Shadow AI is not a security threat to lock out
Shadow AI is described as a security threat, but 57 per cent of employees hide their AI use and almost half breach policy. A ban does not move the behaviour, it makes it invisible, and the duty already sits with the employer.

Key insights
- Shadow AI, staff using AI without the employer's visibility, is widespread. In KPMG and Melbourne's global study 2025 (48,000 respondents, 47 countries), 57 per cent of employees hide their AI use.
- Microsoft and LinkedIn's Work Trend Index 2024 (31,000 respondents, 31 countries) found that 78 per cent of AI users bring their own tools to work. A ban races against that behaviour and makes it invisible.
- AI Act Article 4 has, since 2 February 2025, required employers to take measures promoting staff AI literacy, whatever tools they use. Since 27 July 2026 no guaranteed level in an individual is required.
- The GDPR exposure arises the moment personal data is pasted into a public tool, because the organisation is then the controller with no processing agreement. That the tool was unsanctioned does not reduce it.
- The answer to shadow AI is not a ban but a sanctioned path, a policy that permits, and competence by role. A ban without a usable alternative drives the use deeper down.
Shadow AI is almost always described as a security threat. Employees feed company data into tools IT never approved, an attack surface opens, and the fix becomes to detect and shut down. The description is not wrong. It is too narrow, and it points to the wrong action.
For a Swedish or Nordic organisation the more expensive gap is a different one. In KPMG and the University of Melbourne's global study 2025, with over 48,000 respondents across 47 countries between November 2024 and January 2025, 57 per cent of employees say they hide their use of AI and present AI-generated work as their own. Almost half admit to using AI in ways that breach their employer's policies, including by entering sensitive company information into free public tools. These are not a few outliers to lock out. It is majority behaviour, and what hides it is also what turns it into a compliance problem.
What shadow AI actually is
Shadow AI is the use of AI without the employer's approval or visibility, much as shadow IT once was software brought in alongside procurement. Two independent measurements with different methods point the same way. One is the KPMG and Melbourne study above. The other is Microsoft and LinkedIn's Work Trend Index 2024, built on 31,000 respondents across 31 countries: 75 per cent of knowledge workers use AI at work, and 78 per cent of those bring their own tools rather than the employer's.
The two studies measure different things. One the concealment, the other the spread. Together they say that unsanctioned AI use is not the exception but the normal state, and that much of it happens where the employer cannot see it. An inventory of licences does not catch it, because most of the tools are free and open in the browser.
Shares among employees in KPMG and the University of Melbourne's global study 2025, over 48,000 respondents across 47 countries, fielded November 2024 to January 2025.
Source: KPMG and University of Melbourne, Trust, attitudes and use of AI: a global study 2025
Why the ban widens the gap
The security frame leads logically to a ban: block the tools, close the domains, forbid pasting. The problem is that the behaviour to be stopped is already widespread and already hidden. When 78 per cent of AI users bring their own tools and 57 per cent of employees hide that they use AI at all, a ban does not move the use. It moves it out of sight, and takes with it the inventory you needed.
A ban governs only the use you can see, and shadow AI is by definition the use you cannot.
That does not make technical controls wrong. It means they solve a different task than the one you have. They constrain a known and approved use, they do not create knowledge of an unknown one.
This is already your duty, not only IT's
Article 4 of the AI Act has applied since 2 February 2025. It places a duty on both providers and deployers, meaning the organisations that put AI systems to use, to take measures to promote the development of AI literacy among their staff and others handling the systems on their behalf. The duty does not follow from your having chosen a tool, but from your people handling AI.
The wording was softened on 27 July 2026. Through the omnibus Regulation (EU) 2026/1744 it now says explicitly that the obligation does not require any particular level of AI literacy to be guaranteed in an individual. That makes the conclusion stronger, not weaker: the competence requirement got lighter the same summer the GDPR exposure stayed exactly where it was. And since 2 August 2026 national market surveillance authorities have supervised Article 4.
Article 4 is a duty to take measures, not a duty of result, and it carries no fine of its own. A breach can, according to the Commission's guidance on Article 4, be weighed when a supervisory authority sets penalties for other breaches. The point for shadow AI is simpler than the penalty question. The AI use already running in the quiet is exactly what the literacy duty is about, and competence by role is the named measure, not a nice-to-have.
The GDPR does not care that the tool was unsanctioned
The duty under the data protection regulation arises the moment an employee pastes personal data or confidential information into a public tool. The organisation is then the controller, and depending on the tool's terms the data is processed by a provider that is often a processor without any data processing agreement in place, not seldom without an established legal basis, and sometimes with a transfer to a third country. That the tool was unsanctioned does not reduce the responsibility. It removes the controls that would otherwise have been there.
This is where the KPMG figure bites. Almost half use AI in breach of the guidelines, and entering sensitive company information into public tools is one of the examples the study points to. Where the data may sit is decided not by the fact that nobody made a decision, but by which of your own rules is the strictest, and it applies whether or not the paste was sanctioned.
