Delfen
All articlesAI in Practice

Shadow AI: why bans fail and what a real policy looks like

A Dutch municipality's staff uploaded over 1,000 documents to public chatbots in one month, children's BSN numbers among them — the city asked OpenAI to delete the data and never got confirmation it happened. Nobody involved was malicious; they were getting work done.

Jacques Domenie·15 July 2026·7 min read

Between 23 September and 23 October 2025, employees at the municipality of Eindhoven uploaded more than 1,000 documents containing personal data to public AI websites. Youth-care files under the Jeugdwet — children's mental and physical health records, in some cases their BSN numbers and photos. Wmo files with diagnoses, addictions, debts. Applicant CVs. The municipality reported the breach to the Dutch data protection authority on 23 October, blocked public AI sites, moved staff onto a Copilot instance inside the municipal tenant, and asked OpenAI to delete the data. As of the most recent public reporting, no confirmation that it happened has ever come back.

Nobody at that municipality set out to leak a child's medical file. They had a document to summarize and a deadline, and the fastest tool available was a browser tab. That's the entire mechanism of shadow AI, and it's worth sitting with before reaching for a policy.

Shadow AI is the default state, not an anomaly

If your organization has no sanctioned AI path, it already has an unsanctioned one — the data says this isn't edge-case behavior. Zscaler's 2026 AI Security Report, built from 989.3 billion AI-related transactions across roughly 9,000 organizations, found AI/ML activity up 91% year over year, more than 3,400 distinct AI applications in use, and 18,033 terabytes of enterprise data moved into AI tools — a 93% increase. Cyberhaven's 2026 AI Adoption & Risk Report puts a number on what's inside that traffic: 39.7% of all data movements into AI tools involve sensitive data, and the average employee does it once every three days.

KPMG and the University of Melbourne surveyed more than 48,000 people, including 32,352 employed respondents, across 47 countries in 2025 and found the policy gap underneath those numbers: of employees who use AI at work, 48% have uploaded sensitive company information to public AI tools and 57% admit to non-transparent AI use — presenting AI-generated work as their own, hiding that they used AI at all, or both. Separately, among employees generally — regardless of whether they personally use AI — only 40% say their organization has any policy or guidance on generative AI use at all. I've covered the shadow-AI-adjacent side of this — the intake stage of a real operating model — but the Eindhoven case is what happens when that stage doesn't exist yet.

Why the ban keeps failing

The instinct after an incident is to block the tools. Software AG's 2024 "Chasing Shadows" study surveyed 6,000 knowledge workers across the US, UK, and Germany and found a deeper loyalty problem than a simple ban addresses: among the roughly 38% of knowledge workers already using personal, unsanctioned AI tools at work, about half say they'd keep using them even if their employer banned them outright. Blocking doesn't slow adoption so much as it blinds the people trying to manage it — Zscaler's own numbers make the point directly: its 2025 report found enterprises blocking 59.9% of AI/ML transactions at the network level while usage grew more than 3,000% anyway. Blocking and explosive growth coexisted in the same dataset.

The Dutch data protection authority's own casework shows the failure mode in practice. In August 2024 it warned that AI-chatbot use was already causing data breaches — a GP practice employee had entered patient medical data into a chatbot against the practice's own agreements; a telecom employee had entered a file of customer addresses. By December 2025, after Eindhoven became public, the AP raised the alarm again: dozens of breach reports across 2024 and 2025, more in 2025 than 2024, and a detail that should stop any CIO who thinks they've solved this — employees were reaching for free chatbot versions even at organizations that already paid for an enterprise AI contract. The sanctioned tool existed. The shadow path was still easier.

Even the most famous ban just ended

Samsung's 2023 ban is the reference case everyone in this field already knows — three separate leaks within about three weeks of Samsung's semiconductor division first allowing ChatGPT use, a company-wide ban that followed within weeks, disciplinary action up to and including termination on the table. What's less known: that ban was never an end state. Samsung built its own internal model, Gauss, for sensitive work, and spent three years running a closed system while the rest of the market kept moving. In June 2026, Samsung deployed ChatGPT Enterprise and Codex to all its employees in Korea and its Device eXperience division worldwide — though the semiconductor division where the 2023 leak originated reportedly remains under tighter controls — under a governance framework built for the purpose: enterprise access controls, data protection, and an approved path. The ban wasn't the destination. It was a three-year detour that ended in exactly the kind of sanctioned access this article argues for.

