Between 23 September and 23 October 2025, employees at the municipality of Eindhoven uploaded more than 1,000 documents containing personal data to public AI websites. Youth-care files under the Jeugdwet — children's mental and physical health records, in some cases their BSN numbers and photos. Wmo files with diagnoses, addictions, debts. Applicant CVs. The municipality reported the breach to the Dutch data protection authority on 23 October, blocked public AI sites, moved staff onto a Copilot instance inside the municipal tenant, and asked OpenAI to delete the data. As of the most recent public reporting, no confirmation that it happened has ever come back.
Nobody at that municipality set out to leak a child's medical file. They had a document to summarize and a deadline, and the fastest tool available was a browser tab. That's the entire mechanism of shadow AI, and it's worth sitting with before reaching for a policy.
Shadow AI is the default state, not an anomaly
If your organization has no sanctioned AI path, it already has an unsanctioned one — the data says this isn't edge-case behavior. Zscaler's 2026 AI Security Report, built from 989.3 billion AI-related transactions across roughly 9,000 organizations, found AI/ML activity up 91% year over year, more than 3,400 distinct AI applications in use, and 18,033 terabytes of enterprise data moved into AI tools — a 93% increase. Cyberhaven's 2026 AI Adoption & Risk Report puts a number on what's inside that traffic: 39.7% of all data movements into AI tools involve sensitive data, and the average employee does it once every three days.
KPMG and the University of Melbourne surveyed more than 48,000 people, including 32,352 employed respondents, across 47 countries in 2025 and found the policy gap underneath those numbers: of employees who use AI at work, 48% have uploaded sensitive company information to public AI tools and 57% admit to non-transparent AI use — presenting AI-generated work as their own, hiding that they used AI at all, or both. Separately, among employees generally — regardless of whether they personally use AI — only 40% say their organization has any policy or guidance on generative AI use at all. I've covered the shadow-AI-adjacent side of this — the intake stage of a real operating model — but the Eindhoven case is what happens when that stage doesn't exist yet.
Why the ban keeps failing
The instinct after an incident is to block the tools. Software AG's 2024 "Chasing Shadows" study surveyed 6,000 knowledge workers across the US, UK, and Germany and found a deeper loyalty problem than a simple ban addresses: among the roughly 38% of knowledge workers already using personal, unsanctioned AI tools at work, about half say they'd keep using them even if their employer banned them outright. Blocking doesn't slow adoption so much as it blinds the people trying to manage it — Zscaler's own numbers make the point directly: its 2025 report found enterprises blocking 59.9% of AI/ML transactions at the network level while usage grew more than 3,000% anyway. Blocking and explosive growth coexisted in the same dataset.
The Dutch data protection authority's own casework shows the failure mode in practice. In August 2024 it warned that AI-chatbot use was already causing data breaches — a GP practice employee had entered patient medical data into a chatbot against the practice's own agreements; a telecom employee had entered a file of customer addresses. By December 2025, after Eindhoven became public, the AP raised the alarm again: dozens of breach reports across 2024 and 2025, more in 2025 than 2024, and a detail that should stop any CIO who thinks they've solved this — employees were reaching for free chatbot versions even at organizations that already paid for an enterprise AI contract. The sanctioned tool existed. The shadow path was still easier.
Even the most famous ban just ended
Samsung's 2023 ban is the reference case everyone in this field already knows — three separate leaks within about three weeks of Samsung's semiconductor division first allowing ChatGPT use, a company-wide ban that followed within weeks, disciplinary action up to and including termination on the table. What's less known: that ban was never an end state. Samsung built its own internal model, Gauss, for sensitive work, and spent three years running a closed system while the rest of the market kept moving. In June 2026, Samsung deployed ChatGPT Enterprise and Codex to all its employees in Korea and its Device eXperience division worldwide — though the semiconductor division where the 2023 leak originated reportedly remains under tighter controls — under a governance framework built for the purpose: enterprise access controls, data protection, and an approved path. The ban wasn't the destination. It was a three-year detour that ended in exactly the kind of sanctioned access this article argues for.
The regulator has stopped being patient
Italy's data protection authority gave DeepSeek an information request on 28 January 2025 and a definitive processing limitation two days later — the company's answers on what data it held and why were, in the regulator's own assessment, insufficient. The Dutch cabinet followed in February, barring DeepSeek across all ministries under its existing policy on software from countries running offensive cyber programs. Neither move was really about one chatbot. Both were regulators demonstrating they will act on AI tools operating outside visibility and control — which is the exact condition an unmanaged shadow-AI footprint puts you in.
The EU AI Act's Article 4 — the AI-literacy obligation on providers and deployers — has applied since 2 February 2025, and it has carried real fine exposure since 2 August 2025, when the Article 99 penalty regime became applicable. Over a year of "we didn't know" is a weakening excuse, not a strengthening one. And the Article 50 transparency duties — disclosure that a user is talking to AI, marking of synthetic content — land next month, 2 August 2026, on the AI Act's own original schedule. An AI-use inventory isn't a nice-to-have next to that date; it's the artifact that shows the obligation was taken seriously before an incident forced the question.
The evidence that a sanctioned path actually works
Here's the number that should reframe the whole problem: Netskope's Cloud & Threat Report 2026, drawn from telemetry across October 2024 to October 2025, found that AI use through personal accounts — the purest form of shadow AI — fell from 78% to 47% of genAI platform users over that year, while use through organization-approved accounts rose from 25% to 62%. Employees didn't stop using AI. They moved to the sanctioned path once one existed and was good enough to use.
