Blog

Shadow AI and GDPR: 7/30/90 day action plan for CIOs and DPOs

Decorative illustration for title frame

To immediately reduce GDPR risks linked to Shadow AI, launch three actions in parallel: map real uses (proxy logs, anonymous survey), provide approved alternatives hosted in the EU, and deploy technical controls (DLP, CASB, gateway LLM) within 90 days. This is the roadmap that DSI and DPO can activate this week.

The EDPS formulates it unambiguously: Shadow AI generates non-inventoried processing, without AIPD or DPA, directly exposing the data controller to serious GDPR violations. Governance, secure alternatives, technical controls and awareness constitute the four recommended areas of response. (Source)

Who does what, and when:

D+7 (DSI + DPO)

1. Extract 30-day proxy and DNS logs to identify rogue AI domains.

2. Launch an anonymous survey among the teams to measure the real extent of usage.

3. Decide on temporary bans targeted on the most exposed tools (e.g.: ChatGPT general public version on HR and legal positions).

D+30 (DSI + DPO + HR)

1. Finalize the complete mapping and classify the data by sensitivity.

2. Publish a one-page AI charter with a whitelist of approved tools.

3. Make at least one secure alternative available (Microsoft 365 Copilot enterprise, Mistral AI enterprise or local LLM via Ollama).

D+90 (DSI + DPO + professions)

1. Deploy CASB, DLP and gateway LLM to route AI traffic in a controlled manner.

2. Complete the DPA (article 28 GDPR) for each validated tool.

3. Launch the AI ​​ambassador program and measure the percentage of LLM traffic routed via gateway.


Key points

Reducing GDPR risks linked to Shadow AI requires a simultaneous response on three fronts: usage mapping, approved alternatives hosted in the EU, and technical controls deployed within 90 days.

PointDetails
Act in 7 daysExtract proxy logs and launch an anonymous survey to measure the true extent of undeclared AI uses.
Provide alternatives before blockingDeploying Microsoft 365 Copilot for business, Mistral AI or Ollama reduces the shift to out-of-control personal devices.
Combine 5 to 8 detection methodsProxy, CASB, DLP, DNS, endpoint and audit invoices make it possible to achieve coverage estimated between 70% and 90% of detectable Shadow AI.
Validate DPA and AIPD before any deploymentAny AI tool processing personal data requires an Article 28 contract and, for high-risk uses, prior AIPD.
Safe-doc as a layer of protectionStateless pseudonymization upstream of each LLM call reduces residual risk and produces audit proof that can be used by the DPO.

Table of contents

What is Shadow AI, and how does it differ from Shadow IT?

Shadow AI refers to all artificial intelligence tools used by employees without validation or supervision from the IT department or DPO: generative chatbots like ChatGPT (OpenAI) in the general public version, coding assistants like GitHub Copilot on personal accounts, audio transcription bots, or even image generation tools. Usage is often banal and in good faith. The risk is structural.

Three concrete examples illustrate how Shadow AI arises on a daily basis:

  • A lawyer pastes a draft client contract into ChatGPT to obtain a quick summary, without realizing that the text passes to servers outside the EU.
  • An HR manager uses an online transcription tool to transcribe recruitment interviews containing sensitive data.
  • A developer integrates an unapproved LLM API into an internal pipeline, creating an undocumented data flow.

Classic Shadow IT (an unapproved SaaS tool, a personal Dropbox share) already poses governance problems. Shadow AI goes further on three specific points. First, the data injected into a prompt can be used to train the model at the provider, which a simple storage tool cannot do. Next, almost all consumer LLMs operate from American servers, which constitutes a transfer outside the EU subject to the requirements of Chapter V of the GDPR. Finally, processing carried out via an LLM is rarely inventoried in the register of processing activities, making any AIPD impossible to produce in the event of an audit.


What are the concrete GDPR risks of Shadow AI for your company?

The risks of Shadow AI covers six categories, each with a priority parade. The table below summarizes the most exposed types of data and their level of GDPR impact.

Data typeShadow AI usage examplesGDPR impactAdditional risk
Customer dataContract summaries, CRM pasted in promptHigh (art. 28, 32)Transfer outside the EU, loss of business secrecy
HR dataCV, interviews, evaluationsHigh (sensitive data art. 9)AIPD mandatory if scoring or automated sorting
Intellectual propertySource code, patents, strategyMedium to highLoss of confidentiality, competitive risk
Financial dataFinancial statements, forecastsHigh (business secrecy)Violation of sectoral regulatory obligations

On a legal level, three texts directly govern the situation. Article 28 of the GDPR requires a data processing agreement (DPA) with any supplier processing personal data on behalf of the controller. Article 32 imposes appropriate technical and organizational measures. Chapter V conditions any transfer outside the EU to adequate guarantees (adequacy decision, standard contractual clauses). The AI ​​Act adds a layer: high-risk uses (resume sorting, customer scoring, monitoring) require specific compliance assessments before deployment.

Non-inventoried Shadow AI processing is, by definition, processing without a documented legal basis, without verifiable security measures and without the possibility of exercising the rights of individuals (access, rectification, deletion). In the event of a CNIL control, the absence of DPA and AIPD constitutes a serious violation, independently of any actual data leak.

The practical consequences go beyond administrative fines. A company unable to respond to a request for access or erasure because data has passed through an undocumented LLM finds it legally impossible to honor the rights of the persons concerned. The loss of business secrecy is often irreversible.