The regulator has stopped being patient

Italy's data protection authority gave DeepSeek an information request on 28 January 2025 and a definitive processing limitation two days later — the company's answers on what data it held and why were, in the regulator's own assessment, insufficient. The Dutch cabinet followed in February, barring DeepSeek across all ministries under its existing policy on software from countries running offensive cyber programs. Neither move was really about one chatbot. Both were regulators demonstrating they will act on AI tools operating outside visibility and control — which is the exact condition an unmanaged shadow-AI footprint puts you in.

The EU AI Act's Article 4 — the AI-literacy obligation on providers and deployers — has applied since 2 February 2025, and it has carried real fine exposure since 2 August 2025, when the Article 99 penalty regime became applicable. Over a year of "we didn't know" is a weakening excuse, not a strengthening one. And the Article 50 transparency duties — disclosure that a user is talking to AI, marking of synthetic content — land next month, 2 August 2026, on the AI Act's own original schedule. An AI-use inventory isn't a nice-to-have next to that date; it's the artifact that shows the obligation was taken seriously before an incident forced the question.

The evidence that a sanctioned path actually works

Here's the number that should reframe the whole problem: Netskope's Cloud & Threat Report 2026, drawn from telemetry across October 2024 to October 2025, found that AI use through personal accounts — the purest form of shadow AI — fell from 78% to 47% of genAI platform users over that year, while use through organization-approved accounts rose from 25% to 62%. Employees didn't stop using AI. They moved to the sanctioned path once one existed and was good enough to use.

JPMorgan Chase restricted employee use of ChatGPT in February 2023. It launched its own tool, LLM Suite, in July 2024, and by the bank's own account reached 200,000 employees onboarded within eight months. By late 2025, roughly 250,000 employees had access company-wide, and its Chief Analytics Officer told McKinsey that "a little under half" use it daily. AXA built Secure GPT on Azure OpenAI in three months, launching in July 2023 to a 1,000-employee pilot, with a stated goal of extending it to all 140,000 employees globally. Eindhoven's Copilot-only tenant is the minimum viable version of the same move, built under incident pressure instead of foresight. None of these organizations solved shadow AI by banning it. They solved it by making the approved path faster than the alternative.

The cheap intake door

Here's the fix, and it's deliberately small: one form, one owner, one 48-hour answer, three possible outcomes — approved, approved with conditions, or here's the sanctioned tool that already does this. The form asks four things: which tool, what task, what data it touches, and who's asking. The owner is a named role, not a committee — usually whoever already owns AI governance stage two, inventory, since the two stages feed each other directly. The inventory of what AI is actually running falls out as a by-product — but only if people use the door, and only if it's faster than opening a private browser tab. Skip the 48-hour SLA and the door quietly becomes theater: requests queue, someone opens ChatGPT while they wait, and the form stops being the fastest path to getting work done. This is stage one of the five-stage operating model I've written about before — intake, inventory, enforcement, monitoring, audit — and it's the stage every organization in the data above skipped until an incident made it non-optional.

Discovery tooling covers what already happened before the door existed — the shadow AI use already running before anyone built an intake process. Microsoft Purview's DSPM for AI and Defender for Cloud Apps catalog more than 1,000 generative-AI applications with a risk score per app — the highest-leverage option for any organization already licensing Microsoft E5, since the capability is often sitting there unused. Netskope rates over 85,000 SaaS and AI applications, including 1,800-plus generative-AI tools, on enterprise-readiness — strong where an inline proxy already exists, blind to the on-premises AI agents that a proxy never sees traffic from (Netskope's own separate research on shadow and agentic AI found 5.5% of organizations running exactly this, built with frameworks like LangChain). Zscaler covers the same proxy-level ground at Zero Trust Exchange scale, with the advantage of Zero Trust customers already routing traffic through it — worth choosing over Netskope only if that's already your stack, since the blind spot is identical either way. None of them replace the intake door: discovery tools are backward-looking, telling you what already happened; the door is the only piece that's forward-looking.

Here's the falsifiable test I'd apply to any organization claiming AI governance: ask for the intake form, and ask how long the last approval actually took. No form, or an honest answer measured in weeks, and the inventory is fiction — a spreadsheet from before the last incident, waiting on the next one.

Building the AI intake door is a governance-design decision, not a vendor shortlist — that's a conversation worth having before the incident, not after.

Sources & further reading

Continue reading

Get the next article in your inbox.

One deep-dive per week. Free. No pitch. Unsubscribe anytime.

Subscribe to the Delfen Briefing →