Shadow AI: why "we didn't approve that" isn't a GDPR defence

Most companies don't roll out AI with a strategy meeting and a signed-off policy. It starts smaller than that, someone on the team tries a new AI assistant, a vendor quietly bolts AI features onto software you already use, or a department finds a quicker way to summarise reports or sort through data. None of that is a red flag on its own. It's usually just people trying to work smarter.

The trouble starts when AI use spreads faster than anyone in the business can keep track of it. This is often called "Shadow AI", AI tools being used across the organisation that nobody has actually approved or reviewed. It sounds like an IT problem. It's really a data protection problem.

Here's why. Under GDPR, if personal data, customer details, employee records, health information, anything that identifies a person, goes into an AI tool, your business is responsible for what happens to it. That's true whether the tool was approved by management or downloaded five minutes ago by someone trying to save time on a Friday afternoon. GDPR doesn't ask who signed off on the tool. It asks who's processing the data, for what purpose, and whether that's being done lawfully, fairly and with proper safeguards. If you can't answer that, you have a compliance gap, regardless of the intent.

So the real question for leadership isn't "which AI tools has IT approved?" It's "which AI tools are actually being used, and what's going into them?" If you can't answer that with confidence, that's your starting point.

You can't protect data you can't see
You don't need a massive compliance programme to get a handle on this. You need visibility. In practice, that means knowing:

  • which AI tools people are actually using;

  • what they're being used for; what data goes into them;

  • who's responsible for each use case;

  • which uses need sign-off before they go further;

  • and how the higher-risk ones get checked once they're live.

Getting there usually involves a handful of practical pieces, a short AI policy people can actually understand, a simple way for staff to flag new AI tools before or as they start using them, a running list of what's in use, clear ownership, and a proportionate approval step for anything touching sensitive data. None of this needs to be heavy. In fact, if it's slow or overly bureaucratic, people will just go around it, and you're back to square one, except now with less visibility, not more.

The right level of scrutiny depends on the use case. Someone using AI to tidy up an internal email is a very different risk to AI being used with health records or influencing a decision about a customer's contract or an employee's job. Good governance and good GDPR practice tells those two situations apart instead of treating them the same way.

Don't start by banning AI
Trying to stop staff from experimenting with AI altogether rarely works, and it isn't the goal anyway, the tools are genuinely useful, and GDPR was never designed to stand in the way of that. The better move is building a light framework that gives you visibility and accountability without killing the upside.

So ask yourself honestly:

Do you know which AI tools are being used across your business right now, including the ones nobody formally signed off on? If personal data is flowing into any of them, that's a GDPR question as much as a technology one.

If the answer is "not really," that's exactly where your AI governance should start, not with a policy binder, but with finding out what's actually happening in your business today.

Next
Next

Legitimate interests: getting the most from your data, lawfully