Shadow AI: when staff use AI on their own initiative
Somewhere in the building, someone is typing a customer email into an AI chat right now. The account is private, and the organisation knows nothing about it. That is exactly what shadow AI is: staff doing work tasks with AI tools that nobody has approved. The term comes from shadow IT, meaning programs that employees get hold of behind IT's back. What is new is that texts and documents leave the building in the process, and that in the end the organisation is still the one answerable for it.
How widespread shadow AI is
How often this happens was measured by Bitkom in the summer of 2025, in a telephone survey of 604 companies with 20 or more employees. The result, published in October, shows above all a gap: considerably more companies reckon with private AI accounts than provide one themselves, for instance through an AI platform.
What happens legally
The controller under the GDPR is whoever decides on the purposes and means of a processing operation (Art. 4(7)). An application is reviewed because the organisation is filling a post, so the responsibility stays with the organisation and does not travel with the account.
The processing itself may be lawful under Art. 6 GDPR in an individual case. Everything else is missing regardless: no contract with the provider under Art. 28, no entry in the record under Art. 30, no demonstrable safeguards under Art. 32, and neither access nor erasure is possible. The steps that belong before an approval are in the article on GDPR-compliant AI use.
Who is personally on the hook
Of the managing directors of a GmbH, section 43(1) GmbHG requires "the care of a prudent businessman", and under section 43(2) they are liable to the company for the damage that arises from a breach of duty. That presupposes an attributable loss; for fines and removal from office this restriction does not apply. In an association, a board member working unpaid is liable under section 31a(1) BGB only for intent or gross negligence.
What that care means organisationally was spelled out by the Higher Regional Court of Nuremberg on 30 March 2022 (case 12 U 1520/19): an internal structure including a compliance system against legal breaches by employees. The judgment says nothing about AI, but the standard applies regardless of the tool. An assessment, not legal advice.
Who has to be involved inside the organisation
Before the first official seat is handed out, the staff representation has to be involved. A platform with access logs and usage reporting is objectively suitable for capturing conduct and performance, and the right of co-determination hangs on that alone, whether or not anyone intends to monitor. Which set of rules applies depends on the type of employer.
| Type of employer | Representation and legal basis | Result |
|---|---|---|
| private-sector business | works council, section 87(1) no. 6 BetrVG, information duty under section 90(1) no. 3 | works agreement |
| public body | staff council, section 80(1) no. 21 BPersVG or the state equivalent | service agreement |
| Catholic employer | employee representation, section 36(1) no. 9 MAVO | service agreement, section 38 MAVO |
| Protestant employer | employee representation, section 40 MVG-EKD | service agreement, section 36 MVG-EKD |
| no body at all | no representation internally | a written internal rule adopted by management |
Why a ban alone is not enough
In 2025 the University of Melbourne and KPMG asked 48,340 employees in 47 countries whether they upload sensitive company data into public AI tools. The result is surprising: where AI is banned, 67 per cent do, under a usage rule 56 per cent, and with no policy at all 33 per cent. What is being compared here, though, is a ban against a policy, not a ban against an offer of the organisation's own.
A second problem: anyone who has accidentally uploaded a customer file does not report it if the report is at the same time a breach of the rules. What a notification under Art. 33 GDPR needs then never arrives.
What works instead
Three steps, and their order matters.
First an official offer. As long as nothing approved exists, every rule remains an imposition. For small teams, business plans with a data processing agreement and a training exclusion are enough. From several departments upwards an AI platform with central user management and logging pays off, for instance Langdock.
Then a written usage rule. One page is enough if it says which tools are approved, which data may go in, and where to report a mistake without getting into trouble for it.
Finally, training. It also satisfies the AI literacy duty under Art. 4 of the AI Act, in force since 2 February 2025.
What the approved access then gets used for
Access for which nobody names a task sits idle, and the private accounts come back. Two tasks to start with: the assistant to management has a draft set of minutes written from the notes of a meeting and approves it before it goes into the meeting folder. In fundraising, the call for a funding programme turns into a comparison: what does the application require, what is already held, what is missing?
Both of these have long been happening in many places, only in a private account. An official access point makes them visible, and everything else builds on that: shared assistants, automation with n8n, company knowledge via RAG. How a rollout runs is set out under introducing Langdock.
Turn shadow AI into governed use?
arocom records what is in use, sets up approved access and trains the people involved. For organisations from 10 people upwards, whatever their legal form.
What is shadow AI, and how widespread is it?
Doing work tasks with AI tools that nobody has approved, usually through private accounts. According to Bitkom, 42 per cent of companies reckon with it, and 26 per cent provide access of their own.
Who is liable when staff use AI on their own initiative?
The organisation first, because the controller under the GDPR is whoever decides on purposes and means. Personally, the managing directors are liable under section 43 GmbHG if an attributable loss arises from a breach of their duty of care.
Is a ban on AI tools enough?
The data argue against it. In the University of Melbourne and KPMG survey, employees upload sensitive company data most often where AI is banned: 67 per cent against 33 per cent with no policy at all.
We have no works council. Who do we have to involve?
That depends on the type of employer: public bodies involve the staff council, church employers the employee representation, in each case through a service agreement. Where there is no body at all, a written internal rule adopted by management takes its place.
How does AI & Automation hold up on your website? The Future Check shows where the biggest levers are — in 2–4 weeks.
Go deeper
Read next
Copy this prompt and paste it into ChatGPT, Claude, or another AI — you'll get a personal learning plan for „Shadow AI: figures, legal position and what helps“.
You are an experienced coach for AI & Automation. I want to understand the topic "Shadow AI: figures, legal position and...Reviewing an AI platform
24 review questions across six axes, with a findings sheet. Vendor-neutral.
Was this article helpful?