LIVE
Study finds gender bias in GPT models is not reduced but reshaped across generations17/09/26 · OpenAI|Architectural tweaks may break conventional scaling law exponents16/09/26|OpenAI publishes a framework for reporting model misalignment16/09/26 · OpenAI|NVIDIA's Vera Rubin NVL72 Debuts in MLPerf Inference v6.116/09/26 · NVIDIA|OpenAI expands ChatGPT advertising with Sponsored Agents16/09/26 · OpenAI|OpenAI moves into advertising with 'Sponsored Agents'16/09/26 · OpenAI|Google DeepMind Introduces Gemini 3.8 Live and Its Extended Thinking Variant15/09/26 · Google DeepMind|What's at stake in AI's trillion-dollar infrastructure bet15/09/26|A Flaw in Chain-of-Thought Safety Monitoring14/09/26|Stellar Colosseum: A Multi-Agent System for Long-Horizon Mathematical Research14/09/26|Apple Code Hints Siri Could Be Swapped for ChatGPT or Claude14/09/26 · Apple|Anthropic says Houthi-linked actors used Claude Code for missile guidance software13/09/26 · Anthropic|Study finds gender bias in GPT models is not reduced but reshaped across generations17/09/26 · OpenAI|Architectural tweaks may break conventional scaling law exponents16/09/26|OpenAI publishes a framework for reporting model misalignment16/09/26 · OpenAI|NVIDIA's Vera Rubin NVL72 Debuts in MLPerf Inference v6.116/09/26 · NVIDIA|OpenAI expands ChatGPT advertising with Sponsored Agents16/09/26 · OpenAI|OpenAI moves into advertising with 'Sponsored Agents'16/09/26 · OpenAI|Google DeepMind Introduces Gemini 3.8 Live and Its Extended Thinking Variant15/09/26 · Google DeepMind|What's at stake in AI's trillion-dollar infrastructure bet15/09/26|A Flaw in Chain-of-Thought Safety Monitoring14/09/26|Stellar Colosseum: A Multi-Agent System for Long-Horizon Mathematical Research14/09/26|Apple Code Hints Siri Could Be Swapped for ChatGPT or Claude14/09/26 · Apple|Anthropic says Houthi-linked actors used Claude Code for missile guidance software13/09/26 · Anthropic|
Intermediate👥

Shadow AI: the invisible danger in business

78% of your employees use personal ChatGPT at work. Your data may be going to OpenAI without you knowing. We explain the phenomenon, real incidents, and 30-day remediation plan.

14 min readPublished May 5, 2026· Updated September 17, 2026

In one sentence

Shadow AI is the use of ChatGPT, Claude, Gemini and other AIs outside the official corporate framework. Your salespeople pasting client contracts into ChatGPT, your developers copying proprietary code into personal Cursor, your HR team summarising CVs via NotebookLM. 78% of companies are affected. And most don't know it.

👥
The analogy that works
Shadow AI is the communal fridge in the open-plan office. Everyone puts what they want in it, no controls, no hygiene. It works for 3 months, then one day, it stinks badly, and nobody knows who put what in there. Except in the case of AI, what stinks is your client data, your contracts, your proprietary code : and it's at OpenAI now.

🛡️ Want the complete AI security guide for your company?

SAIF frameworks, OWASP, AI Act, 90-day action plan.

Read the CISO guide

The scale of the phenomenon

The figures are staggering:

Shadow AI: the 2026 figures

Without authorisation78%
% CISOs who underestimate Shadow AI65%
Proprietary code47%
Client data31%
Financial data23%
With official authorisation22%
% employees who used ChatGPT at work0
% who pasted sensitive data0

The gap: employees massively use unauthorised AIs (78%), but CISOs underestimate the phenomenon (65%). You have 3-4× more Shadow AI than you think.

