
04.09.2026
Shadow AI occurs when employees use AI tools without official approval. Discover the risks involved and how companies can create secure AI governance, clear guidelines and suitable tools.
Shadow AI occurs when employees use AI tools in their daily work without these applications being officially authorised or known to the organisation. The quick productivity gain is tempting. At the same time, sensitive data can leak and regulations on data protection, security or compliance can be violated.
The usage also shows that employees want to work with AI and see concrete application possibilities. Companies should understand this need, provide secure tools and establish clear rules. In this way, unmanaged AI usage can be transformed step by step into viable AI governance.
Leonard Püttmann, Solution Architect at accompio AI, explains in an expert interview why shadow AI is so widespread, which risks companies should be aware of, and how personal initiative can be turned into a controlled use of artificial intelligence.
In the interview, Leonard Püttmann demonstrates why technical controls alone are not enough and how companies can combine their employees' needs with clear guardrails and secure AI solutions.
How can companies enable the use of AI whilst protecting sensitive data? In the video, Leonard Püttmann shows how control, clear rules and employee initiative can be combined.
Shadow AI refers to a situation where employees use AI applications that are neither officially approved, known, nor controlled within the company. The term is based on shadow IT. It refers to a form of uncontrolled use rather than a specific product.
A typical example is a public AI chatbot into which employees enter texts, spreadsheets or documents to complete a task more quickly. From the organisation's perspective, this leaves important questions unanswered: What data is being processed? Where is the processing taking place? Is anything stored? Who can access the information?
Shadow AI can also lead to silos. Individual teams use different tools, knowledge is rarely shared and security requirements are implemented inconsistently. A joint AI strategy creates transparency here.
During the conversation, Leonard Püttmann mentions two main reasons. Firstly, employees want to work more efficiently and are looking for suitable tools themselves. AI now supports many tasks, such as structuring information, drafting texts or handling repetitive work steps.
Secondly, many employees are already familiar with AI applications from their personal lives. Positive experiences with ChatGPT, Google Gemini and other tools shape the expectation of being able to use comparable support in their professional lives too.
When suitable enterprise solutions or clear guidelines are lacking, teams find their own ways. Shadow AI is therefore frequently an organisational signal. It shows the areas where employees need support and where the internal provision of AI is not yet keeping pace with practical demand.
The greatest risk arises when sensitive information enters external AI applications. This includes personal data, customer information, contract documents, patents, internal records and trade secrets. A clear Data classification helps to identify information worthy of protection. For users, it is often barely recognisable how a service processes or stores input.
Unregulated AI usage makes it harder to comply with legal and internal requirements. With the EU AI Act furthermore, AI literacy is gaining importance within companies. Providers and operators of AI systems must take measures to promote the AI literacy of their employees. Training should therefore take into account the specific work context and the systems used.
If confidential information is disclosed, this results in reputational damage alongside potential legal consequences. Customers expect companies to protect their data reliably. Uncontrolled AI usage can undermine this trust.
Seamless technical detection is difficult. Companies can analyse network traffic, but the number of available AI tools is constantly growing. New services and private access points can only be tracked to a limited extent via this method.
Greater transparency is achieved through direct dialogue. Managers and IT managers should ask which tools teams are already using, which tasks they use them for, and which functions they feel are missing in the approved solutions. A low-threshold reporting channel for desired tools makes these needs visible.
„You just have to face the risks, and then the whole thing can work out well too.“
Leonard Püttmann, Solution Architect at accompio AI
A blanket ban usually does not eliminate the need for AI assistance. A more effective approach is one that reduces risks and transfers good use cases into a secure framework.
Organisations should clarify, together with the business departments, which AI tools are already in use and what purpose they serve. A list for tool requests helps to identify and prioritise recurring requirements.
Guidelines should explain clearly which applications are permitted, which data may be used and who reviews new tools. Short, concrete rules are more helpful in everyday life than general prohibitions.
Self-paced introductory courses on artificial intelligence teach the basics at one's own pace. Workshops are suitable for examining real use cases from individual teams. Employees learn where risks lie and how they can safely use AI in their work area.
Approved solutions must genuinely support employees in their tasks. For sensitive company data, an internal Confidential AI environment be a suitable basis. If the alternative is secure and usable in everyday life, the incentive to switch to unknown external services decreases.
The AI landscape is changing rapidly. Companies should regularly review the tools and rules they use. Shadow AI is therefore becoming an established part of the IT Governance and is losing its uncontrolled character step by step.

You want to record existing AI usage, evaluate suitable use cases and provide your teams with secure tools? accompio supports you in developing a practical AI strategy, with technical implementation and with the secure integration of AI into your existing infrastructure.
AI tools used on one's own initiative show where processes can be improved. Teams gain practical experience and often recognise early on which applications offer genuine added value. These impulses are valuable for companies if they are openly received and professionally evaluated.
Managers play an important role in this. They create opportunities for discussion, take needs seriously and quickly provide secure solutions. Such a culture of innovation combines curiosity with responsibility. Individual experiments can thus develop into approved use cases that benefit multiple teams.

Leonard Püttmann works as a Solution Architect at accompio AI. He deals daily with how companies can use AI technologies securely and efficiently and thus create tangible added value.
Shadow IT encompasses all unauthorised hardware and software solutions. Shadow AI specifically refers to the unregulated use of AI applications and the associated processing of data.
A complete technical control is hardly realistic given the many available tools. Companies can significantly reduce risk by making usage transparent, offering secure alternatives, defining clear rules and regularly training employees.
Personal data, customer information, contracts, patents, internal documents, and trade secrets require a particularly high level of protection. Before entering them, it must be clarified whether the tool being used is authorised for such data.
A practical AI guideline specifies permitted tools, allowed data, prohibited applications, responsibilities, and the process for reviewing new tools. It should be easily accessible and explained using real-world examples.
Unregulated use is a risk. At the same time, it makes a willingness to innovate and concrete requirements visible. If companies take up these impulses, assess risks and provide secure solutions, this can result in productive and controlled AI usage.
