In most small companies, AI is already at work on personal accounts. It has access to proposals, spreadsheets and customer email, it halves the time routine tasks take, and it comes with no agreement of any kind: none with the company, none about data processing, none inside the team about what never gets pasted. Nobody decided any of this, so nobody knows what is allowed. That is the shadow in shadow AI: the shadow of a decision nobody made.
My commentary on shadow AI ran in Wprost, a Polish business weekly, on 1 August 2026, the day before the main body of the EU AI Act started to apply. Today the rules apply, and the conversation they were supposed to start has not happened. This article is about having it in one afternoon.
What is shadow AI?
Shadow AI is AI used at work outside the company's knowledge and oversight, usually through a personal consumer account, with no alert and no log on the company's side. There is nothing to notice, because nothing looks like an incident. Nobody breaks into a system, nobody walks out with a file.
Someone opens a second browser tab and pastes in a piece of their work, and the company finds out months later, by accident.
The word "shadow" does the wrong job here. It sounds like something someone hid. Nobody is hiding anything.
The sales rep drafts proposals with a model at an open desk, the office manager summarizes meeting notes in a chat she mentions over coffee. The shadow is cast by the company, not by the employee. It is the shadow of a decision nobody made.
The older term is worth separating out. Shadow IT was unapproved software: an install, a license, a ticket somebody could refuse. Shadow AI is an approved-looking browser tab, which is why the old detection playbook finds so little to detect.
A typical scene, not a case from our work. Someone in accounts gets a spreadsheet of vendors to clean up and pastes it into a free chat because that is faster. Tax IDs, addresses and invoice amounts now sit on someone else's server and, on default consumer settings, may end up in model training. She did something sensible: she shortened a task she had to finish anyway. The person who did nothing is the owner who never said that spreadsheet does not get pasted anywhere.
Why is shadow AI a problem?
The damage comes in three layers at once: data that can feed someone else's model, the absence of a processing agreement, and a breach cost that rises where nobody controls access. AI on a personal account has nobody to sign a document with, because the account belongs to the person, not the company.
- Technical. Content pasted on a consumer account can feed model training. Netskope, which measures traffic rather than opinions, reports that 47% of GenAI users still access tools through personal, unmanaged accounts, down from 78% a year earlier (Netskope Cloud and Threat Report 2026). The direction is good, the level is still half.
- Legal. The company that employs the person in accounts remains the data controller, not the chat vendor she pasted the spreadsheet into. A personal account changes none of that. It adds one thing: the absence of a processing agreement under GDPR Article 28. Which plans do what with your data is covered in our piece on where your company data goes when you use AI.
- Financial. Shadow AI was a factor in one in five (20%) of the breaches IBM studied. Those breaches cost $4.63M on average against $3.96M, or $670,000 more per breach. Among breached organizations that had an AI-related security incident, 97% lacked proper AI access controls, and 63% of the organizations surveyed have no AI governance policies in place (IBM Cost of a Data Breach Report 2025, Ponemon Institute, 600 organizations).
The same report counts an average of 223 GenAI-linked data policy violations per organization each month. To violate a policy you first have to have one, so in a company without a policy the counter reads zero, and zero is the worst possible reading.
Is it acceptable to use AI at work?
Yes, and the question is framed wrong. People reach for the tool because the task is due today, the tool halves it, and nobody has said "not that one, this one." The answer is not permission or a ban, it is a named tool and one rule. Supply the third and the first two stop being a problem.
"This is a big-company problem, we have twenty people" is the line that comes up most often and holds up least. A large company has an IT department that at least sees the traffic. A small company has an owner who uses a chat on a personal account himself and assumes that is normal. It is normal, nobody wrote it down. And twenty people on personal accounts is twenty separate privacy policies nobody has read.
Most companies now have a workforce that taught itself to use AI on its own accounts. That is a head start nobody has claimed, and an account alone does not claim it, which is why AI training for your team belongs next to the account rather than after it.
Polish data, illustrative for the EU rather than global: 38.4% of workers in Poland use AI at work regularly against a European average of 29.3% (SD Worx, "2026 HR and Payroll Pulse", 16,500 workers, 16 countries), while 27% of Polish companies have formal rules for it (Cyberportret polskiego biznesu 2026, ESET and DAGMA, survey by ARC Rynek i Opinia, n=1,026). Usage runs well ahead of rules, and there is no reason to think that gap is a peculiarly Polish habit.
How to avoid shadow AI without banning it?
A ban without a company account is not a security policy. It is a memo that says "keep doing it, just on your own phone." What works instead is a pair: one licensed tool on a business plan, plus one rule about what never gets pasted. The account gives people somewhere safe to go and the rule tells them what stays out of it.
