Shadow AI at Work: Why Employees Secretly Use ChatGPT and What the AI Act Says
Surveys show that the majority of knowledge workers use AI tools at work that their employer doesn't know about. This is called "shadow AI" — and under the EU AI Act, it's a ticking compliance bomb. Here's why and what to do about it.
What Is Shadow AI
Shadow AI is an extension of the well-known "shadow IT" phenomenon — when employees use software or services without IT department approval. With AI, the problem is many times larger: a tool like ChatGPT, Claude or Copilot can be set up in 30 seconds via a personal account, and the data the employee inputs can end up in training data or with the model provider.
The most common shadow AI tools in companies: ChatGPT (personal Plus account), Claude.ai, Gemini, Perplexity, Copilot from a personal Microsoft account, NotebookLM, ElevenLabs, Midjourney, Notion AI and dozens of specialised tools for marketing, copywriting or development.
Why Employees Do It
4 Real Risks Under the AI Act
When an employee pastes a contract, an invoice with a national ID or HR documents into public ChatGPT, that's a leak of personal data to a processor outside any contractual regime. That breaches GDPR (Art. 5, 28, 32) and the deployer obligations under the AI Act at the same time. The fines stack — GDPR up to 4% of turnover + AI Act up to 3% of turnover.
Article 4 of the EU AI Act has applied since 2 February 2025 and requires the company to ensure a sufficient level of AI literacy for EVERY person using AI on its behalf. If employees use AI in secret, they haven't had any training — and that's a separate breach.
If an employee publishes AI-generated content on behalf of the company (blog, ad, customer email, voice bot, deepfake video) without disclosure, from August 2026 that's a breach of the transparency obligation. Fine up to 3% of global turnover.
Some tools employees download from the internet already fall under prohibited practices — emotion analysis of employees, biometric categorisation, social scoring. If the company deploys them (even without management's knowledge), the fine is up to 7% of global turnover.
How to Detect Shadow AI in 3 Steps
Send teams an anonymous form (Google Forms, Typeform): "Which AI tools do you use at work? How often? What tasks?" No sanctions. You only get realistic numbers this way.
Check DNS/proxy logs for domains like chatgpt.com, claude.ai, gemini.google.com, perplexity.ai. Go through company cards and reimbursements — personal Plus/Pro accounts often surface as expensed items.
Especially marketing, HR, dev and customer support. Don't ask "do you use it?" — ask "what would you make easier with an AI tool?" The answers reveal what they already use.
5-Step Plan: From Shadows to Governance
Anonymous survey + IT audit + conversations. Goal: a complete list of AI tools actually used in the company.
Place each tool in a risk category: prohibited practices, high risk, limited risk (Art. 50), minimal risk. This decides what can continue and what must stop immediately.
For popular shadow tools, provide company-approved equivalents with a DPA: ChatGPT Team/Enterprise instead of personal Plus, Microsoft 365 Copilot with your tenant, Gemini for Workspace. Without alternatives, the shadows come back.
Run Article 4 training for all employees (4–6 hours) and issue an AI policy — what is allowed, what isn't, what data sensitivity goes into which tool. The policy is your compliance evidence during an inspection.
Register approved AI systems (mandatory from 2 December 2027 for high-risk, best practice for all). Repeat discovery quarterly — new tools appear every week.
Ban vs. Governance
The most common mistake: a ban — "no AI at work". Shadow AI only gets worse — employees will do it more secretly, on personal laptops, out of IT's reach. Better strategy: allow, but govern.
Ban (anti-pattern)
Governance (best practice)
Conclusion: Shadow AI is not a technology problem — it's a governance problem. The AI Act doesn't require you to ban AI, but to know what is used in the company, by whom and for what. Discovery, classification, approved alternatives, training, registry — five steps that pull real value out of the shadows and prepare the company for August 2026.
Map AI in Your Company in 5 Minutes
Our checker walks you through discovery and classification of AI tools and flags where you have shadow risks under the AI Act.
Start Free Check