Shadow AI in the company: how to find it, write an AI usage policy and offer an approved tool
Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software
- Shadow AI is the use of AI tools for work without the approval of IT and the data protection officer: public chatbots on personal accounts, AI browser extensions, meeting note-takers, AI features in SaaS tools and coding assistants that developers pay for themselves
- On a personal account the consumer terms apply: as of October 2026, OpenAI says it may use content from its services for individuals, such as ChatGPT, to train its models unless the user opts out, and by default not from ChatGPT Business, Enterprise, Edu or its API
- Personal data in a prompt on a personal account reaches the provider without the contract that Article 28(3) of the GDPR requires for processing on the company’s behalf, and Chapter V on transfers applies where the data goes to a third country
- Proxy and DNS logs, CASB discovery reports, expense claims, browser extension inventories and OAuth app grants show which AI services are used and by which departments
- A workable set of controls combines an approved tool, DLP on pastes and uploads, warning or block pages for other AI services, a workspace restriction header such as ChatGPT Enterprise’s and AI literacy training under Article 4 of the AI Act
Eurokommerz × Vixen.UNO: Private AI/ML Talk to an expert →
What shadow AI is and how common it is
Shadow AI is the use of AI tools for work without the approval, and often without the knowledge, of IT, security and the data protection officer. Typical forms are public chatbots on personal accounts, AI browser extensions, note-takers that join video calls, AI features switched on inside SaaS tools and coding assistants that developers pay for themselves. Prompts and files then leave the company under terms it has not reviewed, which can conflict with client contracts and the GDPR, and, according to the Commission, the AI Act’s literacy duty covers staff who use such tools for work. The answer is discovery, a usage policy, technical controls and an approved tool for the same tasks.
IBM’s Cost of a Data Breach Report 2025, published on 30 July 2025, covers breaches at 600 organisations. In IBM’s words, “One in five organizations reported a breach due to shadow AI, and only 37% have policies to manage AI or detect shadow AI.” A global study led by the University of Melbourne with KPMG surveyed more than 48,000 people in 47 countries. According to a KPMG press release of 9 May 2025, almost half of employees admit to using AI in ways that contravene company policies, including uploading sensitive company information into public AI tools.
Shadow AI risks: where prompts and uploads go
What happens to a prompt depends on the account type more than on the provider. OpenAI’s help centre, read on 6 October 2026, says that for its services for individuals, such as ChatGPT, “we may use your content to train our models”, unless the user turns off Improve the model for everyone under Settings, Data controls. OpenAI adds that, even after an opt-out, a conversation the user rates with a thumbs up or down may be used to improve its models. For ChatGPT Business, Enterprise, Edu and its API, it says inputs and outputs are not used to improve its models by default. On a personal account the setting belongs to the employee, and the company can neither check nor enforce it.
Google’s Gemini Apps privacy hub for personal Google Accounts, as read on 6 October 2026, asks users not to enter confidential information “that you wouldn’t want a reviewer to see” and says that chats reviewed by human reviewers are retained for up to three years, even when the user deletes the activity. The European Data Protection Supervisor’s revised orientations on generative AI (28 October 2025), written for the EU institutions, describe the mechanism: “Once in production, some systems use the input data obtained through the interaction with users as a new training dataset to refine the model.”
The ENISA Threat Landscape 2026, published in September 2026, says AI applications and their ecosystems “are increasingly becoming targets, particularly where they have access to files, credentials, browser sessions or development environments”. An AI browser extension that reads every page, or a note-taker connected to mailboxes and calendars, has that access, and the documents and emails it reads can carry injected instructions, as our article on prompt injection and LLM security explains.
GDPR, client contracts and the AI Act literacy duty
The company is normally the controller of the personal data its staff handle at work, and pasting it into a chatbot discloses it to the provider. A personal account gives the company no data processing agreement (DPA) with the provider, the contract that Article 28(3) of the GDPR requires for processing on its behalf. Where the data goes to a recipient in a third country, Article 44 allows the transfer only under the conditions of Chapter V. Article 9(1) prohibits processing health data and the other special categories unless an exception in Article 9(2) applies. Client contracts and NDAs often restrict disclosure of confidential information to named parties. Whether a given use was lawful, and whether it is a personal data breach, is a legal assessment for your data protection officer and legal department.
