
Shadow AI refers to the unsanctioned use of artificial intelligence tools or applications by employees without the formal approval or oversight of the IT department, leading to potential security risks and compliance issues for organisations. From 2023 to 2024, the adoption of generative AI applications by enterprise employees grew from 74% to 96%, highlighting the increasing prevalence of shadow AI. Over one-third (38%) of employees acknowledge sharing sensitive work information with AI tools without their employers' permission, indicating a significant risk of data leakage and exposure of company data. Shadow AI expands an organisation's attack surface by introducing unvetted third-party applications and APIs, creating new entry points for cyberattacks and increasing potential risks. The lack of visibility in shadow AI creates "blind spots" that can lead to severe security and operational consequences.
Policy without enforcement is just a dream. The combination of clear policy, proper contracts and technical back-up is the only approach that stands up to scrutiny.
This article looks into the security risks, potential risks, and compliance issues raised by shadow AI for UK GDPR, and offers practical advice for compliance teams, IT bods, and business owners who need to keep data safe and stay on the right side of the law. Spotting and dealing with shadow AI is a must, because if you don't, you risk getting slapped with hefty fines, suffering reputational damage and finding out the hard way that improper use of AI tools can be a real threat to your data security.
What happens when you paste sensitive data into ChatGPT - behind the scenes
How data gets transmitted to OpenAI's servers
The moment you paste personal data into ChatGPT, that data, whether copied from the clipboard or uploaded from a file, is sent directly to OpenAI's servers, where it may be used to train or improve AI models. This is what happens when you perform various actions in the browser that put sensitive data at risk, especially when using third-party AI services. OpenAI's default position is that they'll use the data to improve their models but, if you're a business user on a certain plan, you can opt out. However, transmitting sensitive data to external AI models always carries a risk of data leakage.
Browser-based risks and the problem with traditional DLP
When your staff paste data into ChatGPT or upload it from a file, and then decide to click the 'send' button, all that can happen before your traditional data loss prevention solutions have even put up a flag. That's the problem. They usually can't monitor clipboard actions, browser uploads, or pretty much anything else that's going on in the browser, which means they're often blind to the risk of data getting leaked.
The limitations of DLP
To address this you need to put in place a DLP strategy that includes real-time monitoring and access controls to prevent data from getting out in the first place. Audit trails are essential for maintaining compliance and security in AI usage, as they provide a record of all actions taken with sensitive data. Organisations can implement audit trails to monitor user activities, ensuring that any non-compliant actions are logged and reported. Regular audits of AI usage and the associated audit trails can help organisations identify unauthorised activities and ensure that AI tools are used in compliance with established policies and regulations. And you need to keep a record of it all, so you can track who's accessed what data and when, just in case.
When data leaves your organisation's systems and goes off to be worked on by someone else, suddenly you've got a whole heap of new obligations under UK GDPR to worry about. Using unapproved tools can breach all sorts of data protection laws - GDPR, HIPAA, the EU AI Act - you name it.
Understanding all this is crucial if you're going to work out the implications under UK GDPR.
The Shadow AI problem and the growing attack surface
The adoption of generative AI tools in the workplace has gone from 74% to 96% between 2023 and 2024. Alongside this, the use of SaaS apps with embedded AI features is also increasing, often without IT oversight. Employees may access external models via API or other integrations outside the organisation's sanctioned environment, introducing additional risks. Uncontrolled use of AI tools can also lead to unexpected financial costs through consumption-based pricing models affecting SaaS tools. This means more and more staff are introducing Shadow AI into their workflow and creating more and more entry points for cyber attacks and data leaks.
Policy is all well and good but unless you back it up with proper contracts and technical measures then you'll find it's not worth the paper it's written on.
So to answer the question in a nutshell: yes, it's a possibility, and the consequences are serious enough to warrant a closer look.
With the context all set, let's look at the legal side of things and examine the relationships at play when using AI tools with personal data.
The relationship between you and the AI tools you're using
When it comes to UK GDPR, your organisation is usually the one that's in charge of the data, the data controller. You're the one who works out why and how it's used. So if you use a third-party tool to work with that data, then that tool becomes a data processor on your behalf. It's especially important to define clear data boundaries and restrictions for customer data when using AI tools, as mishandling customer data, particularly through shadow AI or unsanctioned tools, can lead to significant security and governance risks.
