Shadow AI in companies refers to the use of tools like ChatGPT, Claude, Copilot, or Gemini by employees without the employer’s approval. This is not primarily a problem of disobedience: it is the symptom of a real need that is poorly managed. For an SMB, the challenge is clear: gain productivity without exposing customer data, contracts, margins, or internal files to uncontrolled services.
Shadow AI in companies: what exactly are we talking about?
The term shadow AI, sometimes called BYOAI for “Bring Your Own AI,” describes the use of artificial intelligence tools at work without company approval or IT department oversight. Put simply: an employee pastes meeting notes, a contract excerpt, a sales file, or code into ChatGPT using their personal account because it’s fast.
Microsoft and LinkedIn were already describing this phenomenon in 2024 in their Work Trend Index, conducted among 31,000 people in 31 countries: 75 % of knowledge workers said they used AI at work, and 78 % of AI users said they brought their own tools. The signal is simple. Usage is advancing faster than internal rules.
The issue also concerns SMBs. Not just large corporations with a well-staffed IT department. A sales team summarizing calls, an HR department rewording job descriptions, a business owner asking ChatGPT for a market analysis: all of this can be useful, but all of it also creates a gray area if no one knows what is authorized.
Why employees use ChatGPT without telling anyone
The first reason is rarely malicious. In 2025, TELUS Digital indicated that 57 % of employees using generative AI at work were doing so to make their work easier. In France, APEC also reported that 35 % of executives and 42 % of managers used AI at least every week, notably to save time, improve quality, or generate ideas.
An employee who has to produce a summary before 6 p.m. does not spontaneously think about governance, the RGPD or the terms of use of an American tool. They are thinking about finishing the job properly. That is human. According to BlackFog in 2026, 60 % of employees would be willing to take risks to meet their deadlines. This figure should be read as a management warning, not just as a problem of cyber security.
Another driver: the lack of official tools. Lenovo, in its Work Reborn content published around 2026, identifies the absence of tools, training, and guidelines as a factor in fragmented AI adoption. When the company says “do not use ChatGPT” without offering a credible alternative, usage continues, but becomes invisible.
In the projects we lead, we often see the same gap: management thinks AI is used only by two or three curious profiles, whereas teams have already integrated it into daily micro-tasks. Rewording an email. Comparing two versions of a document. Preparing a quote template. Nothing spectacular, but a lot of data is moving around.
What this changes for your risks, timelines, and budget
The trap that non-technical people underestimate lies in the nature of the data being sent. A prompt (the instruction given to the AI) can contain more sensitive information than an attachment: customer names, revenue figures, pricing terms, legal issues, HR data. Even if the tool is well known, use through a personal account often escapes company settings.
The GDPR, applicable since 2018, requires control over the processing of personal data. If an employee sends CVs, internal evaluations, or suppor tickets to a public AI assistant without a contractual framework, the company may lose track of that processing. The risk is not theoretical: it affects confidentiality, compliance, and sometimes trade secrets.
There is also a more discreet operational risk. If a team bases its procedures on unverified AI responses, it can produce very convincing errors. Generative AI predicts likely text; it does not guarantee the truth. For a quote, a contractual clause, or an SEO analysis, human validation remains essential.
On the budget side, blocking everything rarely costs less. An outright ban can push usage undors the radar, thereby increasing risk. Conversely, deploying an AI suite without a framework can generate unnecessary subscriptions and a false sense of security. For a French SMB, expect often a few days of audit and workshops to frame usage, or around €2,000 to €8,000 depending on team size and the level of documentation expected. A more complete rollout, with an internal policy, training, professional account configuration, and initial use cases, often exceeds €10,000 to €25,000.
| Option | Indicative cost in France | Typical timeframe | Main boundary |
|---|---|---|---|
| Ban without an alternative | Low in the short term | 1 to 2 weeks | Hidden usage, weak control |
| AI charter and short training | €2,000 to €8,000 depending on the provider | 2 to 4 weeks | Requires real oversight |
| Managed professional AI accounts | Subscriptions + setup | 3 to 8 weeks | Tool choice and data to be clarified |
| Secure space with workflows AI | €10,000 to €25,000 and more | 1 to 3 months | A more structuring project |
The wrong reflex: choosing a tool before defining the use cases
Many business leaders start by comparing ChatGPT, Microsoft Copilot, Google Gemini or Claude. It’s tempting. But that’s not the right first step. The right question is: what data can be sortir, for which tasks, with what level of validation?
