Key Takeaways
- Shadow AI is already here: According to the German Federal Office for Information Security (BSI), one in four companies is affected. Employees use private AI tools without approval, and the real number is higher.
- Bans make it worse: Lock systems down and people move to private devices and accounts, where you have no visibility at all. Channel the demand instead of forbidding it.
- Amnesty beats manhunt: An anonymous tool inventory shows what is actually in use, without blaming anyone.
- Provide an official tool: First review the process and ask whether it can be dropped. Then offer one approved, genuinely productive AI tool.
- Traffic-light policy and data classification: Four confidentiality levels along ISO 27001 lines, enforced technically in Microsoft Purview. What is blocked by design needs no policing.
- Mind the EU AI Act: Article 4 requires AI literacy training, and high-risk use cases such as CV scoring need a human in the loop.
What Shadow IT and Shadow AI actually mean
Do you know what your people do all day? Most managers think of home office, long breaks or a cigarette outside. I think of something else entirely: shadow IT. Shadow IT means the quiet, unapproved use of tools inside a team, and shadow AI is its current, far more powerful form. One in four German companies is affected according to BSI figures, and because most of it goes unnoticed, the real number is considerably higher.
The phenomenon is not new. What is new is the leverage. AI multiplies whatever you feed it, and that includes mistakes. Shadow IT was always risky. Shadow AI takes the same risk and adds customer data, contracts and applicant records to the equation.
Why shadow AI appears in the first place
It appears wherever people are handed locked-down systems and still have work to finish. The first stage is to stretch the approved company tool as far as it goes. When that fails, people bring their own equipment. At that moment the process leaves your control entirely, and no policy in the world can see it any more.
What really happens in daily business
After 38 years in this business I am not quoting half-knowledge from a search engine. I see the same patterns everywhere. Someone says: just draft an email to that customer. Off it goes, complete contact details included. Or: here is a contract, compare it against the standard one. No review, no approval. It gets genuinely hot when someone decides that AI could screen job applications. That is high-risk AI territory under the EU AI Act, and scoring candidates without a human in the loop can trigger serious penalties.
Why bans do not work: amnesty instead of manhunt
Anyone who has been a child knows how this ends. Our parents could forbid whatever they liked. If we understood the reason, we accepted it. If we did not, we found a way around it. Companies are no different. Germany has an odd relationship with mistakes: we say we want more of them, and then we punish whoever makes one. People learn quickly, stop admitting mistakes, and the organisation stops learning too. In large corporations this is the dominant culture, and it is a bad idea.
Tool one: the anonymous inventory and one official tool
Ask anonymously. The point is not who uses what, but which tools exist in the company at all. Before you replace anything, ask what people actually do with those tools. You will often find processes that can be eliminated instead of automated. My order of operations is: eliminate, then structure, then automate, and only then add AI on top. Once you know the real demand, provide one official, approved tool that is genuinely good enough to use.
Tool two: a traffic-light policy people can follow
A policy only works when it is operational. A traffic-light system does that: green for uncritical content, yellow for internal information that needs a case-by-case decision, red for anything confidential. Combine it with four confidentiality levels along ISO 27001 lines and you can enforce the rules technically. In Microsoft Purview, documents at the highest level simply cannot be uploaded. What is prevented by design does not have to be audited afterwards.
Training beats control
Explain the guardrails and people accept them, provided they have a productive tool in their hands. That combination is the whole trick: understanding plus a usable alternative. Ignore the topic and you get uncontrolled growth, and uncontrolled growth is exactly what you cannot afford once AI is involved.
Mentioned Tools & Resources
- Microsoft Purview - classifies documents and enforces confidentiality levels technically inside Microsoft 365.
- Microsoft Copilot - works on data that already sits in your tenant, which keeps the additional risk low.
- ISO 27001 - information security standard and a solid basis for an operational classification scheme.
- BSI - the German Federal Office for Information Security, source of the shadow IT and shadow AI figures.
- EU AI Act video course - 14 lessons in English and German with a certificate, covering the Article 4 training obligation.
Frequently Asked Questions
What is shadow AI?
Shadow AI is the use of AI tools by employees without approval from IT. It is the continuation of classic shadow IT, but with far greater leverage, because AI moves company data into external systems.
How widespread is shadow AI in companies?
BSI figures put it at one in four companies. Since most of this use goes unnoticed, the actual number is higher. Without an anonymous inventory, no organisation really knows where it stands.
Why do bans on AI tools fail?
Because a ban removes the tool, not the need. People switch to private devices and accounts, where there is no oversight at all. What works is the opposite: provide an approved, productive tool and explain the guardrails.
Which three measures help against shadow AI?
First, amnesty instead of manhunt - an anonymous tool inventory without blame. Second, one official approved AI tool. Third, a traffic-light policy that states clearly which data may go into which system.
How should we classify data for AI use?
Four confidentiality levels along ISO 27001 lines, translated into a simple traffic-light system for employees. Microsoft Purview can then enforce technically that top-level documents cannot be uploaded at all.
What does the EU AI Act require from companies?
Among other things, AI literacy for employees under Article 4. Certain applications are classified as high risk, and AI-based CV screening without human review is one of them, with substantial penalties attached.
Conclusion
Shadow AI is not a discipline problem, it is a supply problem. People reach for private tools when the official ones do not carry them through the working day. Bring the usage into the open with an amnesty, give your teams one approved tool that is actually good, and make the rules operational with a traffic-light policy and technical enforcement. Train your people rather than policing them. If you need support building an AI policy, running workshops or training your team on the EU AI Act, feel free to get in touch.




