AI tools give teams a real productivity leap: faster writing, summarising, analysing and programming. But without central policy a blind spot appears in which business data drains away. The Dutch Data Protection Authority (AP) warns that the use of AI chatbots in the workplace is leading to more and more data breaches: in 2024 and 2025 the regulator received dozens of reports of sensitive information shared through chatbots, and the number is growing.
Shadow AI — AI tools that employees use on their own initiative, outside the organisation's view and control. Often free versions, where it is unclear how entered data is stored and whether it is used to train models.
The benefits are real
Employees draft a proposal in minutes, summarise long documents or have code reviewed. For many organisations AI has quickly become a natural tool, often faster than policy could keep up. Banning it does not work: the tools are everywhere and it costs you the head start.
The downside
When there are no agreements, employees paste sensitive information into public AI tools: customer data, contracts, personnel files, source code. According to the AP, free versions are particularly risky because data may be retained and possibly used to train models further. The risks in a row:
- Data breaches when personal or confidential information ends up in external tools.
- Loss of intellectual property when engineering or business knowledge leaks away.
- Hallucinations: convincing but incorrect output taken for truth.
- Shadow AI: a sprawl of tools nobody manages, secures or can switch off.
A workable AI policy
The answer is to set boundaries. Designate approved tools, with business licences in which data is not used for training. Classify which data may and may not go into AI. Train employees in safe use and in checking output. Offer copilots that run inside your own secured Microsoft 365 environment, so the tempting free alternatives become unnecessary. And record who is responsible; since the AI Act, AI literacy is also a legal duty.
Frequently asked questions
May an employee put customer data into ChatGPT?
Not in a free or personal version. Sharing personal data with an external party without agreements is a data breach under the GDPR. With a business licence, a data processing agreement and a data classification it can be done, within the agreed limits.
Is Microsoft 365 Copilot safer than separate tools?
Copilot works within your own tenant and respects the existing permissions on files; data is not used to train the models. The condition is that those permissions are correct, otherwise Copilot also finds what is shared too widely.
How do I find out which AI tools are already in use?
The logging of your firewall or Microsoft Defender for Cloud Apps shows which AI services are accessed from the network. Combine that with a short, honest inventory with the teams themselves.
Opportunity and risk, but with the right set-up mainly opportunity. Qteco helps with drafting AI policy and with AI solutions that are secure and usable.
Sources
- Caution: use of AI chatbot may lead to data breaches — Autoriteit Persoonsgegevens
- AI-gebruik leidt tot meer datalekken — Binnenlands Bestuur
Read also
When AI Recruited Its Own Reinforcements
The government is waking up. Is your boardroom still asleep?
Ready to run worry-free?
Book a no-obligation introduction. We map your IT and security and show where the difference lies.
Book a call →
