visibus
Back to the blog

visibus Blog

Shadow AI - your employees already use AI. The only question is whether you know it.

Lubomira Schmid

by Lubomira Schmid · June 14, 2026 · 4 min read

It starts harmlessly. A clerk in your office has a messy customer list in Excel and needs it cleaned up by noon. She pastes it into ChatGPT, "turn this into a proper table," done in two minutes. Nobody told her not to. Nobody gave her an alternative. She just wanted to get her work done.

That's not carelessness. That's the norm - and it's happening in your company right now, whether you know it or not.

The numbers - and this time from Switzerland

You don't need to look to Germany for this. The KPMG 2025 study (with the University of Melbourne, over 48,000 respondents worldwide) shows for Switzerland: 77 percent of working people use AI in a professional context - well above the global average of 58 percent. And the key finding: more than half of users admit to using AI against company policy - for example, by uploading sensitive data into freely available AI tools.

So the question isn't whether AI is being used in your company, but whether it happens under control. (In Germany, the Bitkom 2025 study paints the same picture: four in ten companies assume their employees use private AI tools on the job - while only about a quarter provide official access.)

This phenomenon has a name: Shadow AI. Like the Shadow IT of the 2010s, only faster and with far more sensitive content.

Why it happens - and why it's not a staffing problem

The temptation is to treat this as a discipline problem: "People don't follow the rules." That falls short. The tools are free, instantly available, and honestly good. They save real time. And as long as the company offers no official alternative, a vacuum forms - and a vacuum gets filled.

So Shadow AI isn't a sign of bad employees. It's a sign that the organization hasn't yet answered the question "How do we use AI safely?"

The real risk

The problem isn't that someone uses AI. The problem is that nobody sees it.

  • Data leaves the building uncontrolled. Customer names, contracts, HR data, figures - typed into a private account, often under free-tier terms where the inputs are used to improve the model.
  • No visibility. You don't know who uses which tool, what data ends up there, or what comes back. There's no place where you would even notice.
  • No accountability. If a data breach occurs, you can neither show what happened nor that you took precautions - and that's exactly what data protection law requires.

It's the leak nobody reports, because nobody notices it's a leak.

Why a ban makes the problem worse

The first reflex of many management teams: ban AI in the company. That doesn't work - it makes things worse.

A ban doesn't eliminate the usage, it drives it underground. The employee just types her list into her personal phone instead, outside the company network, without you having even a chance to steer it. You can't ban your way out of a productive tool - you only lose the last opportunity to have any influence.

The answer is an official path, not a ban

Shadow AI doesn't disappear when you ban AI. It disappears when the official path is better than the covert one.

AI use can be sorted into five stages - from uncontrolled Shadow AI to your own infrastructure. Most SMEs today sit at stage 1 or 2:

5

Your own infrastructure

Risk: Minimal

Self-hosted, on-premises, local models

Possible too - but most SMEs don't need it.

4

Managed AI platform

Risk: Low

Your own instance, privacy filter, all models, AI governance

This is where we get you. In just a few days.

3

Provider cloud with a contract

Risk: Medium

ChatGPT Business, Claude Team, Copilot

Some buy this as the solution - but it's not enough.

2

Shadow AI (no training)

Risk: High

ChatGPT Plus with opt-out - no training, but no control

1

Shadow AI (with training)

Risk: Critical

ChatGPT Free, DeepSeek - data flows into model training

Most SMEs are on level 1 or 2 today - often without realizing it.

That's exactly what we built visibus Chat for: an AI instance for your company, where your employees can use the leading models - but in one place, under your control.

  • One official access point instead of fifty private accounts. People get the tool they want anyway - legally.
  • Anonymization kicks in automatically, before a request reaches the model: names, addresses, IBANs are detected and replaced. Nobody has to remember to do it.
  • The instance sits in the EU or Switzerland, history and documents stay with you - not on private US accounts.
  • You see what's happening - one place where usage, budget, and rules come together.

The crucial point: you don't win back control by fighting AI, but by giving it a safe place.

The bottom line

Shadow AI is neither an IT problem nor a staff problem. It's a signal - that your organization needs an answer to AI before your employees give themselves one. The good news: the answer is doable, and it isn't a ban.

If you want to know what official AI access for your company looks like - write to us. A conversation, not a sales funnel.

Your free AI check

In the AI check, we look together at where controlled AI delivers the most value in your company: which tasks and departments benefit right away, which models fit, and what level of data protection you need. You walk away with a clear assessment - no strings attached.

Free and non-binding. An open conversation, no sales pressure.