Learnery
EN
Get started
All articles

Shadow AI at Work: Your Team Already Uses It. Nobody Trained Them.

Key takeaways

  • Shadow AI means employees using unsanctioned AI tools at work, usually free chatbots on personal accounts.
  • Bans do not stop shadow AI, they hide it and remove your ability to set rules.
  • The real risks are data leaks, confident errors reaching customers, and no audit trail.
  • The fix is clear rules plus around eight hours of role specific training per employee.

Ban ChatGPT at work and you will not stop it, you will only stop seeing it. Shadow AI is the use of unsanctioned AI tools by employees without approval, usually free chatbots on personal accounts. In most companies with 10 to 200 people it is already routine, and the practical fix is not a firewall but around eight hours of training plus clear rules per employee.

What is shadow AI and how common is it in small companies?

Shadow AI is any use of AI tools for work tasks without the employer's knowledge or approval. In practice it looks ordinary: a sales rep pastes a difficult client email into a free chatbot to draft a reply, an accountant asks it to summarize a contract. The work gets done faster, so nobody mentions it.

Shadow AI thrives in companies with 10 to 200 people precisely because there is rarely a formal policy. Nobody decided to allow AI and nobody decided to forbid it, so employees decide for themselves. The tools are free, they sit one browser tab away, and they visibly help. Most of this is initiative, not sabotage.

The problem is not that employees use AI, it is that they use it on personal accounts, with no rules about what data may leave the company, no training on when the output is wrong, and no record that any of it happened.

Why do bans on AI tools at work fail?

Bans on AI tools fail because they remove visibility without removing demand. The employee who saved eight hours a day drafting quotes with a chatbot does not stop when you block the site on office machines. They switch to a personal phone or a private browser tab, and they stop talking about it.

That silence is the real cost. Before the ban you had unmanaged AI use you could still ask about. After the ban you have employees using ChatGPT secretly, which means no questions, no shared lessons, and no chance to correct a risky habit before it causes damage.

Prohibition loses because the productivity gain is personal and immediate, while the risk is corporate and abstract. Policy that ignores that asymmetry will be ignored in return. The workable alternative is to sanction a safe way to use AI and train people to use it well, an approach covered in this guide to AI training for employees.

What are the real risks when employees use ChatGPT secretly?

The realistic risks of shadow AI fall into three categories: data leaving the company, wrong answers reaching customers, and no record when you need one.

Data leaks come first. When staff use consumer chatbots on personal accounts, confidential text such as client names, pricing, contracts, or source code leaves your control the moment it is pasted. Depending on the account and its settings, that content may be retained by the provider or used to improve models, and you usually cannot even find out what was shared.

Confident errors come second. AI chatbots produce fluent, plausible text even when the substance is wrong. An untrained employee tends to judge output by tone rather than accuracy. That is how an invented contract clause or a made up product spec travels from a chatbot into a customer email with nobody checking it.

The missing audit trail comes third. If a client claims you mishandled their data, or a regulator asks how AI is used in your company, shadow AI leaves you with nothing: no list of tools, no record of prompts, no training evidence, no accountable owner. Each of these risks shrinks sharply once employees know the rules and know how to verify what AI produces.

Shadow AI risk vs trained behavior: the same tasks, very different outcomes

The table below compares untrained shadow AI habits with trained behavior on sanctioned tools, task by task.

SituationShadow AI behaviorTrained behavior
Customer dataPasted into a free chatbot on a personal accountSensitive fields removed or an approved tool used under clear rules
AI output qualitySent onward unverified because it sounds confidentChecked against source facts before it reaches a customer
Tool choiceWhatever is free and open in a browser tabA sanctioned tool the company can see and manage
Record keepingNo record of what was shared or generatedTraining records and a verifiable certificate per employee
AccountabilityNobody owns the outcome when something goes wrongClear rules define who may use AI for what

What is the eight hours fix for shadow AI?

The fix for shadow AI has three parts, and none of them is a bigger firewall: written rules, short practical training, and a sanctioned way to use AI so nobody needs to hide. Rules can fit on one page: which data must never be pasted into an AI tool, which tools are approved, and who checks AI output before it reaches a customer. Rules alone are not enough, though, because employees need judgment, not just prohibitions.

