ChatLock

Shadow AI: Your Employees Are Already Pasting Company Data Into ChatGPT

Shadow AI is the use of unapproved AI tools at work. Learn why banning ChatGPT doesn't work, what data is really at risk, and how to give your team a safe AI assistant they'll actually use.

7 min read

Ask IT or security managers whether their company has an AI policy, and many will say yes. Ask whether employees use personal ChatGPT accounts for work anyway, and most will admit they probably do.

That gap is called shadow AI.

What is shadow AI?

Shadow AI is employees using AI tools without the company's approval or knowledge. It's the AI version of shadow IT, like personal Dropbox accounts or browser extensions nobody reviewed.

What makes it riskier is what people paste in. They use an AI assistant for the content they're stuck on: a difficult contract, a tense client email, the spreadsheet with this quarter's numbers, the performance review they have to deliver tomorrow.

Why it happens

People turn to shadow AI because they want the tool and nobody gave them a safe one.

The tools are useful. Drafting, summarising and rewriting are faster with AI, and employees know it. Often the approved alternative doesn't exist or is worse, and if the official answer is "no AI", people use it from their phone. And nobody explained the risk: most employees don't know that consumer AI accounts can use conversations for training, or that the company has no contract with the provider.

What's at risk

When an employee uses a personal AI account for work, your company usually loses control over confidential information (client data, contracts, source code, pricing, M&A plans) and over personal data such as customers' or colleagues' names, emails and HR details. With no processor agreement in place, that is a GDPR problem.

The content also lives in the employee's personal account, on the provider's servers, for as long as they decide. When they leave the company, their chat history goes with them.

The best-known case happened at Samsung in 2023. Engineers pasted confidential source code and internal meeting notes into ChatGPT to debug and summarise them, and Samsung responded by restricting generative AI tools across the company.

Why banning AI doesn't work

Blocking ChatGPT on the corporate network feels like control. Mostly it moves usage to personal devices, where you see even less.

A ban also costs you something: competitors' teams get faster with AI while yours copy text to their phones. Under the EU AI Act you're already required to ensure AI literacy among staff, which is hard to do for a tool you pretend nobody uses.

What worked for shadow IT works here too. Give people an approved tool at least as good as the one they'd use anyway, and make the rules clear.

How to tackle shadow AI in 5 steps

1. Measure first

Run an anonymous survey asking which AI tools people use and for what. You'll learn more from it than from firewall logs, and people will see that the goal is to help them.

2. Provide an approved AI assistant

Choose a tool that matches consumer chatbots on quality and that your security and legal teams can sign off on. For work use you need no training on your data, a Data Processing Agreement, and clear data location and retention. Ideally, the architecture should make it impossible for the provider to read prompts at all, which is stronger than a policy promising it won't.

3. Write a one-page AI policy

Keep it short enough that people read it. Say which tools are approved, which data can never go into any AI tool, and that a person must review outputs before they're used.

4. Train briefly and practically

A 30-minute session with real examples from your company works better than a 40-page policy. Show what good prompting looks like, and what a data leak looks like.

5. Revisit every quarter

New tools appear every month, so keep the list of approved tools and use cases up to date.

Where ChatLock fits

We built ChatLock to be an AI assistant companies can approve without worrying. Employees get a ChatGPT-like experience with leading open-source models, file uploads, projects and web search.

Prompts are encrypted in the browser and only decrypted inside a hardware-secured enclave. Neither ChatLock nor the cloud provider can see the data while the model processes it, and you can verify this through cryptographic attestation. Nothing is kept after the response or used for training. The Business plan adds SSO, audit logs, a DPA and dedicated support.

If the safe option is also the easiest one, people have little reason to go around it.

FAQ

What is shadow AI?

Shadow AI is the use of AI tools, such as ChatGPT or other chatbots, by employees without the company's approval or oversight, often through personal accounts.

Is shadow AI a GDPR risk?

Yes. If employees paste personal data into a personal AI account, the company processes that data without a processor agreement and without control over retention or transfers, which is difficult to justify under the GDPR.

Should we block ChatGPT at work?

Blocking alone tends to push usage to personal devices. Providing an approved, secure AI assistant, with a clear policy and short training, works better.

How do I detect shadow AI in my company?

Combine an anonymous survey with network and SaaS discovery tools. The survey often tells you more, because much of the usage happens on personal devices.