Shadow AI in Companies: How to Detect It Without Spying, and How to Channel It
· CompaniesAutomation
Your team is already using AI nobody approved. The five real risks, four ways to detect it without surveillance, the one-page policy and a 30-day plan.
Shadow AI is the use of AI tools nobody approved, contracted or reviewed: the salesperson pasting a client contract into a free chatbot to summarise it, the marketer uploading the customer list to a tool whose terms nobody read, the developer using a coding assistant on a personal account. It is not sabotage. It is people trying to work faster with whatever is within reach.
Which is exactly why banning it does not work. When a company blocks access without offering an alternative, the usage does not disappear — it moves to personal phones, where there is no log, no policy and no way to know what left the building. What does work is surfacing the real usage, understanding why it exists, and replacing it with something better and official. We have run this exercise in our own company and in clients', and the pattern repeats almost every time.
What are the real risks of shadow AI?
Five, and only the first is the one everyone mentions. Ordering them matters, because they do not share the same likelihood or the same cost.
- Confidential information leaving. Contracts, price lists, customer data and proprietary code pasted into tools whose terms nobody read. On free plans, content can be used to improve the service unless that is explicitly disabled.
- GDPR breach. If an employee uploads personal data to a service the company never contracted, there is no data processing agreement, no international transfer safeguards and no documented legal basis. The controller is still the company.
- AI Act breach. The AI literacy obligation has applied since February 2025, and widespread use of unapproved tools is the clearest evidence that nobody trained anyone. If unreviewed generated content also gets published, Article 50 transparency comes into play, applicable since August 2026.
- Errors nobody reviews. An invented figure in a proposal or a badly summarised clause does not arrive as a security incident. It arrives as a customer problem, months later, with no trace of where the number came from.
- Invisible dependency. Processes that only work because someone routes things through a personal tool. The day that person leaves, the process breaks and nobody knows how to rebuild it.
The most expensive in the short term is usually the fourth, not the first. Leaks are frightening, but unreviewed errors are what generate real invoices.
Why do people do it? (not what you think)
Three reasons, and none of them is bad faith. First, the official tool does not exist and something has to be used. Second, the official tool exists but is worse — slower, on an older model, with no access to the documents that matter — and people compare. Third, asking permission takes three weeks and the work is due today.
That inverts how to read the problem: shadow AI is not a discipline failure, it is an indicator of unmet demand. When it shows up strongly in one department, that department is telling you exactly where to automate first. Treating it as information rather than as an infraction changes the conversation entirely — and the success rate of whatever you do next.
How do you detect it without building a surveillance regime?
With aggregate data, not individual data. The goal is to know which tools are used and for what, not who wrote what. These four methods cover most of the ground and none requires reading anyone's conversations:
| Method | What it shows | Intrusiveness |
|---|---|---|
| Aggregate network or proxy logs | Which AI domains are visited and at what volume, without identifying people | Low when queried in aggregate |
| Expense and subscription review | Licences paid on company cards or reimbursed as expenses | None: it is accounting data |
| OAuth grants in Workspace or Microsoft 365 | Third-party apps with access to mail, calendar or documents | Low, and it is a security review you should be doing anyway |
| Two-minute anonymous survey | What they use, for what, and what the official tools lack | None, and it yields the most useful information |
The anonymous survey usually surprises leadership more than the technical logs do. In practice it returns two very valuable lists: the tasks where AI is genuinely saving time already, and the tools people picked on their own — a free shortlist compiled by the people who know the work.
What we do not recommend: individual clipboard monitoring, conversation review, or anything staff will read as spying. It destroys the trust you need immediately afterwards, when you have to ask them to tell you what they use.
The conversation that works: amnesty and an official channel
The move that has worked best for us is explicit and announced in a meeting: for two weeks, anyone who says which tool they use and what for faces no consequences; in exchange, from then on there is a channel for requesting tools with a 48-hour response. The amnesty surfaces around 80% of real usage; the response commitment is what stops it going underground again.
