What shadow AI is (and why it isn't a legal term)
"Shadow AI" appears in neither the AI Act nor the GDPR. It's industry and cybersecurity shorthand, borrowed from "shadow IT" — the software employees install or use without IT ever knowing or approving it — now applied to generative AI: staff using ChatGPT, Copilot, Gemini, or other AI tools for work without formal authorization or without IT or compliance being aware.
It's rarely bad faith. It's almost always a case of individual efficiency outrunning collective governance: the tool solves the task faster, so people use it. The tool itself isn't the problem — what that ungoverned use means for the company is:
- Without an inventory, Article 4 of the AI Act can't be met — you can't run AI literacy measures on tools the company doesn't even know are in use.
- Without a data processing agreement (free plan), data leaves the company with no cover under Article 28 of the GDPR — covered in detail below.
- Without a record of what went in, the company can't respond to a security breach or to a data subject's access or erasure request, because it doesn't know what personal data reached a third party, or when.
The real problem: the free plan has no data processing agreement
When a company signs up for ChatGPT Team, ChatGPT Enterprise, or the OpenAI API, a Data Processing Addendum (DPA) exists in which OpenAI formally declares itself a "Data Processor," and the international transfers that processing involves are backed by Standard Contractual Clauses (SCCs).
That DPA only covers API, Business, or Enterprise customers. Free accounts and the consumer Plus plan run on OpenAI's standard consumer Terms of Use, with no equivalent data-processing relationship. It's the difference between a contract that spells out what OpenAI does with the data you send it, and simply accepting terms of service written for an individual user.
| Free / Plus (consumer) | Team / Enterprise / API | |
|---|---|---|
| Contractual basis | Standard consumer Terms of Use | Data Processing Addendum (DPA) |
| OpenAI's role under GDPR | Not formally declared a data processor | Declared "Data Processor" |
| International transfers | No equivalent dedicated framework | Standard Contractual Clauses (SCCs) |
| GDPR Article 28 cover for the company | No equivalent cover exists | Covered by the DPA |
The consequence is direct: an employee who enters personal data about customers or coworkers into the free version of ChatGPT does so with no agreement covering that data leaving the company. The company, which remains the data controller regardless of who typed the prompt, is left with a likely breach of Article 28 of the GDPR.
On what happens to that data afterward, the most authoritative EU-level source is the report of the EDPB's ChatGPT Taskforce, published May 23, 2024. Among its findings: OpenAI relies on legitimate interest (Article 6(1)(f) GDPR) both for its training-data scraping and for training on users' own prompts and interactions; data subjects must be clearly informed that their "Content" may be used for training; transparency alone is not enough to satisfy the accuracy principle; and, in a line that captures the regulator's stance well, "technical impossibility cannot be invoked to justify" non-compliance with the GDPR.
What the AI Act says: literacy, not a ban
The AI Act doesn't prohibit using ChatGPT. A company that simply uses it — without retraining it or bringing it to market — is a "deployer," not a "provider" of a general-purpose AI model. That provider-specific obligation sits with OpenAI, Microsoft, or Google, not with the client company giving its staff access to the tool.
What it does require, and has for over a year now, is Article 4 — AI literacy, in force since February 2, 2025. It obliges both providers and deployers to take measures to ensure a sufficient level of AI literacy among their staff and anyone else operating the system on their behalf. Article 3(56) defines "AI literacy" as the skills, knowledge, and understanding that allow for informed use of AI systems and proper awareness of their opportunities, risks, and possible harms. Article 4 doesn't require guaranteeing a specific individual knowledge level for every employee, but it does require measures — documentable ones, not just good intentions.
The second relevant piece is Article 50(4) — transparency, which starts applying on August 2, 2026. It requires deployers who publish AI-generated or AI-manipulated text intended to inform the public on matters of public interest to disclose that the text was AI-generated, except when the content has gone through human review or editorial control and a natural or legal person holds editorial responsibility for the publication. This is directly relevant if your company uses ChatGPT to draft press releases or public-facing content without a real editorial review process behind it.
What the Spanish DPA does — and doesn't — say yet
Worth being precise here: as of this writing, Spain's data protection authority (the AEPD) has not published a guide specifically dedicated to "generative AI in the workplace" for private companies. That document doesn't exist, and it shouldn't be cited as if it did — the same gap holds across most EU national authorities.
What does exist are two adjacent references, useful but not equivalent. First, the AEPD's general 2020 guide, "Adecuación al RGPD de tratamientos que incorporan Inteligencia Artificial" (bringing AI-based processing into line with the GDPR), written before generative AI went mainstream and not specific to tools like ChatGPT. Second, the AEPD's own internal policy on generative AI use (November–December 2025), written for its own staff and not binding on third parties, but naming risks that translate directly to any company: "hallucinations, algorithmic bias, or data leaks," and requiring that generative AI be used as a "support tool" under human supervision, never as an autonomous decision-maker.
That gap in specific guidance isn't a reason to wait: Article 4 of the AI Act and Article 28 of the GDPR already apply, guidance or no guidance.
Practical steps to bring ChatGPT use under control
1. Inventory what generative AI your staff actually use
Not what the internal policy says is used — what's actually used: ChatGPT, Copilot, Gemini, AI plugins buried inside other tools. Without this inventory, everything else is theoretical.
2. Move to a plan that comes with a DPA (Business, Enterprise, or API)
This is the single change that does the most to reduce Article 28 GDPR risk: moving from a free or consumer Plus account to a plan that includes a Data Processing Addendum.
3. Train staff on what can and can't go in (Article 4)
A "don't paste customer data" policy is a reasonable starting point, but Article 4 requires real AI literacy measures — not just a formal ban buried in a document nobody reads.
4. Document usage as evidence of governance
A record of which tool, which plan, who uses it, and for what. It's the difference between having something to show a regulator or a breach response, and having nothing.
Frequently asked questions
Is it illegal for an employee to use free ChatGPT for work tasks?
Not illegal per se, but if personal data about customers or coworkers goes in without a data processing agreement in place — something only the paid Business, Enterprise, or API plans include — the company is likely breaching Article 28 of the GDPR.
Is a "don't paste customer data into ChatGPT" policy enough to comply with the AI Act?
It's a good first step but not enough on its own: Article 4 requires AI literacy measures suited to the context, not just a formal ban, and it has applied since February 2, 2025.
If we upgrade to a paid plan, does the GDPR risk go away?
It's reduced, not eliminated: the paid plan comes with a DPA built on Standard Contractual Clauses for international transfers, but the company is still the data controller and still has to apply data minimization, a valid legal basis, and proper information to data subjects.
Can ChatGPT-written content go into a public statement without disclosing it's AI-generated?
It depends: if the content concerns a matter of public interest and there's no real human editorial review behind it, Article 50(4) of the AI Act (in force from August 2026) requires disclosure; with substantive human editorial review and someone taking editorial responsibility for the publication, the article's own exception removes that requirement.
