Key Takeaways from the Article
The development of artificial intelligence and its use in daily work is systematically increasing; however, in practice, this does not always go hand in hand with appropriate recognition and control of this area by organizations. Information can be disclosed with great ease, for example, through prompts or by pasting text (copy-paste). Consequently, many personal data or other legally protected information (e.g., trade secrets) may end up in AI tools without a legal basis and without the possibility of managing or deleting them – and over which the organization has lost control, although it remains responsible for them.

It is therefore crucial for organizations to identify areas of shadow AI and take actions to prevent the loss of control over the processed information. Blocking access to AI-supported tools may not be the right solution. In situations where AI tools genuinely facilitate employees' work, the temptation to continue using them may be strong enough to lead to attempts to circumvent the prohibition. As a result, the use of AI will be even more concealed.
A starting point for organizing this area seems to be the identification of AI tools that employees are using, as well as the information that may be input into these tools. The context in which this occurs (e.g., editing text, reviewing a document) is also significant. This allows the organization to take proportional actions to capture threats, such as by blocking the ability to upload documents containing personal data. It also enables the creation of appropriate procedures indicating safer alternative solutions. A coherent and enforceable policy tailored to the realities of the organization is crucial here.
In the following article, we present the key recommendations from European supervisory authorities on how to mitigate risks associated with shadow AI and protect the organization from uncontrolled use of artificial intelligence.
What is Shadow AI?
Shadow AI refers to uncontrolled use by employees of artificial intelligence tools that have not been formally authorized by the organization and are used outside its management framework. This is unmanaged risk: data enters systems that the organization has not assessed for security and compliance with the GDPR.
Examples of tools used:
chatbots, browser plugins based on translation engines and coding assistants, text, presentation, and report generators, tools for analyzing and summarizing documents and meetings, log and incident analysis tools, text anonymization tools, publicly available AI tools used from personal accounts for business purposes.
The lack of formal authorization for the use of AI tools results in protected data, such as personal data or information constituting trade secrets, being entered into systems that have not been previously assessed by the organization for security and potential impacts on that data. This may lead to breaches of personal data protection, particularly when the input of personal data into an AI system constitutes disclosure to unauthorized third parties, such as the providers of those tools. This also poses a risk of violating applicable regulations, including those concerning unlawful transfers of personal data outside the European Economic Area and their use for training AI models.
What is the source of the shadow AI problem?
The employees' drive to streamline the way they perform their duties is natural – AI-based tools can significantly increase productivity, save time, and enhance work quality. However, the scope and manner of using such tools should, in every case, stem from the internal regulations of the organization and be verified for compliance with regulations. If the organization has not systematically regulated this area, there is a high probability that practices referred to as shadow AI are already present within it.
For this reason, it is essential to promptly undertake actions that include: identifying AI tools that can assist employees in performing their duties, assessing the compliance of these tools with applicable regulations, particularly with the GDPR, and – after ensuring this compliance – implementing procedures that guarantee transparent and lawful use of the opportunities provided by artificial intelligence.
A certain picture of how the issue of shadow AI is shaping up in practice can be derived from the document “Strategic Report. Study of the Needs of Organizations Regarding the Use of Artificial Intelligence and Personal Data Protection”, which was prepared by the Working Group on Artificial Intelligence established within the Social Team of Experts at the President of the Polish DPA. Although this report was developed based on a relatively small sample of organizations (mainly from the public sector), it is worth citing some of the conclusions:
- 17% of organizations use AI in their daily operations (the most common positive response),
- 43% of organizations do not use AI at all,
- approximately 40% of organizations are in the preliminary testing, planning, or interest phase,
- the most common applications of AI are: automation of administrative processes (41.2%), data analytics (31%), customer/citizen service – chatbots and voicebots (28%), support in research and development (28.2%),
- operational applications that streamline daily tasks, such as: text writing, handling inquiries, communication support, preparation of educational materials, or basic diagnostics, are clearly dominant.
As indicated in the referenced report (based on the most common responses from organizational units of local government, local administration, schools, universities, and cultural institutions), the most concerning conclusions arising from the quantitative study relate to awareness regarding personal data:
- 41% of organizations believe that developing AI is not associated with the processing of personal data, or do not know whether it is associated, or cannot assess this issue,
- over 30% of respondents have no experience with developing AI systems,
- 58.5% declare the same regarding the use of AI.
The report also indicates that 95.9% of organizations consider themselves unprepared or uncertain regarding the application of the GDPR in the context of AI. Qualitative research conducted in the private sector suggests that the level of awareness concerning personal data processing in the context of AI varies significantly depending on the size and type of organization. According to the report, low awareness in this area constitutes one of the most important systemic barriers revealed in the study.
In the context of the widespread availability of AI tools that can realistically support the performance of daily employee duties, complete abstention from using such tools by employees is becoming increasingly difficult. Although some employees likely use them with due caution, without inputting protected information, this issue should not depend solely on the self-awareness of employees but should be formally regulated internally and monitored. Ensuring employee awareness is one of the organization's obligations and should include regular training and other activities that deepen knowledge in this area. Prudent use of technology by individuals is the foundation of safe personal data processing.
What Risks Does Shadow AI Pose?
Shadow AI is not solely a technical problem – it is a phenomenon at the intersection of information security, legal compliance, data management, and operational risk. The common denominator of all threats is the loss of control: over what data leaves the organization, where it is processed, who has access to it, and how to demonstrate compliance. The most significant risks are:
- Loss of control over data. Information entered into AI tools is sent to the servers of external providers – often without knowledge of where it is processed, how long it is stored, and whether it will be used to train a model. The organization ceases to manage it, although it remains responsible for it.
- Data leakage and disclosure (exfiltration). Personal data, client data, source code, documentation, or trade secrets can easily end up in prompts and attachments. This usually occurs "incidentally" during daily work – when attempting to quickly summarize a document or find an error in the code.
