The question of whether AI is being used in your organisation has already been answered. It is being used, and has been for some time. The open question is whether you know about it, where it happens, and what information leaves the company along the way.
The pattern is the same everywhere. An employee is under time pressure, opens a freely available language model in a private browser profile and pastes in the draft contract she wants summarised. A developer asks for an explanation of a difficult function and copies in the source code, comments included. A salesperson asks for wording for a proposal and supplies the price list with it.
None of them is acting in bad faith. All three are trying to do their job well. That is precisely why a ban is the weakest available answer.
What is actually happening
Three things happen at once, and none of them shows up on an invoice.
- Confidential material leaves the controlled environment: no contract, no defined purpose, no deletion concept, no record of where it now sits.
- No record exists of which decisions were made with what support. In an audit, you have no answer.
- Knowledge accumulates outside the company. Whatever is created in private accounts walks out of the door with the person who created it.
There is also a regulatory angle that is often overlooked in Switzerland. As soon as personal data flows into a tool without a data processing agreement, that is a data protection incident, regardless of whether anything harmful ever comes of it. With customer or applicant data, the reporting threshold is reached quickly.
A ban does not prevent use. It only prevents you from hearing about it.
Why bans make the problem worse
The first reaction in many companies is a policy prohibiting private AI tools. The result is well documented: usage barely falls, it simply becomes invisible. People switch to a personal device, use a hotspot instead of the corporate network, and stop talking about it. You lose your last opportunity to recognise risks and correct mistakes.
Worse, you lose the people who are furthest ahead. Anyone who uses these tools productively and is sanctioned for it stops sharing what they have learned. Those are exactly the people you need as multipliers.
The approach that works
What works is a combination of three measures, in this order. First, an honest stocktake with no blame attached. Ask teams openly which tools are actually in use, and give an assurance that nothing personal will follow from the answers. You will be surprised how much you learn in two weeks.
Second, a fast and genuinely good alternative. The most effective protection against shadow AI is an approved tool that is at least as good as the unofficial one. If the sanctioned option is slower, clumsier or weaker, you lose. Every time.
Third, short and clear rules that a person can actually remember. Not twelve pages of policy, but three sentences on what belongs in, what does not, and who to ask when you are unsure.
An example of such rules
Public and internal information without personal data may go into approved tools. Customer, HR and contract data only into tools with a contractual basis. Anything you would not write in an email to an external partner does not belong in a public model. If you are unsure, ask a named point of contact, and you get an answer within a day.
Three sentences and one clear responsibility. In practice that works better than any policy nobody reads to the end.
What this means for leadership
Shadow AI is not an IT problem. It is a signal. Where it is widespread, the organisation is telling you it has a real need you are not yet meeting. That is useful information, provided you treat it as information rather than as a breach of the rules.
A clean stocktake takes a few weeks. The cost of a reported data protection incident is considerably higher, and the conversation with a major customer cannot be priced in francs.