"Shadow AI" describes situations where employees use AI applications inside an organisation without formal oversight or corporate policies. Generative AI tools such as ChatGPT, Gemini and Claude offer fast, convenient assistance, and their use is rapidly spreading — including in Hungary. Unchecked, however, this practice poses hidden data protection and security risks.
Concrete incidents and risks
This risk is not hypothetical: in 2023 Samsung engineers uploaded internal corporate documents and confidential source code into ChatGPT to speed workflows and for testing, resulting in data leakage. The information was stored on external servers and the company had limited ability to remove it; following the incident Samsung banned employees from using ChatGPT. Amazon took similar measures after observing AI responses that closely resembled its own confidential material.
These examples illustrate how easily business information can leave corporate control when employees use AI tools without restrictions.
The Hungarian picture and research findings
Although fewer incidents are public in Hungary, the phenomenon is present locally. Many Hungarian companies lack comprehensive AI strategies and internal rules while employees already use generative AI tools in daily work.
Sicontact Kft., the distributor of ESET products in Hungary, investigated this area. Their pioneering study — mapping the interaction of artificial intelligence, IT security and mental health in corporate environments — produced notable findings. The industry report titled "MI a baj? mesterséges intelligencia, IT-biztonság és mentális egészség" concludes that shadow AI is spreading quickly and organisations are largely unprepared to handle employee-driven AI adoption. According to the survey, 75 percent of respondents believe data is shared with AI too freely, and 63 percent think people place too much trust in AI recommendations.
Specific ways shadow AI can harm organisations
- Data leakage: business information or source code entered into chatbots can end up in external systems.
- Legal risks: data stored outside the EU can cause GDPR compliance problems.
- Faulty decisions: unverified AI outputs can be misleading and lead to poor business choices if not human-checked.
- Vulnerable code: development tasks may produce buggy or insecure code.
- Malicious applications: fake AI tools can be used to steal data or money.
The emergence of autonomous AI agents — able to perform tasks independently and potentially access sensitive systems — further complicates the situation.
How should organisations respond?
Béres Péter of Sicontact Kft. stresses that outright bans are not the solution; AI use is already widespread and cannot realistically be stopped. Instead, organisations should channel AI adoption into controlled, secure frameworks. Recommended actions include:
- Establish clear internal policies and acceptable-use rules for AI.
- Train employees on AI limitations and failure modes.
- Require human review for significant business decisions influenced by AI.
- Apply technical controls (designate approved tools, monitor network traffic and data handling).
"The aim is not to prohibit AI use but to direct it into safe boundaries. This requires clear guidelines, education and appropriate technological controls. Employee training, designation of permitted tools and continuous monitoring of network traffic and data handling are key," says Béres Péter, IT director at Sicontact Kft.
Why this is a business issue
Artificial intelligence can be a growth engine for companies in the coming years, but it also brings new types of risk. Firms that can both support innovation and protect their data will gain competitive advantage. Managing shadow AI is therefore not just an IT task but a strategic priority.