- Violation of GDPR and other regulations. Entering personal data into an unauthorized tool typically constitutes processing without a legal basis, and often also involves disclosure to a third party. This poses a risk of violating the principles set out in Article 5 of the GDPR (data minimization, purpose limitation, confidentiality), and in some cases, may result in unlawful transfers of data outside the EEA.
- Risk to intellectual property and trade secrets. Transferring code, specifications, or confidential content to an external service may violate IP protection and licensing obligations. This data may be used to enhance models and become accessible to unauthorized individuals.
- Weakening of cybersecurity. Tools not evaluated by the IT department increase the attack surface, especially when used by personal devices, plugins, and integrations that require extensive permissions. Transferred data may also be intercepted and used in attacks against the organization.
- Hallucinations and erroneous decisions. Models generate content that sounds credible but may be false. Acting on unverified or biased results leads to incorrect business decisions, and in extreme cases, to legal and financial consequences.
- Loss of reputation and trust. Data breaches, regulatory violations, or the public disclosure of incorrect information diminish the organization's credibility in the eyes of clients and partners, which also affects its market position.
An additional problem is the lack of auditability and accountability – when using shadow AI, it is difficult to reconstruct what data was used, who made the decision and on what basis, and whether the result was verified.
Shadow AI and shadow IT
Shadow AI is a direct relative of the long-known phenomenon of shadow IT, which involves the use of IT resources and services for business purposes that remain outside the knowledge, oversight, and risk management processes of the organization – from private cloud services to unauthorized applications. The mechanism in both cases is the same: employees resort to unofficial solutions when they find approved tools insufficient or impractical.
This analogy is directly pointed out by supervisory authorities. The British NPSA notes that shadow AI poses risks to organizations similar to those of shadow IT. The French CNIL, referring to shadow IT, emphasizes that its occurrence usually reveals real, unmet needs of staff or structural irregularities – arising from the fact that the organization has not taken into account the actual practices and expectations of users. Since AI tools also fall within the category of IT products, the same conclusions can be drawn regarding shadow AI.
However, there is a significant difference. As noted by the Turkish KVKK, generative AI tools directly affect decision-making mechanisms, content creation, and data processing. Therefore, shadow AI is not only the use of an uncontrolled tool but also an additional risk associated with the nature of the data being input, the results generated, and how these results are utilized in business processes. In other words, the consequences reach deeper than in classic shadow IT.
It is also important to consider the attitude towards employees. The British NCSC advises that individuals using unauthorized solutions should be approached without blame – punishing leads to further cases being hidden even more effectively, and the organization loses insight into real threats.
Shadow AI and GDPR
Who is responsible for shadow AI?
Primarily, the data controller, which is the organization. According to Article 29 of the GDPR, an employee processes data solely at the direction of the data controller – by inputting data into an unauthorized AI tool, they act outside of that directive. The consequences may affect the employee, the employer, and the individual whose data has been disclosed.
The issue of shadow AI is real and widespread. It is also recognized by supervisory authorities – both the President of the Polish DPA and foreign authorities. The main conclusion that can be drawn from their positions is that the solutions implemented by organizations should be based on compliance with regulations protecting personal data. Employees must know which tools they can use, to what extent this is permissible, what data they can input into them, and what risks are associated with this and how to counteract them. If a breach occurs – the responsibility primarily lies with the data controller.
According to Article 29 of the GDPR, the data processor and any person acting on behalf of the data controller or the data processor and having access to personal data process it solely at the direction of the data controller, unless required by Union law or the law of a member state.
An employee entering personal data independently into an unauthorized AI tool acts outside the instructions of the data controller, which may lead to consequences both for them – for acting beyond their authorization – and for the employer – for lacking effective control mechanisms over the processing of personal data. Ultimately, the individual whose data has been unlawfully entered into the AI tool may also face consequences – related to the loss of control over their data and the resulting sense of harm.
The organization is obligated to implement appropriate technical and organizational measures to ensure the secure processing of data and the protection of the rights of individuals whose data is being processed. One of the risks that the organization must mitigate is the risk associated with uncontrolled use of AI tools.
The President of the Polish DPA pays significant attention to the topic of AI and recognizes the substantial threats it poses to personal data. Wherever systems based on artificial intelligence appear, the issue of personal data protection must therefore be taken into account. And wherever personal data is present, the obligations arising primarily from the GDPR remain ever relevant.
The topic of AI is of increased interest to supervisory authorities. Below, we present selected positions directly or indirectly related to the issue of shadow AI.
Shadow AI and the AI Act
As of August 1, 2024, the AI Act (Regulation 2024/1689) will come into force – the first comprehensive regulation concerning systems and models of artificial intelligence. Importantly, its requirements apply not only to providers of AI tools but also to organizations that use them. This makes the uncontrolled use of AI by employees a problem under this regulation as well, not solely under the GDPR.
The fundamental difficulty lies in the lack of transparency. If an organization does not know which AI tools are being used within it, for what purposes, and on what data, it cannot fulfill the obligations arising from the AI Act – including conducting the required assessments or ensuring proper oversight. The scale of these obligations depends on the level of risk that can be classified for a given system: the higher the risk, the more requirements.
For organizations using shadow AI, three areas are particularly significant:
- Risk assessment. Before implementing a tool, the associated risks must be assessed, and where necessary, a Data Protection Impact Assessment (DPIA) should be conducted, and in some cases, an assessment of the impact on fundamental rights (FRIA).
- Human oversight. Decisions that have legal effects should be made by a human. The results of AI should serve as support, not as an unquestionable source of truth – the employee must retain actual decision-making freedom and the ability to verify.
- Competencies in AI (AI literacy). The AI Act imposes an obligation to ensure that individuals working with AI systems possess appropriate knowledge – not only about the technical functioning but also about the risks and ethical aspects. Shadow AI directly undermines this obligation: if the organization is unaware of the tools used by employees, it cannot effectively impart the necessary competencies.
