Shadow AI in Agencies: Opportunities and Risks

Shadow AI in Agencies: Opportunities and Risks in Practice
The use of Shadow AI has become a significant topic in marketing and communication agencies in the German-speaking region. The phenomenon is a double-edged sword: on the one hand, there are immense opportunities for efficiency gains, and on the other hand, there are risks that cannot be ignored. The urge for innovation, in particular, clashes with a lack of control mechanisms.
Extent of Shadow AI Usage in Germany
One of the most important aspects in the discussion about Shadow AI is the extent of its usage. A study by iBusiness shows that in Germany, 23 percent of professionals use unauthorized AI tools daily. Another 29 percent use them weekly and 12 percent monthly (Source: iBusiness). Internationally, the proportion of users who use AI without authorization stands at an impressive 64 percent.
These figures are particularly relevant for agencies, as they show that technical and creative teams often do not adhere to the official guidelines of company management. Only 26 percent of companies officially offer their employees access to generative AI, while 17 percent are planning this step (Source: Bitkom). In 8 percent of companies, private tools like ChatGPT are already frequently used, and in 17 percent, there are at least isolated cases.
Smaller and medium-sized agencies (20-99 employees) are particularly affected. While 43 percent of companies with more than 500 employees provide access to generative AI, only 23 percent of smaller businesses do so (Source: Bitkom). This discrepancy indicates that small and medium-sized agencies are particularly susceptible to the uncontrolled use of Shadow AI.
Motivations and Drivers of Shadow AI Usage
Agencies need to understand the reasons why employees use unauthorized AI tools. Often, the reasons are very pragmatic: one-third of users state that Shadow AI helps them speed up their work. At the same time, 75 percent of users expect concrete productivity benefits that they can achieve through the use of generative AI. Particularly interesting is that 29 percent of users acquire skills through Shadow AI that their company does not provide (Source: iBusiness).
For agencies, these figures are indicative: employees resort to Shadow AI to compensate for missing internal tools and training offers. However, the use of unauthorized technologies can quickly become an organizational challenge. What at first glance appears to be a useful work aid can lead to serious problems if used incorrectly or unchecked. An example is the use of ChatGPT for processing client projects without clarifying data protection issues. This poses a significant risk for compliance with regulations such as the GDPR.
Risk Landscape for Agencies: Data Protection and ROI Measurement
A major problem with the use of Shadow AI lies in the area of data protection and client data. Marketing and communication agencies work daily with sensitive information: campaign data, client lists, creative assets, strategic insights. The uncontrolled entry of this data into private AI tools that do not have explicit data processing agreements can lead to serious GDPR compliance risks. The Netskope report shows that 60 percent of users use personal, unmanaged apps that offer no data protection guarantees (Source: Netskope).
Another problem with the use of Shadow AI concerns the measurability of the Return on Investment (ROI). An MIT study shows that informal Shadow AI usage systematically complicates the measurability of ROI. Since many employees use private tools without official tracking, the actual productivity contribution remains unclear (Source: MIT-Studie). For agencies, this means it is almost impossible to quantify which efficiency gains are attributable to approved systems and which to the use of Shadow AI.
The challenges thus lie on several levels: On the one hand, agencies must ensure that data protection standards are adhered to, while at the same time ensuring that the use of Shadow AI is officially recorded and appropriately measured.
Governance Status and Recommendations for Action for Agencies
Regarding the governance status, it appears that many companies have already started to develop rules for the use of AI. Nevertheless, only 23 percent of German companies have established clear guidelines for AI use, while 31 percent are planning to do so (Source: Bitkom). Almost three-quarters of agencies currently have no formal AI policies. Furthermore, there are companies that fundamentally oppose AI governance rules (16 percent) or have not yet dealt with them (24 percent).
For agencies, it is essential to implement formalized AI policies as a recommendation for action. These internal guidelines must clearly define which tools are allowed and how data may be handled. An authorized AI infrastructure is urgently needed to avert Shadow AI. The Netskope report shows a clear trend: companies are centralizing around enterprise-driven ecosystems or genAI platforms (Source: Netskope). These controlled solutions create the conditions for the secure use of AI technologies.
Another important step is the training and qualification of employees. Prohibitions alone cannot prevent shadow IT (Source: iBusiness). Structured further education can create a secure environment that reduces the pressure to use private tools.
Finally, new business areas are also opening up for agencies. Consulting services on data protection, AI governance, and risk analyses are becoming increasingly important for many corporate clients. Here, agencies can impress with expertise and tailored solutions.
Technological Dimension: The Role of AI Agents
Another technological dimension that agencies should keep in mind is the use of AI agents. An IBM study shows that 99 percent of developers are exploring or developing AI agents, which creates a new form of Shadow AI infrastructure (Source: IBM). For agencies, the trend towards agent-driven workflows presents a new challenge. Processes such as automated campaign optimization or content creation can quickly become uncontrolled if not managed proactively.
The Netskope report warns that AI agents are often tightly interwoven with corporate data and critical workflows without central governance structures being in place (Source: Netskope).
Conclusion
The use of Shadow AI presents agencies with both opportunities and risks. While there is a clear drive for efficiency gains and innovation, without formal policies and clear structures, agencies risk losing control over sensitive data and processes. Through targeted measures such as the introduction of AI governance rules, the creation of an authorized infrastructure, and targeted employee training, agencies can leverage the benefits of AI technology while overcoming its challenges.
I look forward to exchange and networking!
If you are interested in AI integration in agency processes or would like to share your own experiences, let's connect on LinkedIn.
Sources

Mario Lohe
General Manager with 15+ years of experience in business operations, agile transformation, and AI enablement. Former Director of Operations at Havas Creative Group, Head of Operations at Audiencly. Certified: CSPO, CSM, ISO 31000, Systemic Coach (DCA).
Verwandte Artikel

Shadow AI in Companies: Opportunities, Risks, and Smart Mitigation Strategies
Shadow AI has long since arrived in the corporate world - often unnoticed, highly productive, but with serious risks for security, compliance, and reputation. In this post, I show what...

I canceled my OpenAI account. And here's why.
Disclaimer. Why this text is not 'just drama.' I didn't cancel my OpenAI account out of frustration with a feature, a prompt, or a bill. It's not about complaining about...

Agentic AI 2026: Opportunities and Challenges in Focus
Agentic AI represents a paradigm shift in machine intelligence. High-quality data is key for successful implementations....

