Safety

Shadow AI in companies: hidden data and security risks from unsanctioned employee use

Shadow AI — employees’ unsupervised use of generative AI tools like ChatGPT, Gemini or Claude — is spreading rapidly in Hungary and poses data protection and security risks.

Shadow AI in companies: hidden data and security risks from unsanctioned employee use

“Shadow AI” refers to the unsanctioned use of generative artificial intelligence tools by employees within an organization — for example ChatGPT, Gemini or Claude. These services can speed up everyday work and are therefore often adopted by staff independently. The phenomenon is spreading quickly in Hungary, while many companies lack corresponding internal rules.

Serious but often invisible risks

One of the main dangers of shadow AI is that organizations lose visibility into which tools employees use and what data they share with them. Béres Péter, IT director at Sicontact Kft., warns: “One of the biggest dangers of shadow AI is that the organization has no visibility into when and which tools employees use, and what data they share with them. As a result, business-critical information can fall outside the company’s control.”

This risk is not merely theoretical. In 2023 engineers at Samsung uploaded internal corporate documents and confidential source code into ChatGPT to speed up workflows and for testing, which resulted in data leakage. Because those data were stored on external servers, the company had little ability to retrieve or have the sensitive content removed; Samsung responded by banning employee use of ChatGPT. Amazon also implemented restrictions after detecting AI-generated outputs that resembled the company’s confidential data.

Findings from the Sicontact / ESET study

Sicontact Kft., the Hungarian distributor of ESET products, conducted a pioneering study that connects artificial intelligence, IT security and mental health in the workplace. The industry report titled “MI a baj? mesterséges intelligencia, IT-biztonság és mentális egészség,” available for free download, shows that shadow AI is spreading quickly while many firms are unprepared to manage employee-driven AI adoption.

According to the survey, 75% of respondents believe that people share data with AI too carelessly, and 63% think that people place too much trust in AI recommendations. Those figures highlight the business risk posed by uncontrolled AI use.

Concrete risks posed by shadow AI

The report and industry experience list several specific threats:

  • Data leakage: business information and internal documents can end up in external systems, causing loss of control.
  • Legal risks: data may be stored outside the EU, raising GDPR compliance issues.
  • Faulty decisions: unchecked AI-generated recommendations can be misleading and lead to poor business choices without human oversight.
  • Vulnerable code: code produced by AI during development tasks may include bugs or security flaws.
  • Malicious applications: the number of fake or harmful AI tools aimed at stealing data or money is increasing.

The emergence of autonomous AI agents, capable of executing tasks independently and possibly accessing sensitive systems, complicates the situation further.

Don’t ban AI — control it

Experts argue that shadow AI should not be addressed by outright bans but by regulated, controlled use. Since AI is already widely used in corporate environments, the key question is whether organizations will manage it through rules, training and technological controls.

As Béres Péter puts it: “The aim is not to ban the use of AI, but to put it into safe frameworks. This requires clear policies, education and appropriate technological controls. Training employees, designating approved tools, and continuous monitoring of network traffic and data handling are crucial.”

Practical measures include:

  • Creating a corporate AI policy that defines approved tools and forbids sharing certain types of data.
  • Regular training on AI limitations and safe use.
  • Technical safeguards — such as network filtering and data loss prevention (DLP) — to protect sensitive information.
  • Human approval steps for critical decisions.

Why this matters long term

Artificial intelligence can be a growth driver for businesses in the coming years, but it also introduces new organizational risks. Companies that support innovation while ensuring appropriate data protection controls will be better positioned competitively. Managing shadow AI is therefore not only a security task but a strategic priority for digital workplaces.