Shadow AI und the underestimated danger of data leakage

Sep, 17 2026
Shadow AI und the underestimated danger of data leakage

Reading and processing emails is one of the most time-consuming individual tasks in everyday office work and, in many organizations, takes up a significant share of employees’ working time. To increase efficiency and, above all, save time, employees often use AI models with good intentions to summarize emails and prepare responses.

 

At this point, users are often unaware that this is exactly where Shadow AI can emerge. If complete email threads are copied into an AI tool because the model needs context, there is a significant risk that sensitive personal data or trade secrets may be disclosed to third parties without authorization - in this case, to the providers of the AI models.

 

Once a user has transferred data to an AI model, they often have little or no control over how that data is processed, logged, stored, or deleted. This can make it difficult for the employee or the company to comply with its obligations toward the data subject, including transparency, purpose limitation, and deletion requirements. Depending on the model and configuration, users may also have only limited control over whether submitted data is used for training purposes. Requests for information or deletion may therefore become difficult to fulfill.

 

However, the use of AI should by no means be demonized. On the contrary, AI should be used in modern companies to improve efficiency. What is needed is a clear framework.

 

Web-based external AI services should only be used when the data being uploaded has been properly anonymized and no identifiable individuals remain, and when the AI tools are configured so that submitted content is not used for training purposes.

 

Only enterprise AI tools approved by company management should be used instead of private or free consumer versions. In addition, data processing agreements should be concluded with the AI provider where required. Depending on the use case, local AI models may also be preferable, as processing can take place within the company’s own IT infrastructure and sensitive data does not need to be transferred to external providers.

 

From a technical perspective, Data Loss Prevention solutions can help prevent sensitive information such as email addresses, passwords, or confidential contractual content from being uploaded to an AI model in the first place.

 

Employees also need to develop a strong awareness of how AI tools should be used. It is particularly important to understand that entire mailboxes must not simply be connected to third-party services via OAuth for automated reading, nor should complete email accounts or calendar data be transferred to external providers without prior approval.

 

Without authorization from company management and without a prior data protection assessment covering issues such as purpose limitation, international data transfers, technical safeguards, transparency, and deletion, such data transfers may be unlawful.

Shadow AI becomes a risk when employees unknowingly disclose personal or confidential data to external AI services.

Conclusion: Annual employee training and practical example scenarios can help raise awareness of the responsible use of AI tools. In many cases, it is simply a lack of knowledge that leads employees to disclose data to third parties without an appropriate legal basis. A company-wide AI policy can provide employees with clear guidance on which AI tools may be used, which categories of data - classified according to risk, with personal data treated as high risk - may be transferred to which tools, and how AI-generated content should be handled from a legal and organizational perspective, including any applicable transparency or labeling requirements.

Tags

Recent articles

starsstars
line
line