JPMorgan Chase restricted employee use of ChatGPT in February 2023. It launched its own tool, LLM Suite, in July 2024, and by the bank's own account reached 200,000 employees onboarded within eight months. By late 2025, roughly 250,000 employees had access company-wide, and its Chief Analytics Officer told McKinsey that "a little under half" use it daily. AXA built Secure GPT on Azure OpenAI in three months, launching in July 2023 to a 1,000-employee pilot, with a stated goal of extending it to all 140,000 employees globally. Eindhoven's Copilot-only tenant is the minimum viable version of the same move, built under incident pressure instead of foresight. None of these organizations solved shadow AI by banning it. They solved it by making the approved path faster than the alternative.
The cheap intake door
Here's the fix, and it's deliberately small: one form, one owner, one 48-hour answer, three possible outcomes — approved, approved with conditions, or here's the sanctioned tool that already does this. The form asks four things: which tool, what task, what data it touches, and who's asking. The owner is a named role, not a committee — usually whoever already owns AI governance stage two, inventory, since the two stages feed each other directly. The inventory of what AI is actually running falls out as a by-product — but only if people use the door, and only if it's faster than opening a private browser tab. Skip the 48-hour SLA and the door quietly becomes theater: requests queue, someone opens ChatGPT while they wait, and the form stops being the fastest path to getting work done. This is stage one of the five-stage operating model I've written about before — intake, inventory, enforcement, monitoring, audit — and it's the stage every organization in the data above skipped until an incident made it non-optional.
Discovery tooling covers what already happened before the door existed — the shadow AI use already running before anyone built an intake process. Microsoft Purview's DSPM for AI and Defender for Cloud Apps catalog more than 1,000 generative-AI applications with a risk score per app — the highest-leverage option for any organization already licensing Microsoft E5, since the capability is often sitting there unused. Netskope rates over 85,000 SaaS and AI applications, including 1,800-plus generative-AI tools, on enterprise-readiness — strong where an inline proxy already exists, blind to the on-premises AI agents that a proxy never sees traffic from (Netskope's own separate research on shadow and agentic AI found 5.5% of organizations running exactly this, built with frameworks like LangChain). Zscaler covers the same proxy-level ground at Zero Trust Exchange scale, with the advantage of Zero Trust customers already routing traffic through it — worth choosing over Netskope only if that's already your stack, since the blind spot is identical either way. None of them replace the intake door: discovery tools are backward-looking, telling you what already happened; the door is the only piece that's forward-looking.
Here's the falsifiable test I'd apply to any organization claiming AI governance: ask for the intake form, and ask how long the last approval actually took. No form, or an honest answer measured in weeks, and the inventory is fiction — a spreadsheet from before the last incident, waiting on the next one.
Building the AI intake door is a governance-design decision, not a vendor shortlist — that's a conversation worth having before the incident, not after.
Sources & further reading
- Gemeente Eindhoven blokkeert ChatGPT na datalek — Binnenlands Bestuur, December 2025
- Waarschuwing voor personeel dat met AI aan de slag gaat: kans op datalek groot — NOS Nieuwsuur, June 2026
- Gemeente Eindhoven lekt persoonlijke gegevens inwoners via AI-websites — Security.NL, December 2025
- AP waarschuwt voor datalekken bij AI-chatbots — Computable, August 2024
- Tientallen meldingen over datalekken door AI-gebruik, privacywaakhond waarschuwt voor risico's — Het Financieele Dagblad, December 2025
- Zscaler 2026 AI Security Report: 91% year-over-year surge in AI activity — GlobeNewswire, January 2026
- Report finds an over 3,000% surge in enterprise use of AI/ML tools (ThreatLabz 2025 AI Security Report) — Zscaler, May 2025
- Cyberhaven 2026 AI Adoption & Risk Report — Cyberhaven, February 2026
- Shadow AI ("Chasing Shadows" study, 6,000 knowledge workers) — Software AG, 2024
- Netskope Cloud & Threat Report 2026 — Netskope, January 2026
- Cloud and Threat Report: Shadow AI and Agentic AI 2025 — Netskope, August 2025
- Trust, attitudes and use of AI: a global study 2025 — KPMG / University of Melbourne, 2025
- The shadow AI surge: study finds 50% of workers use unapproved AI tools — SecurityWeek, October 2024
- Samsung bans ChatGPT and other generative AI use by staff after leak — Bloomberg, May 2023
- Samsung Electronics deploys ChatGPT and Codex company-wide — OpenAI, June 2026
- The Garante imposes a definitive limitation on the processing of Italian users' personal data (DeepSeek) — Bird & Bird, January 2025
- Kabinet verbiedt gebruik DeepSeek — Computable, February 2025
- Article 4: AI literacy — EU AI Act Explorer (Regulation (EU) 2024/1689), 2024
- JPMorgan Chase becomes a "fully AI-connected" megabank — CNBC, September 2025
- How JPMorganChase democratized employee access to gen AI — American Banker, May 2025
- LLM Suite named 2025 "Innovation of the Year" by American Banker — JPMorganChase, June 2025
- JPMorgan Chase's Derek Waldron on building an AI-first bank culture — McKinsey, October 2025
- AXA offers secure generative AI to employees — AXA, 2023