visibus Blog
Shadow AI - your employees already use AI. The only question is whether you know it.

by Lubomira Schmid · June 14, 2026 · 4 min read
It starts harmlessly. A clerk in your office has a messy customer list in Excel and needs it cleaned up by noon. She pastes it into ChatGPT, "turn this into a proper table," done in two minutes. Nobody told her not to. Nobody gave her an alternative. She just wanted to get her work done.
That's not carelessness. That's the norm - and it's happening in your company right now, whether you know it or not.
The numbers - and this time from Switzerland
You don't need to look to Germany for this. The KPMG 2025 study (with the University of Melbourne, over 48,000 respondents worldwide) shows for Switzerland: 77 percent of working people use AI in a professional context - well above the global average of 58 percent. And the key finding: more than half of users admit to using AI against company policy - for example, by uploading sensitive data into freely available AI tools.
So the question isn't whether AI is being used in your company, but whether it happens under control. (In Germany, the Bitkom 2025 study paints the same picture: four in ten companies assume their employees use private AI tools on the job - while only about a quarter provide official access.)
This phenomenon has a name: Shadow AI. Like the Shadow IT of the 2010s, only faster and with far more sensitive content.
Why it happens - and why it's not a staffing problem
The temptation is to treat this as a discipline problem: "People don't follow the rules." That falls short. The tools are free, instantly available, and honestly good. They save real time. And as long as the company offers no official alternative, a vacuum forms - and a vacuum gets filled.
So Shadow AI isn't a sign of bad employees. It's a sign that the organization hasn't yet answered the question "How do we use AI safely?"
The real risk
The problem isn't that someone uses AI. The problem is that nobody sees it.
- Data leaves the building uncontrolled. Customer names, contracts, HR data, figures - typed into a private account, often under free-tier terms where the inputs are used to improve the model.
- No visibility. You don't know who uses which tool, what data ends up there, or what comes back. There's no place where you would even notice.
- No accountability. If a data breach occurs, you can neither show what happened nor that you took precautions - and that's exactly what data protection law requires.
It's the leak nobody reports, because nobody notices it's a leak.
Why a ban makes the problem worse
The first reflex of many management teams: ban AI in the company. That doesn't work - it makes things worse.
A ban doesn't eliminate the usage, it drives it underground. The employee just types her list into her personal phone instead, outside the company network, without you having even a chance to steer it. You can't ban your way out of a productive tool - you only lose the last opportunity to have any influence.
The answer is an official path, not a ban
Shadow AI doesn't disappear when you ban AI. It disappears when the official path is better than the covert one.
AI use can be sorted into five stages - from uncontrolled Shadow AI to your own infrastructure. Most SMEs today sit at stage 1 or 2:
Your own infrastructure
Self-hosted, on-premises, local models
Your own infrastructure
Self-hosted, on-premises, local models
Possible too - but most SMEs don't need it.
Managed AI platform
Your own instance, privacy filter, all models, AI governance
Managed AI platform
Your own instance, privacy filter, all models, AI governance
This is where we get you. In just a few days.
Provider cloud with a contract
ChatGPT Business, Claude Team, Copilot
Provider cloud with a contract
ChatGPT Business, Claude Team, Copilot
Some buy this as the solution - but it's not enough.
Shadow AI (no training)
ChatGPT Plus with opt-out - no training, but no control
Shadow AI (no training)
ChatGPT Plus with opt-out - no training, but no control
Shadow AI (with training)
ChatGPT Free, DeepSeek - data flows into model training
Shadow AI (with training)
ChatGPT Free, DeepSeek - data flows into model training
Most SMEs are on level 1 or 2 today - often without realizing it.
That's exactly what we built visibus Chat for: an AI instance for your company, where your employees can use the leading models - but in one place, under your control.
- One official access point instead of fifty private accounts. People get the tool they want anyway - legally.
- Anonymization kicks in automatically, before a request reaches the model: names, addresses, IBANs are detected and replaced. Nobody has to remember to do it.
- The instance sits in the EU or Switzerland, history and documents stay with you - not on private US accounts.
- You see what's happening - one place where usage, budget, and rules come together.
The crucial point: you don't win back control by fighting AI, but by giving it a safe place.
The bottom line
Shadow AI is neither an IT problem nor a staff problem. It's a signal - that your organization needs an answer to AI before your employees give themselves one. The good news: the answer is doable, and it isn't a ban.
If you want to know what official AI access for your company looks like - write to us. A conversation, not a sales funnel.