{"id":9611,"date":"2026-05-15T09:00:13","date_gmt":"2026-05-15T09:00:13","guid":{"rendered":"https:\/\/dev.empiricus.eu\/schatten-ki-im-unternehmen-warum-ungeplante-ki-nutzung-zur-fuehrungsfalle-wird\/"},"modified":"2026-08-12T15:16:40","modified_gmt":"2026-08-12T15:16:40","slug":"schatten-ki-im-unternehmen-warum-ungeplante-ki-nutzung-zur-fuehrungsfalle-wird","status":"publish","type":"post","link":"https:\/\/empiricus.eu\/en\/schatten-ki-im-unternehmen-warum-ungeplante-ki-nutzung-zur-fuehrungsfalle-wird\/","title":{"rendered":"Shadow AI in the Workplace: Why Does Unplanned AI Use Become a Management Pitfall?"},"content":{"rendered":"<h4>KI-Governance within the company | Article 2<\/h4>\n<p><em>This article explores why shadow AI emerges, the risks it entails, and how leadership can respond effectively.<\/em><\/p>\n<p><strong><em>Artificial intelligence is currently transforming the world of work faster than most companies can react. Not because the technology is so complex\u2014but because it is so accessible. Today, any employee with a smartphone and a browser can access tools in minutes that, just ten years ago, would have required companies to budget six-figure sums for licenses. What this means for leadership is a question that is still asked too rarely. <\/em><\/strong><\/p>\n<div class=\"element element-textarea first\">\n<div>\n<h2>What shadow AI actually is\u2014and why it arises<\/h2>\n<p>When I speak with entrepreneurs and executives, I often notice one thing: the term \u201cshadow AI\u201d instinctively triggers unease. People think of rule-breaking, loss of control, and employees who deliberately cross boundaries. That image is inaccurate.<\/p>\n<p>The reality is much more down-to-earth\u2014and humanly understandable.<\/p>\n<p>A sales representative writes ten proposals every day. He discovers that ChatGPT can provide him with a solid first draft in a fraction of the time. A colleague in marketing uses an AI image generator because the graphics department is swamped. The executive assistant has meeting minutes transcribed automatically because it saves her an hour a day. None of these people are acting with malicious intent. On the contrary: they simply want to do their work better and more efficiently.<\/p>\n<p>Shadow AI doesn\u2019t arise because employees deliberately flout rules\u2014it arises from dedication. And because of a leadership vacuum.<\/p>\n<p>The numbers speak for themselves. According to a representative Bitkom study from fall 2025, around 42 percent of German companies know or suspect that their employees are using personal AI tools for work. Only 26 percent officially provide access to AI systems, and only 23 percent have established clear rules. The rest leave the issue vague, having neither clear rules nor a clear framework.<\/p>\n<p>Shadow AI is therefore not an IT problem; it affects more or less the entire company. It sends a clear signal: employees have a need that the company is not meeting. The question leaders must ask themselves is therefore not, \u201cHow do I stop this?\u201d The right question is, \u201cWhat does this tell me about my company, and what can I change?\u201d<\/p>\n<h2>The risks no one is aware of<\/h2>\n<p>In my conversations, I hear time and again what worries executives most about shadow AI: They simply have no idea what their employees are actually doing. It is precisely this lack of awareness that opens up three dimensions of risk, which become dangerous when combined.<\/p>\n<h3>Data protection \u2013 a structural problem, not an isolated case<\/h3>\n<p>Anyone who enters a customer contract into ChatGPT, or uploads applicant or personnel data to an AI tool, is transferring personal data to external servers\u2014usually in the U.S.\u2014without a data processing agreement and without a legal basis under Article 6 of the GDPR. The responsibility for this lies with the company\u2014whether the CEO is aware of it or not.<\/p>\n<p>But even those who don\u2019t enter any personal data aren\u2019t in the clear. The best-known real-world example comes from Samsung. Shortly after the company made ChatGPT available to its engineers, three incidents occurred within 20 days: Employees uploaded source code, transmitted semiconductor test sequences, and fed in confidential meeting minutes\u2014all to get help with their daily work. The result: trade secrets on external servers, with no way to retrieve them. What happened to Samsung could have happened to any company. It\u2019s happening right now\u2014quietly, unplanned, possibly even in your company.<\/p>\n<h3>Quality \u2013 when no one checks what the AI produces<\/h3>\n<p>AI systems hallucinate\u2014that is, they invent facts, figures, or sources that simply do not exist. This is not a bug that will eventually be fixed, but a structural feature of current language models. I\u2019ve experienced it myself: I included AI-generated statements about the overall economic situation in an annual report without verifying them. These statements were completely fabricated and bore no resemblance to reality. Fortunately, the auditors noticed it in time. Since then, I\u2019ve known that texts generated by AI systems must always be checked for accuracy, and someone must take responsibility for the content. In companies where AI is used without oversight, this simply doesn\u2019t happen.<\/p>\n<h3>Legal Compliance and the Next Level of Escalation<\/h3>\n<p>The EU AI Act makes the time pressure clear: Starting in February 2025, employees who use AI must have received adequate training. Starting in August 2025, certain practices will be prohibited\u2014including emotion recognition in the workplace. Starting in August 2026, obligations will apply to high-risk AI, which includes AI used in personnel selection. Anyone who doesn\u2019t know today which tools their employees are using will not be able to meet these requirements.