We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

Data & AI

Shadow AI: The Invisible Threat to Your Business in 2026

Vos collaborateurs utilisent déjà l'IA sans votre accord. Le Shadow AI, pourquoi c'est un risque pour les dirigeants et comment l'encadrer sans l'interdire.

Shadow AI: The Invisible Threat to Your Business in 2026

Has your CIO ever presented you with a report on the use of AI in your company? Probably not. And yet, some of your teams are already using ChatGPT, Claude, or Gemini to process business data—such as client contracts, HR data, and strategy memos. Without a policy. Without traceability. Without your approval.

This phenomenon is called Shadow AI. By 2026, it had become the biggest blind spot for business leaders.

‍

What is Shadow AI?

Shadow AI refers to employees using artificial intelligence tools outside of any framework established by the company.

The term comes from "Shadow IT"—software installed without IT department approval (personal Dropbox, WeTransfer, professional Gmail accounts, etc.)—but the comparison ends there. AI tools don't just store files: they read, analyze, summarize, and generate text from your data. It's a difference in nature, not in degree.

‍

The most commonly used tools in Shadow AI

ChatGPT (OpenAI) is the most widely used: drafting emails, summarizing documents, and preparing analyses. Claude (Anthropic) is popular for handling long documents. Gemini (Google) is often shared via employees’ personal Google accounts. Microsoft’s Copilot itself can pose a problem: a personal Microsoft account grants access to Copilot without any corporate data protection—not to be confused with the enterprise version. Perplexity, Mistral, and Llama’s web interfaces are less well-known but their use is growing rapidly.

‍

A concrete example

A sales representative is preparing a proposal. Instead of spending an hour on it, they paste the client’s specifications into ChatGPT and get a first draft in just a few seconds.

What he failed to consider: the client’s industry, business needs, budget, and name have just been transmitted to a server located outside the European Union, where they could potentially be used to train a future model, without any valid legal basis under the GDPR.

‍

Why Shadow AI Is the Top Risk for Executives in 2026

Près de 50 % des DSI déclarent ne pas se sentir prêts à gérer les risques liés à l'IA dans leur organisation (Gartner via Lighthouse Global, 2026). Selon le Microsoft Work Trend Index 2024, 75 % des salariés des métiers de bureau utilisent l'IA générative au travail, 78 % de ceux qui l'utilisent apportent leurs propres outils, et 52 % hésitent à reconnaître qu'ils s'en servent pour leurs tâches les plus importantes.

In other words: your teams are using AI, they know it, but they aren't telling you. And you aren't picking up on it.

‍

The specific risks to your business

The first risk is data leakage. Free or personal versions of AI tools may use conversations to improve their models. Contract terms, customer data, financial information, or ongoing projects could end up feeding third-party systems beyond your control.

The second risk is legal. The GDPR requires that all processing of personal data be based on a legal basis and governed by contractual safeguards. Transferring customer or HR data to a tool that is not covered by a contract constitutes a potential violation. In the event of an inspection by the CNIL or a legal dispute, liability extends all the way up to the executive.

The third risk is operational. AI tools sometimes generate inaccurate content—professionals refer to this as "hallucinations." An employee who makes a decision or sends out an external communication based on unverified output exposes the company to costly mistakes.

‍

How Shadow AI Takes Root in an Organization

Shadow AI doesn't stem from malicious intent. It stems from a gap between the tools available and employees' actual needs.

The pattern is almost always the same. An employee discovers ChatGPT in their personal life. They realize how much time it saves. They start using it for simple work tasks. Gradually, the data they handle becomes more sensitive. No one notices, because no monitoring tools are in place. This behavior spreads to other team members.

This cycle takes a few weeks to take hold in most organizations. Once it’s established, it’s very difficult to eliminate through bans alone: banning something without offering an alternative is like asking your employees to give up their main source of productivity gains.

‍

The wrong answers that companies (all too often) give

"We're going to ban AI." That won't work. Your employees use their personal phones, their private accounts, and their 4G connections. Blocking internet access from their desks isn't realistic.

"We're going to wait for the market to stabilize." The market has already stabilized. The tools are here, mature, and widely used. Every month we wait is another month of unregulated Shadow AI.

"Our CIO is handling that." Shadow AI is a corporate governance issue, not just a technical problem. It falls under the CEO's responsibility regarding data protection, GDPR compliance, and strategic risk management.

‍

Shaping AI rather than being at its mercy

Interdire ne marche pas, tout ouvrir non plus : les données partent sans contrôle, avec un risque RGPD et de transfert hors d'Europe. Il reste une troisième voie : encadrer sans interdire. Elle prend deux formes, qui se combinent.

La première consiste à donner aux collaborateurs un outil d'entreprise qui répond à leurs besoins, comme Microsoft Copilot dans sa version entreprise. La seconde consiste à placer une passerelle, un proxy IA, entre les collaborateurs et les outils qu'ils utilisent déjà (ChatGPT, Claude, Gemini, Mistral) : les données sensibles sont remplacées avant l'envoi et chaque usage est tracé.

‍

What sets Copilot apart from the tools used in Shadow AI

The risk doesn't come from the tools themselves: ChatGPT, Claude, and Gemini also offer enterprise versions with robust safeguards. The risk stems from your employees using personal accounts without any framework or corporate contract. That, precisely, is Shadow AI.

