Bernard Sonnenschein
14.8.2026

Shadow AI in companies: why unofficial AI use becomes a risk – and how to get it under control

Three-dimensional orange "AI" letters in front of an abstract, radiant background in shades of blue and orange
Download Article

Most management teams underestimate how much AI is already running inside their company – just not the approved kind. A representative Bitkom survey of 604 companies makes the gap plain. Four in ten assume their employees use private AI tools at work. At the same time, only a quarter officially provide access to generative AI.

The space between those two numbers is what the industry calls shadow AI. And that gap is not only a security problem, it is also a signal. Here is what is actually going on, which risks are real, and why the most obvious reaction – banning it – is usually the worst one.

What is shadow AI?

Shadow AI is employees using generative AI tools off their own initiative, without approval, without a policy and without IT knowing. The term borrows from shadow IT: software and services used inside a company that IT neither knows about nor has cleared.

In practice it looks like this. Someone pastes a draft contract into ChatGPT to have it summarised. A colleague in sales has Gemini write a customer email. Marketing tests an AI chatbot for editing copy. All through private accounts, all outside any form of control. Because generative AI is now available in any browser at any moment, shadow AI tends to creep in almost by accident, out of nothing more than wanting to get the job done faster.

The comparison with shadow IT is more than a borrowed phrase. Just as unapproved cloud services and apps once seeped into companies, AI tools are spreading today – only faster and with a far lower barrier to entry, because there is nothing to install. An ESCRIBA study from June 2026 shows the scale: almost half of all employees use AI tools without their manager's approval, and other surveys put the figure higher still. The exact number varies from study to study; the direction does not. In mid-sized companies, shadow AI is the rule rather than the exception.

Why shadow AI happens

The main reason is uncomfortable but simple. Where the official route is missing or too slow, people work around it. If only a quarter of companies provide official AI access while productivity pressure keeps rising, employees close the gap themselves.

The second driver is that it obviously works. Anyone saving several hours a week with AI support is not going to wait for an approval process that takes weeks. And that reflex runs through every level, not just the shop floor. According to a study of 2,001 employees in the US and the UK, almost two thirds of managers reach for unauthorised AI tools – twice as often as regular staff. That is exactly why executives need to set the example on AI. It is hard to demand clear rules from your teams while working in the shadows yourself.

There is a structural reason on top of that. Officially rolling out AI tools tends to get stuck in IT security reviews and procurement, while the tools themselves sit one click away. That mismatch between how fast the need arises and how slowly approval comes is the real breeding ground for shadow AI.

In our experience, shadow AI is therefore rarely a discipline problem. It is usually a sign that official processes are not keeping pace with day-to-day work.

Shadow AI risks: the four that are real

Wanting to work more productively is a good thing. Doing it without oversight is the problem. Four risk areas stand out.

Uncontrolled data leakage

The biggest risk lies in data leaving the building. Once customer records, strategy papers or HR information land in the free version of a generative AI tool, they are outside the company and can end up as training data. The ESCRIBA figures show how sensitive that material is: 42.7 per cent of respondents use AI for internal emails, 15.7 per cent process strategic information with it and just under 13 per cent apply it to customer data. Those are trade secrets on someone else's servers, not harmless boilerplate.

Data protection breaches

With no data processing agreement, no EU hosting and no contractual bar on training, processing personal data in private AI accounts is generally not GDPR compliant. We have covered in detail how to deploy AI tools on a sound legal footing, in our article on AI, data protection and the GDPR. Shadow AI bypasses precisely those safeguards.

Security and compliance gaps

When nobody knows which AI applications are in use, you get security holes no IT department can close, and risks nobody can quantify. Compliance risk follows. The EU AI Act imposes transparency and labelling obligations, and anyone who does not know where AI-generated content is finding its way into quotes and reports simply cannot meet them. The official overview of the EU AI Act sets out the applicable rules. Which security questions companies should settle before their first AI project is covered in our article on data security and AI.

