What shadow AI is
Shadow AI is the use of AI tools without approval from your own IT, usually through private accounts to services like ChatGPT, Gemini or Claude. Staff have texts drafted for them, emails summarized or quotes written up, often with real company data. The term echoes the older shadow IT, that is, software running in a business without IT knowing about it. The difference: AI arrived in everyday work within weeks, not years, and adoption is high. According to Bitkom, for the first time one in two companies in Germany deployed AI (2024 survey). Use by individuals runs ahead of the official rollout.
Data basis and methodology
This analysis draws on the representative Bitkom Research survey "Employees increasingly use shadow AI", published on October 21, 2025. It surveyed 604 companies in Germany with 20 or more employees, by telephone, in the period from calendar week 27 to 32 of 2025. For adoption context we use the Bitkom data on AI use in 2024. We bring together public surveys, we do not invent numbers and we do not interpolate values between reporting cycles.
Finding 1: Shadow AI has arrived in the mid-market
8 %
widespread (2024: 4 %)
17 %
isolated cases
17 %
suspected but not confirmed
Taken together, four in ten companies assume their staff use private AI accounts in a work context. In 8 percent of companies this is, by their own estimate, widespread, a figure that has doubled compared with 2024 (4 percent). Another 17 percent report isolated cases, and a further 17 percent suspect it without knowing for sure. The real number is likely higher, since not every private use catches the employer's eye.
Finding 2: The governance gap is the real risk
Only 23 percent of companies have set up any rules at all for the use of AI. Put differently: in more than three out of four companies, staff use AI without it being clear what is allowed and what is not. This is exactly where the risk arises. Anyone who copies a quote, a customer email or a draft contract into a private AI account hands company data, and possibly personal data, to a service the company has no data processing agreement with and whose servers are often located outside the EU. This is not a theoretical problem but an everyday action without a legal framework.
Finding 3: Why bans don't work
The obvious reaction is a ban. Several large corporations led the way in 2023, among them Samsung, JPMorgan and Amazon prohibited the use of ChatGPT within the company. But a ban only solves the problem on paper. As long as staff work faster and better with AI yet get no approved tool, they switch to private accounts. Shadow AI is therefore not a discipline problem but a supply problem. Whoever provides no sanctioned, GDPR-compliant tool gets the unsanctioned variant, just without any control.
What the data say together
Three structures. First: AI has reached the broad workforce, faster than most IT departments could react. Second: governance is lagging behind, three out of four companies have no rules, and a ban only pushes the problem into the shadows. Third: the leverage lies with what you offer. An approved, European-hosted AI tool with access to your own company knowledge takes away shadow AI's reason to exist, because then the approved variant is also the more convenient one.
What this means for companies
The practical consequence is not more control but a better offer. An internal AI assistant that accesses documented company knowledge, runs on European infrastructure and comes with a data processing agreement covers exactly the cases for which staff otherwise reach for private accounts. It is approved, it is GDPR-compliant, and it knows your own processes better than a public service does. That way AI use doesn't disappear, the shadow around it does.
Source list
- Bitkom, "Employees increasingly use shadow AI" (press release, October 21, 2025, representative, 604 companies with 20 or more employees)
- Bitkom, AI use in German companies (2024 survey)
