BLOG · GUIDE ·

Shadow AI in the company: how to find it, write an AI usage policy and offer an approved tool

Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software

IN BRIEF
  • Shadow AI is the use of AI tools for work without the approval of IT and the data protection officer: public chatbots on personal accounts, AI browser extensions, meeting note-takers, AI features in SaaS tools and coding assistants that developers pay for themselves
  • On a personal account the consumer terms apply: as of October 2026, OpenAI says it may use content from its services for individuals, such as ChatGPT, to train its models unless the user opts out, and by default not from ChatGPT Business, Enterprise, Edu or its API
  • Personal data in a prompt on a personal account reaches the provider without the contract that Article 28(3) of the GDPR requires for processing on the company’s behalf, and Chapter V on transfers applies where the data goes to a third country
  • Proxy and DNS logs, CASB discovery reports, expense claims, browser extension inventories and OAuth app grants show which AI services are used and by which departments
  • A workable set of controls combines an approved tool, DLP on pastes and uploads, warning or block pages for other AI services, a workspace restriction header such as ChatGPT Enterprise’s and AI literacy training under Article 4 of the AI Act

Eurokommerz × Vixen.UNO: Private AI/ML  Talk to an expert →

What shadow AI is and how common it is

Shadow AI is the use of AI tools for work without the approval, and often without the knowledge, of IT, security and the data protection officer. Typical forms are public chatbots on personal accounts, AI browser extensions, note-takers that join video calls, AI features switched on inside SaaS tools and coding assistants that developers pay for themselves. Prompts and files then leave the company under terms it has not reviewed, which can conflict with client contracts and the GDPR, and, according to the Commission, the AI Act’s literacy duty covers staff who use such tools for work. The answer is discovery, a usage policy, technical controls and an approved tool for the same tasks.

IBM’s Cost of a Data Breach Report 2025, published on 30 July 2025, covers breaches at 600 organisations. In IBM’s words, “One in five organizations reported a breach due to shadow AI, and only 37% have policies to manage AI or detect shadow AI.” A global study led by the University of Melbourne with KPMG surveyed more than 48,000 people in 47 countries. According to a KPMG press release of 9 May 2025, almost half of employees admit to using AI in ways that contravene company policies, including uploading sensitive company information into public AI tools.

Shadow AI risks: where prompts and uploads go

What happens to a prompt depends on the account type more than on the provider. OpenAI’s help centre, read on 6 October 2026, says that for its services for individuals, such as ChatGPT, “we may use your content to train our models”, unless the user turns off Improve the model for everyone under Settings, Data controls. OpenAI adds that, even after an opt-out, a conversation the user rates with a thumbs up or down may be used to improve its models. For ChatGPT Business, Enterprise, Edu and its API, it says inputs and outputs are not used to improve its models by default. On a personal account the setting belongs to the employee, and the company can neither check nor enforce it.

Google’s Gemini Apps privacy hub for personal Google Accounts, as read on 6 October 2026, asks users not to enter confidential information “that you wouldn’t want a reviewer to see” and says that chats reviewed by human reviewers are retained for up to three years, even when the user deletes the activity. The European Data Protection Supervisor’s revised orientations on generative AI (28 October 2025), written for the EU institutions, describe the mechanism: “Once in production, some systems use the input data obtained through the interaction with users as a new training dataset to refine the model.”

The ENISA Threat Landscape 2026, published in September 2026, says AI applications and their ecosystems “are increasingly becoming targets, particularly where they have access to files, credentials, browser sessions or development environments”. An AI browser extension that reads every page, or a note-taker connected to mailboxes and calendars, has that access, and the documents and emails it reads can carry injected instructions, as our article on prompt injection and LLM security explains.

GDPR, client contracts and the AI Act literacy duty

The company is normally the controller of the personal data its staff handle at work, and pasting it into a chatbot discloses it to the provider. A personal account gives the company no data processing agreement (DPA) with the provider, the contract that Article 28(3) of the GDPR requires for processing on its behalf. Where the data goes to a recipient in a third country, Article 44 allows the transfer only under the conditions of Chapter V. Article 9(1) prohibits processing health data and the other special categories unless an exception in Article 9(2) applies. Client contracts and NDAs often restrict disclosure of confidential information to named parties. Whether a given use was lawful, and whether it is a personal data breach, is a legal assessment for your data protection officer and legal department.

Article 4 of the AI Act has applied since 2 February 2025 and, as amended by Regulation (EU) 2026/1744, the Digital Omnibus on AI, asks providers and deployers to take measures “to support the development of AI literacy” of their staff. The Commission’s AI literacy Q&A, last updated on 27 July 2026, asks whether a company whose employees use ChatGPT for writing advertisement text or translating text has to comply with Article 4, and answers “Yes, they should be informed about the specific risks, for example hallucination.” Our EU AI Act guide for companies running LLMs covers the deployer duties and dates.

