AI

Shadow AI: ChatGPT has long been in your business

3 min read

Dark green graphic reading “Schatten-KI längst da” with a list of three items: in use ticked, policy and training not
Quick answer

Shadow AI means employees using AI tools for work through private accounts, without the business knowing. In the 2024 Work Trend Index by Microsoft and LinkedIn, 75 per cent of surveyed knowledge workers used AI at work, 78 per cent of them with their own tools. The risks are data leakage and unchecked mistakes. A ban only pushes the use out of sight. What helps: an anonymous look, one page of rules, training on real cases.

Asked whether AI is used in the company, many owners say: hardly. Asked anonymously, the teams say something else. Between those two answers lies the subject of this article.

What is shadow AI?

Shadow AI means employees using AI tools for work without the business knowing, usually through private accounts. The email to the difficult customer, the proposal in English, the summary of the draft contract. The problem is not that employees help themselves, but that nobody sees it.

How widespread is it?

More widespread than most assume. In 2024, Microsoft and LinkedIn surveyed 31,000 knowledge workers in 31 countries for the Work Trend Index – people who mostly work at a desk. Among them, 75 per cent said they use AI at work. And 78 per cent of users brought their own tools rather than waiting for their employer to provide one.

One limit we state openly: for Austrian small and medium-sized businesses we know of no dedicated, reliable survey. Our observation from conversations with businesses matches the direction of the figures, though.

This article in three sentences:

Shadow AI means employees using AI tools for work through private accounts, without the business knowing. According to the 2024 Work Trend Index, 75 per cent of surveyed knowledge workers used AI at work, 78 per cent of them with their own tools. A ban only pushes this use out of sight; looking closely, one page of rules and training on real cases bring it into the light.

Source: Microsoft and LinkedIn, Work Trend Index 2024 (opens in a new tab)

What can go wrong?

Two things, at different costs. First the data: whatever goes into a private account leaves the business, depending on tool and settings even as the provider's training material. Whether that is permissible in a given case depends on tool, settings and data; when in doubt, that is a question for legal advice. What is certain: whoever does not know what flows where cannot even ask the question.

Second the mistakes. AI tools deliver wrong answers in the same confident tone as right ones. Whoever does not know the limits carries the mistake into the proposal or the customer email, and nobody double-checks, because officially no AI is in use.

Does a ban help?

From everything we see: no. The work does not shrink, so it moves to the private phone, where the business loses sight of it for good. A ban feels like control and is the opposite of it.

The counter-position is just as comfortable and just as wrong: let everyone get on with it, it will sort itself out. Without rules and training it is not the benefit that grows but the risk.

What helps instead?

Three steps, in this order. First, look: a short anonymous survey in the team, who uses what and for which tasks. Anonymous, because otherwise nobody answers honestly.

Second, one page of rules: what is allowed, what is off limits, who to ask when in doubt. One page everyone understands beats thirty pages nobody reads. Our data traffic light answers the most frequent single question free of charge.

Third, train the people concerned, on the tools and tasks that actually occur, including the limits. Where your business stands on rules and records is shown by the AI literacy check in three minutes.

What does the honesty cost?

You have to admit that the use has long been there and that the sense of control was just that – a feeling. In return you get the real thing: not by banning, but by looking.