People say this themselves. In the Polish survey above, 35% of AI users would try to get around a company block, and 26% would generate the content on a personal device and email it to their work inbox. Read that as instructions rather than as a threat: a ban does not remove the behavior, it moves it where the company sees even less.
Banning AI in a company that gave nobody a company account is like banning phone calls in a company that has no phone. People will not stop calling. They will call from personal numbers, and the customer will not know who is on the line.
Companies ran this exact experiment ten years ago under the name shadow IT: personal Dropbox, personal Gmail for large files, a spreadsheet on someone's own Google account. Most reached the same conclusion: you cannot ban convenience, you can supply it.
One difference matters: Dropbox stored the file, while a language model on a consumer account may train on it. A leak in shadow IT was an event. In shadow AI it can be a default setting, cast by the same decision nobody made.
A tool never taught anyone caution either, so the account comes with training or with the same habits on a better plan. Our guide to an AI policy for business covers what the one-page version needs to say.
What changed on 2 August 2026?
From that date the main body of the EU AI Act applies, including the Article 50 transparency duty, which sits with the company deploying the tool rather than with the model vendor. The regulation entered into force on 1 August 2024; 2 August 2026 is when these provisions started to apply.
Two misreadings that keep showing up in headlines.
Penalties did not start in August 2026. The penalties chapter has applied since 2 August 2025. August 2026 brought the duties of the companies deploying these tools, Article 50 transparency among them.
Not every AI-assisted text needs a label. A proposal or an email drafted with a model does not. Article 50 targets the case where a person might take the machine for a human, such as a chat on your website.
In my commentary in Wprost I wrote that the headlines would read "penalties begin" and that this was wrong. With hindsight I would add one thing: for a small company on off-the-shelf tools, transparency costs less to satisfy than any schedule of fines.
Poland shows what this looks like where the law has landed. It passed a national AI act on 3 July 2026, in force since 11 August 2026, and is standing up a supervisory body that has not started work. Member states are adding national layers, and liability arrives before the regulator does.
If the chat on your website promises a customer something that is not on your price list, pointing at the vendor will not help. Air Canada tried that argument, and a tribunal in British Columbia held the airline liable for what its chatbot said, in February 2024, for CAD 650.88. The amount is small, the principle is not. You can delegate work to a model, not liability.
Article 4 gets almost no attention. It has applied since 2 February 2025 and, after the Digital Omnibus (Regulation (EU) 2026/1744), speaks of supporting AI literacy among the people who use these tools on the company's behalf. No form and no agency, just an expectation that people understand the tool they work with, and shadow AI is the state in which a company cannot know whether they do. The rest is in what the EU AI Act requires of your company.
How to spot shadow AI in your company in a week
Three questions and one sheet of paper. Inventory first, policy second. Most companies do it the other way round and end up with a document describing a company that does not exist: it bans tools nobody uses and says nothing about the ones the team has worked in for a year. Collecting the answers takes an afternoon and writing them down takes another. That is the whole audit, on no budget.
- Which AI tools do our people use? Ask it so you get an honest answer. Not "do you use AI," which sounds like an interrogation and gets a "no." Ask "where does AI save you time," which sounds like interest and gets you a list.
- What must never be pasted into them? Three categories are enough: customer personal data, contracts, financials.
- Who checks the output before it reaches a customer? One name per document type, not a two-page procedure.
A typical result in a 20-person company, a scenario rather than a measurement: several tools, some the owner has never heard of, all on personal accounts, none on a business plan. That is not a disaster, it is the baseline, and you cannot count anything until you know where zero is.
You do not have to start the rules from a blank page either. Our free AI policy template has fields for exactly those three answers, so you can fill it in the same afternoon you do the inventory.
Ban it or organize it - what works in a small company?
In a small company the answer is a pair, not a choice: one licensed tool on a business plan plus one rule about what never gets pasted. Each half fails on its own. A ban with no company account pushes the behavior onto personal laptops, and an account with no rule gives people a safe tool they will paste everything into anyway. A business plan is not a comfort purchase. It is the line between "the data stays with us" and "the data trains someone else's model."
| Route | What the company does | What people do | What the company sees |
|---|---|---|---|
| Silence | says nothing | use personal accounts | nothing |
| Ban alone | blocks the tools | use personal devices and email the result to themselves | even less than before |
| Account plus rule | supplies one tool on a business plan and three lines of rules | use what they were given | usage, cost, and who uses what |
The rule has to fit in three lines: customer personal data, contracts, financials. One sheet, not a twenty-page document. The test of a good rule is whether a new hire can repeat it in their first week without opening the file. If not, it is not a rule. It is an attachment.