<\/p>\n<p>And the risk curve continues to rise. Autonomous AI agents\u2014systems that not only respond but also independently access systems and execute processes\u2014are already in use. Security researchers recently deployed such an agent on the internal platform of the consulting firm McKinsey. The system took two hours to gain full administrative access to millions of internal documents. The message: The risk lies not only in what happens\u2014but in the speed at which it can happen.<\/p>\n<h2>The Real Leadership Trap: Blindness in Four Dimensions<\/h2>\n<p>It is possible to provide objective information about data protection, hallucinations, and regulatory requirements. That is important\u2014but it is not what truly concerns me about shadow AI as a leadership issue. What concerns me is something more fundamental: shadow AI blinds leadership. Not maliciously, not negligently\u2014structurally. And that has consequences that go far beyond compliance.<\/p>\n<h3>Blindness to Results<\/h3>\n<p>A leader who doesn\u2019t know how results are produced cannot assess them. They see a log, an analysis, a customer report\u2014but not whether there is careful work behind it, a well-managed AI conversation, or an uncritically accepted output that may have hallucinated. The surface is smooth. What lies beneath remains invisible.<\/p>\n<p>Managers who make decisions based on AI-generated, unverified analyses are making decisions on a basis whose quality they do not know. This could be interpreted as a mistake on the part of employees. However, it is more of a structural leadership problem.<\/p>\n<h3>Blindness to Potential<\/h3>\n<p>Shadow AI produces valuable results behind the scenes. Employees discover use cases that work. They develop prompts that deliver real efficiency gains. They figure out where AI helps\u2014and where it doesn\u2019t.<\/p>\n<p>But this knowledge disappears. It isn\u2019t shared, documented, or scaled. It remains as individual experiential knowledge in the minds of individual employees\u2014invisible to the organization, worthless for strategy.<\/p>\n<p>Those who don\u2019t know what\u2019s already happening within the company aren\u2019t just losing control\u2014they\u2019re missing out on the learning process that could give rise to a genuine AI strategy.<\/p>\n<h3>Blindness to Performance and Fairness<\/h3>\n<p>Imagine two employees who appear to be doing the same work. One writes five reports a day; the other, three. One answers customer inquiries in an hour; the other takes two. The obvious conclusion: The first is more productive, more committed, and more efficient.<\/p>\n<p>That may be true. Perhaps he is simply using AI\u2014while the second follows rules that the company has never explicitly formulated.<\/p>\n<p>This creates two problems at once. The manager misjudges performance\u2014they may be rewarding not competence, but AI affinity. And they unintentionally disadvantage those who work by the book. This is the inevitable consequence of an unregulated state.<\/p>\n<h3>Blindness to Strategy<\/h3>\n<p>This is the fourth and most consequential dimension. Companies that allow AI to grow unchecked from the bottom up may gain experience\u2014but not insights. They have no answers to the crucial questions: Where does AI truly create value for us? Which use cases warrant systematic implementation? How do we measure success?<\/p>\n<p>According to the 2024 Work Trend Index from Microsoft and LinkedIn, 55 percent of German executives say their companies lack a vision and a plan for AI adoption. At the same time, 77 percent believe that AI adoption is crucial to remaining competitive. This gap between awareness and action\u2014that is the real leadership trap.<\/p>\n<p>Because the market won\u2019t wait. Competitors who implement AI in a structured way gain not only efficiency\u2014they gain speed and better decision-making. Those who leave this to chance are leaving their competitive advantage to chance.<\/p>\n<h2>Why a ban isn\u2019t the answer<\/h2>\n<p>The obvious reaction to everything described so far is a ban. No private AI tools. No ChatGPT on company computers. A clear statement\u2014problem solved?<\/p>\n<p>I consider this a mistake.<\/p>\n<p>Bans do not drive usage away\u2014they drive it underground. Visible shadow AI becomes invisible shadow AI, completely beyond the control of the IT department. The risk remains. Those who ban AI lose twice: they forgo efficiency gains and simultaneously send the signal that they do not want to shape today\u2019s working world. Samsung understood this after its data leaks\u2014and instead of banning it, they provided training and developed their own internal AI service.<\/p>\n<p>The question isn\u2019t: AI or no AI. The question is: Who\u2019s at the helm?<\/p>\n<h2>What Leadership Needs Now\u2014Not Someday<\/h2>\n<p>I\u2019m often asked what the first step is. My answer sometimes comes as a surprise: It\u2019s not a policy, not a tool, not a workshop. The first step is an honest assessment.<\/p>\n<p>Do you know today which AI tools are actually being used in your company\u2014not officially, but in reality? Which departments are already experimenting? Who has had positive experiences that the entire company could benefit from? I\u2019ve learned that such answers rarely come to the surface on their own\u2014especially not when employees fear they\u2019ve done something unauthorized. Visibility must be actively created. That is leadership.