Article 4 of the AI Act has applied since 2 February 2025 and, as amended by Regulation (EU) 2026/1744, the Digital Omnibus on AI, asks providers and deployers to take measures “to support the development of AI literacy” of their staff. The Commission’s AI literacy Q&A, last updated on 27 July 2026, asks whether a company whose employees use ChatGPT for writing advertisement text or translating text has to comply with Article 4, and answers “Yes, they should be informed about the specific risks, for example hallucination.” Our EU AI Act guide for companies running LLMs covers the deployer duties and dates.
How to find shadow AI: proxy, DNS, CASB and expense data
Start with logs the company already keeps. A forward proxy or secure web gateway records the host name of each request, the user where authentication is on and the bytes sent, so it shows which AI services are used, by whom and how much data goes up. Where the gateway or CASB has a category for generative AI services, filter on it.
| SOURCE | WHAT IT SHOWS | WHAT IT MISSES |
|---|---|---|
| Proxy or secure web gateway | AI services by host name, users, upload volume | traffic outside the company network; AI features inside SaaS tools |
| DNS resolver logs | devices looking up AI service domains | user and content; clients using other resolvers |
| CASB or SSE discovery | services by category, users and data volume | services its catalogue does not know yet |
| Expense claims, card data | paid personal subscriptions to AI services | unpaid accounts |
| Browser management | installed extensions and their permissions | unmanaged browsers |
| IdP and SaaS app grants | third-party apps with access to mail, files or calendars | tools without company sign-in |
| Anonymous staff survey | the tasks people use AI for, and why | what people prefer not to report |
Our summary of what each source records; field names and categories differ by product.
These logs identify employees, so they are personal data too. Agree the purpose and the level of detail with your data protection officer (DPO), and involve workers’ representatives where the company has them, before any report names individuals. A report by department and service is enough to decide which approved tool to offer.
What an AI usage policy for employees contains
A usage policy states which tools are approved and with which account type, which data classes may go into each, how a new tool is approved, what is logged and who may read the logs, how outputs are checked and which training comes before access.
| DATA CLASS | PERSONAL ACCOUNT | BUSINESS PLAN, DPA | INTERNAL ASSISTANT |
|---|---|---|---|
| Public information | allowed | allowed | allowed |
| Internal, not confidential | not allowed | allowed | allowed |
| Client data under NDA | not allowed | where the client contract allows | allowed, within access rights |
| Personal data | not allowed | after DPO review of the terms | allowed, with the query log |
| Health and other Art. 9 data | not allowed | not allowed | for DPO-approved processes only |
| Source code, configurations | not allowed | as the repository owner decides | allowed |
| Passwords, keys, tokens | not allowed | not allowed | not allowed |
An example policy; special categories as in Article 9(1) GDPR. The classes and decisions are yours, and the personal data rows need your data protection officer.
The policy also needs a rule that AI output is not used to filter job applications, evaluate staff or assess the creditworthiness of natural persons unless the company has decided on that use separately, because Annex III of the AI Act lists such purposes for high-risk systems. A new tool is approved in five steps.
- The requester names the tool, the task, the users and the data classes.
- IT security checks single sign-on, admin controls, logging and where the data is processed.
- The data protection officer checks the terms on training and retention, the DPA and any transfer to a third country.
- Legal checks the client contracts if client data is involved.
- The tool enters the approved list with its data classes, or the requester receives a reason and the approved alternative.
Technical controls: block, warn or allow with conditions
A secure web gateway can block a service, show a warning page the user acknowledges before continuing, or allow it. Blocking every AI service before an approved tool exists can move the same prompts to personal phones, outside every company log, so the warning page should link to the approved tool. Category and host name decisions work without decrypting traffic. On an HTTPS site, the warning page and any check of what is pasted or uploaded need TLS inspection on the gateway or an agent on the endpoint or in the browser; without them, a warning ends in a connection error.