Missing quality control

AI systems hallucinate. Unchecked output that quietly finds its way into customer correspondence or decisions can get expensive. Without a defined review step, nobody is doing that checking.

Why a ban is the wrong move

The instinctive reaction at many companies is a blanket ban. It sounds like control and achieves the opposite. A ban does nothing about why people are using these tools – the productivity pressure is still there. It only moves the behaviour to where nobody is looking: the private browser, the personal phone, outside every monitored system.

In doing so, a ban creates exactly the blind spot it was meant to prevent. The IBM Cost of a Data Breach Report 2025 shows what that blind spot costs. Shadow AI was involved in one in five data breaches and added roughly 670,000 US dollars per incident on average. In 97 per cent of those cases, basic access controls were missing. Driving usage underground raises the risk rather than lowering it.

Some companies take the easy option and deliberately look away. As long as nothing happens, quiet use is tolerated. But looking away is not a strategy, it is deferred risk. And when something does go wrong – a breach, an audit – there is no record at all of who put which data into which tool, and when.

Shadow AI is therefore not purely an employee problem, it is an infrastructure problem. And infrastructure problems are not solved with bans, but by offering people something better.

How to get shadow AI under control

The constructive route is not to push AI out of the company but to steer it into orderly channels. Instead of fighting it, you channel it: out of uncontrolled sprawl and into deliberate, secure use. Four steps work well in practice.

1. Create visibility

Ask openly and without blame what AI is already being used for in the team. Unofficial use tells you precisely where the greatest friction sits in day-to-day work.

2. Provide approved tools

Offer official, business-grade access – ChatGPT Enterprise, Claude for Work, Gemini in Google Workspace or Microsoft Copilot, with a data processing agreement and EU hosting. Give people a secure, fast option and there is no reason to go via a private account.

3. Define clear guardrails

An AI policy people can actually understand is the core of any workable AI governance. Above all it should answer four questions:

  • Which tools are approved for which use cases?
  • Which categories of data must never go into external AI systems?
  • How is AI-generated output reviewed and labelled?
  • Who is the point of contact for questions or incidents?

4. Build capability

Approved tools are of little use if nobody knows how to operate them safely. Ongoing training means people spot the risks, recognise hallucinations for what they are, and know what to do if something goes wrong.

The order matters. First the official access, then the rules. Ban it first and offer nothing in its place, and you drive people straight back into the shadows. This combination of visibility, tools, rules and skills is at the same time the basis for compliance and data protection, because you can only document, secure and evidence what is running officially.

How teams then use approved tools productively – from the single prompt to a structured working system, and how companies manage that transition in practice – is what you will hear first-hand at d:u27 on 13 and 14 April 2027 in Münster.

Reading shadow AI as a signal

In the end, a change of perspective pays off. Unofficial use is irritating, but it is also a free process analysis. It shows you in black and white where your teams are looking for support and which tasks lend themselves to secure, official AI use.

Take those signals seriously and a governance problem turns into a roadmap: identify the most common unofficial use cases, create a secure option for exactly those, and turn uncontrolled shadow AI into deliberate, productive AI use.

Conclusion: out of the shadows

In mid-sized companies, shadow AI has long been the rule rather than the exception. Ignoring it is dangerous, banning it is ineffective. The only approach that works is visibility, secure tools, clear rules and building AI skills. That turns an uncontrolled risk into a managed competitive advantage – and lets your people finally do openly, and safely, what they are already doing anyway.

How other companies are walking that path, from AI governance through to practical rollout, is best learned from the people who have done it. d:u27 on 13 and 14 April 2027 in Münster brings together around 17,000 participants across six stages, with more than 80 masterclasses and over 350 speakers, including a dedicated SME Stage that tackles exactly these questions in practical terms. Secure your tickets for d:u27 now!

GET YOUR TICKETS NOW
for the d:u27!
On April 13 & 14, 2027 the data:unplugged Festival, d:u27, will take place for the fourth time in Münster.