Symboldbild: Schloss aus den Ziffern 0 und 1
Information on data protection

Shadow AI

Introduction

Artificial intelligence (AI) can help to speed up business processes and make them more effective. According to a survey commissioned by the digital association Bitkom, a quarter (26 %) of companies provided their staff with access to AI systems last year, whilst other companies are planning to introduce AI systems. The figures show that the need to use AI systems is growing not only in everyday life but also in the workplace. Where companies have not introduced AI systems, or where existing ones are regarded by staff as inadequate or slow, the risk of shadow AI increases. This refers to the unauthorised use of AI systems or AI tools by staff. In other words, there is a lack of authorisation or oversight by the IT department or management. In a survey conducted by Cybsafe Ltd. in 2025, just under half (43 %) of employees admitted to having already shared sensitive business information using AI tools without their employers authorisation. Companies then find themselves facing various risks, such as data breaches, data protection sanctions or reputational damage.

Use Cases

In day-to-day business operations, there are various use cases for AI that involve the processing of personal data. Personal data includes, for example, contact and health details, as well as interests, personality traits or specific characteristics that enable the identification of an individual. If employees have not received training in data protection law, they may unwittingly enter personal data into an AI system or use AI systems that have clearly been configured in a manner that contravenes data protection regulations.

It is conceivable that customer service staff might use a chatbot to draft an email and, in doing so, enter a customer’s personal data – such as their interests. Furthermore, the creation or summarisation of texts often involves documents containing personal data relating to a customer, employee or business partner.

In the field of marketing, it is conceivable that AI is used for campaigns or social media posts, thereby disclosing trade secrets or photographs of other employees.

If, for example, sales staff wish to analyse customer data using AI for the purposes of analysis or data visualisation, this may result in profiling. Where personal data is processed automatically to evaluate or predict certain personal aspects – such as financial circumstances or personal preferences – the strict requirements of Art. 22 of the GDPR apply. Accordingly, data subjects have the right not to be subject to a decision based solely on automated processing – including profiling – which produces legal effects concerning them or similarly significantly affects them. Even the purely automated rejection of a job applicant falls under the prohibition in Art. 22(1) of the GDPR and can only be justified under the conditions set out in paragraph 2 – the data processing must be necessary for the performance of a contract, there must be a provision of national law, or the data subject must have given their consent. The same applies to other decisions based solely on automated processing without human intervention.

Loss of Data Control and Forgotten Data Sets

With shadow AI, companies have no control over what information has been processed in which AI systems or how long it is stored there. 

When personal data is entered into AI systems, this data is often stored by the operator and is therefore beyond the company’s control. In particular, employees often use free versions that do not comply with European data protection standards and which, for example, use the data entered for training purposes. It may not be possible to rule out the operator using the data for their own purposes, publishing it or otherwise misusing it. If the AI systems have security vulnerabilities that go unnoticed by the employee, this creates an opportunity for cybercriminals to exploit them. Furthermore, the use of AI may involve the transfer of data to third countries, which may not be adequately protected.

The company must comply with certain requirements of the GDPR, including information obligations. However, shadow AI causes the company to lose control over data flows and prevents it from ensuring transparent data processing for data subjects. Any fines or claims for damages will then be directed against the company and may result in significant financial loss. Shadow AI has the potential to cause particularly severe financial damage, as its use can often only be detected at a very late stage. In our newsletter 10/2025, we explained when the unauthorised actions of employees can be attributed to the company and who is liable for the data protection breach. However, reputational damage is also a possible consequence once the unverified integration of AI systems is revealed. Since August 2, 2026, companies have been obliged under the European Regulation on Artificial Intelligence (AI Regulation) to disclose whether content has been created or modified by an AI system, or whether users are interacting with an AI.

Furthermore, the AI systems used secretly by employees are not necessarily designed to cope with the complexity and demands of the organisation and may produce false information. For example, scientific studies or technical terms may be hallucinated. This can lead to incorrect decisions or work outcomes. Decision-making processes can no longer be traced or documented.

Whilst companies draw up data deletion policies, document data sets and implement retention periods, shadow AI creates new data storage repositories outside these established processes. Personal data may remain on the operator’s servers even though it has long since been deleted from the company’s own systems. 

Steps to Follow

The risks associated with shadow AI can be minimised by the organisation through various measures.

Collaboration With the IT Department

If AI systems are to be used within the organisation, the first step should be to collaborate with the IT department to identify AI systems that comply with data protection regulations and to introduce them in a controlled manner. By having the organisation provide the AI systems, data protection-compliant systems can be selected, thereby significantly reducing the risk of shadow AI and the loss of data control from the outset. In this context, it can also be clarified whether the use of unauthorised AI systems can be monitored or prevented through technical and organisational measures, such as role-based access control or blocking certain websites. 

When personal data is entered into the tool, the data is usually transferred to the operator of the AI system, who then processes this data to generate the output in the context of data processing on behalf of the controller, in accordance with the controller’s instructions and on the controller’s behalf. Therefore, in such cases, a data processing agreement in accordance with Art. 28 of the GDPR must be concluded with the operator of the AI system.

Internal AI Policy

Regardless of whether an AI system has been introduced within a company, it is advisable to draw up an internal policy governing the use of AI in an employment context. Last year, more than half (54 %) of companies had already established internal rules for the use of AI or had at least firm plans to do so (survey of 604 companies commissioned by the digital association Bitkom). 

The policy can specify which AI tools may be used and for what purpose. It may also include guidelines setting out what must be taken into account when using the tool or its individual functions. The company may also stipulate a labelling and verification requirement, under which employees must verify every output from the AI system and label the use of the AI system. It is important that the policy is accessible to every employee at all times.

Raising Staff Awareness

Under Art. 4 (1) of the AI Regulation, organisations must take measures to support the development of AI competence among their staff who are involved in the operation and use of AI systems on their behalf. In addition to guidance provided in the organisation’s internal policy, it is advisable to organise training sessions covering organisation-specific use cases. Alternatively, or in addition, employees can be made aware of the issues through guidance documents and fact sheets.

Documentation Requirement

As part of the accountability requirement under data protection law pursuant to Art. 5 (2) of the GDPR, organisations should document the use of AI and the awareness-raising measures undertaken for staff. The internal company policy can also serve this purpose.

Conclusion

Shadow AI poses significant data protection risks for organisations. If AI systems are used in day-to-day work without the organisation’s authorisation and oversight, personal data and trade secrets may be processed outside the established data protection and data erasure frameworks. Even the mere input of customers’ personal interests into a chatbot to draft an email, or the summarisation of a document containing personal data, is sufficient to trigger these risks.

The company loses control over data flows and can no longer fulfil its data protection obligations under the GDPR – such as the information and documentation requirements or ensuring an adequate level of protection when transferring data to third countries. In addition to the risks of fines and liability, the company may also suffer reputational damage and lose its competitive advantages. Furthermore, shadow AI creates new data storage locations outside the scope of data erasure policies and documentation, which may only be discovered at a late stage.

Companies should therefore work with their IT departments to select suitable and data-protection-compliant AI systems, establish clear internal AI policies and provide regular training for their staff to ensure the responsible use of AI and reduce the risk of shadow AI.