Everyone uses AI – almost nobody has an overview
"Shadow AI" refers to using AI tools without official approval or the knowledge of IT or management – usually not out of bad intent, but because a free chatbot delivers an answer faster than the official, often slower or more restricted company channel. Current studies show: around 71% of knowledge workers at German SMEs use generative AI tools without formal approval, nearly 43% of them even for internal emails. This isn't the exception, it's the normal case.
The trust gap: 82% believe they're protected
The truly decisive number isn't usage itself, but the perception gap around it: only about 30% of organisations can reliably detect shadow AI in their own network at all. At the same time, around 82% of executives believe their existing policies already sufficiently prevent unauthorised actions by AI systems – while in the same period around 88% of companies actually reported a confirmed or suspected AI security incident. This gap between perceived and actual security is the real core of the problem, not the existence of shadow AI alone.
Why a policy alone isn't enough
A policy is a document, not a technical control – it doesn't change what's technically possible, only what's supposed to be allowed. Without visibility (who uses what) and without an accepted, good-enough alternative, an outright ban tends to increase concealment rather than actually end the use – employees just use the tools more quietly. Only around a quarter of companies have actually adapted their governance structures to real AI use, even though more than half already actively use AI.
Practice section: visibility before prohibition
The sensible first step isn't a ban, but visibility: an honest, undramatic stocktake of which AI tools the team actually uses and for what – without punishing the answer, or the survey stays dishonest. Only after that can you distinguish uncritical use (e.g. research without confidential data) from genuinely risky use (e.g. customer data in an unapproved tool). The following modules of this course build on that stocktake: from concrete attack patterns like prompt injection all the way to the practical roadmap at the end.