WZ-IT Logo

Shadow AI in companies: why a policy alone is not enough

Timo Wevelsiep
Timo Wevelsiep
•
#ShadowAI #AILiteracy #AIAct #AIPolicy #WorksCouncil #LocalAI

Editorial note: The information in this article was compiled to the best of our knowledge at the time of publication. Technical details, prices, versions, licensing terms, and external content may change. Please verify the information provided independently, particularly before making business-critical or security-related decisions. This article does not replace individual professional, legal, or tax advice.

Shadow AI in companies: why a policy alone is not enough

Your staff already use AI, just not through approved tools? WZ-IT sets up an internal AI assistant with company login, approved models and source references, locally in your own network or on a managed GPU server. More in the AI hub. Book a meeting

In many companies, AI is in use before anyone has decided on it. Employees draft emails with a private chat account, have contracts summarised or translate customer correspondence through a free service. This is called shadow AI: AI use outside of reviewed and approved tools.

The usual response is an AI policy. It is necessary, but it changes little as long as there is no tool the policy permits. This article explains what the AI Act requires on AI literacy after the Digital Omnibus, which risks shadow AI actually carries and what an approved alternative looks like. The legal sections are a technical and organisational classification, not legal advice. As of September 2026.

Table of Contents

  1. What counts as shadow AI
  2. How widespread private AI tools are
  3. The actual risks
  4. Article 4 after the Digital Omnibus
  5. Article 50 and your own assistant
  6. Why a policy alone does not end shadow AI
  7. Three routes to an approved alternative
  8. Technical guardrails instead of block lists
  9. Involve the works council and data protection early
  10. A five-step process
  11. Our approach at WZ-IT
  12. Further guides

What counts as shadow AI

Shadow AI is not limited to a chat in the browser. The forms differ in how visible they are to IT and which data they touch.

Form Example Visibility to IT
Private account with a chat service pasting a contract and having it summarised low, often on private devices
Browser extension writing assistant that reads web forms and emails low if extensions are not managed
AI feature in software already in use newly enabled summary in the CRM or ticket system medium, depending on admin settings
Meeting transcription external bot joins video conferences medium, visible in participant lists
API keys in scripts analysing customer data through a model API with a private key very low

What all forms have in common is that company data goes to a service for which neither contract nor data classes nor responsibility have been clarified.

How widespread private AI tools are

Reliable figures on shadow AI are scarce because respondents are reluctant to report unauthorised use. Two primary sources give an order of magnitude:

Survey Result Basis
Microsoft and LinkedIn, Work Trend Index, May 2024 78 percent of AI users bring their own AI tools to work, 80 percent at small and medium-sized companies 31,000 knowledge workers in 31 countries
Bitkom, September 2025 36 percent of companies use AI; 8 percent offer AI training to all employees, 43 percent have no such offering 604 companies with 20 or more employees in Germany

The figures come from different years and populations and are not directly comparable. They do show two things that fit together: using your own tools is common, and most companies have not yet prepared their employees systematically.

The actual risks

The risk of shadow AI rarely lies in the model itself. It lies in data and results leaving the governed framework.

Risk What it is about Basis
Personal data without a contract Entering customer data into a private account transfers it to a service without a data processing agreement Art. 28 GDPR
Training on inputs With free consumer offerings, inputs may be used for training depending on provider and settings; Mistral, for example, allows this in free mode with an opt-out (Mistral Help Center) provider's terms of use
Protection of trade secrets Under German law, only information subject to reasonable secrecy measures is protected as a trade secret Section 2 no. 1 GeschGehG
Professional secrecy Law firms, medical practices and tax advisers may disclose third-party secrets only under narrow conditions Section 203 StGB
Unchecked results Hallucinated facts, figures or legal statements end up in offers, contracts or customer communication the company's liability for its own statements
No overview Nobody knows which tools are used with which data; an incident cannot be contained notification duties under Art. 33 GDPR

The trade secret point is often underestimated. If a company tolerates confidential documents being entered into arbitrary external services, it can become harder to demonstrate reasonable secrecy measures in a dispute.

