Summarizing an email, polishing minutes, explaining a table: Public AI tools often provide a usable draft in seconds. That is exactly where the temptation lies to use them even without company approval. Experts often refer to this as Shadow AI at work: Employees use AI applications outside of the officially intended systems, processes, or controls.
This is not automatically prohibited for every input. A prompt with freely accessible information is to be judged differently than an uploaded customer document. The shortcut becomes risky when data, rights, or operational obligations are overlooked. This guide shows employees in Austria which information should not be put into an unverified tool, how to request a secure alternative, and what to do immediately after an accidental input.
What Shadow AI means in everyday work
Shadow AI is a practical term, not a separate legal offense. It refers to the professional use of an AI application that has not been tested, approved, or integrated into the intended workflow within the company. This can be a freely accessible chatbot, a browser extension, an automatic meeting transcriber, a translation site, or an image AI.
Typical situations include:
- A customer email is copied entirely into a private AI account.
- An extension reads websites or the content of the opened mailbox.
- A meeting service records participants without an agreed-upon process.
- Internal figures are uploaded to have a presentation formulated.
- Employees bypass a blocked tool via their private smartphone.
Therefore, it is not just a matter of whether a tool works technically. It must be checked what information is processed, where it is transmitted, what settings apply, and whether the use is permitted for the specific task. Even a free account with disabled model training does not automatically become an approved corporate system.
Why the quick shortcut can become risky
The Austrian Data Protection Authority on AI and data protection reminds us that the principles of the GDPR continue to apply when using AI. These include lawfulness, purpose limitation, data minimization, accuracy, as well as integrity and confidentiality. The authority also points out that with third-party AI systems, personal data can reach the manufacturer or other third parties.
In addition to personal data, it is about business and trade secrets. The WKO guideline on company data and confidentiality advises not to use confidential information about the company or third parties in AI applications. API keys should be treated like passwords. Unpublished orders, price calculations, financial information, or product ideas can also be in need of protection.
Three risks are particularly easily underestimated in everyday life:
- The input leaves the controlled area. Data can be transmitted to an external provider, stored, or processed for technical checks.
- The output seems safer than it is. A linguistically convincing answer can be factually incorrect, incomplete, or legally inappropriate.
- The process is difficult to explain later. Without approval, documented purpose, and established control, a traceable way of working is missing.
The goal is therefore not to prevent every AI use. A clear framework should enable useful applications without giving away sensitive information or professional responsibility.
The data traffic light before every prompt
Before you insert text or upload a file, assign the information to one of three levels. The traffic light does not replace an internal policy, but it creates a quick first boundary.
| setting | Examples | Practical decision |
|---|---|---|
| Green | Publicly published information, self-invented sample data, general formulation tasks | Only use in an allowed tool and check the result professionally. |
| Yellow | Internal processes without names, non-public drafts, aggregated key figures, own work knowledge | Check approval and tool conditions; in case of doubt, anonymize or ask internally. |
| Red | Customer and employee data, health data, contracts, access data, source code, price lists, trade secrets | Do not enter or upload into an unverified public tool. |
Important: Removing names is not always enough. A combination of function, location, project, date, and facts can still make a person or a company identifiable. True anonymization is more than replacing a name with "Person A". Where the content cannot be reliably defused, it stays out of the tool.
The five-second check before sending
Ask yourself five short questions for every professional AI input:
- Am I allowed to pass on this information at all?
- Is exactly this tool approved for the task?
- Does the AI need the full content or is a neutral pattern sufficient?
- Can I professionally control and take responsibility for the result?
- Would I also show the input to my manager, IT, or data protection office?
A single "no" or "I don't know" is a stop signal. First, formulate an abstract example or ask for the intended system. This takes a few minutes and is usually faster than dealing with the aftermath of an unclear data transfer.
You should be particularly careful with automatic functions. A meeting bot can capture more than the spoken order. A browser extension can have permissions for multiple pages. An AI function in well-known software can have different contract or storage conditions than the rest of the service. Therefore, check not only the product name but the specific function and the account used.
What employees should classify legally and organizationally
The Chamber of Labour Styria on AI in the working world states that AI as a tool does not fundamentally exclude personal work performance. However, employees remain responsible for their work and must observe data protection, personality rights, copyright, trade secrets, and operational requirements.
Since February 2, 2025, Article 4 of the EU AI Act on AI literacy has also been in effect. The current Questions and Answers page of the European Commission explains that providers and operators of AI systems must take measures to develop the AI literacy of their staff. Since the beginning of August 2026, the rules on supervision and enforcement have also been in effect. According to the Commission, the obligation does not mean that every single person must pass a test. Rather, measures should take into account knowledge, experience, and the context of use.
For employees, this does not result in permission to use any tools they want. Rather, it shows why companies need understandable rules, suitable systems, and task-related training. The jobspot guide Building AI competence on the job offers a personal learning plan for this.
Accidentally entered data: These six steps count
A mistake should not be covered up. The sooner the responsible department knows the facts, the sooner it can limit access, contact providers, and assess reporting obligations. Proceed objectively:
- Stop usage. Do not send any further prompts and do not upload any supplementary files.
