Site icon De Luca & Partners

Shadow AI in the workplace: how to govern risks, data, and security (Agenda digitale, 29 September 2026 – Vittorio De Luca and Martina De Angeli)

The spread of artificial intelligence tools used without corporate authorization exposes businesses to risks involving personal data, confidential information, know-how, and cybersecurity. To govern Shadow AI, organizations need clear policies, prior assessments of AI tools, employee training, and secure enterprise solutions.

Generative artificial intelligence entered the workplace long before companies were truly prepared to govern it. Not through large-scale digital transformation projects or complex technological implementations, but through individual initiatives by employees and managers who, in search of greater efficiency, began using AI tools freely available online (and otherwise). It is in this context that the phenomenon of Shadow AI has emerged, namely the use of artificial intelligence applications that have not been authorized or are not controlled by the organization. In recent months, this issue has become increasingly relevant in discussions surrounding corporate digital governance.

The phenomenon closely resembles that of Shadow IT, namely the use of software and IT services outside corporate approval processes. However, Shadow AI presents distinctive characteristics that significantly amplify the associated risks. While in the past the main concern was the installation of unauthorized applications, today the risk directly involves data, corporate knowledge, and decision-making processes. Employees use generative AI chatbots to summarize documents, draft emails, analyze Excel spreadsheets, and prepare presentations, sometimes sharing sensitive business information with external platforms outside the organization’s standard control procedures.

Read the full article published on Agenda Digitale.

Exit mobile version