Shadow AI

Should you ban ChatGPT in your organisation?

Ban it, let it happen or govern it: the three options have very different consequences. What shadow AI is, what labour law allows (with France as an example), and why most public guidance points towards governance.

Published on Updated on 6 min readBy the Tacite-IA editorial team

Contents
  1. Shadow AI: what is it?
  2. Use is already widespread
  3. Can you ban ChatGPT? What the law says
  4. What a personal account changes
  5. Why a ban on its own rarely works
  6. Ban, allow or govern
  7. Governing AI in practice
  8. Frequently asked questions
  9. Sources

Faced with the risk of data leaks, some organisations are tempted by the simplest solution: banning ChatGPT and other AI assistants. Others let things happen, for lack of time. Between the two, a third way is gaining ground: governing use. This article looks at shadow AI, at what labour law allows (taking French law as an example), and at the practical consequences of each option.

Shadow AI: what is it?

“Shadow AI” refers to employees using AI tools without the organisation’s approval or visibility. The term extends “shadow IT”, which refers to software used outside the framework set by the IT department. Typical examples: a free ChatGPT account opened with a personal email address, a browser extension that summarises web pages, a coding assistant installed without asking.

The problem is not the tool but the lack of a framework: no contract with the vendor, no shared settings, no rule on data. Yet the organisation remains responsible for the personal data it processes (GDPR, Article 24)7, including when an employee pastes it into an unauthorised service. France’s data protection authority, the CNIL, makes the point: the user organisation is the one held responsible if its staff misuse AI.3

Use is already widespread

Personal use of AI tools at work is well documented. In its 2024 Work Trend Index, carried out with LinkedIn among 31,000 knowledge workers in 31 markets, Microsoft reports that 75% of them use generative AI and that 78% of AI users bring their own tools to work, a figure that rises to 80% in small and medium-sized businesses.1

75%
of knowledge workers use generative AI
Survey carried out in 31 markets.
78%
of AI users bring their own tools
A trend known as “BYOAI”.
80%
in small and medium-sized businesses
Share of users who bring their own tools.
Microsoft and LinkedIn, Work Trend Index 2024, survey of 31,000 people (source 1). Global data, not specific to any one country.

In other words, in most organisations, the question is not “should we open the door?” but “what do we do about what is already coming in through the window?”

Can you ban ChatGPT? What the law says

Under French law, yes: an employer can restrict or ban the use of tools on company equipment and for company tasks. But two rules of the French Labour Code apply. First, any restriction on employees’ rights and freedoms must be justified by the nature of the task and proportionate to the aim pursued (Article L1121-1).4 Second, for a breach to be sanctioned, the rule must in principle appear in the règlement intérieur (the company’s internal rules) or an annex to it, adopted after obtaining the opinion of the CSE, the French staff representative body (Articles L1321-1 and L1321-4).5,6 Other countries have their own rules on employee consultation and workplace policies; check the labour law that applies to you.

Bans have happened. In May 2023, Samsung temporarily restricted the use of generative AI tools on company devices, following internal incidents in April.2

What a personal account changes

Shadow AI almost always goes through consumer accounts, whose rules differ from those of business plans. At OpenAI, content submitted to services for individuals may be used to improve the models14, unless the user turns off the “Improve the model for everyone” setting15. Google states that human reviewers read some Gemini app conversations and asks users not to enter confidential information.16 Anthropic has asked users of its consumer Claude plans to choose whether they allow their data to be used for training, with retention extended to five years if they agree.17

These rules are public and every user can adjust their settings. But the organisation cannot see these accounts, cannot enforce the right settings and has not signed any processing agreement with the vendor. It is this lack of control, more than the tool itself, that makes shadow AI a compliance issue.

Why a ban on its own rarely works

A ban on work computers does not prevent use on a personal phone or at home. The text then goes through an even less visible channel: a personal account, outside any contract, on a device the organisation does not manage.

The message is sent as it is: the name, IBAN and health information reach the vendor, which processes and retains them under the rules of the plan being used.

Whether it goes through a company computer or a personal device, text pasted as it is reaches the vendor. A local check is only possible on computers managed by the organisation. Fictitious data.

A ban also deprives teams of tools many of them already use, and makes training harder: it is difficult to teach good habits for a tool that is officially absent. France’s CNIL, for its part, recommends governing use through a policy that distinguishes permitted and prohibited uses.3

Ban, allow or govern

The table below summarises the usual consequences of each option. It is an analytical grid, not a quantified measurement.

CriterionBanAllowGovern
Teams save time on routine tasksNoYesYes
Use is visible to the organisationNoNoYes
Data goes through accounts under contractPartlyNoYes
Employees know which data not to enterPartlyNoYes
Low risk of workarounds (personal accounts and devices)NoPartlyYes
No set-up costPartlyYesNo
Analytical grid drawn up by the editorial team on the basis of the recommendations of the French CNIL (source 3). A qualitative assessment, which depends on each organisation.