Mapping: where Shadow AI hides

The 8 forms of Shadow AI in a typical company
YOUR COMPANY 🏢 Data • IP • Clients 1. Personal accounts 💬 Personal ChatGPT/Claude → Data leaves outside 2. Browser extensions 🧩 Monica, GPT for Sheets, → Reads everything you see 3. Personal code copilots 💻 Cursor, personal Copilot → Proprietary code sent 4. SaaS adding AI ⚙️ Notion AI, Slack AI, → Auto-enabled in contracts 5. Freemium tools 🆓 Otter.ai, Loom AI, → Meetings transcribed + summarised 6. AI websites 🌐 Perplexity, Phind, ChatPDF → Upload client PDFs 7. APIs without IT 🔌 Devs create scripts → With their own API keys 8. Mobile apps 📱 iPhone Apple Intelligence → Bypass the firewall 🌊 Shadow AI: 8 invisible vectors in a typical company
Shadow AI nests everywhere. Mapping = the 1st step to control.

The 6 reasons why it happens

📚Why your employees bypass IT

1. Official AI is too limited

You deployed Microsoft Copilot? Cool, but it's worse than ChatGPT Plus for many tasks. Employees perceive a degradation in productivity and switch to personal.

Solution: deploy ChatGPT Enterprise or Claude for Work. It costs £30-60/user/month but it's cost-effective.

2. The IT process is too slow

Requesting a new AI takes 3-6 months (validation, contracts, security). In 6 months, 5 new AIs have come out.

Solution: create a fast-track process for AI tools (validation in 2 weeks).

3. Nobody explained the rules

"We have a charter", which doesn't clearly say what's forbidden or not. Many employees DON'T KNOW that pasting client data into ChatGPT is a problem.

Solution: clear, short AI policy + flash training.

4. The productivity gain is real

A salesperson who writes a proposal in 2 hours instead of 8 thanks to ChatGPT, they'll continue. Even if it's forbidden. Productivity pressure will win.

Solution: officially recognise the need + provide an approved tool.

5. Nobody's monitoring

IT has no visibility on the web SaaS tools used by employees. Without a CASB (Cloud Access Security Broker), it's the blind leading the blind.

Solution: deploy a CASB or Zscaler AI Security to see what's happening.

6. AI arrives without us knowing

Notion, Slack, Microsoft 365 add AI features to their existing tools. Your employees use AI without even realising it.

Solution: audit the AI features of all SaaS used. Disable those that pose problems.

Real Shadow AI incidents in 2024-2026

3 real cases that hurt
### 1. Samsung (May 2023, but lesson still valid) What happened: 3 Samsung Semiconductor engineers pasted proprietary code into ChatGPT to debug it and summarise meeting notes. The code and notes went to OpenAI. Consequence: Samsung banned ChatGPT internally. Creation of an in-house AI. Cost: several million dollars + project delay. Lesson: don't underestimate your engineers' creativity. If you don't provide, they'll find. ### 2. Law firm (anonymous, 2024) What happened: a junior lawyer uploaded 30 client contracts to ChatGPT to analyse and synthesise them. He thought "save time". Except the contracts contained confidential clauses and personal data. Consequence: massive GDPR breach. Client complaint. Risk of CNIL fine: €100K-2M. Plus loss of reputation. Lesson: train your legal teams as a priority. They handle the most sensitive data. ### 3. Biotech startup (USA, 2025) What happened: R&D used NotebookLM (free, Google) to analyse their research data on a drug in development. NotebookLM is free partly because the data can be used for training (with opt-out, but they hadn't activated it). Consequence: their intellectual property (drug formula) potentially accessible to Google and therefore competitors. Lawsuit ongoing. Lesson: free tools have a hidden cost. Always read AI terms of service.

How to detect Shadow AI in your company

Shadow AI detection pyramid
🎯 PRO: AI Red Team Regular offensive testing 📊 Analytics: CASB + Zscaler AI Automatic AI traffic detection Microsoft Purview AI Hub, Netskope, Zscaler 🔍 Audit: Network logs + DNS Which domains are visited? openai.com, anthropic.com, gemini.google.com Tools: Splunk, ELK, Cisco Umbrella 📝 BASE: Anonymous survey "Which AI tools do you use? (anonymous, no sanctions)" Google Forms, Typeform, Microsoft Forms Quickest to implement, 1 week COST $$$$ $$$ $$ $ Shadow AI detection pyramid: start with the base
Combination of 4 methods to have complete visibility

The 30-day remediation plan

📚From Shadow AI to controlled AI

Week 1: Diagnosis

Action 1: Anonymous survey (15 min/employee)

  • 5-7 short questions:

- Which AI tools do you use for work? - How many times per week? - For what (summaries, code, emails, ...)? - Have you pasted company data into an AI? - Do you know what's allowed?

