Faced with the risk of data leaks, some organisations are tempted by the simplest solution: banning ChatGPT and other AI assistants. Others let things happen, for lack of time. Between the two, a third way is gaining ground: governing use. This article looks at shadow AI, at what labour law allows (taking French law as an example), and at the practical consequences of each option.
Shadow AI: what is it?
“Shadow AI” refers to employees using AI tools without the organisation’s approval or visibility. The term extends “shadow IT”, which refers to software used outside the framework set by the IT department. Typical examples: a free ChatGPT account opened with a personal email address, a browser extension that summarises web pages, a coding assistant installed without asking.
The problem is not the tool but the lack of a framework: no contract with the vendor, no shared settings, no rule on data. Yet the organisation remains responsible for the personal data it processes (GDPR, Article 24)7, including when an employee pastes it into an unauthorised service. France’s data protection authority, the CNIL, makes the point: the user organisation is the one held responsible if its staff misuse AI.3
Use is already widespread
Personal use of AI tools at work is well documented. In its 2024 Work Trend Index, carried out with LinkedIn among 31,000 knowledge workers in 31 markets, Microsoft reports that 75% of them use generative AI and that 78% of AI users bring their own tools to work, a figure that rises to 80% in small and medium-sized businesses.1
In other words, in most organisations, the question is not “should we open the door?” but “what do we do about what is already coming in through the window?”
Can you ban ChatGPT? What the law says
Under French law, yes: an employer can restrict or ban the use of tools on company equipment and for company tasks. But two rules of the French Labour Code apply. First, any restriction on employees’ rights and freedoms must be justified by the nature of the task and proportionate to the aim pursued (Article L1121-1).4 Second, for a breach to be sanctioned, the rule must in principle appear in the règlement intérieur (the company’s internal rules) or an annex to it, adopted after obtaining the opinion of the CSE, the French staff representative body (Articles L1321-1 and L1321-4).5,6 Other countries have their own rules on employee consultation and workplace policies; check the labour law that applies to you.
Bans have happened. In May 2023, Samsung temporarily restricted the use of generative AI tools on company devices, following internal incidents in April.2
What a personal account changes
Shadow AI almost always goes through consumer accounts, whose rules differ from those of business plans. At OpenAI, content submitted to services for individuals may be used to improve the models14, unless the user turns off the “Improve the model for everyone” setting15. Google states that human reviewers read some Gemini app conversations and asks users not to enter confidential information.16 Anthropic has asked users of its consumer Claude plans to choose whether they allow their data to be used for training, with retention extended to five years if they agree.17
These rules are public and every user can adjust their settings. But the organisation cannot see these accounts, cannot enforce the right settings and has not signed any processing agreement with the vendor. It is this lack of control, more than the tool itself, that makes shadow AI a compliance issue.
Why a ban on its own rarely works
A ban on work computers does not prevent use on a personal phone or at home. The text then goes through an even less visible channel: a personal account, outside any contract, on a device the organisation does not manage.
The message is sent as it is: the name, IBAN and health information reach the vendor, which processes and retains them under the rules of the plan being used.
A ban also deprives teams of tools many of them already use, and makes training harder: it is difficult to teach good habits for a tool that is officially absent. France’s CNIL, for its part, recommends governing use through a policy that distinguishes permitted and prohibited uses.3
Ban, allow or govern
The table below summarises the usual consequences of each option. It is an analytical grid, not a quantified measurement.
| Criterion | Ban | Allow | Govern |
|---|---|---|---|
| Teams save time on routine tasks | No | Yes | Yes |
| Use is visible to the organisation | No | No | Yes |
| Data goes through accounts under contract | Partly | No | Yes |
| Employees know which data not to enter | Partly | No | Yes |
| Low risk of workarounds (personal accounts and devices) | No | Partly | Yes |
| No set-up cost | Partly | Yes | No |
Governing use has a cost: business subscriptions, drafting a policy, training. But it is the only option that combines productivity, visibility and a contractual framework. The business plans of the main vendors also provide that customer data is not used for training by default, according to OpenAI, Microsoft, Anthropic and Google.10,11,12,13
Governing AI in practice
- Take stock. Ask teams which tools they use and why, without any intention of sanctioning them. This is the basis of the list of approved tools.
- Provide an official alternative. A business account, with a data processing agreement, makes personal accounts less attractive.