As of October 2026, OpenAI documents Workspace Blocking for ChatGPT Enterprise, which lets the company’s own workspaces through and keeps personal accounts out. The gateway inserts the header ChatGPT-Allowed-Workspace-Id with the allowed workspace IDs into requests to chatgpt.com, and “any other workspaces (including personal workspaces) are filtered out by the system”. This requires TLS inspection, and the ChatGPT desktop and mobile apps then need your certificates in their pin list, distributed through MDM.
Chrome’s ExtensionSettings policy, for example, takes entries that allow approved extension IDs, a list of blocked permissions and a default entry * set to blocked, which stops installation of anything else from the Chrome Web Store. In the identity provider, require administrator approval for third-party apps that ask for access to mail, files or calendars, which is how many AI note-takers connect, and put the AI features of SaaS tools you already pay for through the same approval as a new tool.
Offering an approved AI tool before you block
Staff who use public chatbots have tasks for which the company offers no tool, and a block alone does not remove those tasks. The approved tool can be a business plan of a public service, with a data processing agreement and single sign-on, or an internal assistant on GPU servers under your control. Our guide to a private ChatGPT alternative lists the parts of an internal assistant, from the model server to permission-aware document search and the query log. Which option costs less depends on token volume, and the data class can decide before cost does, as our comparison of a private LLM and a cloud API shows; the two can run side by side, with personal and client data on the internal assistant.
Our Private AI/ML service builds that platform under your control: public APIs are used only for tasks you enable, and what goes there is visible in the query log. Tell us which public AI tools your staff use today and for which tasks.
A shadow AI programme step by step
Discovery shows what to offer, and the approved tool has to exist before blocking starts. In the monthly review, traffic that still goes to unapproved tools points to tasks the approved tool does not cover yet.
| STEP | TOOL | OWNER |
|---|---|---|
| Find current use | gateway, DNS, CASB and expense reports | IT security, with the DPO |
| Classify data | classification scheme, the matrix above | information security, DPO |
| Decide on tools | approved list with account types | CIO, DPO and legal |
| Offer the approved tool | business plan with a DPA, or an internal assistant | IT |
| Train before access | AI literacy measures per role, with a record | HR with IT |
| Enforce | warning or block pages, DLP, workspace header | IT security |
| Review monthly | gateway report against the approved list | information security |
Our summary; the owners are an example.
Staff complete the training before they get access to the approved tool. The Commission’s Q&A says no certificate is needed and that organisations “can keep an internal record of trainings and/or other guiding initiatives”. Users learn which data may go into which tool and how to check an answer against its source; our guide to AI literacy training under Article 4 sets out the content per role.
We start with a pilot on one process with clear metrics, such as the task your staff most often take to public chatbots. Describe that task and who does it in the form below.
What we do
Our Private AI/ML service starts where this article does, with employees who already use public chatbots on their own while the company cannot see which work data goes there. We build an AI platform under your control, on your servers or on dedicated hardware in a Tier-3 data centre in Lithuania, where nothing goes to public services unless you explicitly enable it and a query log with data and permissions management shows how it is used. We scale only what has proved its value in the pilot and train your team to run the platform and develop it further. Eurokommerz holds the contract and supplies the hardware, with engineering by our partner Vixen.UNO; the first call is free of charge, and the price of the technical assessment is fixed before work begins. Data handling during a project is set out on our security and compliance page.
FAQ
What is shadow AI?
What are the risks of shadow AI?
How do you detect shadow AI in a company?
What should a generative AI usage policy for employees include?
Should a company block ChatGPT or allow it under a policy?
Does the AI Act require training for employees who use ChatGPT?
Send us a list of the AI tools your staff use or you suspect they use, the departments and tasks involved, your data classes and where your documents are stored. We reply within one business day to arrange a first call, from which you leave with two or three possible solution scenarios. The first call is free of charge.
Talk to an expertWe reply within one business day