Shadow AI is a data-breach risk, not a productivity debate
Rasmus Kjaer Damgaard, Co-founder ·
Šo rakstu izstrādāja ar AI palīdzību un pārskatīja cilvēks. Rasmus Kjaer Damgaard uzņemas redakcionālo atbildību par saturu.
TL;DR: The European Data Protection Supervisor's 2026 essay "Managing Shadow AI's Hidden Data Breach Risk" put a regulator's name on what security teams already knew: unmanaged AI use is a breach vector, not a productivity side-story. The mechanism is simple: an unapproved AI tool is an unvetted processor with no contract, no logs and no data map, which means an unanswerable Art. 33 notification when something leaks. The fix that works is not a ban but a maintained approved-tools register with per-tool data limits, a protective reporting path, and an alternative worth preferring. Generate the register and the rules in ten minutes with our free AI policy generator.
The mechanism, stated plainly
When an employee pastes customer information into a private AI account, three GDPR facts become true at once:
- Processing has occurred with the company as controller, whether or not anyone approved it.
- No processor agreement exists (Art. 28), so there is no contractual basis governing what the tool's vendor does with the data, including whether it trains on it.
- The company cannot scope a breach. If the tool leaks, mistrains or is compromised, the 72-hour notification duty (Art. 33) attaches to an incident with no logs, no inventory and no data map. You cannot notify precisely about data flows you never knew existed.
None of this requires the AI to malfunction. The breach risk is architectural: data left the controlled environment the moment it was pasted.
Why bans fail and registers work
Blocking consumer AI tools at the network edge moves usage to phones and home machines, where visibility drops from partial to zero. Every serious treatment of the problem, including the supervisory framing above, lands on governance rather than prohibition:
| Control | What it does |
|---|---|
| Approved-tools register | Names the tools that MAY be used, each with an approval state and the highest data tier it may receive |
| Data classification | A traffic-light model anyone can apply in seconds, plus a prohibited-input list |
| Protective reporting duty | Whoever finds an unapproved tool reports it; the response is migration to an approved alternative, not discipline |
| A sanctioned alternative | The decisive control: shadow use collapses when the approved path is genuinely better |
The register does the heavy lifting because it converts an unbounded problem ("employees might be using anything") into a bounded one ("these tools, these limits, this process for adding more"). It is also the first thing a supervisory authority or enterprise customer will ask to see.
Where we stand in this
Nordvec exists because of this exact problem: one controlled, EU-hosted platform where the company's documents are searched with citations, an audit trail, and a data processing agreement, instead of an unknown number of consumer tools nobody can audit. That is our interest in the topic, stated openly. The tools below are free and useful whether or not you ever become a customer:
- AI policy generator: the register, the data tiers, the reporting duty and the rest of the policy, assembled from structured answers with the legal citation behind every section.
- Article 50 checker: which transparency duties your AI use triggers, with an evidence record.
Sources
- EDPS: "Managing Shadow AI's Hidden Data Breach Risk" (W. Wiewiórowski, 15 June 2026)
- Regulation (EU) 2016/679, Art. 28 (processors)
- Regulation (EU) 2016/679, Art. 33 (breach notification)
- Our guide to Article 50's transparency duties
Bieži uzdotie jautājumi
What is shadow AI?
Employees using AI tools for work without IT's knowledge or approval: private ChatGPT accounts, browser extensions, free-tier assistants. The organisation has no processor agreement, no data-flow visibility, and no way to answer a supervisory authority's questions about where the data went.
Why is shadow AI a GDPR problem and not just an IT policy problem?
Because pasting personal data into an AI tool is processing. Without a processor agreement (Art. 28) the transfer is unmanaged, and if the tool trains on inputs or leaks them, the company faces a personal-data breach it cannot even scope, with the 72-hour notification clock (Art. 33) running on an incident it has no logs for.
Should we just block AI tools at the firewall?
Bans push usage to personal devices where visibility is exactly zero. The approach that works is an approved-tools register with per-tool data limits, a protective reporting duty, and a sanctioned alternative that is genuinely good enough to prefer.
How do we find the shadow AI already in use?
Ask department by department, protectively: which tools, for what tasks, with what data. Amnesty first, register second. The point of the exercise is an accurate register and moved usage, not punishment.