What exactly is shadow AI?

Shadow AI is the use of generative AI tools by employees, for work purposes, without the IT or security team approving, assessing, or even knowing it's happening. It doesn't have to be deliberately covert — most cases are far more mundane than "clandestine."

  • An employee pastes an entire contract into ChatGPT to get it summarized.
  • HR uploads résumés to a free app to screen them faster.
  • Sales loads a customer spreadsheet into an AI assistant to draft personalized outreach.
  • Someone installs a browser extension with built-in AI that IT never reviewed.

None of this comes from bad intent. It comes from the tool working better, faster, or simply existing — while the company's approved alternative, if there is one, doesn't measure up.

21.1%of Spanish companies with 10+ employees already use AI (INE)
42%have a formal generative AI use policy (Zoho, 2026)
29%of employees use unauthorized AI agents (Microsoft Cyber Pulse, 2026)

Why banning it doesn't work

The instinctive response for many leadership teams, the moment they discover shadow AI, is to ban it outright. It's understandable, and it's bound to fail: a large share of employees would keep using these tools even after a formal ban, according to 2025-2026 industry surveys. Banning without offering an alternative doesn't reduce usage — it just hides it better, and the company loses the little visibility it had into what's actually happening with its data.

The approach that actually reduces risk isn't prohibition, it's governed access: knowing what's being used, deciding deliberately what gets authorized and under what conditions, and what gets replaced with a safer option — not flipping the switch off and hoping the problem disappears.

Why it's already a compliance problem, not just a culture one

An August 2026 analysis from the AEPD's Privacy Lab (Spain's data protection authority) makes the point plainly: a single prompt can contain personal data, confidential information, trade secrets, or restricted documentation. Entering personal data into an external tool can itself constitute processing of personal data under GDPR — which means reviewing what role that tool's provider plays, where it processes the information, and under what conditions.

Before authorizing any service that will receive corporate information, you should be able to answer some very concrete questions: what data it processes, for what purpose, how long it retains it, whether subprocessors are involved, where processing happens, whether inputs can be used to train or improve the service, and whether the tool lets you delete or export that data on request. Without an inventory of what's actually being used, none of those questions has an answer.

The AI Act connection: Article 4 requires AI literacy for staff who use it, and the Article 50 transparency obligations assume the company knows which AI systems are in use. Neither is achievable against an inventory that doesn't exist.

How to detect shadow AI without building a surveillance system

The goal isn't to police every individual — it's to build a reasonably reliable map of what's actually in use. A handful of sources, combined, are usually enough:

  • Corporate card expenses and subscriptions — most AI tools run on subscriptions, and those charges leave a trail.
  • Extensions installed on company-managed browsers — a large share of shadow AI enters this way, not through desktop apps.
  • SaaS apps with corporate single sign-on — many everyday tools have quietly added AI features that were never reviewed for that specific use.
  • A direct, non-punitive survey of the team — openly asking what people actually use, and why, usually surfaces more, faster, than any technical tool — as long as it's clear there's no penalty for answering honestly.

With that map in hand, you can decide deliberately: which uses continue as-is, which need more controls (a DPA with the provider, restrictions on what data can be entered), and which should be retired and replaced with an approved alternative.

Shadow AI Detection & Regularization The full methodology to find what AI tools your workforce is actually using outside the official inventory, and how to regularize them without slowing the business down. €29.
View product →

From detection to regularization

Detecting without regularizing just produces an uncomfortable list nobody knows what to do with. The step that actually closes the loop is turning that map into three decisions per tool: authorize (with clear conditions on what data it can receive), replace (with an already-vetted alternative that covers the same need), or retire (when the risk doesn't pay off, explaining why instead of just banning it). Communicating those decisions — and the reasoning behind each one — is what stops the next wave of shadow AI from walking in through the same door.