- Write the rule down. A short policy, focused on prohibited data and anonymisation; in France, it is annexed to the règlement intérieur after obtaining the opinion of the CSE.3,6
- Train. The European AI Act requires organisations to take measures to support AI literacy among their staff (Article 4, in its version amended in 2026).8,9
- Measure, then adjust. A tool in audit mode shows which services are used and what data is sent to them, before you decide to block anything. Tacite-IA offers this mode, followed by alerts and on-device anonymisation, in Chrome, Edge and coding assistants. It does not cover desktop apps such as the ChatGPT desktop app.
One last point argues in favour of governance: it turns a ban that people put up with into a rule they understand. An employee who knows why a customer’s name or a payslip must not go into an assistant, and who has an approved tool for everything else, has far fewer reasons to look for a workaround.
Frequently asked questions
What is the difference between shadow AI and shadow IT?
Shadow IT refers to software and services used without the IT department’s approval. Shadow AI is a specific form of it, applied to artificial intelligence tools: chat assistants, browser extensions and coding assistants used with personal accounts.
What is shadow AI?
It is the use of artificial intelligence tools by employees without the organisation’s approval or visibility, for example a personal ChatGPT account used for work tasks. The organisation nevertheless remains responsible for the personal data entered into it.
Can an employer ban ChatGPT?
Under French law, yes, provided the restriction is justified by the nature of the task and proportionate to the aim pursued (Article L1121-1 of the French Labour Code). For a breach to be sanctioned, the rule must in principle appear in the règlement intérieur (the company’s internal rules) or an annex to it, adopted after obtaining the opinion of the CSE, the staff representative body. Other countries have their own rules; check the labour law that applies to you.
Is banning ChatGPT enough to protect data?
Rarely. A ban on work computers does not prevent use on a personal phone or computer, out of sight. France’s data protection authority, the CNIL, recommends governing use instead, through a policy that distinguishes permitted and prohibited uses.
How many employees use their own AI tools?
According to the 2024 Work Trend Index by Microsoft and LinkedIn, based on 31,000 knowledge workers in 31 markets, 78% of AI users bring their own tools to work, rising to 80% in small and medium-sized businesses.
Sources
- AI at Work Is Here. Now Comes the Hard Part (Work Trend Index 2024). Microsoft and LinkedIn, May 2024. Accessed on 5 October 2026.
- Samsung bans use of generative AI tools like ChatGPT after April internal data leak. TechCrunch, 2 May 2023. Accessed on 5 October 2026.
- Les questions-réponses de la CNIL sur l’utilisation d’un système d’IA générative. CNIL (French data protection authority), 18 July 2024. In French. Accessed on 5 October 2026.
- French Labour Code (Code du travail), Article L1121-1 (justified and proportionate restrictions). Légifrance (official French legal database). In French. Accessed on 5 October 2026.
- French Labour Code (Code du travail), Article L1321-1 (content of the règlement intérieur, the internal rules). Légifrance (official French legal database). In French. Accessed on 5 October 2026.
- French Labour Code (Code du travail), Article L1321-4 (opinion of the CSE, publication, labour inspectorate). Légifrance (official French legal database). In French. Accessed on 5 October 2026.
- Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation). EUR-Lex. Accessed on 5 October 2026.
- Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). EUR-Lex. Accessed on 5 October 2026.
- Regulation (EU) 2026/1744 of 8 July 2026 (digital omnibus on AI). EUR-Lex. Accessed on 5 October 2026.
- Enterprise privacy at OpenAI. OpenAI, page updated on 8 January 2026. Accessed on 5 October 2026.
- Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat. Microsoft Learn. Accessed on 5 October 2026.
- Is my data used for model training?. Anthropic Privacy Center. Accessed on 5 October 2026.
- Generative AI in Google Workspace Privacy Hub. Google Workspace. Accessed on 5 October 2026.
- How OpenAI handles data in consumer services. OpenAI Help Center. Accessed on 5 October 2026.
- Data controls in ChatGPT. OpenAI Help Center. Accessed on 5 October 2026.
- Gemini Apps Privacy Hub. Google. Accessed on 5 October 2026.
- Updates to Consumer Terms and Privacy Policy. Anthropic, 28 August 2025. Accessed on 5 October 2026.
ChatGPT is a trademark of OpenAI, Copilot of Microsoft, Claude of Anthropic, Gemini of Google. Tacite-IA is not affiliated with any of these vendors. This article is for information only and does not constitute legal advice.