KI-Governance within the company | Article 2
This article explores why shadow AI emerges, the risks it entails, and how leadership can respond effectively.
Artificial intelligence is currently transforming the world of work faster than most companies can react. Not because the technology is so complex—but because it is so accessible. Today, any employee with a smartphone and a browser can access tools in minutes that, just ten years ago, would have required companies to budget six-figure sums for licenses. What this means for leadership is a question that is still asked too rarely.
What shadow AI actually is—and why it arises
When I speak with entrepreneurs and executives, I often notice one thing: the term “shadow AI” instinctively triggers unease. People think of rule-breaking, loss of control, and employees who deliberately cross boundaries. That image is inaccurate.
The reality is much more down-to-earth—and humanly understandable.
A sales representative writes ten proposals every day. He discovers that ChatGPT can provide him with a solid first draft in a fraction of the time. A colleague in marketing uses an AI image generator because the graphics department is swamped. The executive assistant has meeting minutes transcribed automatically because it saves her an hour a day. None of these people are acting with malicious intent. On the contrary: they simply want to do their work better and more efficiently.
Shadow AI doesn’t arise because employees deliberately flout rules—it arises from dedication. And because of a leadership vacuum.
The numbers speak for themselves. According to a representative Bitkom study from fall 2025, around 42 percent of German companies know or suspect that their employees are using personal AI tools for work. Only 26 percent officially provide access to AI systems, and only 23 percent have established clear rules. The rest leave the issue vague, having neither clear rules nor a clear framework.
Shadow AI is therefore not an IT problem; it affects more or less the entire company. It sends a clear signal: employees have a need that the company is not meeting. The question leaders must ask themselves is therefore not, “How do I stop this?” The right question is, “What does this tell me about my company, and what can I change?”
The risks no one is aware of
In my conversations, I hear time and again what worries executives most about shadow AI: They simply have no idea what their employees are actually doing. It is precisely this lack of awareness that opens up three dimensions of risk, which become dangerous when combined.
Data protection – a structural problem, not an isolated case
Anyone who enters a customer contract into ChatGPT, or uploads applicant or personnel data to an AI tool, is transferring personal data to external servers—usually in the U.S.—without a data processing agreement and without a legal basis under Article 6 of the GDPR. The responsibility for this lies with the company—whether the CEO is aware of it or not.
But even those who don’t enter any personal data aren’t in the clear. The best-known real-world example comes from Samsung. Shortly after the company made ChatGPT available to its engineers, three incidents occurred within 20 days: Employees uploaded source code, transmitted semiconductor test sequences, and fed in confidential meeting minutes—all to get help with their daily work. The result: trade secrets on external servers, with no way to retrieve them. What happened to Samsung could have happened to any company. It’s happening right now—quietly, unplanned, possibly even in your company.
Quality – when no one checks what the AI produces
AI systems hallucinate—that is, they invent facts, figures, or sources that simply do not exist. This is not a bug that will eventually be fixed, but a structural feature of current language models. I’ve experienced it myself: I included AI-generated statements about the overall economic situation in an annual report without verifying them. These statements were completely fabricated and bore no resemblance to reality. Fortunately, the auditors noticed it in time. Since then, I’ve known that texts generated by AI systems must always be checked for accuracy, and someone must take responsibility for the content. In companies where AI is used without oversight, this simply doesn’t happen.
Legal Compliance and the Next Level of Escalation
The EU AI Act makes the time pressure clear: Starting in February 2025, employees who use AI must have received adequate training. Starting in August 2025, certain practices will be prohibited—including emotion recognition in the workplace. Starting in August 2026, obligations will apply to high-risk AI, which includes AI used in personnel selection. Anyone who doesn’t know today which tools their employees are using will not be able to meet these requirements.
And the risk curve continues to rise. Autonomous AI agents—systems that not only respond but also independently access systems and execute processes—are already in use. Security researchers recently deployed such an agent on the internal platform of the consulting firm McKinsey. The system took two hours to gain full administrative access to millions of internal documents. The message: The risk lies not only in what happens—but in the speed at which it can happen.
The Real Leadership Trap: Blindness in Four Dimensions
It is possible to provide objective information about data protection, hallucinations, and regulatory requirements. That is important—but it is not what truly concerns me about shadow AI as a leadership issue. What concerns me is something more fundamental: shadow AI blinds leadership. Not maliciously, not negligently—structurally. And that has consequences that go far beyond compliance.
Blindness to Results
A leader who doesn’t know how results are produced cannot assess them. They see a log, an analysis, a customer report—but not whether there is careful work behind it, a well-managed AI conversation, or an uncritically accepted output that may have hallucinated. The surface is smooth. What lies beneath remains invisible.
Managers who make decisions based on AI-generated, unverified analyses are making decisions on a basis whose quality they do not know. This could be interpreted as a mistake on the part of employees. However, it is more of a structural leadership problem.
