Shadow AI: what to do when staff use ChatGPT on their own
Short answer
Shadow AI is the use of AI tools such as ChatGPT, Gemini or Claude by employees without the organisation having approved it or being able to see it. The risk is that confidential and personal data ends up at an outside party, which regulators such as the Dutch Data Protection Authority treat as a possible data breach. A ban alone does not work: you need a better alternative that runs under your own control.
What exactly is shadow AI?
Shadow AI is the successor to shadow IT: employees choosing their own tools because the official route is too slow or too limited. With AI this happens faster than ever. A chatbot is free, runs in the browser and makes someone’s work lighter today. Summarising a report, rewriting a difficult email, having a spreadsheet formula explained: none of that needs an IT project.
The problem is not the tool, but what goes into it. To get a good answer, an employee pastes in the context: the customer file, the draft contract, the list of names. At that moment the data sits at an outside party, in a personal account the organisation has no agreement with and no view of.
What happens when you cannot see it: the city of Eindhoven
In October 2025 the Dutch municipality of Eindhoven found, in an internal sample, that staff had uploaded files containing personal data of residents and colleagues to public AI websites. They included youth welfare documents, internal reports and CVs. The municipality reported the breach to the Dutch Data Protection Authority and blocked public AI websites.
Two things make this example instructive. First: the sample covered one month, and how much data had been shared in total could no longer be established. Second: the staff were doing their jobs. They were looking for help with heavy, time-consuming writing. The use arose from a need, not from bad intent.
Eindhoven is not an exception. The Dutch regulator receives a growing number of breach reports caused by AI chatbots at work, and had already warned about it in 2024, with examples from a GP practice and a telecoms company. See also Is ChatGPT GDPR-compliant for your organisation?
Why a ban alone does not work
The first reflex is to block. As an emergency measure that is sensible, but as a policy it falls short:
- It moves the use elsewhere. Whoever is blocked at the office picks up their phone. Then you see even less.
- The need remains. Staff used AI because it works. Take it away without an alternative and you take away productivity, while the pressure to use it anyway stays.
- It gives you no insight. A block does not tell you which tasks staff wanted to do with AI, while that is exactly your list of candidates for responsible automation.
Bringing shadow AI under control in five steps
- Map the use. Look in your proxy, DNS or CASB logs to see which AI services are visited, by which departments and how often. Also simply ask teams what they use AI for. That yields more than you expect.
- Write a clear AI policy. Which tools are allowed, which data may go into them, and what does an employee do when in doubt? Make it concrete, with examples per department. Put it before the DPO and the works council.
- Offer an alternative that works at least as well. This is the step that makes the difference. An approved AI environment that runs under your control, with models that can handle the daily tasks.
- Then block the public services on the network and on managed devices. Now it works, because there is an alternative.
- Train and measure. AI literacy has been part of the AI Act since 2025. See The EU AI Act in 2026. Then look, in aggregate, at which questions keep coming back: that is your list of processes to automate.
The alternative: AI under your own control
A business subscription with a large AI vendor is a step up from personal accounts. The data still goes to an outside party, only under better terms. If you want to end shadow AI for data that must not leave the organisation, you need an environment in which the AI comes to the data.
With private AI from werqly, the language model runs on a node of your own in your server room. Staff get a chat environment that feels like what they are used to. In werqly AI Control your IT department decides per role which model is available, blocks patterns such as ID numbers and IBANs before they reach a model, and chooses how much insight the organisation gets into use: anonymous, per department, or per user with approval from two administrators. Everything is recorded in an audit log you can export to your SIEM.
Frequently asked questions
Questions on this topic
What is the difference between shadow IT and shadow AI?
Shadow IT is any use of software outside IT’s view. Shadow AI is the variant with AI tools, and it is riskier because staff actively paste content into them: documents, emails and customer data, to get a better answer.
Is employees’ use of ChatGPT a data breach?
It can be. According to the Dutch Data Protection Authority, it is a data breach when an employee enters personal data into an AI chatbot against company agreements, because the provider then gains unauthorised access to that data.
Should we block ChatGPT?
As an emergency measure that can be sensible, as the city of Eindhoven did. As a policy it only works together with an approved alternative. Otherwise the use moves to personal phones, where you have even less visibility.
How do I find out which AI tools staff use?
Your proxy, DNS filter, firewall or CASB logs show which AI domains are visited and how often. Combine that with conversations per team about what they use AI for. The latter tells you which tasks an alternative must handle.
Sources
- Municipality of Eindhoven — Data breach involving public AI (press release, Dutch)
- Dutch Data Protection Authority — Caution: use of AI chatbot may lead to data breaches (2024)
- Binnenlands Bestuur — AI use leads to more data breaches (Dutch)
This article is general information, not legal advice. Rules and guidance change; check the sources listed or ask your lawyer or DPO if in doubt.