Key takeaways
- Shadow AI is already widespread. Employees are adopting AI tools faster than many organisations can formally review and approve them.
- It shows up in two different ways. Personal data can be shared into a personal AI account, or an AI tool can be granted direct access to company systems. Each needs a different fix.
- The data behind the tools matters. If Microsoft 365 contains unnecessary or outdated personal data, AI can make that information much easier to find.
- An AI policy is useful, but it isn't enough. Organisations also need visibility into the tools employees use and the data those tools can access.
- Cleaning up data before expanding AI use reduces exposure from the start.
- Prioritisation matters. Compliance teams need to focus on genuinely sensitive information without getting buried in false positives.
What is Shadow AI?
Shadow AI is the use of AI tools, applications or plugins for work without formal approval or oversight from IT, security or compliance teams.
In practice, it can be something as simple as an employee pasting a customer email into ChatGPT to draft a reply, a manager uploading meeting notes containing HR information to a transcription tool, or a developer connecting an AI coding assistant to a repository.
Broadly, that risk falls into two categories, and it's worth keeping them separate. The first is data shared into personal AI accounts: an employee copies, pastes or uploads a document, email or dataset into a private ChatGPT, Gemini or Claude account. The organisation has no oversight of that account, so once the data is shared, it's gone. The second is access granted to AI tools. Here an employee, or an app already connected to Microsoft 365, gives an AI tool or plugin direct, ongoing access to email, files or chat history, through a browser extension, a connected app, or a third-party permission. This happens less often than manual copy-pasting. But it creates a standing connection that keeps working without anyone having to act again.
Most Shadow AI conversations focus on the first scenario, because it's the one employees encounter daily. The second deserves attention too, since it doesn't depend on anyone remembering to be careful each time.
Most of the time, employees are not deliberately trying to bypass security. They have simply found a tool that helps them work faster. The issue is that the organisation may have no visibility into how that tool handles data, what permissions it has or what information is being shared with it.
The consequence is a discrepancy between what the organisation thinks it controls and what's actually happening with its data. Personal information ends up processed in places outside its oversight, which is precisely where GDPR obligations get hard to meet.
Shadow AI vs Shadow IT
Shadow AI is closely related to Shadow IT, but the two are not exactly the same. Shadow IT refers to software or hardware being used without approval, such as a personal Dropbox account, an unapproved file-sharing platform or a browser extension that IT hasn't reviewed.
Shadow AI adds another layer of risk because AI tools don't just store information. Depending on the tool and the permissions it has, they can read documents, summarise conversations, generate content from internal information or interact with connected systems.
A forgotten folder in an unapproved cloud account is a risk on its own. An AI tool granted the kind of direct, standing access described above can go further. Once connected, it can search and surface information employees may not even remember still exists, with nobody having to share it manually each time. Forgotten data used to be low-risk precisely because nobody was looking. That protection disappears once an AI tool has that kind of access. It's exactly why the technical controls further down in this article matter.
Why Shadow AI creates a GDPR risk
GDPR doesn't treat Shadow AI as a separate legal category. What it does is make existing data protection problems much harder to ignore. The majority of organisations worldwide have accumulated years of information across Exchange, SharePoint, Teams and OneDrive. Not all of it still needs to be there.
Old CVs, customer records, scanned IDs, HR documents, support tickets or spreadsheets can remain stored long after their original purpose has disappeared. Before widespread AI adoption, much of this information could stay buried for years. AI changes that because it makes large amounts of data much easier to search, summarise and use, once it reaches a tool one way or another.
Which GDPR principles are affected?
Several GDPR principles become particularly relevant when AI tools interact with unmanaged personal data.
Data minimisation — Article 5.1(c) Organisations should only keep personal data that is necessary for its intended purpose. If unnecessary information remains in Microsoft 365, AI tools may surface it alongside the information employees genuinely need.
Storage limitation — Article 5.1(e) Personal data should not be kept longer than necessary. If retention policies are not reflected in what is actually stored, AI may be searching through years of information that should already have been removed.
Integrity and confidentiality — Article 32 Personal data needs appropriate technical and organisational protection. An unreviewed AI tool with access to company information creates another route through which that data may be processed or shared.
Accountability — Article 5.2 Organisations need to understand what personal data they hold and how it is handled. Unsanctioned AI use makes that harder because some processing may happen outside established controls.
What connects all four is knowledge: you can't minimise, retain, protect or account for data you haven't located.