Article 4 after the Digital Omnibus

Article 4 of the AI Act governs AI literacy. It belongs to Chapter I and has therefore applied since 2 February 2025. Regulation (EU) 2026/1744, the Digital Omnibus on AI, replaced it. The amending regulation was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026.

2024 version Version since 27 July 2026
Addressees providers and deployers of AI systems providers and deployers of AI systems
Obligation measures to ensure, to their best extent, a sufficient level of AI literacy of their staff measures to support the development of AI literacy of their staff
Guaranteed level sufficient level required explicitly no guarantee of any specific level for any individual
Role of Commission and Member States not addressed support companies, in particular SMEs; Commission publishes practical examples
To be taken into account knowledge, experience, education, context of use, affected persons unchanged

Sources: Regulation (EU) 2024/1689, Article 4, and Regulation (EU) 2026/1744, Article 1 point 5.

The obligation has been softened, not removed. Anyone who is a deployer of an AI system must still take measures. The term deployer covers any person or organisation using an AI system under its authority, except in the course of a personal non-professional activity.

One statement from the European Commission is particularly relevant to shadow AI. In its questions and answers on AI literacy, it explicitly names a company whose employees use ChatGPT for advertising copy or translations: this company should also comply with Article 4, and employees should be informed about risks such as hallucinations. According to the Commission, no certificate is required; an internal record of trainings is sufficient. Supervision lies with national market surveillance authorities.

Article 4 is not subject to fines within the meaning of Article 99(4). Member States lay down penalties and other enforcement measures under Article 99(1). In practice, the fine question is secondary anyway: without training and without an approved tool, it is hard to show that a company has governed its use of AI.

Article 50 and your own assistant

Article 50 and its transparency obligations have applied since 2 August 2026. Paragraph 1 obliges providers of AI systems that interact directly with people to inform users of this, unless it is obvious. The paragraph does not distinguish between customers and employees.

This becomes relevant once a company replaces shadow AI with its own assistant. Anyone who builds a system themselves and makes it available under their own name can become a provider as a result. For generative systems placed on the market before 2 August 2026, the machine-readable marking under paragraph 2 applies only from 2 December 2026 under the new Article 111(4). The details and the role distinction are covered in the article on the AI labelling obligation under Article 50. In practice, a notice in the assistant's interface is usually sufficient.

Why a policy alone does not end shadow AI

An AI policy defines what is allowed. It does not remove the reason employees turn to private tools: they have a task that AI helps them complete faster, and no approved tool for it.

This leads to four patterns that can be observed in companies regularly:

  • Ban without alternative. The need remains. Network or DNS blocks only work on the company network and on managed devices. Use moves to the private smartphone, where the company sees neither data nor results.
  • Permission without data rule. The policy allows AI in general but does not say which data may go into which tool. The decision is then left to each individual.
  • Rule without training. Employees know the policy but not the risks. This is exactly where Article 4 comes in.
  • Tool without quality. An approved tool that is noticeably worse than the private service gets bypassed.

A policy becomes effective only together with two further building blocks:

Building block Content Evidence
Rule permitted tools, data classes per tool, duty to check results, contact person policy with a date, works agreement where applicable
Tool approved assistant with company login and clear data assignment system description, contract or own operation, model list
Competence role-based training: model limits, hallucinations, data classes, prompt injection internal record of measures

Three routes to an approved alternative

Which alternative fits depends mainly on the data classes to be processed.

Route Data flow Fits when To check
Business plan from a cloud provider provider infrastructure, depending on plan and region general texts, no professional secrecy, quick start without own operation DPA, storage location, sub-processors, enabled features
European model API behind your own interface question and context go to a European provider medium protection needs, fluctuating load location, training policy, model catalogue
Internal assistant with own inference nothing leaves your network or your own server confidential documents, professional secrecy, answers from your own documents hardware, operation, updates

The comparison between a cloud workspace and local AI is shown in Local AI or ChatGPT Business. European model APIs are compared in the article on European LLM APIs.