Training supplies the judgment. Learnery is a browser based AI training platform that certifies employees in around eight hours for 39 euros per seat as a one time payment. Each employee completes one seminar in twelve steps: steps 1 to 3 cover AI foundations, safe use at work, and everyday prompting, step 4 adapts to your industry, and step 5 to the exact subsector and role. Learners practice in a prompt lab on live AI, and completion earns a certificate with a verifiable code anyone can check online. The course is self paced, runs on any device, and needs no installation or IT integration. Above 10 seats the price drops by 20 percent.

The third part is habit. Once people are trained and a sanctioned path exists, shadow AI loses its reason to exist. The payback math is straightforward, and you can see how quickly saved time covers the seat price in this breakdown of the ROI of AI training.

Does the EU AI Act make shadow AI a compliance problem?

Yes, shadow AI is now also a compliance question in the EU. Article 4 of the EU AI Act (Regulation (EU) 2024/1689) has applied since 2 February 2025: companies whose staff use AI systems at work, including ordinary tools like ChatGPT, must take measures to ensure sufficient AI literacy of their staff. There is no exemption for small companies, and shadow AI makes the gap obvious: staff demonstrably use AI while the employer can show no measures.

Two dates matter in 2026. The Digital Omnibus, approved by Parliament on 16 June 2026 and the Council on 29 June 2026, softened Article 4 into an obligation of effort: companies must take appropriate measures to support the development of AI literacy rather than guarantee a result. The duty itself remains in force. And on 2 August 2026, only weeks away, national authorities begin supervising and enforcing the AI literacy rules.

Keep the risk in proportion. Article 4 breaches do not carry the headline AI Act fines; penalties are set by each Member State and must be proportionate, and no company had been fined under Article 4 as of July 2026. The European Commission's AI literacy guidance says instructions for use alone are not sufficient and points to training as the expected practical measure. No certificate is legally required, internal training records suffice, though a certificate with a verifiable code is convenient evidence.

Where should an owner start this week?

Start by finding out what is actually happening, not by writing a ban. Ask your team, without threat of punishment, which AI tools they already use and for what. Then publish a one page rule set, pick a date, and get every employee through a short course within the month. If you want to check the numbers first, the free ROI calculator shows what eight hours of training returns for your team size and hourly rates. You can set up seats at Learnery in a few minutes, or talk to sales about a larger rollout.

Frequently asked questions

What is shadow AI at work?
Shadow AI is the use of AI tools for work tasks without the employer's approval or knowledge, typically free chatbots accessed through personal accounts. Employees paste emails, documents, or data into these tools to work faster. It is common in small and midsize companies because most have no AI policy, so staff decide for themselves.
Should I ban ChatGPT in my company?
A ban on ChatGPT usually backfires. Employees who benefit from AI move to personal phones and private accounts, so use continues without any visibility or rules. A better approach is to approve specific tools, publish clear data rules, and train staff to verify AI output. That keeps the productivity and removes most of the risk.
What are the main risks of unsanctioned AI tools?
The three main risks of unsanctioned AI tools are data leaks, wrong answers, and missing records. Confidential text pasted into consumer chatbots leaves company control, fluent but false output can reach customers unchecked, and when a problem surfaces there is no audit trail showing what was shared, generated, or approved.
Does the EU AI Act require AI training for employees?
Article 4 of the EU AI Act has applied since 2 February 2025 and requires companies whose staff use AI at work to take appropriate measures to support sufficient AI literacy. Training is the expected practical measure, national supervision begins on 2 August 2026, and there is no exemption for small companies.
How much does it cost to fix shadow AI with training?
With Learnery, training costs 39 euros per employee as a one time payment for a certified course of about eight hours. Volume discounts apply: 20 percent off above 10 seats, 40 percent above 40, and 60 percent above 100. There is no subscription, and each certificate carries a verifiable code.

Ready to train your team on AI?

Over 8 hours per person, a certificate at the end, and pricing that fits every team size.

Start training Talk to sales

Keep reading

AI Training Records: What to Document for EU AI Act Compliance What Not to Share With ChatGPT: A Data Safety Guide for Work