Where Shadow AI shows up in Microsoft 365
Shadow AI rarely looks dramatic. In most cases, it looks like normal day-to-day work: an employee trying to finish a task faster, using a tool that has not gone through the organisation's usual approval process.
Some common examples include:
- Copying information into public AI tools. An employee pastes a customer email, HR document or contract into ChatGPT or another AI tool to summarise it or draft a response.
- Using personal AI accounts for work. Employees use their own ChatGPT, Gemini or Claude accounts instead of a company-managed service, leaving the organisation with limited visibility into what is being shared.
- Installing AI browser extensions or plugins. Meeting assistants, writing tools and AI sidebars can request access to email, documents or browser content without going through a formal security review.
- Rolling out Microsoft Copilot before reviewing existing data. Copilot may be sanctioned and centrally managed, but it can still surface information employees already have permission to access, including data that may no longer need to be stored.
- Connecting AI tools to development environments. Repositories, logs, test environments and support tickets can contain personal data that becomes accessible to coding assistants or AI automation tools.
None of these happen out of bad intent. The common thread is usually a lack of visibility over the tools being used and the data available to them.
How widespread is Shadow AI?
Microsoft and LinkedIn's Work Trend Index found that 78% of people using AI at work were bringing their own AI tools rather than relying only on technology provided by their employer.Cisco's Data Privacy Benchmark also found that 48% of organisations were entering non-public company information into generative AI applications.
These figures help explain why Shadow AI is difficult to manage through policy alone. Employees have already found useful ways to use these tools, so the challenge for organisations is not simply to stop adoption, but to support it without losing control of the information being processed.
Why banning AI isn't enough
An AI policy is an important starting point, but simply telling employees not to use unapproved tools is unlikely to solve the problem. People use AI because it saves time: it helps them summarise documents, draft content, analyse information and automate repetitive work.
If that need still exists, blocking one tool may simply push employees towards another. The real challenge for organisations is supporting that adoption without losing control of the information being processed. That means looking beyond which AI applications are allowed, to what data those tools can actually access.
If unnecessary personal data has already been removed, there is less information available to expose, whether the tool is Copilot, ChatGPT or the next AI application employees decide to try.
A framework for giving employees safer access to AI
Banning tools rarely removes the underlying need. A more durable approach usually combines four layers, each closing a different part of the gap:
- Provide approved tools that cover the need. Most Shadow AI happens because there's no good sanctioned alternative. An enterprise AI tool with a proper data processing agreement, no training on company data, and clear retention terms removes most of the reason to paste documents into a private account.
- Set clear, concrete rules — and train on them. A short policy naming specific examples works better than a general GDPR paragraph nobody reads twice. "Don't paste customer threads into private ChatGPT" is more useful than a broad principle.
- Close the technical loopholes. Require admin approval for third-party app connections and review old consents that predate current policy. Tools such as Microsoft Defender for Cloud Apps and web filtering can flag or block unapproved AI services on managed devices, Microsoft Purview can catch sensitive data being pasted or uploaded to AI sites, and a Teams meeting lobby stops AI note-takers joining unnoticed.
- Limit the data itself. This is the layer that protects you even when the other three fail, including with an approved tool like Copilot: know where sensitive data lives, delete what's past its retention period, fix oversharing (broad "anyone with the link" access, org-wide SharePoint permissions), and apply sensitivity labels that stop AI tools from processing certain content.
Approved tools reduce what employees feel they need to share elsewhere. Technical controls reduce what any AI tool — approved or not — can reach. Data minimisation reduces what's actually there to expose, and it's the one layer that still protects you if the first two don't hold. We'll go deeper into each of these, with concrete examples, in a follow-up article.
How to reduce Shadow AI risk
Managing Shadow AI requires policies, access controls and employee training, but it should also start with the data itself. Before expanding the use of AI, organisations need to understand what personal data already exists inside Microsoft 365 and whether all of it still needs to be there.
1. Understand what personal data you already have
The first step is visibility. Organisations need to know what personal data is stored across Exchange, OneDrive, SharePoint and Teams, including information inside documents, scanned files and images that standard keyword searches can easily miss.
2. Prioritise the highest-risk data
Not all personal information carries the same level of risk. A name in an email signature is very different from a passport scan, national ID number or medical document, so compliance and IT teams need to prioritise the information that would create the greatest exposure if surfaced or shared.
Without that prioritisation, data discovery can quickly become another overwhelming list of files to review.
