Using AI safely rather than promoting ‘shadow AI’

EU AI Act & AI Empowerment

Paid enterprise AI such as Copilot remains blocked, whilst personal AI is used. This gives rise to ‘shadow AI’, which poses a genuine data protection risk.

Generative AI is already being used in many companies, associations and social organisations. Often regardless of whether it has been officially approved.

Employees use AI, for example, for spelling, translations, email drafts, summaries, research and ideas.

The benefit is obvious. A blanket ban therefore often fails to prevent its use. Instead, uncontrolled solutions emerge via private ChatGPT or Gemini accounts, private smartphones, personal email addresses or freely accessible translation services.

The real risk

With private AI accounts, the organisation loses control over entered data, contractual conditions, data protection, storage, deletion, traceability and access by former employees.

Translation services such as DeepL are also critical if internal, confidential or personal texts are entered without an appropriate company contract.

The problem is therefore rarely the use of AI itself. The problem is unregulated AI use without approval, without training and without traceable responsibility.

The better way

Many organisations do not need a large AI strategy at first. They need a secure basis:

  1. approved tools

  2. clear rules for company data

  3. understandable usage guidelines

  4. trained employees

  5. documented responsibilities

  6. regular review of new applications

Microsoft 365 Copilot Chat can be a useful starting point for many Microsoft 365 environments. When used with a business account, the protection mechanisms of the Microsoft 365 environment apply. Nevertheless, Copilot also does not replace clear rules, data classification or professional review of results.

GDPR and the EU AI Act

The GDPR also applies to AI use. Personal, confidential and business-critical data may only be processed within the permitted framework.

The EU AI Act also requires a responsible approach to AI. A central element is the AI literacy of the people who use AI systems. They must understand which tools are allowed, which data may be entered, where AI can make mistakes and when human review is required.

What matters is: this is not about an arbitrary certificate of attendance. For normal AI use, there is no generally prescribed “EU AI Act compliance certificate”. What is useful instead is traceable internal documentation of the measures actually taken.

Evidence of responsible AI use

I support organisations in building such evidence pragmatically.

This typically includes:

  1. inventory of the AI systems in use

  2. simple risk assessment of use cases

  3. clarification of permitted and prohibited uses

  4. short AI usage guideline

  5. training on safe AI use

  6. documentation of content, participants and open measures

  7. assignment of responsibilities

  8. recommendations for next steps

The result is not an official certification and not a blanket legal guarantee. It is a robust organisational record: the AI systems in use are known, risks have been assessed, employees have been prepared and rules are documented.

Recommendation

The better strategy is:

approve a secure company solution, set clear rules, enable employees and limit private shadow AI.

This creates productivity gains while improving control over data protection, quality and information security.

If you want to use AI more safely in your organisation and address the requirements around GDPR and the EU AI Act pragmatically, I support you with inventory, training, usage guidelines and evidence of responsible AI use.

CONVERSATION

Where does your organisation stand today?

A conversation is low-pressure and often clarifying in itself. We look at your situation together and see whether a collaboration makes sense.