Shadow AI: your teams already use AI, take back control without slowing them down
Updated: 6 days ago
In most of the SMEs we meet, the question is no longer "will we use AI?" but "who is already using it, for what, and with which data?". The answer is often uncomfortable: many people, for many things, and nobody really knows. This is what is known as shadow AI, and it is today one of the most concrete governance topics for an SME leadership team.
A massive, and largely invisible, phenomenon
According to the Work Trend Index published by Microsoft and LinkedIn in May 2024, 75% of knowledge workers already use generative AI at work, and 78% of those users bring their own tools, without the company having provided or approved them. More telling still: 52% are reluctant to admit they use it for their most important tasks, for fear of looking replaceable.
What stands out in these figures is not adoption. It is the gap between real usage and what management knows about it. In a 40-person SME, this means that around thirty employees are probably pasting excerpts of emails, contracts or spreadsheets into a consumer assistant every week, with no rule in place.
We do not see this as a failing of the teams. They are doing what intelligent people do when faced with a useful tool: saving time. The problem lies elsewhere, in the absence of a framework.
The concrete risks, without drama
Shadow AI is not a disaster scenario. It is an accumulation of small, ordinary risks, three of which we consider priorities for a Swiss SME.
Customer and personal data. The revised Swiss Federal Act on Data Protection (nFADP), in force since 1 September 2023, requires you to know where the personal data you process ends up. An employee who pastes a customer list into a tool whose terms allow training on submitted data creates, unintentionally, a transfer you have neither documented nor authorised.
Trade secrets. The best-known example remains that of Samsung engineers who, in spring 2023, submitted confidential source code to ChatGPT to fix it. Nothing malicious, just poorly framed efficiency. In an SME, the equivalent is a strategic quote, a pricing formula or a supplier list.
Quality and accountability. A reply sent to a customer, drafted by an assistant and never proofread, commits your company. If nobody knows which content comes out of an AI tool, nobody can define an appropriate level of review.
There is also a calendar point: the European AI Act entered into force on 1 August 2024. A Swiss SME is not directly subject to it, but its European clients and partners will gradually start asking questions about its practices. Better to have an answer ready.
Banning does not work, and it is expensive
The instinctive reaction of some leadership teams is to block the tools. We advise against it, for two reasons.
The first is practical: a block is bypassed in thirty seconds with a personal phone. You do not remove the usage, you only make it more invisible, and therefore riskier.
The second is economic. The same Work Trend Index notes that AI users report saving time on repetitive tasks and focusing more on higher-value work. An SME that bans AI deprives its teams of a productivity gain that its competitors will capture. To see where your own organisation stands, our AI Barometer gives a first diagnosis in a few minutes.
Taking back control in four steps
Here is the approach we apply with our clients. It takes a few weeks and requires no heavy software investment.
Map real usage. An anonymous ten-question survey, then three or four interviews per team. The goal is not to punish but to understand: which tools, which tasks, which data. In a 25-person Geneva fiduciary firm we supported this year, we identified seven different tools, two of which management was entirely unaware of.
Classify data into three levels. Public (can go into any tool), internal (only into a tool approved by the company), confidential (never into an external AI tool, except under a specific contract). Three levels are enough; beyond that, nobody applies the rule.
Provide an approved alternative. A business licence for a general-purpose assistant, with contractual terms that exclude training on your data and compliant hosting, costs a few dozen francs per user per month. This is the most effective lever: teams switch on their own as soon as the authorised tool is as good as the forbidden one.
Write a one-page charter, and keep it alive. Not a twenty-page legal document: one page, with the three data levels, the authorised tools, the review rule before anything is sent to a client, and a named contact for questions. Reviewed every six months.
In the fiduciary firm mentioned above, these four steps took six weeks. The result is not only a controlled risk: employees shared their best practices with each other, and two of them became structured use cases (preparing payment reminder letters, summarising client exchanges before meetings) that now save around three hours per week for each employee concerned.
What we take away
Shadow AI is the symptom of good news: your teams want to work better. The question for an SME leadership team is not how to prevent it, but how to turn scattered, risky usage into shared, safe practice.
Three convictions guide our approach: map before you regulate, provide an alternative before you ban, and keep the rules simple enough to be applied. If you would like to review AI usage in your organisation, let's talk.





Comments