As noted by German authorities, unauthorized use of AI systems poses a risk of violating both the AI Act and the GDPR simultaneously – and the risk of failing to ensure competencies in artificial intelligence remains ever-present.
How to prevent shadow AI? Best practices
Recommendations from European and non-European supervisory authorities are surprisingly consistent: the key is not prohibition, but organization. Below are the most important actions that an organization should implement to mitigate the risk of shadow AI.
- Do not impose a total ban. Authorities unanimously indicate that a restrictive approach pushes the use of AI underground and complicates any form of control. More effective are guidance, balance, and raising awareness.
- Identify tools and data. Check which AI tools employees are using, for what purposes, and what information is being inputted. Without this audit, it is impossible to assess the risk or design proportional measures.
- Implement an AI usage policy. Define permitted tools, objectives and conditions of use, types of information that can be inputted, rules for utilizing results, as well as confidentiality and data security issues.
- Provide work accounts and devices. Employees should not work on personal accounts and devices – this complicates control and creates profiles linked to specific individuals. Work accounts are best kept without employee names.
- Engage the Data Protection Officer and assess the risk. Before implementation, conduct a risk assessment, and where necessary – a Data Protection Impact Assessment (DPIA), and in some cases, a Fundamental Rights Impact Assessment (FRIA).
- Minimize data in prompts. Use general and anonymous formulations; do not input personal data or special categories of data. Remember that identity can also be inferred from context, not just from names.
- Disable training participation and history. Where possible, take advantage of options to opt-out of using data for training the model and disable history saving – especially when sharing a single account.
- Verify results. Treat AI responses as support, not as the basis for final decisions. Check them for accuracy and the risk of discrimination; decisions with legal consequences should be made by a human.
- Train employees. Regular training on the safe use of AI and building competencies (AI literacy) is an obligation for organizations, not merely a matter of employee awareness.
- Create a feedback channel. Allow employees to report experiences and issues with AI tools – this is a source of knowledge about real risks and gaps.
Recommendations from British authorities (ICO, NPSA, NCSC)
Artificial intelligence is a priority area of interest for the British data protection authority (ICO) due to the high risks it may pose to individuals whose data is involved, as well as their rights. The ICO emphasizes that personal information drives many AI technologies, and their use therefore requires particular caution.
In one of its reports on agentic AI (autonomous AI tools operating without direct human oversight), the ICO indicated that the use of such tools by employees remains a concern – individuals using the tools see the benefits of these solutions but do not identify the associated risks. This leads to violations in high-risk areas. Even the most advanced AI systems will not absolve data controllers of their responsibility for compliance with regulations.
The ICO addresses the issue of shadow AI in the context of agentic AI, citing as an example employees testing new applications of more autonomous agents in their daily work, which allow them to quickly process personal data in various, unforeseen ways. The operation of these agents in secrecy or in short cycles complicates oversight issues. The challenges become more serious if AI agents have unrestricted access to various personal data stored by the organization or can utilize external sources beyond the data sources and systems controlled by the organization. The ICO indicates that these risks can be mitigated by developing effective management structures and clearly defined parameters for employees using agents. Of course, the Data Protection Officer should be involved in the process, as this matter pertains to personal data.
By the aforementioned management structures and parameters, we mean the relevant procedures and the boundaries and conditions established by the organization for the use of agentic AI by employees. Although the ICO refers specifically to agentic AI technology, it is reasonable to assert that analogous requirements also apply to other artificial intelligence solutions. The ICO itself indicates in its publications that many obligations related to data protection in the context of using agent-based systems do not differ from the obligations pertaining to other AI applications.
It is also worth mentioning the position of the National Protective Security Authority (NPSA) – the UK government body responsible for physical security and personnel protection:
“Where AI tools are functioning well, organizations should be aware of the potential loss of skills and competencies among security personnel. Over-reliance on advanced tools should pose a risk that must be continuously monitored.”
This institution also indicates that the use of shadow AI solutions poses risks to organizations similar to those associated with the use of shadow IT solutions.
Meanwhile, the National Cyber Security Centre (NCSC) – the UK national body for cyber threats and information security – states:
“Most importantly, one should always approach individuals who have been compelled to implement shadow IT with a positive attitude and without blame. If you blame or penalize employees, their colleagues will be reluctant to inform you about their unauthorized practices, and you will have even less insight into potential threats.”
Recommendations of the French supervisory authority (CNIL)
The French data protection authority (CNIL) in its 2024 practical guide on personal data security referred to shadow IT, indicating, among other things, that the occurrence of this phenomenon within an organization may reveal significant, unmet needs of the staff or structural irregularities. The reason for resorting to shadow IT is the organization's failure to consider the actual practices, expectations, and needs of users when defining the rules for using IT resources.
By analogy, similar conclusions can be drawn regarding shadow AI, especially since tools based on artificial intelligence also fall within the category of IT products.
CNIL emphasizes on its website that the use of artificial intelligence requires adherence to specific precautions. AI systems are susceptible to failures and attacks, and their impact on individuals and society can be unexpected. Therefore, it is crucial to be aware of the risks associated with this. The responsibility for identifying these threats and countering them lies, of course, with the data controller.
Recommendations from German supervisory authorities
The State Commissioner for Data Protection of Lower Saxony in the FAQ section on artificial intelligence addressed the recurring question about the risks associated with the use of AI-based chatbots, which involves employees who have been prohibited from using them on company computers resorting to personal devices to perform work tasks. In response to this question, the authority indicated (all further translations have been performed automatically using translation tools and may not fully convey the meaning of the original text):
“Unauthorized use of AI systems in a professional context is also understood as shadow AI. This occurs when employees utilize publicly available AI systems, such as ChatGPT, Gemini, or Claude, without their integration into the IT infrastructure of the office or enterprise and without obtaining consent for their use. This primarily carries the risk of violating regulations related to both the Artificial Intelligence Regulation and the General Data Protection Regulation. The risk of regulatory violations varies depending on the level of risk that can be classified for the AI operating in the background. There is always a risk of failing to ensure competence in the field of artificial intelligence. From the perspective of data protection law, there is primarily the risk that personal data will be processed in an uncontrolled manner and without a legal basis. To avoid such GDPR violations, responsible individuals should not tolerate the use of shadow AI. The use of shadow AI can, for example, be addressed in a company instruction and prohibited. Furthermore, authorities and enterprises should consciously decide which AI systems are to be used in the organization and under what conditions.”
