KlarComply
HomeKnowledge › Finding shadow AI

Shadow AI: what is running in your company that nobody told you about

In almost every organisation there are AI tools running that the management knows nothing about. That is not a discipline problem. It is a symptom: people are trying to get their work done. Understand that and you will find the tools in two weeks. Treat it as a breach of the rules and you will find nothing.

By , Founder of KlarComply · Reviewed on

Infographic: Finding shadow AI: five routes, one promise — Tools nobody has reviewed are already running — the question is how you bring them into the light.
The key points of this article as a graphic — feel free to share or download it.

What shadow AI is

The term covers any use of AI tools in a work context that the company does not know about or has not approved. It is broader than the obvious personal account:

A figure from experience with stocktakes: the first proper sweep regularly turns up two to three times as many tools as the management expected. The reason almost never lies with the staff.

Why shadow AI happens

Five causes, in order of frequency. All five are management questions, not compliance questions.

CauseWhat sits behind it
There is no way to askNobody knows who decides. With no named contact there are no requests — only quiet use.
The route takes too longSomeone who waits three weeks for an answer routes around the process next time. A turnaround you keep matters more than a strict assessment.
The approved tool cannot do itWhere the internal option is worse than the freely available one, the freely available one wins. Every time.
A blanket banBans move the use to personal devices and personal accounts. You lose the last of your visibility.
Nobody thought it was reportableA browser extension does not feel like a software rollout. That is precisely why the rule has to name what it means.

Why a ban makes the position worse

A ban does not change whether AI is used. It changes whether you find out. After a ban the use moves to the personal phone and the personal account, where you have no contract, no logs and no way to withdraw access when someone leaves.

There is a legal side effect as well. A ban that the management knows is being circumvented is worth very little as an organisational measure under Article 32 GDPR. What is effective is what is actually followed.

Uncovering it without sowing mistrust

The order matters. Start with people, not with technology. Begin with a network analysis and you will get a list of domains and a workforce that volunteers nothing ever again.

Step 1: the amnesty survey

By far the most effective single measure, and it costs nothing. Ask what is being used, and state expressly that naming something carries no consequence. Without that assurance you will get polite nil returns.

Wording that works

“We are building an overview of the AI tools in use here. The aim is to put the useful ones on a proper footing, not to remove them. Anything named now counts as helping to solve the problem, not as breaking a rule. From [date] our approval process applies to anything new. If a tool you need is missing, please say so at the same time.”

The last sentence is the trick. It turns a control exercise into an opportunity — and it hands you, as a by-product, the list of what you should be buying so that shadow AI does not grow back.

Step 2: ask departments individually

A company-wide email achieves very little. Fifteen minutes per department achieves a great deal, because you can ask concretely: how does text get written here? How do you translate? How do you summarise minutes? How do you assess incoming bids? Ask about tools and you get tool names. Ask about steps in the work and you get the truth.

Step 3: the accounts

Subscriptions give themselves away through payment routes. Go through twelve months of card statements, expense claims and small recurring amounts. Sums between ten and thirty euros a month are typical single licences. This step regularly finds tools that nobody named in the survey — not out of concealment, but because they have long since become routine.

Step 4: browser extensions and installed programs

An overview of the extensions on work devices is quick to produce. Pay attention to the permissions: an extension allowed to “read all your data on all websites” also sees your ERP system and your mailbox. Independently of the AI question, that is a security matter.

Step 5: release notes of the software you already run

The most frequently overlooked step. Go through the programs you use anyway and check which AI features arrived in the last twelve months — and whether they are on by default. This is where shadow AI appears without anyone in the workforce doing anything at all.

Where the line runs: analysing network traffic

Technically, a good deal could be established from network or security gateway logs. Legally it is not straightforward, and this is one of the areas where national law diverges most sharply within Europe.

Two things hold everywhere. Analysis that can be traced to individual employees is a processing of personal data and needs a lawful basis, a purpose and transparency towards staff. And where a works council or equivalent employee representation exists, introducing or using a system capable of monitoring conduct or performance normally requires consultation or agreement — in several member states the mere capability is enough, with no monitoring intention required. Directive 2002/14/EC sets the EU-wide floor for informing and consulting employees; national law goes considerably further in some states than in others. The detail is on AI and employee representation.

What is workable is an aggregated analysis with no personal identifiers: which domains are being reached at all, how often, from which area. That is enough to find tools. Analysing by name in order to identify individuals trades a compliance problem for a larger one.

What to do with what you find

Sort every tool you find into exactly one of four boxes. Anything else produces a list that nobody works through.

DecisionWhenWhat to do
Adoptclear benefit, manageable risktake out a business tier, settle the contract and the processor arrangement, add it to the inventory, define the user group
Replaceclear benefit, but this tool is unsuitableprovide an equivalent approved alternative — before switching the old one off, not afterwards
Restricttolerable only for certain contentapprove subject to conditions, for example no personal data at all, with a date for the next review
Switch offno defensible benefit, or unacceptable riskexplain the reasons, withdraw access, name an alternative, record it in the inventory as refused

The order matters: alternative first, switch-off second. Block first and search afterwards and you will have the same shadow AI back within two weeks, better hidden.

Which risks actually sit behind this

So that the survey does not look like an end in itself, here are the four real points of exposure, ordered by how often they bite in practice.

