Vidimas is live – all leading AI models, securely hosted in the EU or Switzerland.Start free trial
Vidimas
All articles
SecurityUpdated on 26 July 20263 min readVidimas editorial team

Shadow AI: spotting and fixing uncontrolled AI use

Shadow AI describes the use of AI tools by employees without the company's knowledge or approval – the AI counterpart to classic shadow IT. It arises almost inevitably: the tools are freely available, the benefit is immediately noticeable, and official alternatives are often missing.

The problem: with every prompt from a private account, potentially confidential data leaves the company – with no contract, no control and no traceability.

How to spot shadow AI

Typical signals: text produced strikingly fast and in unfamiliar quality, AI domains in the network logs, browser extensions with AI features – and employees mentioning tools in meetings that nobody officially introduced. An anonymous team survey often gives the most honest picture: who is already using what, and for what?

Why shadow AI is riskier than shadow IT

Classic shadow IT usually just stores data outside your control. With AI tools there's more: inputs to consumer versions can be used to train the models, and processing frequently takes place in third countries. A one-off copy and paste can turn into permanent disclosure.

Legally, the company is on the hook: neither the GDPR nor the revFADP makes an exception for unofficial tools. For professions bound by secrecy, criminal law is on the table as well – § 203 of the German Criminal Code, Art. 321 of the Swiss Criminal Code.

The wrong reflex: banning it

A ban without an alternative drives usage underground – onto private phones and home laptops, where no firewall is watching. The productivity gains disappear from the company, the risks remain. Bans only work when an official offering exists alongside them that is at least as good.

The controlled route in three steps

A pragmatic approach has proved itself:

  • Create transparency: take stock of actual usage – without apportioning blame
  • Provide an official offering: one central, secure AI platform with the models the team wants to use anyway
  • Rules and training: an AI policy with clear data categories plus short, practical training

Frequently asked questions

Is shadow AI grounds for dismissal?

That depends on your internal directives and the severity. In most cases, fixing the cause – the lack of official tools – achieves more than sanctions. Providing a good offering solves the problem more durably than any written warning.

How do I find out which AI tools are being used?

Combine technical analysis (DNS and proxy logs, browser extensions) with an anonymous team survey. The survey also shows which use cases matter to the team – valuable input for choosing a tool.

Is an AI policy enough against shadow AI?

No. A policy without a usable official tool gets ignored. What works is the combination: clear rules, an attractive internal offering and regular communication.

Related reading

Bring AI into your company securely.

Try Vidimas with your team – and see how quickly secure AI becomes productive.

Start free trial
  • Try it with the whole team
  • Set up in minutes
  • Productive from day one