Verselo

← Blog

Shadow AI in the workplace: how to spot it and what to do

Your team already uses AI, just not through the company. The signs of shadow AI, why a ban does not work, and five steps that bring it under control.

  • By Vishal Punia
  • 4 min read

In almost any company with office work, someone is using AI today. The question is rarely whether, but on whose account. If the answer is "their own", you have shadow AI.

That is not a suspicion, it is the regulators' starting point. In their guidance on AI and data protection, the German data protection authorities write that without clear rules there is a risk that employees use AI tools on their own initiative and without control, and that this should be assumed to be the reality in many companies and public bodies already.

What exactly is shadow AI?

Shadow AI is any AI used for work that the company has not chosen, reviewed or approved. The term sounds like bad intent. Usually it is the opposite: someone wants the proposal out by five, and a chat window saves twenty minutes.

What you will typically find:

  • personal accounts with ChatGPT, Claude, Gemini and similar services
  • browser extensions that rewrite text or summarise web pages
  • note-taking bots that join video calls and transcribe them
  • AI features inside software you already use, switched on by someone without asking
  • online translation and transcription services that whole documents get uploaded to

How do you recognise it in your company?

You do not need monitoring software. Paying attention is usually enough:

  • Writing suddenly sounds different. Client emails, proposals or reports change tone and structure overnight.
  • Subscriptions on expense claims. Small monthly charges for AI services, paid on a personal card and filed as "software".
  • Strangers in the call. A "notetaker" sits in the meeting that nobody invited.
  • The question "Am I actually allowed to do this?" People who ask usually already do.
  • Speed without explanation. Someone hands you a summary of an eighty-page tender in ten minutes.

None of this is misconduct. It is a sign that your team finds AI useful and the company has not given an answer yet.

Why is shadow AI a risk for the company?

Three reasons, all concrete.

Data protection. When personal data goes into a tool your company has no contract with, the data processing agreement under Article 28 GDPR is usually missing. On free personal accounts, inputs can also be used to train the model unless the user switches that off. Your company remains the controller.

Trade secrets. The EU Trade Secrets Directive only protects information that has been "subject to reasonable steps under the circumstances" to keep it secret (Article 2(1)(c)). If price calculations and contracts are regularly pasted into personal chat accounts and no rule says otherwise, proving those steps later gets hard.

No overview. When an employee leaves, their chats leave too. You do not know which customer data is in them, and you cannot have anything deleted, because the account is not yours.

Then there is the AI Act: since February 2025, companies that use AI must take measures on their staff's AI literacy. Hard to do if you do not know which AI is in the building. More on that in the article on AI literacy under Article 4.

Why does a ban not work?

Because the need stays. Someone who saves an hour a day with AI does not stop because of an all-staff email. The use moves to their phone, and there you see nothing.

The German regulators recommend the opposite route. Employers should provide devices and accounts for work use so that nobody has to work with personal accounts (DSK guidance, section 2.4). And they should give clear, documented instructions, with concrete examples of permitted and prohibited uses (section 2.2).

What do you do about it, step by step?

Five steps a company of ten to fifty people can get through in a few weeks.

  1. Ask instead of hunting. A short, honest survey: which AI do you use, for what, with which data? No consequences for the answers. You only get honest answers if nobody fears trouble.
  2. Keep a list. Which tools are in use, who uses them, for which tasks, with what risk. This is not bureaucracy for its own sake: the Spanish data protection authority AEPD does it for its own organisation and keeps an up-to-date register of the generative AI systems in use, with purpose and risk level.
  3. A one-page rule. What may go into an AI tool, what never does, which tool is approved, who decides when in doubt. With three or four examples from your own work. If you have staff representatives, involve them early.
  4. An approved tool. With company accounts, a data processing agreement and an admin view. Otherwise the rule stays theory, because there is no alternative.
  5. Train and follow up. A session where everyone learns what is allowed and how to check results. After three months, run the same survey again.

The order matters. Start with step 4 and you buy a tool that misses the real tasks.

What does this look like with Verselo?

Verselo is an AI workspace for small and mid-sized companies, and it covers step 4: your team works on company accounts instead of personal ones, the AI runs in EU data centres, and customer data trains no model. As the person in charge, you see who uses AI and what it costs, set which models are allowed and how long chats are kept, and remove access in one click when someone leaves. The technical side is on the security page.

Steps 1 to 3 and 5 need a decision, not a tool. If you want to know where your company stands, the free AI check is a good place to start.

Frequently asked questions

What is shadow AI?

Shadow AI is any AI tool employees use for work that the company has not chosen, reviewed or approved. Typical examples are personal ChatGPT accounts, browser extensions, note-taking bots in video calls and AI features someone switched on by themselves. The problem is not the AI. It is that nobody knows which data goes where.

Is shadow AI illegal?

Not as such. It becomes a problem once personal or confidential data lands in tools your company has no contract with. Then the data processing agreement under Article 28 GDPR is usually missing, and trade secret protection weakens, because EU law only protects information that is subject to reasonable steps to keep it secret. The company is responsible, not the individual employee.

Should we just ban ChatGPT at work?

A ban without an alternative usually moves the use to personal phones, where you see nothing at all. What works better is an approved tool with company accounts, a short rule with examples, and training. The German data protection authorities recommend exactly that: company accounts and clear, documented internal instructions.

How does the Verselo AI check help with shadow AI?

The free Verselo AI check asks how your team uses AI today and shows where your company stands and what to tackle next. It does not replace data protection advice, but it gives you a basis for the conversation with your team and for deciding which tool to approve.

Where does your company stand with AI?

The free AI check asks how your team uses AI today and shows you what to tackle next. No call, no commitment.