← Back to blog

Shadow AI at Work: Why Employees Secretly Use ChatGPT and What the AI Act Says

Surveys show that the majority of knowledge workers use AI tools at work that their employer doesn't know about. This is called "shadow AI" — and under the EU AI Act, it's a ticking compliance bomb. Here's why and what to do about it.

What Is Shadow AI

Shadow AI is an extension of the well-known "shadow IT" phenomenon — when employees use software or services without IT department approval. With AI, the problem is many times larger: a tool like ChatGPT, Claude or Copilot can be set up in 30 seconds via a personal account, and the data the employee inputs can end up in training data or with the model provider.

The most common shadow AI tools in companies: ChatGPT (personal Plus account), Claude.ai, Gemini, Perplexity, Copilot from a personal Microsoft account, NotebookLM, ElevenLabs, Midjourney, Notion AI and dozens of specialised tools for marketing, copywriting or development.

Why Employees Do It

Pressure for productivity and deadlinesIT approval of a new tool takes weeksA colleague showed them how to do it in 5 minutesThe company has no officially approved alternativeFear that no one knows about their needs

4 Real Risks Under the AI Act

1
Data leak — GDPR + AI Act double fine

When an employee pastes a contract, an invoice with a national ID or HR documents into public ChatGPT, that's a leak of personal data to a processor outside any contractual regime. That breaches GDPR (Art. 5, 28, 32) and the deployer obligations under the AI Act at the same time. The fines stack — GDPR up to 4% of turnover + AI Act up to 3% of turnover.

2
Breach of Art. 4 — AI literacy

Article 4 of the EU AI Act has applied since 2 February 2025 and requires the company to ensure a sufficient level of AI literacy for EVERY person using AI on its behalf. If employees use AI in secret, they haven't had any training — and that's a separate breach.

3
Breach of Art. 50 — unlabelled AI content

If an employee publishes AI-generated content on behalf of the company (blog, ad, customer email, voice bot, deepfake video) without disclosure, from August 2026 that's a breach of the transparency obligation. Fine up to 3% of global turnover.

4
Risk of a prohibited AI practice (Art. 5)

Some tools employees download from the internet already fall under prohibited practices — emotion analysis of employees, biometric categorisation, social scoring. If the company deploys them (even without management's knowledge), the fine is up to 7% of global turnover.

How to Detect Shadow AI in 3 Steps

1
Anonymous survey

Send teams an anonymous form (Google Forms, Typeform): "Which AI tools do you use at work? How often? What tasks?" No sanctions. You only get realistic numbers this way.

2
IT and expense audit

Check DNS/proxy logs for domains like chatgpt.com, claude.ai, gemini.google.com, perplexity.ai. Go through company cards and reimbursements — personal Plus/Pro accounts often surface as expensed items.

3
One-on-one with teams

Especially marketing, HR, dev and customer support. Don't ask "do you use it?" — ask "what would you make easier with an AI tool?" The answers reveal what they already use.

5-Step Plan: From Shadows to Governance

1
Discovery (1 week)

Anonymous survey + IT audit + conversations. Goal: a complete list of AI tools actually used in the company.

2
AI Act classification

Place each tool in a risk category: prohibited practices, high risk, limited risk (Art. 50), minimal risk. This decides what can continue and what must stop immediately.

3
Approved alternatives

For popular shadow tools, provide company-approved equivalents with a DPA: ChatGPT Team/Enterprise instead of personal Plus, Microsoft 365 Copilot with your tenant, Gemini for Workspace. Without alternatives, the shadows come back.

4
Training and internal AI policy

Run Article 4 training for all employees (4–6 hours) and issue an AI policy — what is allowed, what isn't, what data sensitivity goes into which tool. The policy is your compliance evidence during an inspection.

5
Register and ongoing monitoring

Register approved AI systems (mandatory from 2 December 2027 for high-risk, best practice for all). Repeat discovery quarterly — new tools appear every week.

Ban vs. Governance

The most common mistake: a ban — "no AI at work". Shadow AI only gets worse — employees will do it more secretly, on personal laptops, out of IT's reach. Better strategy: allow, but govern.

Ban (anti-pattern)

Shadow AI gets worseIT loses oversightEmployees find workaroundsData leak risk increasesNo compliance evidence

Governance (best practice)

Approved tools with DPAAI systems registerTraining and policyRisk classificationReady for inspection

Conclusion: Shadow AI is not a technology problem — it's a governance problem. The AI Act doesn't require you to ban AI, but to know what is used in the company, by whom and for what. Discovery, classification, approved alternatives, training, registry — five steps that pull real value out of the shadows and prepare the company for August 2026.

Map AI in Your Company in 5 Minutes

Our checker walks you through discovery and classification of AI tools and flags where you have shadow risks under the AI Act.

Start Free Check

Blog content is written and reviewed before publication by Bc. Ferko Kiš, who holds editorial responsibility for the published texts.

AiComply asistent Automatizovaný AI asistent
EU AI Act
Dobrý deň! Som AiComply asistent — automatizovaný chatbot s umelou inteligenciou. Poradím vám s EU AI Act a súladom. Čo vás zaujíma? Spustiť bezplatnú kontrolu