Template: one sheet, three lines
Inventory (one sheet): who on the team uses which AI tool, for what, on which account (personal / company).
The rule (three lines, pinned where everyone sees it):
- We never paste customer personal data, contracts or financials into any AI tool.
- We use [tool name] on the company plan. Personal accounts are for personal things.
- Anything AI writes that leaves the company is read by a human first.
Owner of this sheet: [name]. Review: first Monday of each quarter. That is the whole policy for a company of twenty people until the full AI policy template is needed.
Where to start this week
Three moves, each of which fits in an afternoon and none of which needs a budget. Ask the team where AI saves them time and write the answers on one sheet. Buy one business plan for the tool that came up most often. Announce three lines about what never gets pasted. A quarter is what it takes to pretend the problem is technical and needs an implementation.
The afternoon is not enough in one case: when customer data moves through several tools at once, there is a chat on the website, and nobody knows what that chat promises. Then you need someone from outside to check the state of things instead of guessing at it. That is what an AI Trust Layer audit is: an independent check of where data goes, who has access, what your chat says, and where you stand on Article 50, ending in a report that lists the gaps in the order to fix them. We audit, we do not build the controls.
The closing question is not "do my people use AI." They do. The question is whether the company has said out loud what it uses and what it never pastes. The day that gets said, AI at work gets an agreement, a rule and a person responsible, and the shadow of a decision nobody made is gone, because someone turned the light on.
Want to know where you stand? Book an AI Trust Layer audit, or start on your own with the free AI policy template.
Frequently asked questions
Can my employer tell if I use AI?
Usually not, if it is a personal account on a personal device. Larger organizations see AI traffic in network logs and run DLP or CASB tools; in the Polish survey cited above, 25% of companies have them. For a 20-person company that is a sledgehammer to crack a nut. A conversation works faster and does not make the team feel like suspects.
Is ChatGPT shadow AI?
The tool is not the problem. The account and the missing rule are. The same ChatGPT on a business plan, covered by a data processing agreement and named in a one-line policy, is not shadow AI. On a private login, with the same spreadsheet pasted into it, it is.
What is the 30% rule in AI?
A popular rule of thumb, not a study: AI takes roughly 70% of the repetitive part of a task and a person keeps roughly 30%, the judgment and the oversight. Nobody owns the number and nobody should cite it as research. Its use is the reminder that the 30% has to belong to someone by name, and under shadow AI it belongs to nobody.
Is shadow AI a GDPR problem?
It becomes one the moment customer personal data goes into a tool the company has no processing agreement with (Article 28). A personal account cannot sign one, because it belongs to the person. Which plans keep data out of training is covered in where your company data goes when you use AI.
Who is liable for what an AI tool says?
The company using it. The Article 50 transparency duty sits with the deployer, and model vendors have separate obligations. Air Canada argued before a tribunal that its chatbot answered for itself, and lost in February 2024. More in what the EU AI Act requires of your company.
Does a policy fix it or do you need an audit?
A policy says what is not allowed. An audit says what is happening today. The order is inventory, then policy, then review. For a company using one or two tools for text and spreadsheets, the inventory and three lines of rules are the fix. An AI Trust Layer audit pays for itself when customer data crosses several tools, a chat talks to customers, or someone built an automation nobody else understands.
Sources
- Netskope, Cloud and Threat Report 2026 - netskope.com
- IBM, Cost of a Data Breach Report 2025 (Ponemon Institute, 600 organizations) - ibm.com
- ESET and DAGMA, Cyberportret polskiego biznesu 2026 (survey by ARC Rynek i Opinia, n=1,026, 15 June 2026) - purepc.pl
- SD Worx, "2026 HR and Payroll Pulse", 17 July 2026 (16,500 workers, 16 countries) - sdworx.com
- Mikołaj Motel, commentary on AI in Polish companies, Wprost, 1 August 2026 - biznes.wprost.pl
- Regulation (EU) 2024/1689 (EU AI Act), Articles 4 and 50 - eur-lex.europa.eu
- Polish Act of 3 July 2026 on artificial intelligence systems, Journal of Laws 2026 item 1003; Regulation (EU) 2026/1744 (Digital Omnibus)
- Moffatt v. Air Canada, Civil Resolution Tribunal of British Columbia, February 2024 - canlii.org
Want to know where you stand?
We check the tools, the access and where you stand on the EU AI Act, and hand back a report that lists the gaps in the order to fix them - book an AI Trust Layer audit. If you would rather start on your own, take the free AI policy template.
Let's talk