Shadow AI.
The data leak your teams are causing without knowing it.
A contract pasted into ChatGPT to extract its clauses. A balance sheet summarised by Copilot. A client file dropped into a chatbot. These everyday gestures, repeated daily, send your most sensitive data to servers you don't control. It's Shadow AI — and it's already inside your organisation.
2026-09 · 8 MIN READ
The term is new; the phenomenon no longer is. Shadow AI describes your staff's use of AI tools — ChatGPT, Microsoft Copilot, Google Gemini, and dozens of others — outside any security policy, often without your knowledge. In 2026, around 65% of SMEs use at least one generative-AI tool daily. Productivity gains are real. But every prompt can also be a silent data leak.
The mechanism is simple and invisible. When your finance director pastes a forecast balance sheet into a free chatbot to get a summary, that data leaves your company. It travels to servers whose location and retention policy you don't know — and on many free services, it may be used to train the model. This isn't an attack: it's a well-meaning employee trying to save time. That's exactly what makes Shadow AI so hard to see.
Why it's a real risk, not a theoretical worry
- Confidential data leakage. Contracts, client data, HR information, source code, financial figures — anything pasted into an ungoverned tool escapes your control, permanently.
- nLPD exposure. The FDPIC is clear that data-protection principles — transparency, proportionality, human oversight — apply fully to any AI-assisted processing. A personal-data leak via a chatbot is a breach like any other.
- Loss of trade secrets and compliance. For a fiduciary, a law firm or a medical practice, exposing data covered by professional secrecy can bring sanctions and lasting loss of trust.
- A total blind spot. You can't protect what you can't see. Most companies have no idea which AI tools their teams actually use, or for what.
Banning AI without offering an alternative doesn't remove the risk — it moves it to the employee's personal phone, out of all visibility. Governance, not prohibition, is the answer.
The wrong response: ban everything
Many directors' instinct — simply blocking access to ChatGPT — is counterproductive. Your staff will keep using it, but on their personal phones, off your network and out of all visibility. You'll have turned a measurable problem into an invisible one. Generative AI is here to stay; the question isn't whether to ban it, but how to govern it.
The right response: govern the usage
Regaining control of Shadow AI comes down to a few concrete measures:
- Establish visibility. Know which AI tools are actually used, by whom, and for what — the inventory is the starting point of any governance.
- Set a clear, simple policy. What may be submitted to an AI, what never may (personal data, professional secrets, financial data), and with which tools.
- Offer a governed alternative. An enterprise AI solution — ChatGPT Enterprise, Copilot for Microsoft 365, or a sovereign option hosted in Switzerland — where your data doesn't train the models and stays under your control. Give your teams a good tool, and Shadow AI disappears on its own.
- Train, don't just forbid. An employee who understands why pasting a client contract into a free chatbot is risky becomes your best line of defence.
What we do
Our AI-governance practice helps SMEs, communes and foundations across the region step out of Shadow AI: establish visibility on real usage, define an nLPD-compliant policy, and deploy a governed alternative — sovereign and hosted in Switzerland when confidentiality demands it. The goal isn't to slow your teams down, but to let them use AI without your data ever leaving your control.
Book a free auditDo you know what data leaves your company via AI?
Our free audit establishes visibility on real AI use in your organisation, assesses your nLPD exposure, and proposes a governed alternative.