Criterion AI via personal account Copilot for Business
Data remains in your tenant No Yes
Training the model with your data Yes, by default (manual opt-out) Never
Legal Basis under the GDPR Personal Terms of Service, without DPA Signed DPA
Traceability of usage No Logs available to the administrator
Compliance with internal permissions No knowledge of your IT system Zero Trust, M365 permissions
DLP policies and sensitivity labels No Natively integrated

‍

An important point: Copilot does not create new security vulnerabilities. Instead, it identifies those that already exist within your organization—such as overly broad SharePoint permissions. That is why a thorough deployment always begins with a governance audit.

‍

What this means in practice for your teams

By giving your employees an AI tool integrated into Word, Excel, Teams, and Outlook, you eliminate the need for Shadow AI. You no longer ask them to sacrifice productivity. You provide them with the same capabilities within an environment that you control.

‍

Bloquer, ouvrir ou encadrer l'IA générative

Face au Shadow AI, la plupart des entreprises hésitent entre deux réflexes. Tout bloquer : les collaborateurs passent par leur téléphone ou leur connexion 4G, et l'usage devient invisible. Tout ouvrir : les contrats, les données clients et les données RH partent vers des services dont l'entreprise ne maîtrise ni les conditions ni la localisation.

Ce qu'un proxy IA change

Un proxy IA se place entre vos équipes et les modèles d'IA. Il fait quatre choses :

  • il anonymise : les noms, sociétés, numéros SIREN, e-mails, téléphones, IBAN, numéros de carte et autres données sensibles sont repérés et remplacés avant l'envoi au modèle ;
  • il encadre : règles par équipe et par rôle, quotas, refus des demandes sans rapport avec l'activité ;
  • il centralise : un seul accès, avec le compte Microsoft ou Google de l'entreprise, à plusieurs modèles ;
  • il trace : chaque échange est horodaté dans un journal exportable.

Vos collaborateurs gardent l'IA ; vous savez ce qui sort. C'est le principe de notre offre Proxy IA, hébergée et traitée en France, RGPD avec contrat de sous-traitance (DPA) fourni, à partir de 99 € HT par mois plus 3,50 € HT par utilisateur.

Voir les usages avant de décider

Si votre entreprise dispose de Microsoft 365, deux outils Microsoft aident à mesurer le phénomène. Defender for Cloud Apps repère les applications cloud utilisées depuis le réseau et les postes, dont les services d'IA générative. Microsoft Purview, avec sa partie consacrée à la sécurité des données pour l'IA (DSPM for AI), montre quelles données sensibles circulent vers ces outils. Les deux sont inclus dans les modules complémentaires Defender Suite et Purview Suite de Business Premium.

‍

What you can do starting this week

Three questions to ask your CIO—or yourself—before the end of the week.

‍

  • Do you have an AI usage policy? Even a simple guideline outlining what is and isn’t permitted with company data is a good place to start.
  • Are your Microsoft 365 licenses up to date? Copilot Chat is free and can be enabled immediately in your tenant—it’s the first tangible barrier against Shadow AI.
  • Are your SharePoint permissions set up correctly? This is an essential prerequisite for any AI deployment. If your access rights are too broad right now, Copilot will expand them.
  • Savez-vous quels outils d'IA sont déjà utilisés ? Avant d'interdire ou d'autoriser, mesurez : quels services, quelles équipes, quelles données. C'est la base d'une charte réaliste.

Shadow AI is already present in your organization. It operates silently, is difficult to detect, and exposes the company to real legal, security, and operational risks.

Banning it is pointless if you don't offer an alternative. Implementing a regulated alternative—and auditing the governance structure before doing so—is the only approach that works in the long run.

IT SYSTEMES Microsoft Modern Work Partner Solutions Copilot support, AI governance, and security for small and medium-sized businesses

‍

Our latest articles

See more
Cybersecurity

Fuite Hauts-de-France : ce qu'une PME doit vérifier dans la foulée

Deux prestataires de la région Hauts-de-France auraient été piratés, avec des centaines de milliers de personnes potentiellement concernées selon les revendications de l'attaquant. Voici ce qui est connu, ce qui reste à confirmer et les trois vérifications à faire côté PME.
6/10/2026
Cybersecurity

LLMOps : définition et exploitation des agents IA en production

LLMOps : définition, différence avec le MLOps et l'AIOps, et les six briques pour exploiter un agent IA en production. Avec l'exemple de notre agent Helpy.
6/10/2026
Assistant IA symbolisé par un robot au-dessus d'une main devant un ordinateur portable
Cybersecurity

Sécuriser MCP en entreprise : risques et bonnes pratiques pour les DSI

Model Context Protocol (MCP) : les risques de sécurité pour l'entreprise (serveurs non vérifiés, droits trop larges, injections) et les bonnes pratiques.
5/10/2026
IT Systems Consultant showing a monitoring dashboard to a colleague
Cybersecurity

Superviser un agent IA en production : méthode et indicateurs

Superviser un agent IA en production : actions, erreurs, coûts, dérives, seuils de reprise en main et indicateurs. La méthode appliquée à notre agent Helpy.
2/10/2026
Conseil en cybersécurité auprès d'une PME
Cybersecurity

Assurance cyber PME : prix, couverture et limites en 2026

Combien coûte une assurance cyber pour une PME en 2026, ce qu'elle couvre vraiment, et pourquoi elle ne remplace pas une vraie protection technique.
1/10/2026

Rapport ANSSI sur le piratage du fisc : ce que ça change concrètement pour votre entreprise

L'ANSSI a publié le 29 septembre son analyse du piratage de la DGFiP : identifiants volés, double authentification absente, exfiltration non détectée. Voici ce que ces constats changent pour une PME, et les trois mesures à prendre en priorité.
1/10/2026