The authority also referred to the data protection requirements applicable when using AI systems. It indicated that when utilizing AI systems, one must:
- comply with all GDPR provisions,
- depending on the scope of application – consider additional, specific data protection regulations (e.g., the federal data protection act and the telecommunications and digital services data protection act), and in particular adhere to the principles of data protection (Article 5 GDPR), including legality, processing in good faith, transparency, purpose limitation, data minimization, and accuracy,
- ensure the realization of the rights of data subjects (e.g., the right to information, rectification, erasure of data, and objection).
The authority also presented a catalog of measures required before implementing language models in office work:
“Before implementing large-scale language models in daily office work, the following technical and organizational measures must be ensured:
- Conduct a risk assessment in accordance with the Artificial Intelligence Regulation and implement the resulting legal requirements.
- Clearly define the permissible areas of application, objectives, and specific conditions for the use of the artificial intelligence system.
- Data protection measures when processing personal data:
- ensuring that the artificial intelligence model used has not been trained in an unlawful manner,
- verifying whether there is an appropriate legal basis for processing personal data,
- defining and implementing appropriate technical and organizational measures,
- ensuring compliance with data protection principles (e.g., data minimization, purpose limitation),
- ensuring the ability to exercise the rights of data subjects (e.g., right to information, right to erasure),
- checking the threshold at which a Data Protection Impact Assessment (DPIA) is required, and if necessary – conducting a DPIA.
- If necessary – conducting an assessment of the impact on fundamental rights.
- Ensuring employee competence in artificial intelligence (e.g., through training).
- Developing an internal instruction or user manual that regulates the conditions and guidelines for the use of the artificial intelligence system.
Hamburg Commissioner for Data Protection and Freedom of Information in the checklist regarding the use of LLM-based chatbots also identified the issue that in many institutions, language models such as ChatGPT have already entered daily operations, although there is often a lack of binding guidelines for their use:
“The fact that language models are typically operated in the cloud poses various data protection risks. On one hand, the protection of confidential data is at risk, as many companies use the same LLM model in the cloud, and the input data is used for further training of the models, which may lead to the transmission of trade secrets and personal data. On the other hand, there is a risk of unlawful processing of personal data due to incorrect results, especially in the case of categories of data requiring special protection.”
The authority has published a checklist intended to serve businesses and authorities as a guide for using chatbots in compliance with data protection regulations. It consists of the following points:
- Definition of compliance principles – clear and documented internal guidelines specifying whether and under what conditions individual tools may be used: “Those who do not establish internal principles regarding whether and how generative artificial intelligence may be used in daily work can assume that employees and other members of the organization will use these innovative tools on their own and in an uncontrolled manner. In certain circumstances, the employer bears responsibility for these actions.”
- Engagement of Data Protection Officers: “Always involve your internal Data Protection Officer when creating internal guidelines or implementing a specific application for the first time. Depending on the application, a Data Protection Impact Assessment should be conducted in this context.”
- Provision of business accounts: “Business accounts for chatbots should be provided. Employees should not independently create accounts using personal data, as this would link the profile to a specific employee. If the use of a chatbot in a business context is desired, business accounts should also be provided. Whenever possible, business accounts should not contain the names of individual employees. If an email address is required, it is recommended to provide an address created specifically for this purpose. Sometimes, a mobile phone number is also required during registration – in this case, it is also advisable to use a business phone. We discourage allowing the use of business accounts for personal purposes.”
- Secure authentication: “Accounts used for business purposes to operate AI-based chatbots pose significant risks of abuse. If attackers gain unauthorized access to the application interface, they will be able to review previous activity, provided that the chat history has not been disabled. Furthermore, through their own queries, they may obtain personal data and trade secrets. For this reason, particular emphasis should be placed on authentication. Strong passwords should be used, and additional authentication factors should be implemented.”
- Prohibition on entering personal data: “As a general rule, the principle applies: if the chatbot provider reserves the right to use data for its own purposes in the commercial terms, personal data must not be transmitted to the artificial intelligence. This applies to any information that allows for the identification of clients, business partners, or other third parties, as well as the data of employees themselves. Generally, there is no legal basis that would allow this.”
Example of an unobjectionable command: „Write an advertisement text for product X”.
Example of a questionable entry: „Which individuals might be interested in product X?”.
- Caution regarding data enabling identification of individuals: „It is advisable to avoid entering data that, under certain circumstances, may refer to specific individuals. It is not sufficient to remove names and addresses from the text. Also, based on the context, it is sometimes possible to infer the identity of the authors and the individuals to whom the data pertains. In the case of artificial intelligence-based applications, which are designed to create connections even based on unstructured data, this risk is particularly high”.
Example: „Draft a work certificate with a satisfactory evaluation for a customer advisor at car dealership X”. The data may refer to a specific individual if it can be recognized from which company and at what time it was entered.
- Opting out of participation in AI training: „Take advantage of the option to refuse the use of your data for training purposes. AI model manufacturers often use all entered data for further training of their artificial intelligence. Private individuals and employees of other companies may then inquire about this content. However, depending on the service used, it is possible to express an objection to the use of data for training purposes. Sometimes this requires purchasing a special model of the agreement, which differs from the standard free application”.
Example: in the case of ChatGPT, opting out can currently be done through the settings in the section ••• → Settings → Data Control → Chat History and Training.
