Reading and processing emails is one of the most time-consuming individual tasks in everyday office work and, in many organizations, takes up a significant share of employees’ working time. To increase efficiency and, above all, save time, employees often use AI models with good intentions to summarize emails and prepare responses.
At this point, users are often unaware that this is exactly where Shadow AI can emerge. If complete email threads are copied into an AI tool because the model needs context, there is a significant risk that sensitive personal data or trade secrets may be disclosed to third parties without authorization - in this case, to the providers of the AI models.
Once a user has transferred data to an AI model, they often have little or no control over how that data is processed, logged, stored, or deleted. This can make it difficult for the employee or the company to comply with its obligations toward the data subject, including transparency, purpose limitation, and deletion requirements. Depending on the model and configuration, users may also have only limited control over whether submitted data is used for training purposes. Requests for information or deletion may therefore become difficult to fulfill.
However, the use of AI should by no means be demonized. On the contrary, AI should be used in modern companies to improve efficiency. What is needed is a clear framework.
Web-based external AI services should only be used when the data being uploaded has been properly anonymized and no identifiable individuals remain, and when the AI tools are configured so that submitted content is not used for training purposes.
Only enterprise AI tools approved by company management should be used instead of private or free consumer versions. In addition, data processing agreements should be concluded with the AI provider where required. Depending on the use case, local AI models may also be preferable, as processing can take place within the company’s own IT infrastructure and sensitive data does not need to be transferred to external providers.
From a technical perspective, Data Loss Prevention solutions can help prevent sensitive information such as email addresses, passwords, or confidential contractual content from being uploaded to an AI model in the first place.
Employees also need to develop a strong awareness of how AI tools should be used. It is particularly important to understand that entire mailboxes must not simply be connected to third-party services via OAuth for automated reading, nor should complete email accounts or calendar data be transferred to external providers without prior approval.
Without authorization from company management and without a prior data protection assessment covering issues such as purpose limitation, international data transfers, technical safeguards, transparency, and deletion, such data transfers may be unlawful.