Governing use has a cost: business subscriptions, drafting a policy, training. But it is the only option that combines productivity, visibility and a contractual framework. The business plans of the main vendors also provide that customer data is not used for training by default, according to OpenAI, Microsoft, Anthropic and Google.10,11,12,13

Governing AI in practice

  1. Take stock. Ask teams which tools they use and why, without any intention of sanctioning them. This is the basis of the list of approved tools.
  2. Provide an official alternative. A business account, with a data processing agreement, makes personal accounts less attractive.
  3. Write the rule down. A short policy, focused on prohibited data and anonymisation; in France, it is annexed to the règlement intérieur after obtaining the opinion of the CSE.3,6
  4. Train. The European AI Act requires organisations to take measures to support AI literacy among their staff (Article 4, in its version amended in 2026).8,9
  5. Measure, then adjust. A tool in audit mode shows which services are used and what data is sent to them, before you decide to block anything. Tacite-IA offers this mode, followed by alerts and on-device anonymisation, in Chrome, Edge and coding assistants. It does not cover desktop apps such as the ChatGPT desktop app.

One last point argues in favour of governance: it turns a ban that people put up with into a rule they understand. An employee who knows why a customer’s name or a payslip must not go into an assistant, and who has an approved tool for everything else, has far fewer reasons to look for a workaround.

Frequently asked questions

What is the difference between shadow AI and shadow IT?

Shadow IT refers to software and services used without the IT department’s approval. Shadow AI is a specific form of it, applied to artificial intelligence tools: chat assistants, browser extensions and coding assistants used with personal accounts.

What is shadow AI?

It is the use of artificial intelligence tools by employees without the organisation’s approval or visibility, for example a personal ChatGPT account used for work tasks. The organisation nevertheless remains responsible for the personal data entered into it.

Can an employer ban ChatGPT?

Under French law, yes, provided the restriction is justified by the nature of the task and proportionate to the aim pursued (Article L1121-1 of the French Labour Code). For a breach to be sanctioned, the rule must in principle appear in the règlement intérieur (the company’s internal rules) or an annex to it, adopted after obtaining the opinion of the CSE, the staff representative body. Other countries have their own rules; check the labour law that applies to you.

Is banning ChatGPT enough to protect data?

Rarely. A ban on work computers does not prevent use on a personal phone or computer, out of sight. France’s data protection authority, the CNIL, recommends governing use instead, through a policy that distinguishes permitted and prohibited uses.

How many employees use their own AI tools?

According to the 2024 Work Trend Index by Microsoft and LinkedIn, based on 31,000 knowledge workers in 31 markets, 78% of AI users bring their own tools to work, rising to 80% in small and medium-sized businesses.

Sources

  1. AI at Work Is Here. Now Comes the Hard Part (Work Trend Index 2024). Microsoft and LinkedIn, May 2024. Accessed on 5 October 2026.
  2. Samsung bans use of generative AI tools like ChatGPT after April internal data leak. TechCrunch, 2 May 2023. Accessed on 5 October 2026.
  3. Les questions-réponses de la CNIL sur l’utilisation d’un système d’IA générative. CNIL (French data protection authority), 18 July 2024. In French. Accessed on 5 October 2026.
  4. French Labour Code (Code du travail), Article L1121-1 (justified and proportionate restrictions). Légifrance (official French legal database). In French. Accessed on 5 October 2026.
  5. French Labour Code (Code du travail), Article L1321-1 (content of the règlement intérieur, the internal rules). Légifrance (official French legal database). In French. Accessed on 5 October 2026.
  6. French Labour Code (Code du travail), Article L1321-4 (opinion of the CSE, publication, labour inspectorate). Légifrance (official French legal database). In French. Accessed on 5 October 2026.
  7. Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation). EUR-Lex. Accessed on 5 October 2026.
  8. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). EUR-Lex. Accessed on 5 October 2026.
  9. Regulation (EU) 2026/1744 of 8 July 2026 (digital omnibus on AI). EUR-Lex. Accessed on 5 October 2026.
  10. Enterprise privacy at OpenAI. OpenAI, page updated on 8 January 2026. Accessed on 5 October 2026.
  11. Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat. Microsoft Learn. Accessed on 5 October 2026.
  12. Is my data used for model training?. Anthropic Privacy Center. Accessed on 5 October 2026.
  13. Generative AI in Google Workspace Privacy Hub. Google Workspace. Accessed on 5 October 2026.
  14. How OpenAI handles data in consumer services. OpenAI Help Center. Accessed on 5 October 2026.
  15. Data controls in ChatGPT. OpenAI Help Center. Accessed on 5 October 2026.
  16. Gemini Apps Privacy Hub. Google. Accessed on 5 October 2026.
  17. Updates to Consumer Terms and Privacy Policy. Anthropic, 28 August 2025. Accessed on 5 October 2026.
One measure among others

Govern AI use without slowing your teams down

Tacite-IA detects sensitive data in messages and files before they are sent to AI assistants in Chrome and Edge, and in coding assistants (Claude Code, Cursor, Windsurf, Codex, Gemini CLI, Copilot CLI). Analysis runs 100% on the device, with no AI, and comes with an admin console and an audit mode. Desktop apps (the ChatGPT desktop app, the Chat tab in Claude Desktop, Copilot in Windows) are not covered.

€6 excl. VAT per user per month billed annually, €8 excl. VAT billed monthly. 3-month trial.

Further reading