Blindness to Potential
Shadow AI produces valuable results behind the scenes. Employees discover use cases that work. They develop prompts that deliver real efficiency gains. They figure out where AI helps—and where it doesn’t.
But this knowledge disappears. It isn’t shared, documented, or scaled. It remains as individual experiential knowledge in the minds of individual employees—invisible to the organization, worthless for strategy.
Those who don’t know what’s already happening within the company aren’t just losing control—they’re missing out on the learning process that could give rise to a genuine AI strategy.
Blindness to Performance and Fairness
Imagine two employees who appear to be doing the same work. One writes five reports a day; the other, three. One answers customer inquiries in an hour; the other takes two. The obvious conclusion: The first is more productive, more committed, and more efficient.
That may be true. Perhaps he is simply using AI—while the second follows rules that the company has never explicitly formulated.
This creates two problems at once. The manager misjudges performance—they may be rewarding not competence, but AI affinity. And they unintentionally disadvantage those who work by the book. This is the inevitable consequence of an unregulated state.
Blindness to Strategy
This is the fourth and most consequential dimension. Companies that allow AI to grow unchecked from the bottom up may gain experience—but not insights. They have no answers to the crucial questions: Where does AI truly create value for us? Which use cases warrant systematic implementation? How do we measure success?
According to the 2024 Work Trend Index from Microsoft and LinkedIn, 55 percent of German executives say their companies lack a vision and a plan for AI adoption. At the same time, 77 percent believe that AI adoption is crucial to remaining competitive. This gap between awareness and action—that is the real leadership trap.
Because the market won’t wait. Competitors who implement AI in a structured way gain not only efficiency—they gain speed and better decision-making. Those who leave this to chance are leaving their competitive advantage to chance.
Why a ban isn’t the answer
The obvious reaction to everything described so far is a ban. No private AI tools. No ChatGPT on company computers. A clear statement—problem solved?
I consider this a mistake.
Bans do not drive usage away—they drive it underground. Visible shadow AI becomes invisible shadow AI, completely beyond the control of the IT department. The risk remains. Those who ban AI lose twice: they forgo efficiency gains and simultaneously send the signal that they do not want to shape today’s working world. Samsung understood this after its data leaks—and instead of banning it, they provided training and developed their own internal AI service.
The question isn’t: AI or no AI. The question is: Who’s at the helm?
What Leadership Needs Now—Not Someday
I’m often asked what the first step is. My answer sometimes comes as a surprise: It’s not a policy, not a tool, not a workshop. The first step is an honest assessment.
Do you know today which AI tools are actually being used in your company—not officially, but in reality? Which departments are already experimenting? Who has had positive experiences that the entire company could benefit from? I’ve learned that such answers rarely come to the surface on their own—especially not when employees fear they’ve done something unauthorized. Visibility must be actively created. That is leadership.
Once the assessment is complete, three decisions need to be made. First, establish a framework: Which tools can be used, what data can be included, and what is prohibited? A clear framework protects both employees and the company. Second, systematically identify use cases—not imposed from above, but developed together with the employees who understand the processes. This transforms individual experiences into organizational learning. Third, build expertise: Employees who understand how AI works and where its limits lie are not a security risk—they are a competitive advantage.
And one more thing—this is personally important to me: Leaders must take responsibility themselves. Not as AI experts, but as decision-makers who understand what the technology can do and where it fails. Only those who know this can take responsibility where it belongs: at the top of the company.
Shadow AI is not an operational accident. It is a symptom—of a lack of leadership, a lack of guidelines, and a lack of clarity.
What to Expect in This Series
This series guides you through the most important leadership questions surrounding AI in the workplace—with a practical focus and based on personal experience.
In the next article, I’ll address a question that concerns many leaders but is rarely asked openly: “How does AI actually change the leadership role itself? Which tasks that are still part of the core business of leadership today will be taken over by algorithms tomorrow—and what new requirements will this create?”
In the previous article, I addressed the question: “Why the lack of AI governance is becoming a leadership issue—not an IT task”
But first, I’d like to hear your perspective: Have you already encountered shadow AI in your company—and how did you handle it? I look forward to your feedback in the comments.
Who this series is for
This series is aimed at CEOs, board members, advisory board members, and executives who do not want to reduce the handling of AI to a purely IT issue. It is particularly relevant for companies where AI is already being used in specific areas without clearly defined roles, responsibilities, and guidelines.
Especially in medium-sized companies, this quickly creates a complex mix of opportunities, uncertainty, and pressure to act. That is exactly where leadership is needed—not later, but now.
About the Author
Dr. Bernd Kappesser is a partner at empiricus GmbH. With his many years of experience in leadership roles in the IT and technology sectors, he possesses in-depth expertise in transformation, organizational development, and strategic leadership.
He supports executive boards, management boards, advisory boards, and leadership teams in consciously shaping their roles, effectively leading change, and positioning their organizations for the future amid the challenges of digitalization, artificial intelligence, and regulation. His approach combines entrepreneurial practice, strategic thinking, and personal reflection—with a clear focus on sustainable impact.

