"We don't use AI" - Really?

Shadow AI in German Companies: The Unrecognized Wave of AI Usage
In today's corporate landscape, AI is often touted as a future technology, but the reality is different: companies have already started using AI, sometimes without even realizing it. The phenomenon of shadow AI describes this trend, where employees use unauthorized, often personal AI tools to optimize their work processes. The 2025 Bitkom report reveals that 8% of companies report widespread use of such unauthorized tools, while 17% have observed them at least in individual cases [Bitkom]. Shadow AI is not only ubiquitous in the private sector but has also taken root in the public sector. Here, 45% of federal administration employees use tools that are not officially approved [Microsoft].
The unregulated use of shadow AI usually arises out of necessity. While companies struggle to remain competitive and drive innovation, the provision of secure AI tools often falls short of employee expectations. Many companies have not yet established comprehensive guidelines for AI use: only 23% of companies have set concrete rules, while 31% plan to do so, and 24% have neglected the topic so far [Bitkom]. These regulatory deficits provide fertile ground for shadow AI, as the availability and low-cost accessibility of consumer tools like ChatGPT entice employees to integrate them into their daily work.
Nevertheless, the use of shadow AI carries significant risks: data protection concerns and the danger of security gaps are just the tip of the iceberg. Since these tools are used without official authorization, compliance with the General Data Protection Regulation (GDPR) is often not guaranteed, making companies vulnerable to penalties [Proliance]. Centralized control and clear communication about permitted and tested tools are therefore essential to proactively counter shadow AI and minimize legal risks.
Reasons for the Spread of Shadow AI and Its Consequences
Why is shadow AI so widespread? One of the main reasons lies in the accessibility of AI tools and the lack of offerings from companies. Only 26% of companies officially provide their employees with AI tools, meaning that the majority of the workforce relies on untested alternatives. Dr. Ralf Wintergerst, President of Bitkom, emphasized that AI has long become a standard technology, and the urge to use it in a work context is growing stronger [Bitkom].
Furthermore, there is often a lack of clear and communicated guidelines regarding the use of AI in companies. Employees, under increasing pressure, try to find creative ways to increase their efficiency and productivity - even if this means using unauthorized tools. In sectors like finance, where 65% of customer communication employees use shadow AI, this trend is particularly pronounced [Springer Professional].
Alarmingly, shadow AI not only brings internal risks but also jeopardizes external compliance. A lack of transparency in data processing and insufficient knowledge of the tools used often lead to violations of internal and external policies, which can result in potentially high fines [Proliance]. Moreover, they pose the risk of becoming gateways for cyberattacks, as the security standards of such tools are often unknown or inadequate.
The consequences for companies are manifold: security incidents due to data leaks, inefficient work processes due to uncoordinated tool usage, and potential financial damages due to GDPR violations. But despite these dangers, shadow AI tools are widely used thanks to their availability and user-friendly handling.
Opportunities Through Targeted AI Implementation
While the risks of shadow AI should not be underestimated, properly integrated AI programs offer significant opportunities. Companies that proactively address the challenge and implement AI programs structurally report significant efficiency and productivity gains. One example is the automation of routine tasks, which can significantly reduce time expenditure. This leads to higher employee satisfaction, as employees can concentrate on value-adding tasks [Proliance].
Best-practice companies rely on clear IT governance to displace shadow AI. Larger companies, especially those with more than 500 employees, show that the provision of approved AI tools not only reduces uncontrolled proliferation but also offers a competitive advantage [Bitkom]. These companies have not only established clear written guidelines for the use of AI but also ensure that all employees understand and can implement them. Practical training and a transparent system of responsibilities are crucial success factors.
A proactive approach to AI management not only increases efficiency but also strengthens the market position of companies. Firms that systematically rely on AI report increased competitiveness through more accurate data analysis and optimized business processes. In a future where AI plays an increasingly central role, companies that act now and implement clear guidelines can achieve a clear advantage in the long run.
Conclusion: The Path to Controlled AI Use in Companies
For companies, especially in the DACH region, the challenge is clear: to identify shadow AI and minimize risk factors while harnessing the opportunities that AI offers. It is not enough to integrate AI into existing processes - it must be done with caution and governance. Companies should not shy away from using artificial intelligence but equip themselves with the necessary tools and strategies to use it securely.
Marketing and communication agencies, which increasingly work with sensitive data, must be particularly vigilant. The introduction of a clearly defined AI framework that specifies which tools are allowed and which data may be used in which contexts is essential. Regular audits and the adaptation of internal policies ensure that AI usage proceeds in controlled and secured channels.
Ultimately, the understanding is confirmed: companies already use AI - however, its deployment should be guided by clear rules and sound governance. Only then can risks be minimized and the full potential of AI be unlocked. The future belongs to those who consciously and responsibly integrate AI into their workflow.
I look forward to exchange and networking!
If you are interested in AI integration in agency processes or would like to share your own experiences, let's connect on LinkedIn.
Sources

Mario Lohe
General Manager with 15+ years of experience in business operations, agile transformation, and AI enablement. Former Director of Operations at Havas Creative Group, Head of Operations at Audiencly. Certified: CSPO, CSM, ISO 31000, Systemic Coach (DCA).
Verwandte Artikel

Shadow AI in Companies: Opportunities, Risks, and Smart Mitigation Strategies
Shadow AI has long since arrived in the corporate world - often unnoticed, highly productive, but with serious risks for security, compliance, and reputation. In this post, I show what...

I canceled my OpenAI account. And here's why.
Disclaimer. Why this text is not 'just drama.' I didn't cancel my OpenAI account out of frustration with a feature, a prompt, or a bill. It's not about complaining about...

Agentic AI 2026: Opportunities and Challenges in Focus
Agentic AI represents a paradigm shift in machine intelligence. High-quality data is key for successful implementations....

