Back to the blog
Cybersecurity

Shadow AI: when employees quietly paste company data into ChatGPT

It is happening in your company right now, while you read this. Someone pastes a confidential contract, a customer list or an internal report into a public AI tool to make their work easier. Well meant, quickly done, and a real security …

Justin Shabani

Managing Director & Founder

3 min read
Shadow AI: when employees quietly paste company data into ChatGPT, cover image

It is happening in your company right now, while you read this. Someone pastes a confidential contract, a customer list or an internal report into a public AI tool to make their work easier. Well meant, quickly done, and a real security risk. Experts call it shadow AI: the use of AI tools without the knowledge and approval of IT.

The topic is no longer a fringe phenomenon. According to the IBM Cost of a Data Breach Report 2025, shadow AI was involved in 20 percent of all analysed data breaches, and such incidents cost 670,000 US dollars more on average than usual ones1. Time to take the problem seriously.

Why employees reach for shadow AI

The most important point first: shadow AI does not arise from bad intent but from productivity pressure. The tools are there, they are free, and they help immediately. When the company's official offering is missing or too cumbersome, employees switch to whatever works.

That is exactly what makes the problem so stubborn. A ban alone does not solve it, it only drives usage deeper underground. Anyone who wants to contain shadow AI has to understand the real need and offer a better, secure alternative.

What is really at stake

Shadow AI in numbers from the IBM Cost of a Data Breach Report 2025.

The moment confidential content moves into a public tool, knowledge leaves the building. In the worst case, those inputs are reused for training and reappear in other people's answers. For trade secrets, personal data or regulated information, that is a nightmare.

There is also the control gap. The IBM report shows that in AI-related incidents, 97 percent of the affected organizations had no adequate access controls for their AI1. So it is not just about which tool is used, but that nobody keeps an overview of who accesses what. And all of this against a background of tightening regulation: the GDPR and the EU AI Act demand provable control over data processing, not hidden sprawl.

Why a ban is not enough

The typical first reaction is a memo: AI tools are prohibited. That soothes the conscience briefly and changes little. The need remains, usage moves further into the shadows, and IT loses the overview even more.

The reverse path is effective. Instead of banning usage, you channel it onto a secure route. If there is an official, approved system that is at least as convenient as the public tool, the incentive to quietly switch disappears.

The secure alternative: reviewed knowledge under control

A ban displaces the problem, a secure alternative solves it.

This is exactly where AI-THINK. comes in. The AI-VI Core Technology (patent pending with the DPMA) provides company knowledge as a reviewed, approved dialogue, hosted in the EU and GDPR-compliant. The content does not flow into a foreign model but stays in your hands.

That gives employees what they are looking for anyway: fast, understandable answers to their questions. Only from a source the company owns, traceable to the origin document and without confidential data leaving the building. The uncontrolled shadow becomes a secure, official route. That is the most effective protection against shadow AI, because it addresses the need rather than the symptom.

Conclusion

Shadow AI is not a sign of bad intent but a sign of an unmet need. A ban only shifts the problem, it does not solve it. And the costs are real, as the 670,000 US dollar premium per incident shows.

The way out is a secure, convenient alternative from within your own house. Anyone who makes reviewed knowledge accessible without handing over control of their data takes away the breeding ground for shadow AI.

What you can do now

  1. Find out which AI tools are actually in use before you ban anything.

  2. Provide an official, approved channel that is more convenient than the public one.

  3. Set access rules and logging so it stays traceable who accesses what.

And if you need a reviewed basis for that: Get to know AI-VI

Sources

  1. [1]IBM Security: Cost of a Data Breach Report 2025, Shadow AI bei 20 Prozent der Vorfälle beteiligt, im Schnitt 670.000 US-Dollar Mehrkosten; bei KI-bezogenen Vorfällen fehlten in 97 Prozent der Fälle angemessene Zugriffskontrollen; globaler Durchschnitt 4,44 Mio. US-Dollarhttps://www.ibm.com/reports/data-breach
Back to the blog

12 March 2026 · 3 min read

AI-VI, your AI avatar

With your consent we load three Google services: product videos from YouTube, audience measurement with Google Analytics and ad measurement from Google Ads. Data is transferred to Google in the process. Without your consent none of it loads, and videos show a preview image served from our own server. The website works fully either way. You can decide service by service under Settings, and change it at any time. Privacy policy