Security

Data security and Shadow AI: why bans are not enough

4 min read
Watch the video

The real risk when using AI in the company is not only the tool: it is invisible, ungoverned use. If there is no secure and convenient company path, people still tend to use personal tools and upload documents outside control.

The operational truth, without softening it too much

AI is not magic: it is a tool. If you put customer data, confidential strategies, or ongoing negotiations into a system you do not control, you are creating risk. Period.

The problem begins when the company reacts only with a block: “Close ChatGPT and we have solved it.” In many cases you have not removed the need. You have only made it harder to see where that need is being met.

Why bans do not eliminate the need

What often happens in practice?

  • people use their personal phone;
  • they access unauthorized tools;
  • they upload documents to private accounts.

At that point you lose visibility and control. This is not a universal physical law, and not every ban automatically produces leakage. It is, however, a recurring operational pattern: when the official tool is missing or too inconvenient, the temptation to work around it grows.

The UK NCSC guidance on Shadow IT describes similar dynamics: slow processes or unsuitable tools push users toward ungoverned solutions.

What Shadow AI means in practice

Shadow AI is the use of artificial intelligence tools outside approved and monitored company channels.

The Verizon DBIR 2026 reports that the share of employees considered regular AI users on company devices rose to 45%, from 15% the previous year. In the same perimeter, 67% of users access AI services through non-corporate accounts. Shadow AI also appears among the most frequent non-malicious insider actions in the analyzed DLP datasets, with a relevant increase versus the previous year.

These numbers do not say that “banning is always wrong.” They say that use is now mainstream and that a relevant share happens outside the organization’s direct control.

What a truly usable company path requires

The approach that works is different from prohibition alone: give people a safe path.

A useful company path usually includes:

  • a tool that works well and is convenient;
  • company accounts and authentication;
  • logging and traceability of relevant uses;
  • access controls on documents;
  • data loss prevention (DLP) measures where needed;
  • clear rules on retention and data destination;
  • training on the reasons for the rules, not only on the ban.

Then explain the why. You are not limiting people for bureaucracy: you are protecting the company, customers, and them as well. When the message is clear and the solution is practical, collaboration grows. Clarity favors adoption; bans alone favor workarounds.

What the AI Act and GDPR actually say (without legal advice)

Regulation (EU) 2024/1689 (AI Act) and the GDPR are not a general ban on AI. They introduce responsibilities, differentiated obligations, and data protection principles that must be applied to the concrete case.

The EDPB has also clarified relevant aspects on AI models and data protection. Treat these indications as general information: they do not replace a legal assessment of your specific use.

Operational summary: regulating and securing use is often more effective than pretending use does not exist.

FAQ

Is blocking ChatGPT illegal?
No. It can, however, be ineffective if it is not accompanied by a usable alternative and clear rules.

How do you detect Shadow AI?
With network monitoring, CASB, DLP, browser policies, and, above all, dialogue with people about real needs.

Can an SME afford a secure solution?
Yes, if you start from a concrete perimeter and controls proportionate to risk, without copying large-enterprise models.

What is the concrete risk of Shadow AI?
Transfer of sensitive data to uncontrolled infrastructures, less visibility, and greater difficulty demonstrating accountability.

Sources

Explore the series

If you want to map real AI usage and design a governed company path that is usable, traceable, and proportionate to risk, we can run an operational workshop with IT, security, and business. Write to us at info@zendata.it or visit zendata.it.

Pietro Ciattaglia, CEO of Zendata AI, Rome