What actually closes the gap
What closes a governance gap is governance, not a block. The order is the same as for AI governance in general: an inventory of the use that is actually happening, taken from the people themselves and not from the licence list; a classification of which part of it touches sensitive data; a policy that says what may be done, with which data, in which tools, and who to ask when the answer is unclear; a sanctioned path that makes it easier to do the right thing than to work in the dark; and competence by role with a named owner.
An AI policy that only forbids is not what replaces shadow AI. What replaces shadow AI is a path that is better than the hidden one, and better means concretely faster and more capable than the free tool. It was speed and capability that drove the use there in the first place, so a sanctioned path that is worse than the hidden one will not be used.
The pull against our own conclusion
The comfortable reading of this is that a policy and a training solve it. That reading does not hold all the way. A policy that only restricts, without an approved tool that is good enough for the work, drives the 78 per cent further down, not back. And since Article 4 is a duty to take measures with no fine of its own, it is not the threat of penalties that forces the change. What actually bites is the GDPR exposure, and it is triggered by the paste, not by the policy.
The two halves only work together. A training without a sanctioned path teaches people to use tools they are not allowed to, and a sanctioned path without competence merely moves the risk inside the firewall. Neither is done once and for all, because the tools are replaced every quarter.
The criterion that decides whether it is urgent
Two organisations with exactly the same shadow AI can need different answers, and the difference is not in the tools. It is in one question. Do your people handle personal data or confidential information in these tools? If yes, the exposure is already there, the moment something is pasted, and the literacy duty in Article 4 has applied since February 2025. Then it is not a question for next quarter. If your people only use AI on open, non-sensitive material, the literacy duty still applies, but the data exposure is low, and a lighter, right-sized effort is enough.
A second dividing line is whether you are a deployer of an AI system, which Article 4 binds directly, or you only have staff using public chatbots, which makes you a controller under the GDPR the moment data is entered. Which of these is your situation is settled inside your own organisation, and that is where the work begins.
Common questions
Shadow AI is when employees use AI tools at work without the employer's approval or visibility, much as shadow IT once was software brought in alongside procurement. It usually means free public chatbots opened in the browser, which is why an inventory of purchased licences does not catch them. In KPMG and the University of Melbourne's global study 2025, 57 per cent of employees say they hide their use of AI, which is what makes shadow AI hard to see and to govern.
The moment an employee pastes personal data or confidential information into a public AI tool, the organisation processes personal data through a processor, often without a data processing agreement, without an established legal basis, and sometimes with a transfer to a third country. The organisation is the controller and carries the responsibility regardless of the use being unsanctioned. Fines under the data protection regulation can reach 20 million euro or 4 per cent of total worldwide annual turnover, whichever is higher.
No, not if the policy only forbids. When a large majority already use their own AI tools and hide it, a pure ban drives the use further from visibility instead of stopping it. A policy that works says what may be done, with which data and in which tools, and it is combined with a sanctioned path that makes it easier to do the right thing than to work in the dark. The policy is one step among several, not the whole answer.
Article 4 of the EU AI Act requires both providers and deployers, meaning organisations that use AI systems, to take measures to promote the development of AI literacy among their staff and others handling the systems on their behalf. The duty has applied since 2 February 2025. Through the omnibus Regulation (EU) 2026/1744 the wording was softened on 27 July 2026, so that it explicitly does not require any particular level to be guaranteed in an individual. It carries no fine of its own, but according to the Commission's guidance a breach can be weighed when an authority sets penalties for other breaches, and national market surveillance authorities have supervised it since 2 August 2026.
A blanket ban rarely solves the problem. When 78 per cent of AI users already bring their own tools, according to Microsoft and LinkedIn's Work Trend Index 2024, a ban makes the use hidden rather than absent, and the organisation loses the overview it needs. What works is to offer an approved path that is good enough for the work, together with clear rules on which data may be used where. Technical controls have a place, but they only constrain the use that is already known.
Not through the licence list, because most of the tools are free and open in the browser. The use that is actually happening comes out when people describe their own work: which tasks they have stopped doing by hand and which tools they brought in on their own initiative. That gives an inventory of practice rather than of software, and it is the starting point for classifying which part of the use touches sensitive data and therefore has to be governed first.
AI literacy is the ability of staff and others handling AI systems to understand and use them in an informed way, including the risks. Article 4 of the AI Act makes it a duty on the employer to take measures that promote that literacy, weighed against what each role actually needs. Since the omnibus regulation of 27 July 2026 it is explicitly a duty to take measures that does not require a particular level to be guaranteed in an individual. In practice it means two things: that leadership understands what it has decided, and that every role meeting an AI system knows what applies to that role.
Article 4 on AI literacy carries no fine of its own in the AI Act, but according to the Commission's guidance a breach can be weighed when an authority sets penalties for other breaches. The heavier risk sits in the data protection regulation. If personal data is entered into a public tool without a legal basis or a processing agreement, fines can reach 20 million euro or 4 per cent of total worldwide annual turnover. The actual exposure is decided by what information is handled, not by the tool being unsanctioned.
If this lands on your desk, we should talk.
Ampliro Insights
New analysis, roughly weekly.
We write when the rules change and when something turns out to work in practice. One piece at a time, no sequences, and you can leave from any issue.
We store your address to send Ampliro Insights, and for nothing else. More in the privacy policy.