
Article
Cross-industry
7 min read
Shadow AI refers to AI systems operating within a company that are not listed, referenced in policies, or included in budgets. And yes, it is almost certainly already happening in your company. Most companies did not decide to start using AI. It usually starts with someone signing up for a free account, finding it useful, and continuing to use it. Nobody announced, approved, or asked about it.
(2nd in the EBS AI-maturity series)
the short version:
Only 20% of EU enterprises with ten or more employees use AI at the company level. [1]
52% of euro-area workers say they personally use AI in their work. [2]
Individual AI use is often genuinely faster, but even experienced people can't judge their own gain accurately. [3,4]
A well-documented 2023 case (Samsung) shows how ordinary, not malicious, this usually is. [5,6]
The fix costs attention, not money. Determine what's used, write a one-page policy and record what works already.
An EU AI-literacy duty has applied since February 2025 and is now actively enforced. It's one more reason to take the step above, not the main one. [7]
What shadow AI actually means
It's what happens when people adopt AI on their own, one account at a time, before the company has any way to see who's using what, on what data, or with what result.
Historically the term entered the "common use" after a real, well-documented case. As Bloomberg and TechCrunch reported at the time, Samsung's semiconductor division let engineers use ChatGPT at work in March 2023. [5,6] Within about three weeks, three separate incidents happened
one engineer pasted in source code while debugging,
another fed it the transcript of an internal meeting to get notes,
a third used it to optimize a test sequence.
None of them meant any harm; they were solving ordinary problems the way anyone does with a tool that's right there. And that's exactly what made it dangerous. By the time Samsung noticed, the information was already gone, and banning generative AI outright was the only response left. The pattern this term describes is adoption that outran anyone's ability to see it.
This is a common stage in the natural process of adopting AI
Only 20.0% of EU enterprises with ten or more employees used AI at the company level in 2025, up from 13.5% a year earlier. [1] The European Central Bank counts the workers instead, and 52% say they personally use AI in their work, up from 41% in 2025 and 26% in 2024. [2]
That gap tells you something specific: people are already using AI on their own, inside their jobs, whether or not the company has organized around it yet.
That's exactly the phenomenon this piece is about, and the numbers confirm it's the norm, not something unique to your company. The reason it spreads this way, one person at a time, is simple: it feels faster. Whether that feeling holds up is worth a closer look.
An expert isn't necessarily right about the speed of AI in an organization
In 2025, Cui and his colleagues ran three randomised field experiments at Microsoft, Accenture, and a Fortune 100 company. In total, the experiments covered 4,867 software developers. They found that developers using AI completed approximately 25% more tasks. [3] The exact estimate has a wide range, and it is worth noting that Microsoft was both a study site and the maker of the tool tested. Less experienced people tended to benefit the most.
However, there's a catch. People are not reliable judges of their own speed, which changes what can be done about it.
A 2025 preprint from METR tested 16 experienced developers on 246 real tasks in codebases they were already familiar with. [4] When allowed to use AI tools, it took them 19% longer to finish. Before the study, they predicted that AI would make them 24% faster. Afterwards, however, they still believed it had made them 20% faster.
This is exactly why it's worth finding out what's actually happening in your company, rather than trusting anyone's impression of it, including your own.
What actually happens when information leaves the building
Samsung's case is worth returning to for the specifics, because what actually happened is more ordinary than "data breach" makes it sound. An engineer pastes code into a chat window to get help with a bug. Someone transcribes a meeting to get a quick summary. Nobody uploads a file, signs a form, or asks permission. The moment the text is submitted, you have taken the data out of the company, and there's no way to call it back.
Most people who do this never mention it to anyone. In the companies we work with, it is almost never because they are hiding wrongdoing: nobody ever said whether it was fine, and admitting it costs something socially. That matters for what a company does next: the fix isn't catching people. It's removing the reason to stay quiet.
What to do about it, and what it costs
At this stage, the right first step costs attention, not budget. Nothing below requires a purchase.
The three practical steps, in the order that makes each one possible.
Find out what's actually being used
Ask, don't audit.