It's pretty clear in law that if you're processing personal data using a third party tool then you need to have a DPA sorted with the processor. And you need to get formal approval for any AI tool that's going to be used with personal data. The problem is that a lot of the time staff will just use unsanctioned tools without following the proper procedures and that's when you risk getting into trouble for breaching data protection laws.
OpenAI does offer DPAs to business users, but most staff using the free version of ChatGPT won't have one. And if staff are pasting client data into their own ChatGPT account without a DPA in place, then you're probably in breach of Article 28 of UK GDPR before you've even started thinking about the lawful basis for processing the data. Regulatory compliance and risk assessment are key when selecting and approving AI tools to avoid all the hassle and potential fines.
With all this in mind let's take a closer look at the lawful basis for using AI tools to process personal data.
The lawful basis - are you covered?
The lawful basis options
Even if you do have a DPA in place, you still need to be able to explain why you're processing the data. UK GDPR gives you six options to choose from: consent, contract, legal obligation, vital interests, public task, or legitimate interests. For most organisations that are sharing client data with an AI tool, there are a couple of realistic options, a contract (because the processing is necessary for doing a service for the client) or legitimate interests (because you've genuinely got a reason for processing the info, that isn't going to get overridden by the individual's rights).
For example, if your organisation uses an AI tool to automate document review as part of a client service, the lawful basis could be 'contract' since processing the data is necessary to fulfil your contractual obligations to the client. But, when processing personal data with these tools, it's also really important to consider the ethics involved and what the relevant laws actually say, so you're on top of compliance and not using the stuff in an irresponsible way.
Challenges with legitimate interests
The thing is, neither of these options is as easy to get by with as you might have thought. Legitimate interests in particular requires a balancing act, and to be honest, it's hard to argue that just pasting client data into a consumer AI tool for a bit of convenience is going to pass that test, especially if clients haven't been told it might be done and had the chance to say no. Not having a handle on what's going on and not telling people about the risks can lead to serious data breaches and compliance failures, which is why robust risk management is such a big deal.
Transparency and privacy policies
If your privacy policy doesn't so much as mention the use of AI tools to process client data, then you've got a transparency issue, to say the least. Risk management and knowledge sharing are essential to keep things safe, on top of compliance and ongoing trust in your AI processes.
With the lawful basis sorted as a key requirement, let's take a look at what the UK regulator expects from organisations using these tools.
What the ICO has to say on regulatory compliance
ICO guidance - a quick overview
Although the ICO hasn't specifically ruled on ChatGPT, their wider guidance is definitely worth checking out. The ICO expects organisations to:
- Do your homework: on any third party tool that's going to be messing around with personal data
- Get a contract sorted out: before sending any data over
- Be straight up: with individuals about how their data is going to be used
- Assess the risks: take a careful look at the risks of new tech, especially where data might end up being used in ways that aren't exactly what you had in mind
The ICO published a set of 8 questions back in April 2023, that it expects organisations using generative AI to be able to answer, covering lawful basis, controllership, and individual rights. And then they've made it clear through a series of consultations that UK GDPR applies fully to AI tools, with no exceptions just because they're new.
Accountability principle
The ICO's accountability principle (Article 5(2)) means you need to be able to show that you're actually following the rules, not just saying you're going to. If you can't figure out what data went where and on what basis, that's already a big problem in itself.
Security teams and organisations need to apply quality assurance and evaluation processes throughout the AI lifecycle to ensure safety, trustworthiness, and compliance. Your AI initiatives should be designed to support business objectives, with continuous improvement and stakeholder engagement built into the governance framework. AI governance boards are essential for providing oversight, accountability, and strategic guidance in AI adoption, helping manage risks and ensuring that AI adoption actually delivers benefits like innovation and secure alternatives, rather than just imposing restrictions. In sensitive or high-risk scenarios, like social care or healthcare, human intervention remains essential to control decisions and prevent bias.
High-risk scenarios
Some situations are just more risky than others. Here are a few worth thinking about:
Financial services: an adviser pastes a client's portfolio details or pension information into ChatGPT to draft a review letter. This is super sensitive data that the client has no idea is being used, and probably shouldn't be.
