Yes, your employees are almost certainly already using ChatGPT or other generative AI tools with company data: the available studies converge, a large share of employees do so, most often without telling their management. This shadow AI exposes your SMB to leaks of confidential data, GDPR breaches and decisions based on wrong answers. The effective response is not a ban, which consistently fails, but pragmatic governance: a clear policy, approved tools and controlled alternatives.
Shadow AI: massive, invisible and already entrenched
Shadow IT refers to tools used without IT department approval; shadow AI is its most explosive variant. The barrier to entry is zero: a browser, a free account, and any employee can rewrite a customer email, summarise a contract or debug internal code. The phenomenon touches every department, from sales to human resources, finance and engineering, and it escapes traditional monitoring tools because it goes through consumer websites. In most SMBs, there is no policy, no list of approved tools, and no visibility whatsoever on these uses. And the more capable the tools become, the more data employees feed them, widening the gap between actual practice and official policy.
The concrete risks for your company
Leaking confidential data
Every prompt containing a contract excerpt, a customer list, financial figures or source code sends that data to a third party's servers. On the consumer versions of many tools, this content may be retained and, depending on the settings, used to improve the models. The precedent is well known: as early as 2023, Samsung restricted the use of ChatGPT after engineers pasted confidential source code into it.
GDPR and personal data
Pasting employee, candidate or customer data into a consumer tool constitutes processing of personal data without a clear legal basis, often combined with a transfer outside the European Union. In the event of an inspection by the data protection authority or a complaint, the company is liable, not the employee who did it. Enforcement action across Europe shows that regulators now look closely at how AI tools are fed with personal data.
Intellectual property
Your know-how, whether methods, code or commercial documents, loses confidentiality as soon as it passes through services with no contractual guarantees. Conversely, the legal status of generated content remains uncertain: integrating AI-produced code or text without control can create infringement risks.
Wrong answers taken at face value
Generative models produce plausible but sometimes false answers. Professionals have already been sanctioned for submitting documents based on references invented by a chatbot, notably in the legal field. Without a human verification rule, a hallucination can end up in a quote, a contract or advice to a client.
Why an outright ban fails
Blocking AI websites on the company network simply pushes usage onto personal phones, where you have no visibility at all. The productivity gains are real, and your teams will not give up a tool that saves them time every day. A ban therefore produces the worst-case scenario: usage continues, but hidden, without training or safeguards. Companies that banned these tools outright have generally ended up reversing course; it is better to set a framework from the start. The realistic goal is not zero usage but visible, well-framed usage.
Building a pragmatic AI policy
A good policy fits in a few pages and answers three questions: which tools, which data, which practices.
- Approved tools: a short list of validated tools, with the required account type (business, never personal), reviewed regularly.
- Data classification: what may be shared with an AI (public information, anonymised internal content) and what never may (personal data, proprietary code, customer data, trade secrets).
- Usage rules: systematic human review before any external use, disclosure of generated content where relevant, and a ban on letting an AI make a binding decision on its own.
- A simple process: a channel to get a new tool approved within days, otherwise shadow AI takes over again.
- Concrete examples: ten practical cases are worth more than ten pages of abstract principles.
Pair the policy with a short training session: this has in fact been an obligation under the EU AI Act since February 2025 for any organisation using AI.
Controlled alternatives
Governance only works if you offer your teams credible alternatives to consumer tools:
- Business accounts: the professional plans of the major providers contractually exclude training on your data and offer centralised access management. The cost, generally in the range of €20 to €60 per user per month, is small compared with the risk covered.
- An internal gateway: a single portal connected to the models via API, with logging of exchanges, filtering of sensitive data and rules tailored to each department.
- AI hosted in-house: for the most sensitive data, open-source models deployed on your own infrastructure keep everything internal, at the price of a larger investment.
Regaining control over shadow AI is a project of a few weeks, not several months: an inventory of actual usage, a policy, tool selection, training. Running it with a partner who masters both the technology and compliance turns a diffuse risk into a productivity advantage you can stand behind. The companies that handle this best are those that moved early, before an incident forced them to.
