Female representation in the IT sector
Your employees are already using artificial intelligence, with or without your approval. This is known as “shadow AI”: the use of generative AI tools that haven’t been approved by the IT department. The phenomenon is growing rapidly, often with good intentions. The real issue isn’t banning it, but managing it. Here’s how to regain control, in practical terms.
What Exactly Is Shadow AI?
Shadow AI refers to the use of generative AI tools (such as ChatGPT, writing assistants, image generators, or code generators) by teams without going through IT and without a defined framework. It’s the cousin of shadow IT, applied to artificial intelligence.
A sales rep who has an assistant proofread a proposal, an HR employee who rewrites a job posting, a developer who debugs their code: everyone is trying to save time. The problem isn’t the intention—it’s the lack of rules. No one knows what data is being entered, into which tool, or where it ends up. This gray area builds up one employee at a time, without any explicit decision.
Why Shadow AI Is a Real Risk
Behind an apparent productivity gain, several risks are piling up.
Data leaks and trade secrets
What is entered into a consumer-grade tool may be stored outside Switzerland or even reused to train models. A contract, a customer file, or a strategic plan pasted into a prompt is then beyond your control. Trade secrets are compromised—without any intent to cause harm and often without anyone even realizing it.
nLPD Compliance
The new Federal Data Protection Act (nLPD) requires organizations to know where personal data is processed and by whom. Uncontrolled AI usage makes this traceability impossible and exposes the company to a risk of non-compliance, particularly when processing takes place abroad.
Biases and Hallucinations
A generative model can confidently produce a false response or replicate biases present in its data. Without critical scrutiny, a decision may be based on erroneous information. Human vigilance remains essential.
Regulate Without Banning: The Right Approach
Banning AI only drives its use further into the shadows. The goal is to provide a clear framework and secure tools so your teams can innovate with confidence.
1. Map actual uses
Start by observing what’s already happening: which tools are being used, for which tasks, and with what data. This assessment, conducted without the intent to penalize, reveals concrete needs and guides all subsequent decisions.
2. Draft an AI usage policy
A simple, easy-to-read policy sets the ground rules: which tools are authorized, what data must never be entered, and who to contact in case of doubt. A short, practical document is better than a dense set of regulations that no one reads.
3. Offer Approved Tools
The best way to reduce or even eliminate “shadow AI” is to offer an official alternative. This includes AI solutions approved by IT, hosting tailored to the sensitivity of your data, and compliance with the nLPD. When the approved tool is just as convenient as the unauthorized one, the choice becomes obvious.
4. Train and raise awareness among teams
Technology alone isn’t enough. Your employees must understand the risks and know the right steps to take: never enter sensitive data, verify responses, and report incidents. Targeted training turns every user into a first line of defense.
The Role of a Local IT and AI Partner
Managing shadow AI requires three areas of expertise that are rarely found in one place: cybersecurity, expertise in applied AI, and knowledge of the Swiss legal framework. This is precisely our area of expertise.
We help you map out your use cases, establish governance and a policy tailored to your specific situation, deploy secure AI tools on a sovereign infrastructure in Switzerland, and train your teams. AI then becomes a controlled asset, not a blind spot.
Detecting Shadow AI
You don’t need to guess who’s using what: shadow AI can be detected technically. Endpoint detection and response (EDR) tools and network monitoring reveal which AI services are actually being used within the company, from which workstations, and how frequently. In just a few days, you’ll move from vague concerns to a fact-based map: the objective foundation for your policy, the selection of validated tools, and your training plan. And often, there’s a pleasant surprise: these detected uses are your first AI use cases—already tested by your teams—that simply need to be secured.
Conclusion
Shadow AI isn’t inevitable—it’s a signal: your teams want to move forward with AI. By establishing a clear framework and providing secure tools, you can turn this risk into a competitive advantage. Let’s discuss your specific context and work together to build an AI governance framework tailored to your company.
Tags :
7/30/26, 8:00 AM