AI concepts
Shadow AI (hidden use of AI by employees)
The use of AI tools by employees outside the company's knowledge and policy. Pasting customer data into ChatGPT, source code into Claude, contract fragments into Copilot. The consequence: data leakage, GDPR risk, AI Act risk and breach of professional confidentiality.
Primary source: Writer / Workplace Intelligence 2025, Salesforce State of IT 2026
The term describes a phenomenon parallel to the classic Shadow IT of 2010 to 2015, when employees used their own Dropbox, Trello and Slack before IT departments approved them. The difference: Shadow IT was a productivity problem, Shadow AI is a compliance problem.
The scale of the phenomenon
A study by Writer and Workplace Intelligence from 2025, run on a group of 1,600 enterprise employees in the US and the UK, reveals that over 60 percent of people in operational teams use generative AI regularly, including 31 percent who do so knowingly against company policy. Salesforce State of IT 2026 adds to the picture: an average 500-person company has 32 different AI tools used at least once a week, of which the IT department knows about seven.
Why employees take the risk
Three reasons recur in the in-depth interviews of RAND 2024. First, the company tools are slower and worse than consumer ones. Second, company policy is unclear or unknown. Third, pressure to be productive grows faster than access to approved tools.
Legal consequences in Poland
Pasting personal data into the free version of ChatGPT means transferring data to the US without a legal basis under Article 44 of the GDPR. A leak of professional confidentiality (law firms, audits, medicine) breaches Article 266 of the Penal Code. The AI Act of February 2026 adds an obligation to document the use of high-risk AI systems.
What works
An AI policy is not enough if the alternative is worse than ChatGPT. What works is a combination of three elements: a list of approved tools with concrete usage examples, fast approval paths for new tools (days, not weeks), and an audit of the current state as a starting point.
We deliver this through our Cybersecurity & AI Policy service, three to fifteen thousand zloty, one to two weeks.