Action 2: Network logs (1 SOC day)

  • List AI domains visited in the last 30 days
  • Traffic volume to each
  • Identify anonymised "power users"

Result: Shadow AI dashboard to present to the executive committee.

Week 2: Emergency policy

Action 1: Simplified AI charter (1 page)

  • ALLOWED list: deployed tools + what you can put in them
  • FORBIDDEN list: "NEVER paste into a consumer AI..."

- Identifiable client data (GDPR) - Proprietary code - Contracts, NDAs, patents - Detailed financial data - HR data

Action 2: Communication (executive email + intranet)

  • Not guilt-inducing ("we understand you use it")
  • Constructive ("here are alternatives, here are the rules")
  • Clear objective: amnesty + improvement

Week 3: Tooling

Action 1: Official AI deployment

  • ChatGPT Enterprise (£30/user) OR Claude for Work (£60/user) OR Microsoft Copilot (£30/user)
  • Configure Data Residency EU (GDPR)
  • Configure No training data (API clause)

Action 2: DLP (optional but recommended)

  • Block paste of sensitive content to public ChatGPT
  • Tools: Calypso AI, Glean, Microsoft Purview

Week 4: Training and follow-up

Action 1: Flash training (1h all, 4h for techs)

  • Concrete cases ("Here's what my colleague did, here are the consequences")
  • Demo of the official tool
  • Validation quiz

Action 2: AI hotline

  • "Not sure if you can put X in Y?" → Slack channel #ai-doubts
  • Response in <2h during office hours

Action 3: Measurement

  • Re-survey at 3 months to measure impact
  • KPI: % Shadow AI usage (target <20%)

The trap: don't fall for total prohibition

Why 'we ban AI' doesn't work
Many companies (especially finance, defence) first completely banned ChatGPT. Observed consequences: 📉 Productivity drops: -15 to -25% depending on teams 🚀 Shadow AI explodes: employees use their personal phones, their 4G, proxies 🚨 Detection even harder: traffic disappears from corp network 👥 Resignations: the best leave for competitors who allow AI The lesson: AI is a competitive advantage. Your company without AI will lose the war against those that have mastered it. The right approach: not ban, but govern. Provide the right tools + the right rules + training. It's harder but it's what works.

The metaphor that sums it all up

🏗️
Workers and tools
Imagine a construction site. You forbid workers from using power drills because you find it dangerous. What will they do? - Option 1: they accept and use hammers. The site is 6 months late. You go bankrupt. - Option 2: they bring their own drills from home (Shadow AI). No training, no protection. One day, serious accident. - Option 3: you provide certified drills, you train on their use, you set clear rules (goggles, gloves, authorised zones). Productivity + safety. → The right solution is never "ban the tool". It's provide the right tool in the right framework. Shadow AI is just the symptom of an organisation that hasn't done its job.

Absolutely remember

  • 78% of employees use an unauthorised AI at work
  • Risks: data leakage, GDPR, IP loss, AI Act sanctions up to €35M
  • Why: limited official AI, IT too slow, unclear rules
  • Detection: anonymous survey + network logs + CASB
  • 30-day remediation: diagnosis → charter → tooling → training
  • DO NOT ban: govern, that's what works
  • Enterprise tools: ChatGPT Team/Enterprise, Claude for Work, Microsoft Copilot

Shadow AI is not a failure of your employees, it's a failure of your organisation to provide the right tools. Reverse the perspective and you'll find the solution.

🧠 Quiz
Question 1 of 3

What is the approximate percentage of employees using an unauthorised AI at work in 2026?

Go further

Tags
Shadow AICybersécuritéRGPDGouvernanceAI Act

Read next