees entering personal data into AI chatbots. In one, an employee of a GP practice had entered patients' medical data, against the practice's own agreements. In another, a telecom employee had entered a file that included customer addresses (Autoriteit Persoonsgegevens). The regulator's point was simple: most chatbot providers store what is entered, so the data ends up on their servers, and the people it's about don't know.
Beyond privacy, shadow AI causes quieter problems:
- Confidentiality. Contracts, pricing and client documents leave your control under terms you never agreed to.
- No audit trail. When an AI-drafted answer turns out to be wrong, nobody can see what was asked, what came back or who sent it.
- Inconsistent quality. Ten people with ten prompts produce ten versions of your company's voice and ten levels of accuracy.
- Lost knowledge. A clever workflow that lives in one person's browser history leaves when they do.
What the law now expects
Two parts of the EU AI Act are worth knowing here, both as they stand after the Digital Omnibus on AI came into force on 27 July 2026 (Lewis Silkin):
- AI literacy (Article 4). Organisations that provide or deploy AI systems must take measures to support AI literacy among their staff and others operating AI on their behalf. The Omnibus softened the original wording, so no specific level is required of each person, but you should be able to show the training and awareness measures you've taken. That's hard to do for tools you don't know are in use.
- Transparency (Article 50). Since 2 August 2026, people must be told when they're interacting with an AI system. If you turn a shadow habit into something customer-facing, such as a website chatbot or an AI receptionist, it has to say it's AI.
Our EU AI Act guide for businesses covers the wider risk tiers.
Why banning it doesn't work
The instinctive response is a memo: no ChatGPT at work. It rarely survives the first busy week. People who've found a tool that saves them an hour a day don't stop using it; they stop mentioning it, which moves the risk somewhere you can't see. The Work Trend Index figure is the tell: when more than half of users already hesitate to admit using AI for important work, a ban mostly produces silence.
There's a better reason not to ban it. Shadow AI is demand. Every paste into a chatbot is an employee telling you, precisely, which part of their job is repetitive enough to hand to a machine.
Shadow AI is your automation backlog
Look at what people actually use it for and a pattern appears. In most offices the list looks similar:
- Summarising long emails, documents and threads. A sign that information arrives in a form nobody has time to read.
- Drafting replies to routine questions. A sign that the same questions arrive every day.
- Reformatting and cleaning data. A sign that two systems don't talk to each other.
- Pulling details out of PDFs. A sign that documents are being retyped by hand.
- Translating. A sign that customers or colleagues work in more than one language.
Each of these is a process that could be automated properly: inside your systems, with your data protected and a log of what happened. We explain how to rank them in which business processes to automate with AI first.
How we look at shadow AI on site
When the engineer who will build your system spends one to three days in your office as part of a forward deployed engagement, shadow AI is one of the first things we ask about, because it points straight at the repetitive work. How we ask matters:
- No blame, stated up front. Leadership says in advance that the goal is to learn, not to discipline. Without that, nobody tells you anything useful.
- A short anonymous survey before we arrive. Which tools, for which tasks, how often, and what kind of data goes in.
- Conversations at the desk. People show us the prompts and workflows they rely on, which is where the real detail is.
- No surveillance. We don't install monitoring software or read browser histories. Trust gets you better information than tracking does.
Every use then lands in one of three groups:
- Approve. Low-risk uses that a sanctioned business tool handles well. Give people the approved version and move on.
- Build properly. Valuable, recurring uses that touch real data. These become governed systems.
- Stop. Personal, patient or confidential data going into consumer tools. These need a clear rule and a safe alternative, quickly, and where personal data has already gone in, a check with your privacy officer on whether it's a reportable breach.
The build-properly group becomes the written scope: a fixed price and a date for the first system.
Turning shadow habits into safe automation
For the uses worth building, governed means a few concrete things:
- Business terms, not consumer ones. Accounts where your inputs aren't used to train models, with a processor agreement in place.
- The right hosting for the data. European hosting as standard, and self-hosted models where the data is too sensitive to leave your infrastructure.
- Inside the workflow. The summary appears in the ticket, the draft reply in the inbox, the extracted data in the ERP. Nobody copies and pastes anything.
- Access control and logging. People see only what their role allows, and every request and response is logged and kept only as long as your retention policy allows.
- Human review where it matters. Anything sent to a customer is checked by a person until the numbers show it can be trusted, and anything touching health data stays under human review.
An internal knowledge assistant is often the first system worth building. It replaces one of the most common shadow uses, asking a chatbot about your own documents, with one that answers from your sources and cites them.
What goes in a one-page AI use policy
You don't need a thirty-page framework. One page that people actually read beats it. Cover:
- Approved tools, and the kinds of work each is approved for.
- Data that must never go into unapproved tools: personal data, patient data, client documents and passwords.
- How to request a new tool, with a fast and friendly answer.
- Who checks AI output before it goes to a customer.
- What to do after a mistake: who to tell and how quickly, so a possible data breach can be assessed and, if needed, reported.
- Where to learn: short training that counts towards your AI literacy measures.
Shadow AI is what happens when your people are ahead of your systems. The fix isn't to slow them down; it's to catch the systems up. Neurova AI builds AI to healthcare standards, whether or not you work in healthcare, and turns the uses your team already relies on into governed systems you own. If you'd like the engineer who would build it to see how your team really works first, ask for an on-site visit.
Frequently asked questions
What is shadow AI? Shadow AI is the use of AI tools at work without the organisation's approval or oversight, typically staff using personal ChatGPT, Gemini or Claude accounts to draft emails, summarise documents or clean up data. It is usually well-intentioned, but company and personal data can end up with providers the organisation has no agreement with.
Should we ban ChatGPT at work? A blanket ban rarely works. People who find AI useful keep using it, just less visibly. A better approach is to approve suitable business tools, state clearly which data must never be entered, and build governed versions of the most common uses so staff have a safe alternative.
Is putting customer data into ChatGPT a data breach? It can be. The Dutch Data Protection Authority has warned that when employees enter personal data into AI chatbots against their employer's agreements, that is a data breach, and reporting it is mandatory in many cases. Whether a specific case counts depends on the tool, its terms, the data and your agreements, so check with your privacy officer or counsel.