<\/p>\n<p>Once the assessment is complete, three decisions need to be made. First, establish a framework: Which tools can be used, what data can be included, and what is prohibited? A clear framework protects both employees and the company. Second, systematically identify use cases\u2014not imposed from above, but developed together with the employees who understand the processes. This transforms individual experiences into organizational learning. Third, build expertise: Employees who understand how AI works and where its limits lie are not a security risk\u2014they are a competitive advantage.<\/p>\n<p>And one more thing\u2014this is personally important to me: Leaders must take responsibility themselves. Not as AI experts, but as decision-makers who understand what the technology can do and where it fails. Only those who know this can take responsibility where it belongs: at the top of the company.<\/p>\n<p><strong>Shadow AI is not an operational accident. It is a symptom\u2014of a lack of leadership, a lack of guidelines, and a lack of clarity. <\/strong><\/p>\n<h2>What to Expect in This Series<\/h2>\n<p>This series guides you through the most important leadership questions surrounding AI in the workplace\u2014with a practical focus and based on personal experience.<\/p>\n<p>In the next article, I\u2019ll address a question that concerns many leaders but is rarely asked openly: \u201c<em>How does AI actually change the leadership role itself? Which tasks that are still part of the core business of leadership today will be taken over by algorithms tomorrow\u2014and what new requirements will this create?\u201d<\/em><\/p>\n<p>In the previous article, I addressed the question: <a href=\"https:\/\/empiricus.eu\/it-trends-leadership-new-work\/item\/warum-fehlende-ki-governance-zur-f%C3%BChrungsfrage-wird-%E2%80%93-und-nicht-zur-it-aufgabe\" target=\"_blank\" rel=\"noopener\"><em> \u201cWhy the lack of AI governance is becoming a leadership issue\u2014not an IT task\u201d<\/em><\/a><\/p>\n<p>&nbsp;<\/p>\n<p><em>But first, I\u2019d like to hear your perspective: Have you already encountered shadow AI in your company\u2014and how did you handle it? I look forward to your feedback in the comments. <\/em><\/p>\n<h2>Who this series is for<\/h2>\n<p data-start=\"\u201c4666\u201d\" data-end=\"\u201c5175\u201d\">This series is aimed at CEOs, board members, advisory board members, and executives who do not want to reduce the handling of AI to a purely IT issue. It is particularly relevant for companies where AI is already being used in specific areas without clearly defined roles, responsibilities, and guidelines. <br data-start=\"\u201c4984\u201d\" data-end=\"\u201c4987\u201d\/\" \/>Especially in medium-sized companies, this quickly creates a complex mix of opportunities, uncertainty, and pressure to act. That is exactly where leadership is needed\u2014not later, but now.<\/p>\n<p><strong><em>About the Author<\/em><\/strong><\/p>\n<p><em><a href=\"https:\/\/empiricus.eu\/it-personalberater-team?view=article&amp;id=226:dr-bernd-kappesser&amp;catid=17\">Dr. Bernd Kappesser<\/a> is a partner at empiricus GmbH. With his many years of experience in leadership roles in the IT and technology sectors, he possesses in-depth expertise in transformation, organizational development, and strategic leadership. <\/em><\/p>\n<p><em>He supports executive boards, management boards, advisory boards, and leadership teams in consciously shaping their roles, effectively leading change, and positioning their organizations for the future amid the challenges of digitalization, artificial intelligence, and regulation. His approach combines entrepreneurial practice, strategic thinking, and personal reflection\u2014with a clear focus on sustainable impact. <\/em><\/p>\n<p><strong><a href=\"https:\/\/empiricus.eu\/unternehmen\/executive-advisory-leadership\">Learn more about our Executive Advisory and Leadership Development services. Get in touch with us &#8211; Contact<\/a><\/strong><\/p>\n<\/div>\n<\/div>\n<div class=\"element element-media\">No video selected.<\/div>\n","protected":false},"excerpt":{"rendered":"<p>KI-Governance within the company | Article 2 This article explores why shadow AI emerges, the risks it entails, and how [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":9612,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[1170],"tags":[],"class_list":["post-9611","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-governance-and-leadership"],"_links":{"self":[{"href":"https:\/\/empiricus.eu\/en\/wp-json\/wp\/v2\/posts\/9611","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/empiricus.eu\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/empiricus.eu\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/empiricus.eu\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/empiricus.eu\/en\/wp-json\/wp\/v2\/comments?post=9611"}],"version-history":[{"count":3,"href":"https:\/\/empiricus.eu\/en\/wp-json\/wp\/v2\/posts\/9611\/revisions"}],"predecessor-version":[{"id":10794,"href":"https:\/\/empiricus.eu\/en\/wp-json\/wp\/v2\/posts\/9611\/revisions\/10794"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/empiricus.eu\/en\/wp-json\/wp\/v2\/media\/9612"}],"wp:attachment":[{"href":"https:\/\/empiricus.eu\/en\/wp-json\/wp\/v2\/media?parent=9611"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/empiricus.eu\/en\/wp-json\/wp\/v2\/categories?post=9611"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/empiricus.eu\/en\/wp-json\/wp\/v2\/tags?post=9611"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}