Custodos is live – all leading AI models, securely hosted in the EU or Switzerland.Start free trial
All articles
SecurityUpdated on 26 July 20266 min readCustodos editorial team

Shadow AI: spotting and fixing uncontrolled AI use

Shadow AI is the use of AI tools for work tasks without approval and without IT's knowledge – typically through private accounts, private devices or browser extensions. It is the AI case of classic shadow IT, with one decisive difference: data is not merely stored somewhere uncontrolled, it is transmitted to a third party and may be reused there.

Shadow AI does not arise from carelessness but from a gap: there is a task, a privately known tool solves it, and no official offering exists. Once you recognise the pattern you can close it rather than fight it.

This article describes how to spot shadow AI, why it weighs more heavily in legal terms than shadow IT, and what the controlled route looks like.

How to spot shadow AI

Shadow AI is inconspicuous because it needs neither an installation nor a budget. It still leaves traces – four of which can be checked without specialist tooling.

  • Network and proxy logs: calls to known AI domains from the corporate network, even with no application installed.
  • Browser extensions with AI features that access page content – the most frequently overlooked route.
  • Expense claims and card statements: individual subscriptions booked as software or training.
  • Daily work itself: texts produced strikingly fast in an unfamiliar structure, or employees mentioning tools in meetings that were never approved.

Why shadow AI weighs more than shadow IT

Classic shadow IT stores data outside your control – a cloud folder, a private note-taking tool. The damage lies in the lack of availability and in third-party access to stored content.

With AI tools a second layer appears: inputs may be used to improve the models, and processing often happens outside the EU and Switzerland. That touches purpose limitation and the rules on disclosure abroad at the same time.

In both cases the company carries the liability. Neither the GDPR nor the revFADP makes an exception for unofficial tools. For holders of professional secrets the criminally sanctioned duty of confidentiality comes on top – Section 203 of the German Criminal Code, Section 121 of the Austrian Criminal Code, Art. 321 of the Swiss Criminal Code – and it expressly extends to auxiliary staff.

What is actually missing when it matters

The difference between governed and ungoverned use only shows once somebody asks – a client, a regulator, a court.

Question when it mattersWith shadow AIWith governed use
Which data went into which system?Cannot be reconstructedEvidenceable through audit logs
On what contractual basis?None; consumer terms of useData processing agreement
Where was the data processed?Set by the provider, usually undocumentedContractually fixed region
Was it used for training?Depends on the individual's settingContractually excluded
What happens when someone leaves?Account and history remainAccess is revoked centrally

The wrong reflex: banning

A ban without an alternative drives usage onto private phones and home laptops, where no firewall is watching. The productivity gains leave the company and the risk stays – only without visibility.

There is a second effect that rarely gets considered: after a ban, employees stop reporting incidents. Someone who would have to admit breaching an instruction stays silent. The company then loses the chance of a timely notification under Art. 24 FADP or Art. 33 GDPR.

A ban therefore only makes sense once it can point to an available offering. The rule is then not "no AI" but "AI through this route".

The controlled route

A six-step approach works well. The first step matters most and is the one most often skipped.

  1. Create transparency without blame: take stock of actual usage, expressly free of sanctions. Threaten consequences and you get a flattering picture instead of a true one.
  2. Understand the tasks, not just the tools: what work were people routing around for? That list is the requirements list for the official offering.
  3. Provide a central offering that covers those tasks – with the models the team wants to use anyway.
  4. Assign access centrally, define roles, connect single sign-on so access reliably ends when someone leaves.
  5. Put an AI policy with concrete data classes into force, and include all auxiliary staff.
  6. Train briefly and practically with examples from your own organisation – which also addresses the AI literacy obligation in Art. 4 of the EU AI Act.

What to do after taking stock

If the inventory shows that personal data has flowed into unsuitable systems, that is an incident and not a footnote. What has to be assessed is whether a breach of data security occurred and whether it is notifiable.

The thresholds differ: Art. 33 GDPR requires notification within 72 hours where there is a risk to rights and freedoms. Art. 24 FADP requires notification as quickly as possible where the risk is high. Both assessments have to be documented – including where the conclusion is that no notification is required.

The data cannot be retrieved retrospectively. The sensible course is to document the situation cleanly, assess the categories of data affected and stop the inflow, rather than spending effort on a clean-up that is technically impossible.

Frequently asked questions

Is shadow AI grounds for dismissal?

In employment law terms that depends on the individual case, but in practice it is usually the wrong question. As long as there is no clear instruction and no official offering, there is no basis for the accusation. Starting with sanctions costs you the transparency you need to fix the problem.

How do we find out which AI tools are being used?

Combine three sources: network and proxy logs for known AI domains, an overview of browser extensions on company devices, and a sanction-free survey of the teams. In practice the survey yields the most, because it also captures private devices.

Is an AI policy enough against shadow AI?

Not on its own. A policy with no tool available describes a state employees cannot produce. It only becomes effective alongside an official offering that covers the tasks people were routing around for.

Are browser extensions with AI features a problem?

Frequently yes, and they are routinely overlooked. Extensions with access to page content can transmit data from line-of-business applications and mailboxes to third parties without anyone actively pasting anything. An approved list for extensions therefore belongs in the AI policy.

What about data that has already leaked?

It cannot be retrieved. What to do: document the extent, assess the categories of data affected, check the notification duty under Art. 24 FADP or Art. 33 GDPR, and record the outcome of that assessment – including where no notification follows.

Does shadow AI affect small companies too?

Yes, and often more strongly: the smaller the IT function, the less likely an approved tool exists and the more obvious the private account becomes. The duties under data protection and professional law set no lower threshold.

Sources

Related reading

Bring AI into your company securely.

Try Custodos with your team – and see how quickly secure AI becomes productive.

Start free trial
  • Try it with the whole team
  • Set up in minutes
  • Productive from day one