Legal and professional services: a solicitor copies a client's brief containing names, addresses and specific details about an ongoing case into an AI tool for summarising. It's not just that this might be confidential, it's also personal data being processed without a DPA in place.
HR teams: an HR manager uses ChatGPT to help draft a performance improvement plan using an employee's name and specific details about their conduct. Employee data is still personal data, after all.
Healthcare-adjacent organisations: any data touching on health, mental health or medical history is special category data under UK GDPR and comes with a whole lot of extra obligations.
In each of these scenarios, the person doing the paste probably isn't even thinking about GDPR, they're just trying to get something done that bit faster. And you know what? That in itself isn't a criticism. It's just how AI tools have been adopted in the workplace, people are focusing on getting the job done and don't really stop to think about the implications, until something goes wrong, that is. But this lack of awareness does mean that the risk is largely invisible until then.
Staying on top of employee education on AI safety and data handling is super critical, as many employees use AI without any formal data security training.
With the regulatory expectations clear, let's look at practical steps organisations can take to manage shadow AI risks.
Practical steps for managing Shadow AI and GDPR compliance
The trouble with just slapping a policy in place is that it relies on every single employee making the right call, all the time, even when they're under pressure and tempted to use a quicker option. That's a pretty tall order.
There's also a big enforcement gap. Even if people are genuinely trying to behave, it's really tough for the compliance or IT teams to know when personal data is being pasted into an AI tool, unless they've managed to catch up with the latest tech and have some tools in place to keep tabs on things. To manage AI tools responsibly, organisations should create structured processes, such as review systems or intake processes, to ensure oversight and mitigate risks.
Getting this right means building a few solid layers:
- Sort out a clear AI usage policy: Work out which tools are okay to use, and which ones aren't. Decide what sort of data (if any) can go into AI tools, and under what conditions. Make it specific and actionable, so people know what's expected of them.
- Get some DPAs in place for approved tools: Make sure you actually set up Data Processing Agreements for any tools that are okay to use, don't just assume they're there.
- Update your privacy notices: Reflect how you're using AI tools in your business. If you're using AI to process clients' data, they need to know that.
- Provide decent training: Not just some token tick box exercise, but real guidance on what's allowed and why the rules exist.
- Implement some technical controls: Tools like Fendr can help detect and block sensitive data from being pasted into AI tools in real time. This gives compliance and IT teams some visibility into what AI tools are being used across the business.
- Leverage existing solutions: Make use of current tools, systems, or resources within your organisation to ensure transparency and oversight when deploying or managing AI and IT infrastructure.
- Use technologies for AI governance, cybersecurity, and compliance: Adopt frameworks and tools that help manage the risks associated with shadow AI and unauthorised AI use.
The combination of a clear policy, some proper contracts, and a bit of technical back-up is what actually holds up to scrutiny. Any one of those things on its own leaves gaps.
Proactive strategies for managing shadow AI include establishing clear policies, providing secure alternatives, and continuous monitoring of AI usage. Data Loss Prevention (DLP) is a system of technologies designed to identify and safeguard sensitive enterprise data from unauthorised disclosure, which is increasingly critical in a remote work environment. Organisations must implement DLP strategies that include real-time monitoring and control of sensitive data to prevent accidental or malicious data exposure, especially as employees increasingly use personal devices for work.
With these steps in place, organisations can better handle the risks of shadow AI and keep on top of compliance.
Summary: Is pasting client data into ChatGPT a UK GDPR violation?
Pasting client data into ChatGPT without getting proper approval and data processing agreements in place is essentially shadow AI, which can break strict data protection laws like GDPR and lead to data breaches, regulatory non-compliance and reputational damage. Shadow AI, including the unsanctioned use of AI applications and shadow AI tools by employees, often slips past established security and governance protocols, increasing the risk of unauthorised data exposure. To reduce shadow AI risks, organisations must monitor genAI use, identify and manage shadow AI tools and AI applications, and ensure data quality for trustworthy AI usage. This requires clear policies, secure contracts, employee education, and technical controls to monitor and manage AI usage.
The ICO has made it clear that existing data protection law still applies to AI tools. The question is, do you have the controls in place to actually follow the rules? If you have no idea what your employees are putting into AI tools right now, that's probably the first thing you should go and identify.
Ready to see what your team is actually using?