[ Use AI Securely ]

[ Chapter 4 · Recognizing and managing AI risks at work ]

Shadow AI and chatbots at work

3 min read

Shadow AI is the use of AI tools your organisation has not approved: a personal ChatGPT account for work tasks, a free translation site for client documents, a browser extension that "reads" your email, an AI notetaker silently joining meetings. Surveys through 2024 and 2025 repeatedly found that a large share of employees using AI at work do so without their employer's knowledge, often on personal accounts.

Why approved tools are genuinely different

This is not bureaucracy for its own sake. When an organisation approves an AI tool, it typically signs an enterprise agreement changing how data is handled: no training on your inputs, defined retention, security certifications, a data processing agreement as GDPR requires, sometimes EU-hosted processing. A consumer account for the same product may come with none of that. The interface looks identical; the legal reality is not.

  • Same tool, different account = different risk. Work data belongs in work accounts.
  • Extensions and notetakers are AI tools too. Anything that reads your screen, inbox, or meetings has access to everything it sees, and joins the meeting for every participant, consenting or not.
  • Free tools have a business model. If a free service processes your documents, understand what it does with them; the terms of service are usually explicit and rarely read.

If you have already used unapproved tools with work data, treat it like any other security matter: report it through your organisation's usual incident or security channel so the exposure can be assessed. And if your organisation has no AI policy at all, the habits in Chapter 5 are your safety net, and it is worth saying out loud that a policy is needed.