Shadow AI: Your Team Uses AI Without Telling You, and the Obligation Stays With You

At a client I asked which tool they used to transcribe meetings: the answer was five different tools, four of them free, two with GDPR and AI Act problems. Nobody had done anything wrong. Here is why the obligation falls on the company anyway, why a ban does not hold, and where you actually start.

Gaetano Castaldo Gaetano Castaldo
13 Aug 2026
Rules and compliance #ai-act #ai-governance #gdpr #ai-training #security
A meeting in a small company: each person has a different device in front of them while the owner at the head of the table takes notes by hand

Shadow AI: Your Team Uses AI Without Telling You, and the Obligation Stays With You

45% of employees now use AI regularly on company devices, up from 15% the year before (Verizon Data Breach Investigations Report 2026). This is shadow AI. The AI literacy obligation set by the AI Act falls on the company even when the employee picked the tool alone, and it has been in force since 2 February 2025, not since August 2026 as is often written.

What is shadow AI at work?

It is the use of artificial intelligence tools for work without the company knowing, assessing or approving them. It is not sabotage and it is rarely bad faith: it is people trying to finish their own work. 67% of those doing it use non-corporate accounts, invisible to the company (Verizon Data Breach Investigations Report 2026, May 2026).

An example from a client. I asked which tool they used to transcribe meetings. The answer was five different tools, four of them free, and nobody in the company knew that two of those four have problems with GDPR and with the AI Act.

Nobody had done anything wrong. Each person had simply solved their own problem, and in doing so had sent the full content of internal meetings outside the company.

The wider data says this is not an isolated case: shadow AI is now the third most common non-malicious insider action in data loss prevention datasets, a fourfold increase in a year, and the data type most often uploaded to unauthorised platforms is source code, by a wide margin (Verizon DBIR 2026).

Why does the responsibility fall on the company and not the employee?

Because the AI Act looks at whoever deploys the system as an organisation, not at whoever clicked.

Article 4 of Regulation (EU) 2024/1689 requires providers and deployers to ensure a sufficient level of AI literacy among the staff operating on their behalf. It has applied since 2 February 2025, with no transition period, and it was the first provision of the AI Act to become applicable. It is not new for August 2026: August 2026 is the regulation's general application date, which brings other obligations, not this one.

Here belongs the part usually left out, because it changes how the matter should be handled. Article 4 carries no direct penalty. A lack of AI literacy weighs as an aggravating circumstance when penalties for other violations are calculated, under Article 99(7)(g).

In plain terms: nobody fines you for not training your people. They fine you if something else happens, and at that point the fact that you had not trained them makes the bill worse. The same reasoning applies on the GDPR side, where the data that left the building is processing you neither assessed nor documented.

Anyone selling you Article 4 as an incoming fine is selling you fear. The real risk is different and more concrete: the day you do have a problem, you turn up having done nothing.

Why does banning AI not work?

Because a ban does not touch the cause, and the cause is almost always a work need.

Behind an employee uploading a document to a free tool there is usually an impossible deadline, or a task handed to someone without the skill to complete it in the time given. Banning the tools leaves the deadline and the skill gap in place, and simply moves the behaviour to where you cannot see it.

There is a simpler reason too: a ban only works where governance exists to enforce it. With no list of approved tools, nobody to report exceptions to and nobody checking, the ban is a memo that nobody applies.

And then there is the question I always put to the owner, which is the most useful of all: if the problem comes from people trying to work better, would it not make more sense to streamline the organisation by bringing in the right AI, rather than banning the wrong one?

Convincing an owner of this takes longer than writing the ban. It is the only approach that holds, though, because it puts people's knowledge before the rules.

What are the two organisational defects behind shadow AI?

In the companies where I find five different tools doing the same job, the same two things are always missing. They are not technology defects, they are organisational ones.

One: nobody decides which tools may be used. What is missing is the person who governs AI in the company and keeps a charter of approved tools, kept current, with a note against each one saying what it may be used for and with which data. Without that charter every person decides alone, and gets it right only by chance. On who that person should be, I have written here.

Two: there is no channel to IT. Sign-ups to non-compliant tools reach nobody, so nobody sees them and nobody can act. In a structured company that alert is automatic. In a smaller company far less can be enough, but something has to exist.

As long as those two things are missing, shadow AI is not an incident: it is the predictable behaviour of the system.

What should you do first if you suspect it is happening?

An assessment, before any rule.

In the AI Adoption paths we run, the first thing built is the map of what already happens: which processes today pass through an AI tool, which tools those are, what data they work on and who introduced them. That is also where the documents needed on the AI Act side come from, starting with the register of processes using AI and the tools they use.

Two warnings, both worth more than the document itself.

The first is that the register has to be used, not filed. A file completed once and never reopened proves nothing and protects nobody.

The second is the order. First you look at what actually happens, then you decide what to allow. The other way round you write a tool charter that does not match the real work, and it gets worked around within the first month.

In the meantime, the list of things that should never go into a public tool is already written: you will find it in 7 things a small company should never upload to ChatGPT.

Does training solve shadow AI?

Yes, but not on its own and not at any moment.

Training comes after the assessment, for two reasons. The first is that before it you do not know what to train on: you risk training blind, the generic kind about "what artificial intelligence is", which nobody applies the next day. The second is that useful training is specialised to the nature of each department's work: administration, sales and production do not share the same risks or the same use cases.

In AI Adoption paths training always has its own specification, but it comes downstream of the map. If budget is the issue, it is worth saying that in many cases this training can be funded: I wrote about it in mandatory AI training and the funds that pay for it.

Want to know which tools are really running in your company?

Try the question I put to that client: ask which tool is used to transcribe meetings, or rewrite emails, or put quotes together. Do not ask it in a full meeting, ask two or three people separately. The distance between the answers is the size of the problem.

If you do not like the answers, the free Pre-Assessment starts exactly there, and it is the first step of our AI consulting path for small and mid-sized companies. If you would rather see where you stand first, there is the AI readiness test and the deep dive on AI literacy, the AI Act and Italian law 132.

Frequently asked questions

What is shadow AI?

It is the use of artificial intelligence tools for work activities without the company having assessed or approved them, often from personal accounts and with free tools. According to the Verizon Data Breach Investigations Report 2026, 45% of employees use AI regularly on company devices, up from 15% the year before, and 67% do it from non-corporate accounts.

Is the company liable if an employee uses AI without authorisation?

Yes. Article 4 of the AI Act requires those deploying AI systems to ensure a sufficient level of AI literacy among staff operating on their behalf, and it has applied since 2 February 2025. It carries no direct penalty, but a lack of AI literacy weighs as an aggravating circumstance when penalties for other violations are calculated (Article 99(7)(g)).

Should you ban ChatGPT for employees?

Almost never. A ban does not touch the cause, which is usually a tight deadline or a task given to someone without the skill to finish it in time, and it moves the usage to where the company cannot see it. A ban only works where governance exists to enforce it: a list of approved tools, someone to report exceptions to and someone who checks.

Tags

#ai-act #ai-governance #gdpr #ai-training #security
Gaetano Castaldo
Gaetano Castaldo Sole 24 Ore

Founder & CEO · Castaldo Solutions

Sono un consulente di trasformazione digitale con esperienza enterprise. Aiuto le PMI italiane ad adottare AI, CRM e architetture IT con risultati misurabili in 90 giorni.

Read also

Related articles you might find interesting

Does NIS2 apply to your company?

Ten reference areas, a guided questionnaire and a PDF report with the gaps to close first.

Take the NIS2 Readiness Assessment

Free, in ten minutes