---
title: "Shadow AI: what happens when employees use AI without a policy"
url: https://zerofive.ai/en/blog/insights/shadow-ai-company-risks-policy
canonical: https://zerofive.ai/en/blog/insights/shadow-ai-company-risks-policy
language: en
published: 2026-01-20
updated: 2026-09-18
author: "ZeroFive.AI"
tags: shadow AI, company AI policy, ChatGPT at work, employee AI risks, AI literacy AI Act
abstract: "In over 90% of companies employees use personal AI tools. What shadow AI is, which risks it creates and why banning it is the wrong answer."
---

# Shadow AI: what happens when employees use AI without a policy

Try an exercise next time you walk across the open space: count how many ChatGPT, Gemini or Copilot windows are open on personal accounts. In the engagements we run, the answer always surprises management, never the teams. The MIT Project NANDA report (The GenAI Divide, July 2025) put a number on the phenomenon: in over 90% of the companies analysed, employees use personal AI tools for work, often exactly where the official pilots stalled. The researchers call it the shadow AI economy, a parallel economy that appears in no inventory, no budget and no risk assessment.

The instinctive reading is that of a violation to repress. Ours, after meeting it in almost every assessment we have delivered, is different: shadow AI is the most reliable signal in existence of the real demand for AI inside the organisation, and at the same time the most underestimated operational risk of the moment.

## The inventory nobody has

The governance problem starts with a question very few companies can answer: which AI systems are being used today, by whom, on which data. The official version of the answer lists the approved projects. The real version includes dozens of consumer tools, plugins installed autonomously, AI features silently activated inside software already under licence, automations built by individual teams on free accounts.

The distance between the two versions has concrete consequences. A document with customer data uploaded to a consumer service is a personal data processing operation nobody ever assessed, with everything that follows under GDPR. An unverified output flowing back into a decision process is an error with no owner. And since 2 February 2025 there is one more layer: the EU AI Act, through Article 4, asks organisations to ensure an adequate level of AI literacy for the staff using it, and the rule does not distinguish between approved tools and tools brought from home.

## Why the ban does not work

Some companies responded by blocking the domains of the main AI services. In our experience the outcome is predictable: usage moves to personal smartphones, exits the observable perimeter entirely and becomes impossible even to estimate. The ban turns a visible, manageable phenomenon into an invisible one, which is the worst possible configuration for anyone in charge of risk.

There is also a deeper reason why repression fails. People use these tools because they work, because they remove friction from tasks the official workflow makes slow, and this information is gold: every shadow use is a free signal about where AI would produce value if adopted seriously. An organisation that switches off the signal gives up the best map of its own use cases, the one drawn by behaviour rather than by workshops.

## From phenomenon to governed perimeter

The path we propose to clients follows a precise sequence, and the first step is a census with no punitive intent: an amnesty window in which teams and individuals declare which tools they use and for what, with the explicit guarantee that the goal is to understand, and if anything to equip everyone with safe alternatives. The census feeds the AI systems register, which serves both day-to-day management and the risk classification required by the European regulatory framework.

The second step is a policy written to be used, with three clear categories (allowed, allowed with precautions, forbidden), concrete examples for each and one very simple rule about data: what may leave the company perimeter and what may not. Twenty-page policies nobody reads produce the same effect as a ban, which is none.

The third step is the part almost everyone skips, namely giving people an official tool at least as good as the one they were using in secret, together with the training Article 4 of the AI Act requires anyway. Shadow AI is not extinguished by decree, it dries up through convenience: when the internal alternative is comfortable, safe and available, the shadow channel loses its reason to exist.

## Measurement before policy

The priority question remains: where to start, with what urgency, with which resources. The answer depends on how widespread the phenomenon is and how mature the organisation is at handling it, two things that can be measured rather than assumed. In our AI Rating, shadow AI cuts across three of the four dimensions we evaluate, readiness (culture and skills), risk (data and compliance) and confidence (trust and actual behaviour), and the score tells you immediately whether you are facing a marginal phenomenon or a parallel perimeter larger than the official one.

If the doubt crept in while reading, it is worth resolving it with numbers: half an hour at calendly.com/fabiolalli/zerofive, or an email to hello@zerofive.ai. In the meantime the open space exercise remains free, and the question it opens is the right one: if AI in your company is already being adopted by the people, who is deciding how?