A short, anonymous way for people to say what they're using tends to surface more than expected.
In the companies we work with, the list that comes back is usually about double what management expected, and the useful column is who has access. It works better than trying to detect anything, because nobody feels accused of hiding something. Frame it as "help us support what's already working," not "who's been doing this behind our backs."
Write it down (it will take one page, not fifty)
A usable policy fits on one page.
The single most useful distinction it can draw is personal account versus company account: what's approved for work, and what isn't.
Classify your data by sensitivity before you choose the tool. Specific examples of what never goes in: client names paired with financial details, anything under an NDA, personal data. A policy that reads like a legal document is easy to file away and forget. A short one is easy to actually use.
Turn one good habit into a organization shared one
Not everything the inventory turns up is a risk to manage. Some of it is a good idea worth spreading.
Pick one or two cases where AI is clearly working well, and write down exactly what the person did, in enough detail that someone else could follow the same steps. Give people the structure and let them fill it in; a correction takes minutes and a blank page takes weeks. Once it's written down, it stops being one person's private trick and becomes something the rest of the team can use.
One more thing worth knowing: Article 4 of the EU AI Act, Regulation (EU) 2024/1689, has required providers and deployers to support their staff's AI literacy since February 2025, and national authorities began actively enforcing that duty in August 2026. [7] A company whose people use AI tools is a deployer. It doesn't require a specific program. There's no formal exemption for smaller companies, though the Commission and member states are directed to support SMEs specifically. It's not a reason to panic. It's one more reason the step above is worth taking regardless.
It's the same company and the same people. It's a matter of whether there's a policy that decides which path is taken.
What comes next?
The next level of maturity up is Tools, no system, which involves an actual list of tools and users, a signed policy and two or three documented cases that the team can point to. Reaching this level doesn't require a platform or a purchase; it just requires the three steps above to be completed in order.
The level below is the company that has decided against using AI and has made this decision permanent.
If you want to know where your company actually sits on the ladder, EBS Integrator's AI-maturity assessment can help.
Frequently asked questions
Is using ChatGPT at work shadow AI?
It depends on whose account it is and whether anyone else in the company can see it. A person using a personal ChatGPT account for work tasks, with nobody else aware of it, is exactly what the term describes. The same tool used through a company account, with visibility and a policy behind it, isn't.
What are examples of shadow AI?
A developer pasting code into a chat tool to debug it. Someone summarizing a client call with a personal AI account. A marketing person using a free image generator for a client deliverable without anyone signing off on the tool. None of these are unusual, and none of them are done with bad intent.
What are the risks of shadow AI?
The main issue is that information entered into a public AI tool is lost forever. There is also no way to verify reported productivity gains, and the company cannot account for tools it doesn't know exist.
How do I prevent shadow AI?
Start with the inventory, not a detection tool. The fastest way to lose people's trust is to treat this as something to catch rather than something to support. A short policy and a visible, welcoming way to declare tool use closes most of the gap without buying anything.
References
[1] Eurostat, Use of artificial intelligence in enterprises, reference year 2025, published 11 December 2025.
[2] European Central Bank, AI adoption and the productivity promise: what workers report, Consumer Expectations Survey blog, 26 August 2026.
[3] Cui, Demirer, Jaffe, Musolff, Peng & Salz, The Effects of Generative AI on High-Skilled Work: Evidence from Three Field Experiments with Software Developers, Management Science, 2025.
[4] METR, Measuring the Impact of Early-2025 AI on Experienced Open-Source Developer Productivity, arXiv:2507.09089, 10 July 2025. Preprint, not peer reviewed.
[5] Bloomberg, Samsung Bans ChatGPT, Google Bard, Other Generative AI Use by Staff After Leak, 2 May 2023.
[6] TechCrunch, Samsung bans use of generative AI tools like ChatGPT after April internal data leak, 2 May 2023.
[7] European Commission, AI talent, skills and literacy (Article 4 obligations), page updated 27 July 2026.
Share this article on:
More insights
Article
Cross-industry
AI Consulting
Regulatory & Compliance
7 min read
Is AI overhyped? Yes, as a purchase promise. No, as what a prepared company can do with it. The evidence, and what the first step off level zero takes.
26 Aug 2026