The routes are not mutually exclusive. A combination often makes sense: an interface such as Open WebUI, behind it a gateway that provides local models for confidential content and an approved external API for general tasks. What matters is that employees can see which model processes a request.

For in-house operation, WZ-IT offers two routes. The AI Cube is an AI appliance in your own network with Open WebUI, at a purchase price of €6,490 excl. VAT one-time plus AI Cube Care at €349.90 excl. VAT / month. Managed GPU servers from WZ-IT run in a German data centre with an NVIDIA RTX PRO 4000 Blackwell (24 GB GDDR7 ECC) or RTX PRO 6000 Blackwell Max-Q (96 GB GDDR7 ECC), from €699 excl. VAT / month. As of September 2026.

Technical guardrails instead of block lists

An approved assistant replaces shadow AI only if it implements the rules technically rather than merely describing them.

Guardrail Implementation Effect
Company login sign-in through the existing directory service, for example with Keycloak access ends when someone leaves, groups control permissions
Model approval gateway such as LiteLLM with a list of permitted models per group confidential areas reach only local models
Answers from your own sources RAG with permission checks before retrieval fewer hallucinations, verifiable sources
Data-minimising logging timestamp, model, token count, errors; full prompt text only by agreement operation and cost measurable, no performance monitoring
Labelling notice in the interface that an AI system is responding covers Article 50(1)
Managed extensions approve browser extensions through endpoint management policies fewer unnoticed data outflows

How permissions work in the assistant is described in RAG with permissions. The data protection criteria are summarised in GDPR-compliant AI.

Involve the works council and data protection early

An approved assistant is a technical system that generates usage data. That brings two reviews into play which seem to disappear with shadow AI because nobody knows about it. For companies in Germany, the Works Constitution Act (BetrVG) is central:

Provision Content
Section 90 BetrVG information and consultation when planning work processes, including the use of artificial intelligence
Section 87(1) no. 6 BetrVG co-determination for technical systems suitable for monitoring behaviour or performance
Section 87(1) no. 1 BetrVG co-determination on workplace order and employee conduct, which rules of conduct in an AI policy can affect
Section 80(3) BetrVG if the works council has to assess the use of AI, bringing in an expert is deemed necessary

The scope of logging is where most negotiations get stuck. If the wording of requests is not permanently linked to the person, the starting position is considerably easier. The details are in the article AI assistants and the works council. Whether co-determination rights apply in an individual case needs to be clarified under employment law.

A five-step process

  1. Survey current use. Short anonymous survey or conversations per department: which tools are used, for which tasks, with which data. The goal is an overview, not sanctions.
  2. Define data classes. Public, internal, confidential, professional secrecy. For each class, define which route is permitted.
  3. Provide the tool. An approved assistant that covers the most frequent tasks from the survey, with company login and model approvals.
  4. Introduce rule and training together. The policy refers to the approved tool. The training explains model limits and the data classes and is documented internally.
  5. Adjust. After a few weeks, check which tasks still run outside and adapt the tool or the rule.

The order matters: introducing the policy before the tool creates a rule that cannot be followed in daily work. The obligations of the AI Act as a whole are summarised in The EU AI Act for companies.

Our approach at WZ-IT

  1. Assessment. Tasks, data classes, number of users and existing systems. This determines whether local operation, a European API or a mixed setup fits.
  2. Build. Open WebUI as the interface, sign-in through your directory service, LiteLLM as gateway with approved models, and on request answers from your documents with source references.
  3. Operation in your network or in the data centre. AI Cube as an appliance on your premises or a managed GPU server from WZ-IT in a German data centre.
  4. Documentation. Data flow diagram, field list for logging, roles and retention periods as the basis for data protection and the works council.
  5. Operation. Updates, model changes with regression tests, monitoring, and support, consulting and implementation by WZ-IT.

