Shadow AI is the AI equivalent of Shadow IT: employees use AI tools such as ChatGPT, DeepL or Claude without the knowledge or approval of the IT department. According to a Salesforce study, more than half of employees who use generative AI do so without official approval. Only a minority of organisations have a formal AI policy.
The result: company data flows uncontrolled to external AI services, GDPR violations occur unwittingly and the IT department has no visibility of the risks. Yet banning AI tools has proven counterproductive. This article explains why enablement is the better approach — and how pseudonymization as a technical protection layer enables safe AI usage.