- Opting out of saving history: „Chat-based services often offer the option to save previous entries to allow for the resumption of dialogue on a given topic at a later date. This inevitably involves creating a chain of entries belonging to a specific individual. Particularly when the service is used collaboratively by several employees, it is advisable to disable history, as otherwise, the content will be visible to all colleagues” (information about settings, e.g., in ChatGPT, can be found in point 8).
- Verifying the accuracy of results: „Results from queries directed to the chatbot should be approached with caution. Large language models generate texts that mathematically approximate the desired outcome. This does not mean that all provided information is correct. On the contrary: known LLM models typically rely on relatively outdated data. These models are also known for the phenomenon of hallucination, where artificial intelligence fabricates statements that seem correct and logical but are, in fact, erroneous. It is the responsibility of users to verify the accuracy of the results”.
- Checking results for discrimination: „Even if the results are substantively correct, they may be inappropriate, for example, if they are discriminatory in nature. Data processing based on such results may therefore be unacceptable, as it violates, for instance, equal treatment regulations or fails to meet the balancing of interests requirements specified in Article 6(1)(f) of the GDPR. Again, it is the responsibility of users to check whether the responses are permissible within the legal framework for further use”.
Example: even without a direct reference to a specific individual, the information may be discriminatory. Artificial intelligence could, without naming individuals, issue the following recommendation: „For the vacant position, preference should be given to men wearing glasses”. Such a result could be based on an unacceptable analysis of data concerning health and gender.
- No final automated decision: “Decisions that have legal effects should generally be made solely by humans. Otherwise, the conditions specified in Article 22 of the GDPR must be adhered to. If a chatbot based on an LLM model generates proposals that are accepted by employees, they must ensure actual decision-making freedom. Situations should be avoided where, due to a lack of transparency in AI-based preparatory work, employees are effectively bound by these proposals because they are unable to trace the decision-making process. Insufficient resources and time pressure may also lead to accepting results without verification.”
- Raising employee awareness: “Employees should be sensitized through training, guidelines, and discussions about whether and how they can use AI-based tools.”
- Data protection is not everything: “The use of AI-based services must not violate personal data protection. It is also advisable to regulate other aspects, such as copyright protection or trade secrets. In the case of administrative applications, data transfer prohibitions in accordance with the German Security Control Act (SÜG) and other regulations must be taken into account.”
- Monitoring further developments: “At the EU level, work is currently underway on regulations concerning artificial intelligence. Future regulations on artificial intelligence will likely pertain not only to providers of such services but also to certain users. Due to advancing technical solutions and ongoing updates of new systems and language models, internal guidelines should be regularly reviewed for necessary adjustments. Furthermore, data protection authorities are currently conducting model proceedings to determine whether the language models available on the market are fundamentally compliant with the law.”
Meanwhile, in the guidelines from the conference of independent German data protection supervisory authorities at the federal and state level dated May 6, 2024, it was indicated:
“Without clear rules defining whether and how artificial intelligence-based applications can be used in daily work, there is a risk that employees will use AI applications independently and in an uncontrolled manner. It should be assumed that this is currently a reality in many enterprises and offices. This may lead to data protection violations, as well as other harms to the organization. Therefore, clear internal guidelines should be issued and documented, specifying whether, under what conditions, and for what specific purposes individual artificial intelligence-based applications may be used. Specific examples of permitted and prohibited use scenarios may be helpful in clarifying this issue and are therefore recommended. Regardless of whether the AI application processes personal data (including data regarding employee usage), it is advisable to issue a business instruction or enter into a business/works agreement between management and the employee council/works council. In any case, clear frameworks for the use of artificial intelligence-based applications should be established. This particularly applies to situations where personal data is processed. In some cases, the implementation of an artificial intelligence-based application will also serve as a basis for co-determination in the enterprise.”
The same guidelines also pointed out the employer's obligations related to providing business accounts:
“For the professional use of artificial intelligence-based applications by employees, employers should provide devices and accounts. Employees should not work independently using personal accounts and devices with AI applications, as this may lead to the creation of profiles of individual employees. Accounts should not contain the names of individual employees unless the AI application is hosted on their own servers. If an email address is required, a functional email address of the enterprise or office should be provided. In some cases, during registration, a mobile phone number is required – in such cases, the employer is also obliged to provide a phone.”
Recommendations of the Turkish Supervisory Authority (KVKK)
In the context of shadow AI issues, it is worth looking beyond the EEA and paying attention to the position of the Turkish Personal Data Protection Authority (KVKK), which in February 2026 issued a document titled “The Use of Generative Artificial Intelligence Tools in the Workplace”. It presents a general framework for the use of generative AI tools offered by third parties and publicly available in the workplace. KVKK emphasized that the purpose of this document is to “raise awareness among companies, institutions, and organizations, draw attention to potential risks, and promote the conscious use of these tools”.
KVKK points out in this document the risks associated with informal use of AI tools by employees:
“The increasing use of generative artificial intelligence tools in the workplace, while offering opportunities to support efficiency and business processes, is also associated with certain issues that need to be considered due to the nature and scope of this use. In particular, the fact that the use of these tools does not always occur within a clearly defined strategy, policy, or organizational guidelines, and in most cases arises from individual employee preferences aimed at facilitating daily work, may hinder the monitoring and management of generative AI tools at the organizational level.”
KVKK also notes that generative AI brings benefits in various areas such as customer service, marketing and advertising, education, healthcare, law, and software development:
“The ability of these tools to process various types of content and generate results in a short time allows for their integration in different ways into daily workflows. In this context, examples of applications include preparing emails and drafting texts, summarizing documents and assessing their content, supporting the development of ideas, creating meeting notes, and contributing to research activities. (…) The use of AI tools in workplaces mostly occurs through such tools that are offered by third parties and are publicly available. Chat-based AI applications, coding assistants that support software development processes, and AI tools used for translation and text generation are among the applications commonly utilized by employees to support business processes.”