Article
FinTech
AI Consulting
Data Engineering & Analytics
Regulatory & Compliance
5 min read
AI in fintech is everywhere, yet few systems would survive an audit. Why projects stall, what regulators expect, and the three steps that fix it.
21 Jul 2026

Article
Retail & eCommerce
AI Consulting
Data Engineering & Analytics
6 min read
Find out how technology-driven personalization x AI creates closer relationships with customers.
07 Feb 2025

Article
Retail & eCommerce
Business Analysis
AI Consulting
6 min read
How omnichannel strategies and AI-driven personalization help retailers connect online and in-store experiences, improve operations, and keep shoppers coming back.
07 Feb 2025

Article
Retail & eCommerce
Data Engineering & Analytics
AI Consulting
6 min read
Reach customers wherever they shop with AI and real-time data. Discover how targeted marketing, a seamless online and offline shopping experience, and predictive analytics can personalize recommendations and boost sales. Our retail expert, Olga, shares practical insights and strategies to help you take your store digital. Read the full article for actionable tips and real-world examples.
24 Jan 2025

Article
Retail & eCommerce
Data Engineering & Analytics
AI Consulting
8 min read
Big Data is changing the retail industry. (internal expertise) Learn how businesses use data to make smarter decisions, create personalized experiences, and improve customer service with real examples of BigData applied to today’s fast-moving market.
06 Dec 2024

Article
Cross-industry
AI Consulting
Process Automation
7 min read
From ELIZA to modern AI: explore chatbot evolution in customer service. Learn how 1.4 billion users benefit from automated support and instant query resolution.
22 Nov 2021

Article
EdTech
Security
Regulatory & Compliance
11 min read
Student records are among the most sensitive data any institution holds, and the easiest to underprice. What a school breach really costs, and where to start
04 Jun 2026

Article
FinTech
Systems Integration
Regulatory & Compliance
8 min read
How Open Banking works after PSD2 and what the API economy means for banks, instant payments, and system architecture in Europe.
18 Dec 2025

Article
Retail & eCommerce
Regulatory & Compliance
Security
Business Strategy
8 min read
Learn what an eCommerce audit includes and why EU-linked retailers need it in 2025. Covers security, PCI DSS, ISO 27001, SCA, fraud risk, and business continuity.
01 Dec 2025

Article
FinTech
Process Automation
Systems Integration
Regulatory & Compliance
9 min read
Banking process automation enables financial institutions to replace manual approvals with low-code workflows that integrate payments, lending, and compliance in real-time. It ensures PSD2 and KYC/AML compliance while enabling instant payments, such as SEPA Instant and Moldova's IPS, for faster and safer banking.
11 Nov 2025

Article
Retail & eCommerce
Security
Regulatory & Compliance
8 min read
We’re talking about data privacy in all its glory – why it matters to you and your customers, and where it’s all heading in the future. Because this is a part of a series, we’ll try and focus mostly on the aspects that affect us in the eCommerce domain! Let’s discuss why there’s so much hubbub around the topic of data privacy. This is not to say this discussion is anything new for the world, it’s been brought up countless of times, and the issue of “government spying” on you is as old as the idea of structured government is.
18 Feb 2022
Article
Cross-industry
Security
Regulatory & Compliance
In this article, Alex shares his journey through the implementation of a Clean Desk and Clean Screen Policy during his company's ISO 27001 certification process. Initially resistant to the changes, Alex reflects on the impact of the policy on his workflow, physical security habits, and overall job experience. The transition, while initially perceived as a challenge, ultimately led to a cultural shift within the company, emphasizing the importance of information security and organizational efficiency.
21 Jan 2021