That channel has to be real. If the first request takes a month to answer, you have spent your credibility and you are back where you started with less credit than before. This is a change-management problem, not a technology one.
What the usage policy should say (and what it should not)
One page, in plain language, with more examples than principles. What has to be in it:
- Approved tools and how to get access, with actual names.
- What information never leaves the company: customer and employee personal data, health data, credentials, proprietary code, anything under NDA.
- What is allowed without asking: drafting, summarising public documents, coding, translating, brainstorming. This list matters as much as the previous one.
- Mandatory human review before any output reaches a customer or gets published.
- How to request a new tool and how quickly you will answer.
- What happens if you get it wrong: who to tell and with what consequences. If reporting a mistake is punished, people stop reporting.
What should not be in it: blanket prohibitions of the "no unauthorised AI use" variety. Nobody knows what that means in practice, and policies that cannot be applied only serve to document that a rule existed once something has already happened. The controls that do work are the same ones we apply to the agents we build, set out in our guide to AI agent governance and permissions.
Channelling it: give people something better
The only durable way to end shadow AI is to make the official route the most convenient one. There are three levels, and it is worth walking them in this order:
- Business licences for a general-purpose tool. Team plans sit around €20-30 per user per month, enterprise plans between €50 and €100 depending on vendor and volume (August 2026 references, priced in dollars at source). They solve the contractual and data-retention problem in one move, and offer the best cost-to-risk ratio available.
- An internal assistant with access to your documents. This is what people actually want when they paste a contract into a chatbot: answers about your information, not about the internet.
- Agents that run specific processes. Once a process is automated end to end, the temptation to improvise with outside tools disappears by itself.
The trade-off between licensing an off-the-shelf tool and building your own is covered in ChatGPT Enterprise versus custom AI agents. And if data sensitivity is what is blocking you, the architecture decision is in on-premise versus cloud AI.
What not to do
Block domains without offering an alternative, sanction before providing an official route, and set up individual monitoring. All three have the same effect: usage does not fall, it just becomes invisible, and you lose the information you needed.
The opposite extreme does not work either — open season with no policy and no training — because it delegates a legal and confidentiality decision to each individual, which is not theirs to make. The middle ground is boring but it holds: a few approved tools, clear limits on what information may leave, short training, and a fast channel for exceptions.
A 30-day plan
- Days 1-7. Anonymous survey, expense review, OAuth grant review. No accusations.
- Days 8-14. Pick two or three official tools and buy them on business plans. Announce the amnesty.
- Days 15-21. Publish the one-page policy and run 60-90 minutes of training per role. This also covers the AI Act literacy obligation.
- Days 22-30. Open the request channel with a 48-hour commitment and prioritise the first process to automate — it will come straight out of the survey.
Realistic cost for a 30-person company: €700-1,500 a month in licences, plus €1,500-4,000 of initial training. If you would rather do it with people who have already tidied this particular mess elsewhere, that is how we work as an AI consulting partner.
Frequently asked questions
Is it illegal for an employee to use ChatGPT with company data?
Not illegal in itself, but it can be depending on the data. If they upload personal data to a service the company never contracted, the organisation is exposed under the GDPR because there is no processing agreement and no documented safeguards. With non-personal information, the problem is contractual and confidentiality-related rather than data protection.
Is blocking AI domains at the firewall enough?
No, and it usually makes things worse. Usage moves to personal phones, where there is neither logging nor control, and you lose the visibility you had. Blocking only makes sense alongside an official alternative that genuinely works better.
How do I know whether the problem is big in my company?
Three signals are enough: AI subscriptions appearing in expense claims, third-party apps holding access to mail or documents that nobody remembers authorising, and teams delivering work at a quality or speed that does not match the official tooling. If all three are present, usage is already widespread.
What if my sector is heavily regulated?
Then the order reverses: first decide where information may be processed, then choose a tool. In banking, healthcare or legal it is common to start with a tightly controlled deployment and a short list of permitted use cases, widening later. What does not change is the conclusion: without an official alternative, shadow AI appears anyway — and in a regulated sector it costs far more.