Honestly, a general-purpose AI subscription is only justified if the use cases are identified. For simple reformulations of emails without sensitive data, a clear policy may be enough at first. For client documents, legal matters, or support, you need professional accounts, access management, and a clear retention policy.
The European AI Act, adopted in 2024, adds a layer of responsibility depending on AI use cases. An SMB that uses generative assistants is not necessarily in a high-risk case, but it must understand its obligations, especially if AI affects recruitment, evaluation, or decisions that have an impact on people. To dig deeper into this point, a guide dedicated to AI Act compliance for an SMB using ChatGPT and Claude helps lay the groundwork without unnecessary legal jargon.
In some cases, the obvious solution is the wrong one. For example, giving free access to a public chatbot to speed up customer support may seem cost-effective. But if agents paste in historiques of tickets with names, emails, and incidents, the time savings become a leakage risk. At this budget, it is better to frame two or three safe use cases than to generalize too quickly.
How to regain control without blocking teams
An effective policy fits in just a few pages. It says what is autorisé, prohibited, tolerated with precautions, and who decides in case of doubt. Tone matters. If the document sounds like a threat, employees will hide their use cases. Slack observed in 2024 that some employees were not disclosing their use of AI because of uncertainty about disclosure, trust, workload, or their manager’s expectations.
The framework can follow a simple logic:
- map existing use cases, even informels, without first trying to sanction;
- classify data: public, internal, confidential, personal, sensitive;
- allow a few low-risk cases, such as rewording non-confidential texts;
- clearly prohibit sending client, HR, financial, or strategic data through personal accounts;
- train teams with examples of acceptable and prohibited prompts.
The technical side comes next. Microsoft Copilot, ChatGPT Enterprise, Gemini for Google Workspace, or hosted solutions with enhanced control can make sense, depending on your environment. Cloudflare also offers useful security building blocks around access and web traffic, while OVHcloud can fit into more sovereign architectures depending on hosting constraints. The choice depends less on the logo than on the data scope.
If your teams work remotely, the issue becomes more sensitive. Usage goes through personal cormputers, home networks, and unsupervised accounts. In this context, centralized and encrypted workspaces can help; the approach is similar to the one described for secure cloud workspaces for distributed teams.
Measuring shadow AI without creating a culture of surveillance
The temptation to monitor everything is strorng. A bad idea if it becomes the core of the response. Security tools can detect certain access to AI services, but they replace neither trust nor clarity. PagerDuty indicated in 2026 that 66 % of office professionals had used AI tools at work despite the understanding that company policy did not allorw it. The problem is therefore massive, not marginal.
A sound approach combines three sources: anonymous questionnaires, business workshops, and technical analysis of traffic when it is proporrtionate. The goal is not to trap employees. It is to identify the tasks where AI is already helpful and the data that should never leave.
From an agency perspective, the instinct is to start with workflows (task sequences) rather than tools: prospecting, supporrt, content production, reporrting, development, HR. This method avoids overly general policies, such as “AI is allorwed with caution,” which change nothing in practice.
When AI needs to connect to internal data, caution increases another notch. Recent standards such as MCP, Model Context Protocol, are specifically aimed at orrganizing the connection between AI agents and inforrmation systems. The topic deserves to be technically framed, as explained in this analysis of MCP for connecting AI agents to company data.
Framing this type of project upstream avoids most unpleasant surprises: choosing a tool too quickly, exposed data, misunderstood rules, forrgotten training. An external perspective often helps transforrm existing uses into useful, safe, and team-accepted practices.
FAQ on shadow AI in business
Is enterprise shadow AI illegal?
Not in itself. What can be problematic is sending personal, confidential, or protected data into an unauthorized tool, without a contractual basis or controls compliant with the GDPR.
Should ChatGPT be banned at work?
A total ban rarely works if employees find a real benefit in it. It is better to prohibit risky uses, autorize simple cases, and offer a professional alternative for useful tasks.
Which services are most affected by shadow AI?
Sales, marketing, support, HR, legal, and management teams are often involved, because they handle a lot of text. Developers as well, particularly for code assistance or documentation.
How long does it take to put an AI policy in place?
For an SME, a first workable policy can be produced in 2 to 4 weeks. A more comprehensive setup with tools, formation and governance generally takes 1 to 3 months.