How to find shadow AI: proxy, DNS, CASB and expense data

Start with logs the company already keeps. A forward proxy or secure web gateway records the host name of each request, the user where authentication is on and the bytes sent, so it shows which AI services are used, by whom and how much data goes up. Where the gateway or CASB has a category for generative AI services, filter on it.

SOURCEWHAT IT SHOWSWHAT IT MISSES
Proxy or secure web gatewayAI services by host name, users, upload volumetraffic outside the company network; AI features inside SaaS tools
DNS resolver logsdevices looking up AI service domainsuser and content; clients using other resolvers
CASB or SSE discoveryservices by category, users and data volumeservices its catalogue does not know yet
Expense claims, card datapaid personal subscriptions to AI servicesunpaid accounts
Browser managementinstalled extensions and their permissionsunmanaged browsers
IdP and SaaS app grantsthird-party apps with access to mail, files or calendarstools without company sign-in
Anonymous staff surveythe tasks people use AI for, and whywhat people prefer not to report

Our summary of what each source records; field names and categories differ by product.

These logs identify employees, so they are personal data too. Agree the purpose and the level of detail with your data protection officer (DPO), and involve workers’ representatives where the company has them, before any report names individuals. A report by department and service is enough to decide which approved tool to offer.

What an AI usage policy for employees contains

A usage policy states which tools are approved and with which account type, which data classes may go into each, how a new tool is approved, what is logged and who may read the logs, how outputs are checked and which training comes before access.

DATA CLASSPERSONAL ACCOUNTBUSINESS PLAN, DPAINTERNAL ASSISTANT
Public informationallowedallowedallowed
Internal, not confidentialnot allowedallowedallowed
Client data under NDAnot allowedwhere the client contract allowsallowed, within access rights
Personal datanot allowedafter DPO review of the termsallowed, with the query log
Health and other Art. 9 datanot allowednot allowedfor DPO-approved processes only
Source code, configurationsnot allowedas the repository owner decidesallowed
Passwords, keys, tokensnot allowednot allowednot allowed

An example policy; special categories as in Article 9(1) GDPR. The classes and decisions are yours, and the personal data rows need your data protection officer.

The policy also needs a rule that AI output is not used to filter job applications, evaluate staff or assess the creditworthiness of natural persons unless the company has decided on that use separately, because Annex III of the AI Act lists such purposes for high-risk systems. A new tool is approved in five steps.

  1. The requester names the tool, the task, the users and the data classes.
  2. IT security checks single sign-on, admin controls, logging and where the data is processed.
  3. The data protection officer checks the terms on training and retention, the DPA and any transfer to a third country.
  4. Legal checks the client contracts if client data is involved.
  5. The tool enters the approved list with its data classes, or the requester receives a reason and the approved alternative.

Technical controls: block, warn or allow with conditions

A secure web gateway can block a service, show a warning page the user acknowledges before continuing, or allow it. Blocking every AI service before an approved tool exists can move the same prompts to personal phones, outside every company log, so the warning page should link to the approved tool. Category and host name decisions work without decrypting traffic. On an HTTPS site, the warning page and any check of what is pasted or uploaded need TLS inspection on the gateway or an agent on the endpoint or in the browser; without them, a warning ends in a connection error.

As of October 2026, OpenAI documents Workspace Blocking for ChatGPT Enterprise, which lets the company’s own workspaces through and keeps personal accounts out. The gateway inserts the header ChatGPT-Allowed-Workspace-Id with the allowed workspace IDs into requests to chatgpt.com, and “any other workspaces (including personal workspaces) are filtered out by the system”. This requires TLS inspection, and the ChatGPT desktop and mobile apps then need your certificates in their pin list, distributed through MDM.

Chrome’s ExtensionSettings policy, for example, takes entries that allow approved extension IDs, a list of blocked permissions and a default entry * set to blocked, which stops installation of anything else from the Chrome Web Store. In the identity provider, require administrator approval for third-party apps that ask for access to mail, files or calendars, which is how many AI note-takers connect, and put the AI features of SaaS tools you already pay for through the same approval as a new tool.

Offering an approved AI tool before you block

Staff who use public chatbots have tasks for which the company offers no tool, and a block alone does not remove those tasks. The approved tool can be a business plan of a public service, with a data processing agreement and single sign-on, or an internal assistant on GPU servers under your control. Our guide to a private ChatGPT alternative lists the parts of an internal assistant, from the model server to permission-aware document search and the query log. Which option costs less depends on token volume, and the data class can decide before cost does, as our comparison of a private LLM and a cloud API shows; the two can run side by side, with personal and client data on the internal assistant.

Our Private AI/ML service builds that platform under your control: public APIs are used only for tasks you enable, and what goes there is visible in the query log. Tell us which public AI tools your staff use today and for which tasks.