3. Involve employees in the clean-up
The person who created or received a document often has context that an administrator doesn't. They are usually better placed to decide whether a file is still needed, whether it is linked to an active customer or whether it can safely be deleted.
Giving employees a simple way to review relevant findings can make data clean-up much more practical than asking a small compliance team to make every decision centrally.
4. Make data clean-up an ongoing process
A one-off clean-up isn't enough. New emails, documents and files are created every day, while organisations continue to adopt new AI tools and expand platforms such as Microsoft Copilot.
Regular data discovery and review helps prevent the same problem from building up again. This is also the principle behind GDPR data discovery in Microsoft 365: organisations need visibility over the personal data they hold before they can manage it effectively.
Shadow AI readiness checklist
Before expanding the use of AI tools such as Microsoft Copilot, organisations should be able to answer a few basic questions:
- Do you know which AI tools employees are already using?
- Do employees know what information they should not paste into public AI tools?
- Do you know where sensitive personal data currently sits across Microsoft 365?
- Have old or unnecessary personal records been reviewed and removed?
- Are permissions in SharePoint, Teams and OneDrive still appropriate?
- Can IT and compliance identify high-risk information without manually reviewing thousands of files?
- Is there an ongoing process for reviewing new personal data as it accumulates?
These questions don't replace a broader AI governance programme, but they provide a practical place to start.
Common Shadow AI challenges
"We already have an AI policy." That's useful, but policy and data hygiene solve different problems. A policy defines how employees are expected to use AI, while data clean-up reduces the amount of unnecessary information those tools could access in the first place. Organisations ideally need both.
"There's too much data. We don't know where to start." Trying to review every file manually isn't realistic. A more practical approach is to start with the categories that would create the greatest concern if exposed, such as national ID numbers, financial data, health information, scanned identity documents and other sensitive records.
"Employees will see this as another restriction." The objective doesn't have to be to stop people using AI. A cleaner and better-governed data environment can actually make it easier for an organisation to approve and expand useful AI tools.
"Leadership doesn't see Shadow AI as a priority." Shadow AI can feel abstract because much of the activity happens quietly. Connecting the issue to planned AI projects can make it more tangible. If the business wants to roll out Microsoft Copilot, for example, understanding what information Copilot will be able to surface becomes a practical deployment question rather than a theoretical compliance exercise.
Frequently asked questions about Shadow AI
Is Shadow AI illegal under GDPR? Shadow AI itself is not specifically named or prohibited by GDPR. The issue is how personal data is processed and whether the organisation can demonstrate appropriate security, data minimisation and accountability when employees use AI services. If personal data is being sent to unapproved tools without oversight, meeting those obligations becomes more difficult.
What's the difference between Shadow AI and Shadow IT? Shadow IT refers broadly to technology being used without formal approval. Shadow AI is part of the same broader problem, but AI tools can do more than simply store information. Depending on their capabilities and permissions, they can analyse, summarise, generate content from or act on the data they receive.
Does blocking AI tools solve Shadow AI? Not completely. Blocking specific applications can be one useful control, but organisations still need to understand which tools employees are using, why they are using them and what information is being shared. Reducing unnecessary personal data also limits what can be exposed if an unsanctioned tool is used.
Should you clean up data before rolling out Microsoft Copilot? Where possible, yes. Copilot works with information users already have permission to access, so reviewing unnecessary personal data and access permissions before a wider rollout reduces the amount of sensitive or outdated information available to surface.
Getting ready for AI starts with knowing your data
Shadow AI is getting attention because AI adoption is moving fast. Underneath it, though, is a familiar problem: organisations have been accumulating personal data for years, and some of it stopped serving any purpose long ago. What changes is how quickly that old data can now be found and put to use, whichever way it reaches an AI tool.
That has a practical consequence for planning: data governance and AI rollout are no longer separate projects on separate timelines. A Copilot rollout date, a new plugin request, a policy update: each one is also a deadline for knowing what personal data sits behind it. Treating the two as connected, rather than sequential, is what keeps the clean-up from permanently lagging one step behind whatever tool employees pick up next.
Where Sheltr fits in
Sheltr Data Discovery finds personal data across Exchange, OneDrive, SharePoint and Teams, including the scanned documents and images that keyword search alone tends to miss. It gives employees a simple way to review and clear what shouldn't be there anymore. It doesn't write your AI policy or set your consent rules. What it covers is the data-minimisation layer, and no policy or technical control replaces that on its own. See how it works.