The Turkish authority directly addresses the issue of shadow AI, noting that this term refers to situations where employees use artificial intelligence tools in business processes within a given institution or organization without its knowledge, consent, or control:
“Such applications often arise from individual employee initiatives and occur in forms that are not provided for within existing corporate IT infrastructures, management frameworks, and control mechanisms, or are not sufficiently monitored by these mechanisms. Consequently, the ability of authorized entities to gain insight and control over which tools are used for what purposes, what types of data are input into these tools, and how the obtained results are utilized in business processes may be limited.”
With the increasing prevalence of AI tools, their use in daily business processes is growing. This is facilitated by the fact that these tools meet employee expectations related to time savings, reduced engagement in routine tasks, and improved quality of results. As KVKK points out, the rise in individual use of AI tools is also driven by their being free or inexpensive, easily accessible, and provided through a simple interface that does not require advanced technical knowledge. Additionally, this trend may be reinforced by the lack of policies and guidelines regarding the use of AI at the corporate level or insufficient clarity of these frameworks.
In an earlier part of the article, a reference was made to the convergence of shadow AI with shadow IT. KVKK confirms this analogy:
“The phenomenon of shadow AI exhibits certain common characteristics with shadow IT practices that organizations have been grappling with for some time. Generally speaking, shadow IT refers to IT resources and services used for business purposes within an organization but are unknown to it, unmonitored, and not covered by corporate risk management processes. This concept is not limited to devices used by employees but also includes external IT solutions, such as personal cloud storage services. For example, storing sensitive information for the organization on personal cloud accounts by employees to access company data from another location is considered shadow IT, as these services remain outside the organization's security and risk management processes. Shadow IT applications may also arise because employees find approved tools and processes insufficient or impractical, which can lead to the selection of unofficial alternatives to facilitate task completion. A similar dynamic occurs in the case of shadow AI. However, due to the ability of generative AI tools to directly influence the decision-making mechanisms governing data processing, content creation, and business processes, shadow AI is associated with risks that must be considered in various dimensions. In this context, shadow AI does not solely rely on the use of a technological tool that remains outside control but introduces additional risks concerning the nature of the data used, the results generated, and the use of those results in business processes.”
The KVKK summarizes the implications for risk management brought about by the proliferation of shadow AI:
“The widespread use of shadow AI significantly complicates risk management for organizations. In situations where there is insufficient transparency regarding which AI tools are being used, for what purposes, what types of data are being shared through them, and in what context this occurs, it is difficult to assess compliance with legal obligations and effectively intervene in the event of potential violations.”
The Turkish authority identifies some risks associated with shadow AI:
- Risks related to controllability and accountability – there is difficulty in determining what data has been used, for what purpose and extent, and on what basis specific results have been generated.
- Risk related to the quality and accuracy of decisions – tools that have not been assessed by the organization may generate erroneous or inconsistent results and lead to biased conclusions. Acting on such results may have further negative consequences for the organization.
- Risk related to the protection of intellectual property and trade secrets – the lack of regulations may lead to the introduction of confidential data into tools and result in a breach of their secrecy. Such data may be used to create or improve models and become accessible to unauthorized individuals.
- Risk of loss of reputation and trust in the organization – using unverified results generated by an unchecked AI system may impact the organization's image and undermine its credibility.
- Risk related to information security and cybersecurity – the lack of control over systems used within the organization provides greater opportunities for potential attacks, e.g., through personal devices or application programming interfaces.
- Risk related to the protection of personal data – sharing data in AI tools may result in a breach of data protection and regulations in this area. Furthermore, personal data shared through prompts may be reflected in the results generated by these tools and become accessible to unauthorized individuals through them.
So how should one act? The guidelines from KVKK provide several practical tips for organizations:
- An organizational review of the approach and practices related to the use of AI tools should be conducted: “Approaches based on a total ban on the use of these tools will not yield realistic results in practice. Restrictive approaches may encourage forms of using AI tools outside the control and visibility of the organization, prompting employees to use them in an uncontrolled manner.”
- The organization should rely on guidance, balance, and awareness, rather than prohibitions: “Such an approach, supporting safe and responsible use of AI tools, aimed at building awareness among employees and taking into account corporate risk, will contribute to limiting forms of usage that remain uncontrolled.”
- A clear corporate policy or guidelines should be established to define the boundaries of the proper use of AI tools: “In this context, it is necessary to specify: the AI tools that may be used within corporate activities, the actions in which they can be applied, possible objectives and conditions of use, the types of information that may be input into the AI tools, the principles for using the generated results, issues related to confidentiality and data security, the adopted approaches to risk management, and training and awareness-raising activities directed at employees.”
- Particular attention should be paid to issues related to personal data protection in the instructions given to AI tools: “In this context, it is important to have sufficient information about what types of data are collected, for what purposes this data is processed, to whom it is shared, and how long it is retained, as well as to familiarize oneself with the relevant information and privacy policy.”
- It is essential to primarily use anonymous, general, and abstract formulations, exercising caution with AI tools, especially in the case of sensitive data.
- Caution should be exercised in relying on AI results: “It is important not to treat the results generated by AI tools as the basis for final decisions, but rather to consider them as supporting elements, subject to human control and assessment. On the other hand, an approach based on verifying AI results for accuracy, relevance, and context should be adopted, and caution should be exercised regarding content that may lead to biased or discriminatory outcomes.”
- Risk management is necessary – an assessment of the security measures and access controls in place should be conducted, and the tools permitted for use, their frameworks, scope of use, and types of information that may be input into them should be defined.
- Employee awareness should be prioritized – policies and guidelines regarding the use of AI tools and their updates should be communicated to employees and made easily accessible. Training and informational activities are also necessary to raise awareness of the threats and issues that should be considered when using artificial intelligence.