The legal assessment of roles, obligations and co-determination remains with the company and its legal advisers. We implement the agreed limits technically.

Further guides

Replace shadow AI with an approved tool? We set up an internal assistant with company login, approved models and documented data flows, in your own network or in a German data centre. Book a meeting

Sources

Enquiry

An approved AI alternative for your staff

We set up an internal AI assistant with company login, approved models and data-minimising logging, either locally in your own network or on a managed GPU server from WZ-IT.

What is your situation?

How should we get back to you?

Frequently Asked Questions

Answers to important questions about this topic

Shadow AI refers to AI tools that employees use for work without the company having reviewed and approved them. Typical examples are private accounts with chat services, browser extensions, AI features in software already in use, meeting transcription through external services and API keys in self-written scripts.

No. Regulation (EU) 2026/1744, in force since 27 July 2026, replaced Article 4. Providers and deployers must still take measures, namely to support the development of AI literacy of their staff. What is new is that they are not required to guarantee any specific level of AI literacy of any individual. The Commission and the Member States are to support companies in this. This is a classification, not legal advice.

According to the European Commission's questions and answers on AI literacy, yes. The Commission explicitly names a company whose employees use ChatGPT for advertising copy or translations. The employees should be informed about the specific risks, for example hallucinations.

No. The European Commission states that no certificate is needed and that organisations can keep an internal record of trainings and other measures. The regulation does not prescribe a fixed training format.

Usually not. A ban without an approved alternative leaves the need in place, and network blocks only work on the company network and on managed devices. Use then shifts to private devices, where the company sees neither data nor results. A combination of a clear rule, an approved tool and training is more effective.

A business plan with a data processing agreement closes the contractual gap of private accounts, but does not answer every question about storage location, sub-processors, enabled features and permitted data types. For professional secrecy or particularly sensitive data, operation in your own network or on a dedicated server is often the clearer option.

In Germany, frequently yes. Section 90 of the Works Constitution Act (BetrVG) explicitly mentions the use of artificial intelligence when planning work processes, and Section 87(1) no. 6 BetrVG can apply as soon as a system is objectively suitable for monitoring employee behaviour or performance. An AI policy with rules of conduct can also affect workplace order. The specific legal position should be reviewed by employment law counsel.

Article 50 has applied since 2 August 2026. Paragraph 1 obliges providers of AI systems that interact directly with people and does not distinguish between customers and employees. A company that builds an internal assistant itself and makes it available under its own name can be a provider. In practice, a notice in the interface is usually sufficient, unless the AI interaction is obvious anyway.

Article 99(4) of the AI Act does not list Article 4 among the obligations subject to fines. Under Article 99(1), Member States lay down penalties and other enforcement measures, which may include warnings. Supervision lies with national market surveillance authorities. Independently of that, missing training can matter after damage or a data protection incident.

Timo Wevelsiep

Written by

Timo Wevelsiep

Co-Founder & CEO

Co-Founder of WZ-IT. Specialized in cloud infrastructure, open-source platforms and managed services for SMEs and enterprise clients worldwide.

LinkedIn

Let's Talk About Your Idea

Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.

Arrange a callback

Callback

Arrange a callback

Leave your number and we will call back — at the latest on the next business day.

For a longer conversation you can book an appointment instead.

Companies worldwide trust WZ-IT

  • ml&s
  • Rekorder
  • Keymate
  • Führerscheinmacher
  • SolidProof
  • ARGE
  • Boese VA
  • nextGYM
  • SweetConnect GmbH
  • Golem.de
  • Millenium
  • Paritel
  • Yonju
  • EVADXB
  • Mr. Clipart
  • Aphy AG
  • Negosh
  • ABCO Water Systems
1/3 - Topic Selection33%

What is your inquiry about?

First select the service area that best matches your project.