- Do not promise your own cleanup. Only delete the chat if internal policy requires it. A click on "Delete" does not automatically prove that all copies have been removed from the provider.
- Secure facts. Note the tool, account type, time, type of data, affected persons or projects, and the action performed. Do not unnecessarily copy sensitive content into new channels.
- Report internally. Inform the designated department immediately, such as manager, IT security, data protection officer, or incident team.
- Follow instructions. The company assesses contracts, logs, possible deletion requests, risks, and further steps.
- Secure access data immediately. If a password, token, or API key has been disclosed, the responsible access must be blocked or renewed quickly.
The WKO guideline on the legal framework recommends reporting serious AI errors or data breaches to the responsible department immediately. Whether a reportable data breach actually exists is not decided by the affected employee alone. According to Article 33 of the GDPR, the responsible organization must generally report a breach to the data protection authority immediately and, if possible, within 72 hours, provided it likely poses a risk to the rights and freedoms of natural persons. The DPA explains the reporting procedure for data breaches.
The 72 hours are therefore not a time buffer for internal waiting. Employees report immediately; data protection and security officers then check whether and how the authority or affected persons are to be informed.
How to ask for an approved AI tool
A mere ban rarely solves the work need. Anyone who regularly needs to structure texts, summarize information, or create variants should name the concrete benefit and the required protective measures. An objective request can look like this:
"For the recurring task of converting longer public technical texts into an internal structure, an AI tool could save time. Which system and which account are approved for this? I would not use any personal or confidential content and would check the result professionally. If no tool is provided yet, to whom can I submit the use case for review?"
A good request contains the task, data type, expected benefit, and human control. It does not immediately demand a specific brand. This allows IT, data protection, and the specialist department to check whether an existing system is sufficient or if another solution is necessary.
Companies, for their part, should not just distribute a long list of prohibitions. Employees need an easily accessible list of allowed tools, permissible data classes, contact persons, inspection obligations, and reporting channels. The WKO template for operational AI guidelines shows which points an internal agreement can cover.
Three practical cases from Austrian companies
The HR manager and the application documents
An HR manager wants to have ten resumes summarized by a public chatbot. Even if she removes the names, employers, educational paths, and time details can make persons identifiable. In addition, the evaluation concerns an important decision for applicants. The documents therefore do not belong in the unverified tool. More sensible are an approved system, a documented purpose, defined access, and a real human assessment.
The technician and the error message
A technician copies a log excerpt into an AI because he wants to explain a rare error message. However, the text contains internal server names and an access token. He stops the process, informs IT security immediately, and has the key renewed. Afterward, the team creates a cleaned-up example schema for future requests. A professionally correct reaction here means: limiting the error quickly and improving the process.
The project manager and the meeting minutes
A project manager wants to linguistically shorten internal minutes. Instead of uploading the document, she first creates a neutral outline without names, numbers, or project details and has only this structure processed. For the actual content, she uses the approved office software. She thus reduces data without doing without every AI support.
Checklist for everyday work
- I know the company AI policy or know where to find it.
- I only use approved tools and the intended company account.
- I check data class and confidentiality before every prompt.
- I replace real cases with neutral patterns or invented data whenever possible.
- I do not upload contracts, personnel files, customer data, or access data unverified.
- I check facts, figures, sources, and the Austrian legal context of the output.
- I mark uncertainties and let humans make important decisions.
- I report an accidental transmission immediately via the intended channel.
In addition, it is worth taking a look at typical attack patterns. The jobspot article Recognizing phishing and protecting data explains basic warning signs for links, logins, and digital identities.
FAQ on Shadow AI at work
Is the use of a public AI tool at work always prohibited?
No. Decisive factors are operational requirements, task, data, tool conditions, and applicable law. Even with public information, the tool should be approved and the result checked.
Is it enough to remove names from a document?
Not necessarily. Other features can make persons or companies identifiable. Furthermore, trade secrets can exist even without personal data.
Am I allowed to use AI via my private smartphone?
The private device does not change the professional content. Anyone who processes internal data via a private account or a private device can additionally bypass operational protective measures.
Can I simply delete an accidental upload?
You should not rely solely on the visible delete function. Stop usage, document the necessary facts sparingly, and report the incident internally. The responsible department will clarify further measures.
What should a good operational AI rule contain?
At least allowed tools and accounts, permissible data types, prohibited inputs, inspection obligations, documentation, contact persons, training, and the reporting channel for errors.
Conclusion: Working safely starts before the prompt
Shadow AI usually arises not from malicious intent, but from time pressure and a lack of alternatives. Nevertheless, an unverified input remains a real risk. Employees act professionally when they classify data in advance, use only approved systems, check outputs professionally, and report errors immediately.
For the next workday, one concrete step is enough: Find out which AI tools are allowed in your company and to whom you can report a new use case. If both are missing, speak to your manager, IT, data protection office, or works council. A clear process turns secret improvisation into a responsible work aid.