Importantly, the Turkish authority also highlighted the role of feedback mechanisms. Employees should have the opportunity to share their experiences and issues related to the use of AI tools. This will enable the organization to identify risks and areas requiring improvement. Such an approach can contribute to the review of policies and practices, as well as support the development of an organizational culture based on the ethical and responsible use of AI.
Recommendations from the Dutch supervisory authority (Autoriteit Persoonsgegevens)
The Dutch data protection authority in an article on its website emphasizes the importance of AI literacy, which is the obligation to provide individuals working with AI systems with appropriate knowledge and understanding not only of the technical functioning of these systems but also of their ethical aspects and other practical issues. The scope of knowledge and skills that an organization should impart to its employees depends, among other things, on the context of the use of a given system and the associated risks. This means that effective knowledge transfer requires familiarity with the tools used within the organization. The phenomenon of shadow AI undermines the ability to adequately meet the requirement for AI literacy.
The Dutch authority recommends that organizations prioritize AI literacy and approach it strategically. A long-term action plan aimed at achieving a mature level of competence in this area may be helpful.
The Dutch authority also points out that inputting data into chatbots may result in personal data breaches. It also recognizes the issue that employees use such tools in the workplace, for example, to respond to customer inquiries or summarize large text files. While this speeds up work, it carries a high risk. The authority indicates that employees often use artificial intelligence on their own and contrary to agreements made with their employer:
“If personal data has been introduced in the process, it constitutes a data security breach. Sometimes the use of AI-based chatbots is part of an organization's policy. In such cases, it is not a data security breach, but it is often prohibited by law. Organizations must prevent both of these situations. (...) Most companies behind chatbots store all entered data. As a result, this data ends up on the servers of these technology companies, often without the knowledge of the person who entered it, and without a clear understanding of what the company will do with it. Moreover, the data subject will also be unaware of this.”
Recommendations of the Irish Supervisory Authority (Data Protection Commission)
In the position regarding AI and large language models, the Irish supervisory authority emphasized that assessing whether the use of a particular AI product or system is appropriate for the organization requires first identifying the risks associated with the processing of personal data by that system – so that the organization can ensure the compliance of that processing with the GDPR. AI products based on personal data or those in which personal data is entered by personnel may pose new threats to organizations and individuals whose data is involved – previously unrecognized or not taken into account. These threats may vary depending on whether the organization uses a standalone product or a cloud service or an Internet-connected service.
The authority also points out the obligations that may arise from the role of the data controller:
“As a user of an AI product utilizing personal data, your organization may be a data controller, and in such a case, it is advisable to consider conducting a formal risk assessment. Before you start using the AI system, you should first understand what personal data is being used by it, how it is being used, where the data goes in situations where a third-party data processor is involved, whether it is stored by the AI product provider, or if it is reused in any way, as well as how the product enables you to fulfill your obligations under the GDPR. The provider's documentation should clearly and understandably convey this information to you.”
The Irish authority has identified the following risks associated with the use of AI systems:
- The risk of unwanted, unnecessary, or unforeseen processing of personal data – data entered into the AI model may be used for training or fine-tuning, which may violate the GDPR, particularly the principles of lawfulness, fairness, transparency, and purpose limitation.
- The risk associated with the exercise of rights of data subjects – the organization should have a procedure in place to facilitate the exercise of these rights in the context of using AI products. If personal data is input into the tool, the organization should know where it goes and how it is processed, so that it can act in accordance with the GDPR requirements in the event of a request for access to or deletion of data.
- The risk associated with using AI tools provided by third parties – this involves additional threats, so the organization should be aware of how data is protected both internally and externally by entities acting on its behalf.
- The risk associated with the model remembering data – some models may retain input data and repeat those fragments in the output results. In such a situation, the organization may unexpectedly or unnecessarily further process data concerning identifiable individuals. As with training AI models, the obligations arising from the GDPR and how the organization supports users' rights under the GDPR should be taken into account.
- The risk associated with attacks on data filters – filters in the AI model designed to prevent the sharing of certain data with users (e.g., personal data or copyrighted material) may be attacked and circumvented. This could lead to unintended processing of data. The organization should assess whether such a risk is possible, to what extent, and how it can be effectively minimized.
- Risk of automated decision-making – the lack of human oversight over the AI system may pose a risk of automated decision-making. The system may be prone to generating errors or biased information, which could result in potentially harmful decisions affecting the rights and interests of the individuals whose data is being processed.
- Risk associated with the absence of a defined data retention period – the lack of such a period, which can be effectively enforced, complicates compliance with the principle of data minimization.
- Risk associated with the use of data published by the organization – personal data posted on the organization's website may be used to train AI models. It may then be necessary to ensure the protection of this data from being collected and used for training the AI model or other processing, especially if the organization has not agreed on such a purpose with employees or users, or if they do not have reasonable grounds to expect that their data will be used for training AI.
Recommendations of the Spanish supervisory authority (Agencia Española de Protección de Datos)
In the document “Agent-based artificial intelligence from a data protection perspective”, issued in February 2026, the Spanish supervisory authority indicated:
“There are agent-based artificial intelligence (AI) services that are easy to implement, intuitive, and equipped with tools that allow for very rapid task design and connectivity between components, even for end users. Such environments are common in software prototyping in other contexts and facilitate the deployment of systems such as AI agents. This leads to the temptation for unqualified users, enchanted by the capabilities of these solutions, to carry out implementations outside the organization's management policy and information policy. The ease of having a solution that seemingly works with little effort may create the impression that the implications and impact on data protection (and on the organization in general) are trivial, while obscuring the inherent complexity that these tools have in many aspects.
The introduction of an agent-based artificial intelligence system for data processing by the data controller involves redesigning the organizational process, in which at least functional managers, IT, and quality should participate, and, where appropriate, also the Data Protection Officer (DPO).
