Shadow AI

Your employees are already using AI. The only question is where the data goes.

By the GPUwerk team · August 26, 2026

This isn't a hypothetical risk you're deciding whether to take on. It's already happening, on devices and accounts you can't see, and the evidence for that is now well documented. The only real decision left is what happens to the data once it leaves.

The usage is already universal

Multiple independent surveys converge on the same picture: most employees use AI tools at work whether or not IT has approved them. WalkMe's 2025 survey put the figure at 78% of employees using unauthorized AI tools, and UpGuard's 2025 AI risk research reached a comparable figure of just over 80%. Cyberhaven Labs, analyzing real enterprise network traffic, found that 73.8% of ChatGPT accounts used from workplace networks were personal, non-corporate accounts, meaning the enterprise had no visibility into what was typed into them and no contractual protection over what happened to that data. A Salesforce survey of over 14,000 workers across 14 countries found more than half of generative-AI adopters at work use unapproved tools, and, tellingly, many of them said they recognized the need for a company-approved option but proceeded anyway because none existed.

Separately, CybSafe and the National Cybersecurity Alliance's 2025 research found that roughly 38% of employees admit to sharing confidential work information with AI tools without their employer's permission. This isn't a rogue minority. It's the median employee, using the same tools they use at home, for the same reason: those tools are fast and good at their job.

Why the risk is real, not theoretical

The reference case is Samsung's, and it's worth restating precisely because it's often exaggerated in retelling. In March 2023, within weeks of Samsung's semiconductor division lifting an internal ban on ChatGPT, three separate incidents occurred at its Device Solutions unit in Hwaseong: an engineer pasted the source code of a confidential database into ChatGPT and asked it to check for errors, another shared code for optimization, and a third uploaded a recording of an internal meeting and asked ChatGPT to turn it into minutes. None of that data was extracted by an attacker, it was handed over voluntarily, by employees trying to do their jobs faster, into a consumer product whose data-handling terms weren't written with a semiconductor manufacturer's IP in mind. Samsung's response, reported by Forbes and others, was to ban generative AI tools company-wide by May 2023 and open disciplinary reviews into the three employees involved.

Regulators have been paying attention to the same gap between consumer AI products and the obligations that apply to data run through them. Italy's Garante ordered OpenAI in March 2023 to stop processing the personal data of Italian users pending an investigation into transparency and legal-basis failures under GDPR, a suspension it lifted in April 2023 once OpenAI made changes, and which was followed in December 2024 by a €15 million fine from the same authority over how ChatGPT handles personal data. None of that concerned a leak or a breach; it concerned the default terms consumer AI products operate under, which is exactly the layer an employee pasting a customer list or a contract into ChatGPT is exposed to.

Why blocking it doesn't work

The instinctive response, block the domain at the firewall, doesn't hold up, and it's worth being precise about why. Personal devices, mobile hotspots, home Wi-Fi, and DNS-over-HTTPS all sit outside the corporate network perimeter that a firewall rule controls, so the block simply doesn't apply to them. A VPN does the same from inside the office, making traffic look like it originates from a home connection. And even where the network block does hold, it only kills one destination: employees who were using ChatGPT move to Claude, Gemini, or Copilot on a personal account instead, because the underlying need, get this written, summarized, or debugged faster, hasn't gone away.

The practical effect of blocking, in other words, is not less AI use. It's the same AI use, moved further from IT's visibility and further from any device you control, onto a personal phone, a personal laptop, a personal account with no admin console, no audit log, and no way for you to know what was pasted into it. IBM's 2025 Cost of a Data Breach Report found that breaches involving this kind of unsanctioned "shadow AI" cost organizations an average of $670,000 more than the global average cost of a data breach, a difference plausibly explained by exactly that loss of visibility.

The policy that actually works: give people somewhere sanctioned to go

The pattern across the surveys above is consistent: employees don't want to hide their AI use, and a majority say they'd use a sanctioned tool if one existed. Salesforce's respondents said as much directly. The lesson isn't "monitor harder", it's that prohibition without an alternative just pushes usage somewhere you can't see, while an approved, genuinely useful replacement gives people no reason to reach for their own phone. A workable policy has a few concrete pieces:

Where a private, EU-hosted assistant fits

The reason "provide a sanctioned tool" is the load-bearing item on that list is that it's the only one that actually competes with the convenience employees are already voting for. A dedicated, self-hosted assistant closes the specific gap the surveys above describe: it gives people the same chat-style interface they already reach for, but running on infrastructure your organization controls, in the EU, with no prompts leaving the building to train someone else's model. That's what a private ChatGPT alternative is for, the same day-to-day usefulness, minus the account you can't see into. For teams that want the full picture of what running models on owned or dedicated hardware looks like, cost, performance, and governance, see our guide to private LLM hosting.

Give your team somewhere sanctioned to go.

A private ChatGPT-style assistant on dedicated EU infrastructure, deployed in minutes, nothing leaves the building.

See the private ChatGPT setup Talk to us