Trends

Shadow AI in Polish companies, most employees use it without company approval

Half of employees in Polish companies use ChatGPT, Claude, Copilot, without the company's knowledge or a security policy. This is Shadow AI: risks, statistics, how to solve it.

yesfor.ai teamMay 8, 20268 min read

The situation in a typical Polish company of 200 people in 2026:

The marketing team pastes client briefs into ChatGPT to write proposals faster. Salespeople use Claude to research competitors. A developer drops fragments of code into the free version of Copilot. HR asks ChatGPT how to phrase a difficult conversation with an employee being let go, including their performance review.

None of them has company approval for this. No one has signed an AI policy. Half of them do not even know whether it is allowed.

This is Shadow AI. And it is the largest unnoticed business risk in Polish companies in 2026.

The scale of the problem

Research from 2025 shows that most employees in companies regularly use AI tools at work. Most of them, on free accounts, personal emails, without the IT department knowing.

This is not a people problem. It is an organizational problem. An employee sees that AI saves them 2 hours a day. They ask the company "may I". The company answers "we need to check, we will get back to you". It gets back to them after 6 months. In the meantime the employee is already using it, because it is faster, simpler, and it works.

Specific things Polish employees paste into free chatbots (from anonymous surveys):

  • Client data (names, addresses, contract numbers)
  • Fragments of source code from company systems
  • Entire contracts and internal policies "to edit"
  • Employee data: salaries, performance reviews, layoff plans
  • Queries containing confidential information about projects and technology

Why this is a risk

A free chatbot is an external provider's service. With its own terms for processing data. With its own policy on using data for training. With its own jurisdiction (usually the US, not the EU).

Consequences of a leak:

GDPR: every entry of client data into a chatbot without a legal basis is a breach. Fines: up to 4% of the company's annual turnover.

AI Act (2025-2027): AI systems used in personnel, credit, or recruitment decisions carry documentation and oversight obligations. An employee copying a CV into ChatGPT can cause the company to be classified as a "high-risk AI deployer".

Trade secrets: pasting a pricing strategy, product plan, or source code into a public chatbot means losing the legal protection of that information.

Reputation: "Company X left the data of 50,000 clients in ChatGPT" is a headline you do not recover from quickly.

What to do

Do not ban AI. It will not work. People will use it anyway, they will just hide it from the company.

What does work:

01, An AI policy in the company (a 5-10 page document)

  • What may be pasted, and what may not
  • Which tools are approved, which are not
  • How to report misuse
  • Who the AI Officer is

02, Company accounts instead of personal ones

  • ChatGPT Team / Enterprise (USD 25/person/month)
  • Claude Team / Enterprise
  • Copilot for Microsoft 365 (USD 30/person/month)
  • All with a data processing agreement

03, Team training

  • Safe use of AI (what is allowed, what is not)
  • Practical case studies (Shadow AI incidents)
  • A knowledge test after the training

04, A Shadow AI audit

  • An anonymous team survey
  • Interviews with team leads
  • Log analysis (where available)
  • A report: which tools, which data, which risks

Cost vs consequences

Rolling out an AI policy, a Shadow AI audit, and team training costs PLN 3,000 to 15,000 net (with KFS co-funding, a public training subsidy in Poland, the real cost can drop to PLN 600 to 3,000).

A single GDPR fine for a data leak: up to 4% of the company's annual turnover. For a company with PLN 50M in turnover: up to PLN 2M in fines.

This is not a question of "whether" to put an AI policy in place. It is a question of "when", before an incident or after.

Closing

Shadow AI is not an exotic problem of Silicon Valley startups. It is the daily reality of Polish companies of 50 to 5,000 people in 2026.

Employees use AI. The only question is whether they do it consciously and safely, or blindly from personal accounts.

This is a board-level decision. And it has to be a decision at the strategic level, not an ad-hoc reaction to the first leak.

If you are reading this and feel "this is probably us too", it probably is. A Shadow AI audit takes 1-2 weeks. You will know exactly what to avoid.