  1. Data protection. A personal account with no processor contract, receiving customer data, breaches Articles 28 and 32 GDPR. Unlike Article 4 of the AI Act, that is subject to fines. Detail on ChatGPT at work.
  2. Trade secrets. Where pricing calculations land in a tool with no confidentiality undertaking, protection can fall away, because Directive (EU) 2016/943 requires reasonable steps under the circumstances to keep the information secret. More on trade secrets and AI tools.
  3. Transparency duties. You cannot label what you do not know about. Article 50 of the AI Act has applied since 2 August 2026 and it is in the penalty catalogue. Free labels are on our AI labels page.
  4. Loss of control when someone leaves. A personal account stays with the person. Everything put into it stays accessible — including to their next employer.

Stopping it growing back

A stocktake with no follow-up process is a snapshot. Four measures hold the position:

The tone determines the result

Two sentences with the same content and opposite effects:

Does not work: “It has come to our attention that unapproved AI tools are in use. Please report them immediately.”

Works: “We want to know what makes your work easier so we can set it up properly. Please tell us what you use and what you are missing.”

The second costs nothing and produces a fuller picture. The first produces a list missing precisely the tools you most needed to know about.

A timetable for the first sweep

Two weeks is enough in a company of up to two hundred and fifty people, provided the steps run in parallel.

WhenStepEffort
Day 1Announcement by the management, with the amnesty and the cut-off date30 minutes
Days 1 to 5Keep the survey open, answer questionsongoing
Days 2 to 7Department conversations, 15 minutes each2 to 4 hours in total
Day 3Review twelve months of payment routes1 to 2 hours
Day 5Check browser extensions and release notes2 hours
Days 8 to 10Create inventory entries, record risk-class reasoning3 to 5 hours
Day 10Four-box decision per tool, communicate the outcome2 hours

At the end, record how you carried out the survey and when. That description of the method is the actual evidence. No review expects completeness; every review expects a procedure it can follow.

What you do not need

Where you stand after the sweep takes two minutes to check with the free quick check, including the points that typically stay open.

A note for companies outside the EU

The sweep has one extra column for you. Under Article 2 of the AI Act, a deployer established in a third country is in scope where the output produced by the AI system is used in the Union. Shadow AI is exactly the kind of use where nobody has considered that question, because nobody knew the tool existed. Record, per tool found, whether its output reaches the EU. It takes a second per row and it is the answer to a question a customer will eventually ask.

Frequently asked questions

What does shadow AI mean?

AI tools used in a work context without the company knowing about them or approving them. That includes personal accounts, browser extensions, AI features that arrived by update in existing software, and AI used by service providers working on your behalf.

Should we simply ban AI tools?

That is not advisable. A ban does not change whether AI is used, only whether you find out. The use moves to personal devices and accounts, where you have no contract, no logs and no way to withdraw access. A fast approval route plus one genuinely usable approved tool works better.

How do we find out which AI tools are in use?

In this order: an amnesty survey with an express assurance of no consequences, individual conversations per department, a review of twelve months of payment routes, an overview of browser extensions, and finally the release notes of the software you already run. The last of those finds the tools nobody installed.

May we analyse network traffic to find AI use?

Only within limits, and the limits differ by country. Analysis traceable to individuals is processing of personal data and needs a lawful basis and transparency. Where employee representation exists, introducing or using a system capable of monitoring conduct or performance normally requires consultation or agreement, and in several member states the mere capability is enough. An aggregated analysis with no personal identifiers is workable and sufficient to identify tools.

What do we do with the tools we find?

Four options: adopt with a business contract, replace with a suitable alternative, restrict subject to conditions, or switch off. The order matters — the alternative has to be in place before anything is switched off, or the same use returns within weeks, less visibly.

Do we have to sanction staff who used AI without approval?

For the period before a clear rule existed that would be counterproductive and usually unfounded: where there was no known rule, there was no breach. Give an assurance of no consequences, set a cut-off date and publicise the approval route. From then the rule applies, and from then it carries weight.

How often should we repeat the stocktake?

A short half-yearly enquiry with two questions per department — what is new and what is missing — plus an ad hoc check after major software updates. Withdrawal of access and a closing question also belong in your offboarding.

Where does your company stand?

The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.

Start the quick check — free
Read on AI literacy obligation → Building an AI inventory → Labelling AI content (Art. 50) → The AI Act for SMEs → Writing an AI policy → AI in hotels → AI in the beauty salon → Appointing an AI lead → ChatGPT at work and the GDPR → Approving AI tools → AI and employee representation → Classifying AI risk → The AI supplier questionnaire → Customer data in an AI tool → Penalties under Article 99 → Trade secrets and AI tools → AI in physiotherapy practices → AI in dental practices → AI in tax and accounting firms → AI in hair salons → AI in advertising agencies → AI for estate agents → AI in car repair shops → AI in trades businesses → AI in law firms → DPO requirements → Records of processing → DPA (Art. 28) → Data breach & 72 hours → GDPR staff training → US tools & transfers →
Sources:
Article 4 EU AI Act — AI literacy, including persons acting on your behalf
Article 2 EU AI Act — scope, including third-country deployers
Article 32 GDPR — security of processing
Directive 2002/14/EC — informing and consulting employees
Regulation (EU) 2024/1689 — official consolidated text, EUR-Lex
Reviewed on 2 August 2026 · Reflects the Digital Omnibus · This article is general information and not legal advice.