A shadow AI programme step by step

Discovery shows what to offer, and the approved tool has to exist before blocking starts. In the monthly review, traffic that still goes to unapproved tools points to tasks the approved tool does not cover yet.

STEPTOOLOWNER
Find current usegateway, DNS, CASB and expense reportsIT security, with the DPO
Classify dataclassification scheme, the matrix aboveinformation security, DPO
Decide on toolsapproved list with account typesCIO, DPO and legal
Offer the approved toolbusiness plan with a DPA, or an internal assistantIT
Train before accessAI literacy measures per role, with a recordHR with IT
Enforcewarning or block pages, DLP, workspace headerIT security
Review monthlygateway report against the approved listinformation security

Our summary; the owners are an example.

Staff complete the training before they get access to the approved tool. The Commission’s Q&A says no certificate is needed and that organisations “can keep an internal record of trainings and/or other guiding initiatives”. Users learn which data may go into which tool and how to check an answer against its source; our guide to AI literacy training under Article 4 sets out the content per role.

We start with a pilot on one process with clear metrics, such as the task your staff most often take to public chatbots. Describe that task and who does it in the form below.

What we do

Our Private AI/ML service starts where this article does, with employees who already use public chatbots on their own while the company cannot see which work data goes there. We build an AI platform under your control, on your servers or on dedicated hardware in a Tier-3 data centre in Lithuania, where nothing goes to public services unless you explicitly enable it and a query log with data and permissions management shows how it is used. We scale only what has proved its value in the pilot and train your team to run the platform and develop it further. Eurokommerz holds the contract and supplies the hardware, with engineering by our partner Vixen.UNO; the first call is free of charge, and the price of the technical assessment is fixed before work begins. Data handling during a project is set out on our security and compliance page.

FAQ

What is shadow AI?
Shadow AI is the use of AI tools for work without the approval, and often without the knowledge, of IT, security and the data protection officer. It covers public chatbots on personal accounts, AI browser extensions, meeting note-takers, AI features switched on in SaaS tools and coding assistants that developers pay for themselves. IBM’s Cost of a Data Breach Report 2025, based on breaches at 600 organisations, found that one in five of them reported a breach due to shadow AI.
What are the risks of shadow AI?
Prompts and uploads leave the company under consumer terms it has not reviewed; as of October 2026, OpenAI, for example, says it may use content from its services for individuals, such as ChatGPT, to train its models unless the user opts out. Personal data in those prompts reaches a provider without the contract that Article 28(3) of the GDPR requires for processing on the company’s behalf, client contracts may forbid the disclosure, and unvetted extensions or note-takers gain access to browser sessions, mail and files. The AI literacy duty in Article 4 of the AI Act also covers staff who use such tools for work, according to the Commission’s Q&A.
How do you detect shadow AI in a company?
Start with proxy or secure web gateway logs and DNS resolver logs filtered on generative AI services, and with a CASB or SSE discovery report if you have one. Add finance data for paid personal subscriptions, browser management reports for installed extensions and the identity provider’s list of third-party apps with access to mail and files. Agree the purpose and the level of detail with your data protection officer first, because these logs identify employees.
What should a generative AI usage policy for employees include?
It should name the approved tools and the account type for each, say which data classes may go into each tool and describe how a new tool is approved. It should also state what is logged and who may read the logs, how outputs are checked before use and which training staff complete before access. Uses such as filtering job applications or evaluating staff need a separate decision, because Annex III of the AI Act lists such purposes for high-risk systems.
Should a company block ChatGPT or allow it under a policy?
Blocking public chatbots without an approved alternative can move the same prompts to personal devices, where no company log or DLP rule applies. A workable setup approves a business plan or an internal assistant, shows a warning page that links to it for other AI services and stops uploads of confidential data classes with DLP, both of which need TLS inspection or an agent on the endpoint or in the browser. For ChatGPT Enterprise, OpenAI documents a header that the gateway inserts so that only the company’s workspaces are reachable and personal workspaces are filtered out.
Does the AI Act require training for employees who use ChatGPT?
Article 4 of the AI Act, applicable since 2 February 2025 and amended by Regulation (EU) 2026/1744, requires providers and deployers to take measures to support the development of AI literacy of their staff. Asked about employees who use ChatGPT for writing advertisement text or translating text, the Commission’s AI literacy Q&A answers that they should be informed about the specific risks, for example hallucination. The same Q&A says no certificate is needed and organisations can keep an internal record of trainings.

Send us a list of the AI tools your staff use or you suspect they use, the departments and tasks involved, your data classes and where your documents are stored. We reply within one business day to arrange a first call, from which you leave with two or three possible solution scenarios. The first call is free of charge.

Talk to an expert
Talk to an expert

We reply within one business day

By sending this form you agree that we process your details to answer your enquiry – see our privacy policy.

request@eurokommerz.at
Jordangasse 7, 1010 Vienna