The problem

Shadow AI is already inside your organisation

While the AI project waits for budget approval, your staff have already decided. They paste meeting notes, resident correspondence and extracts from council papers into a public AI service, straight from their browser, with no bad intent and no trace whatsoever. The question is no longer whether to go ahead, but under what conditions this happens.

This is not ordinary shadow IT

Classic shadow IT means an unapproved tool: a shared spreadsheet, a file transfer service. The risk is real but it is static, and it is fixed by approving the tool or replacing it.

Shadow AI is a different animal: it is continuous exfiltration, deliberately fed by the member of staff, at a rate proportional to their effectiveness. The better they get at using the tool, the more material they hand it. It is the only security risk that growing skill makes worse.

Invisible

Nothing in your logs. The traffic looks like ordinary web browsing, and the usage moves to a personal phone the moment you get in its way.

Growing

Someone saving two hours a week will not go back. Every month of waiting widens the set of data that has already left.

Attributable to you

The controller remains the organisation, not the individual. "They did it on their own initiative" has never been a defence.

Where the data goes, with and without an internal tool

✗ Without an internal tool A real need summarise, draft No approved tool the project waits Public AI service from the browser Data leaves the EU no trace at all ✓ With an internal AI A real need the same one Tool available SSO, no friction Sourced answer from your documents Inside your perimeter and logged
The need is identical in both cases. Only the destination of the data changes.

Why a ban settles nothing

An internal memo is the most common response. It is also the least effective, for three reasons that have nothing to do with how disciplined your teams are.

It relocates the usage

Blocking it on the workstation does not remove the need, it pushes it onto a personal phone. The usage carries on, off your network and out of your sight.

It is technically bypassable

Filtering blocks a few known domains. New ones appear every week, and tethering to a mobile connection is enough to walk around it.

It costs you the upside

You lose the productivity without removing the risk: the worst of both worlds. And you give up the one thing that would bring you back into the loop, an official tool.

What the regulation says

A prompt containing personal data, sent to a vendor located outside the European Union, is a processing operation and usually a transfer. It binds you even though you never authorised it.

ObligationUnder shadow AIWith an internal AI
Lawful basisNone, the processing was never identifiedDefined and documented at scoping
Informing data subjectsImpossible, nobody knows the processing existsA privacy notice can be drafted
Record of processingThe activity does not appear in itCan be recorded, scope is known
Transfer outside the EUUnframedNot applicable, EU hosting
Right to erasureUnenforceable, nothing is under your controlEnforceable, the index is yours
AuditabilityNoneLogged
Shadow AI does not only create a leakage risk, it makes your GDPR obligations materially impossible to meet.

These obligations are set out in detail on our AI & GDPR and EU AI Act pages.

The only response that holds: substitute

You do not regain control by forbidding, you regain it by offering something better. For someone to drop the unofficial tool, the official one has to meet three conditions, and failing a single one is enough to sink the substitution.

1. Just as good

A model of comparable quality, not a cut-down demo. If the quality disappoints once, people go back to the tool they know and do not come back.

2. Just as easy

Login through your existing directory, no extra password, available from the workstation. Every added step sends people back to the browser.

3. More useful

It knows your council papers, your procedures, your contracts. No public AI service can ever do that, and it is what makes the substitution permanent.

This is exactly the role of RAG over your own documents: it does not merely make the tool compliant, it makes it better than the unofficial alternative. Without that gap in value, substitution does not take.

What you get back

The immediate benefit is not productivity, it is visibility. You move from invisible, unquantifiable usage to measured usage: which departments use it, for what kinds of task, over which corpora. That is what lets you document your compliance rather than discover it during an audit, and decide the next use cases on facts.

Take back control of usage that already exists

A 30-minute demonstration on your own documents, then a three-week pilot with a go/no-go milestone. That is the gap between usage you endure and usage you govern.

Book a demonstration