The consequences of errors in implementing an AI system based on agents in the processing process can affect many aspects: from actual effectiveness to compliance with regulations, reliability, explainability, stability and robustness of processes, their scalability and availability, security gaps arising during processing, lack of control over data flow and its scope and storage, consequences of breaches, or lack of preparedness for incident management.
If the BYOD (Bring Your Own Device) issue has arisen in the case of mobile devices in the workplace, and the BYOAI (Bring Your Own Artificial Intelligence) issue has emerged in the case of AI chats, then in the case of agent-based AI, the BYOAgentic (Build Your Own Agentic) problem arises – stemming from the lack of organizational policies, qualified specialists in management and technical aspects, and the absence of mature methodologies for designing processes and applications.
The ease and availability of AI tools contribute to their uncontrolled implementations, especially since the process itself is fundamentally easy to carry out independently. This leads to bypassing the organization's security policies and operating outside its knowledge and control. As noted by the Spanish authority, the accessibility of these tools and the simplicity of their use often reinforce the belief that using them cannot involve greater risk – which is, of course, a mistaken assumption.
Lawful use of IT cannot be solely a technical decision but must be preceded by a process, an organizational decision requiring the involvement of appropriately qualified individuals, as well as an assessment of the tool. The failure to properly conduct this process by the organization creates a range of risks, including non-compliance with regulations, security threats, and loss of control over data.
The organizational vacuum, including, among other things, the lack of appropriate policies, clearly defined management and decision-making roles, and frameworks for acceptable use of AI tools, fosters the development of shadow AI. The organization's lack of response leads to informal practices becoming the norm, and inappropriate and risky ways of operating becoming standard. The responsibility for this lies primarily with the organization.
Summary
- The occurrence of shadow AI in the organization may reveal significant, unmet needs of employees and systemic problems in process management.
- The lack of policy and guidelines regarding the use of AI at the corporate level or insufficient clarity of established frameworks may reinforce shadow AI practices.
- The responsibility for ensuring that the systems used comply with regulations rests with the data controller.
- The operation of AI tools in the shadows complicates oversight and generates risks for data security.
- Shadow AI poses a risk of violating regulations – both the AI Act and the GDPR, breaches of personal data protection, and other harms to the organization.
- The risk of regulatory violations varies depending on the level of risk to which shadow AI can be classified.
- To avoid violations, responsible individuals should not tolerate the use of shadow AI.
- The use of AI solutions that are powered by personal data requires particular caution due to the increased risks in this area.
- From the perspective of data protection law, there is primarily a risk that personal data will be processed in an uncontrolled manner and without a legal basis.
- A limiting factor for risk is clear procedures and effective management structures.
- The procedures should specify, among other things:
- the AI tools that may be used within corporate activities,
- the actions in which they may be applied,
- possible objectives and conditions of use,
- the types of information that may be input into the AI tools,
- the rules for using the generated results,
- issues related to confidentiality and data security,
- the method of risk management,
- training and awareness-raising activities directed at employees.
- Before implementing AI models in the organization, it is necessary, among other things, to:
- conduct a risk assessment and implement appropriate security measures resulting from it,
- define acceptable scopes, objectives, and conditions for the use of the AI system,
- in some cases – conduct a DPIA or FRIA.
- Employers should provide employees with work devices and accounts for using AI-based applications for business purposes. Employees should not work independently using personal accounts and devices.
- A complete ban on the use of AI tools will not yield the desired results in practice. Such a restrictive approach encourages the use of AI tools outside the control and visibility of the organization.
FAQ – Frequently Asked Questions
What is shadow AI?
Shadow AI refers to the use of artificial intelligence tools by employees without the knowledge, consent, or control of the organization. It most commonly involves the use of chatbots, content generators, coding assistants, or document analysis tools outside the officially approved work environment.
Why does shadow AI pose a threat to organizations?
The greatest risk is the loss of control over data. Employees may unknowingly share personal data, confidential information, or trade secrets with AI tools, which can lead to violations of regulations and data leaks.
Can an employee's use of ChatGPT violate the GDPR?
Yes. If an employee inputs personal data into the tool without an appropriate legal basis, the organization's consent, or the required safeguards, it may result in a violation of the principles set forth by the GDPR.
What data should not be shared with AI tools?
Personal data, special categories of data, information covered by trade secrets, customer data, internal documentation, and other confidential information should not be shared if the organization has not permitted such processing methods.
Does a complete ban on using AI solve the shadow AI problem?
No. Supervisory authorities indicate that total bans often lead to even greater concealment of AI usage by employees. Implementing clear rules, procedures, and secure, approved tools is more effective.
How can the risks associated with shadow AI be mitigated?
The foundation is to create an AI usage policy, conduct a risk assessment, define acceptable uses of tools, train employees, and implement appropriate technical and organizational measures.
Who is responsible for ensuring AI usage complies with regulations?
The responsibility primarily lies with the data controller. The organization should ensure appropriate procedures, oversight, and security measures related to the use of artificial intelligence.
Is using private AI accounts for business purposes safe?
Generally, no. Using private accounts complicates the organization's control over data processing, increases the risk of information leaks, and may lead to violations of applicable security procedures.
Should a risk assessment be conducted before implementing AI?
Yes. Before implementing AI systems, the organization should assess the risks related to data protection, cybersecurity, and regulatory compliance. In some cases, conducting a DPIA may also be necessary.
What elements should an AI usage policy include?
The policy should specify the approved AI tools, the purposes of their use, the types of data that may be processed, the rules for using the results, security requirements, and employee obligations.
How does shadow AI impact cybersecurity?
Unauthorized AI tools increase the attack surface, complicate the monitoring of data flows, and may lead to uncontrolled sharing of information outside the organization.
Does the AI Act matter for the issue of shadow AI?
Yes. The use of AI tools outside the control of the organization can hinder compliance with the obligations arising from the AI Act, including requirements related to risk management, human oversight, and staff competencies in AI.