How to build a prioritized action plan in 5 steps for DSI and DPO?

A five step plan structured over 90 days allows you to move from prohibition to supervision without blocking productivity.

Step 1 - Flash audit (D+7, DSI)

1. Extract proxy/DNS logs and identify the 10 to 15 most used AI domains.

2. Cross-reference with cloud invoices and browser extensions installed on workstations.

3. Launch an anonymous survey of 5 questions to measure frequency and use cases.

Step 2 - Mapping and classification (D+30, DSI + DPO)

1. Build a versioned Shadow AI registry: tool, frequency of use, type of data injected, department.

2. Apply the sensitivity × volume matrix: “confidential/critical” uses take immediate action.

3. Classify the data according to GDPR categories (ordinary data, special categories art. 9).

Step 3 - Charter and whitelist (D+30, DPO + HR)

1. Write a one-page AI charter: scope, authorized tools, prohibited data, request procedure.

2. Publish the whitelist with at least three validated alternatives (see next section).

3. Obtain the signature of the executive sponsor (CEO or CIO) to give weight to the policy.

Step 4 - Secure alternatives (D+30-60, DSI)

1. Deploy Microsoft 365 Copilot in the enterprise version, which offers contractual guarantees of non-reuse of data not available in the general public versions.

2. Evaluate Mistral AI (European player) for sensitive textual uses, with hosting on Scaleway or OVHcloud in France.

3. Test Ollama for local deployment (on-prem) on internal workstations or servers, eliminating any network transfer.

Step 5 - Technical controls and ambassadors (D+90, DSI + professions)

1. Deploy CASB, DLP and gateway LLM (see next section).

2. Appoint an AI ambassador per department to relay the policy and raise needs.

3. Measure the percentage of LLM traffic routed via gateway as the main KPI.

Pro tip: Don't start with the ban. [Provide attractive alternatives before blocking](https://www.automatisation-intelligence-artificielle.fr/blog/shadow-ai-risques-entreprise/) reduces the risk of moving to personal devices or VPNs, which are much more difficult to monitor.


How to build a prioritized action plan in 5 steps for DSI and DPO? - overview diagram

What technical controls make it possible to detect and block unauthorized AI uses?

No single method is enough. Combine at least five to eight complementary methods achieves detection coverage estimated between 70% and 90% of detectable Shadow AI.

Catalog of controls to combine:

  • TLS/SNI and outbound proxy inspection: identify connections to OpenAI, Anthropic, Mistral, and other known LLM providers APIs, without full content decryption.
  • CASB (Cloud Access Security Broker): apply access policies to cloud AI applications, with identity control and session logging.
  • DLP (Data Loss Prevention): detect sensitive data patterns (SIRET numbers, personal data, standard contractual clauses) in outgoing flows before they reach an LLM.
  • DNS Monitoring: identify resolutions to IA domains not listed in the whitelist.
  • Endpoint monitoring: monitor browser extensions and local processes that may call LLM APIs directly.
  • Cloud invoice audit: identify AI subscriptions paid by personal card or via shadow accounts.
  • SIEM with AI rules: correlate events (unusual connections, abnormal outgoing data volumes) to detect undeclared uses.
  • IAM/SSO integration: force single sign-on for approved AI tools, making usage traceable and access revocable.

For SMEs, priority goes to proxy logs and DNS monitoring, which can be deployed quickly without heavy infrastructure. Mid-sized companies and large companies add CASB and DLP for finer coverage. Blind spots to watch out for: APIs called directly from scripts (bypass the proxy), desktop extensions installed outside of MDM, and usage from unmanaged personal devices.

Pro tip: Aligning CASB, DLP and identity control at the flow level, not just the network level, is the recommendation of security teams for a truly effective control architecture. A network blockage alone drives users to their phones.


Documentary pseudonymization: how to neutralize the GDPR risk at the source?

When an employee absolutely must use a public LLM for a sensitive document, upstream pseudonymization is the most direct technical measure to reduce the residual risk. It does not replace network controls, but it neutralizes the main threat: the exposure of identifying data to a non-contractual third party.

When to pseudonymize?

Priority use cases are HR documents (CVs, evaluations, employment contracts), customer contracts containing personal data or confidential clauses, and any financial document injected into an analysis prompt.

Typical operational flow:

StepActionResponsible
1. PreparationAutomatic detection of 90+ types of PII and confidential data in the documentSafe-doc (API or web interface)
2. PseudonymizationReplacement of sensitive entities with neutral tokens, without storage of the original documentSafe-doc (stateless mode)
3. LLM CallSending the pseudonymized document to ChatGPT, Claude or other LLMUser or automated pipeline
4. ResultRecovery of the LLM response on pseudonymized dataUser
5. CateringDeanonymization controlled via mapping export, if necessaryCIO / authorized user

This flow is integrated both on the browser side (extension or web interface) and on the server side via the REST API or the Safe-doc MCP connector. The PDF audit report generated for each processing constitutes proof of auditability that can be directly used during a CNIL inspection.

Integration checklist for DSI and DPO:

  • Check that the DPA Safe-doc covers article 28 GDPR and mentions hosting in the EU.
  • Confirm stateless mode: no document must be stored on the supplier side.
  • Test the mapping export to ensure that restoration is possible in case of operational need.
  • Integrate audit reports into the processing register as proof of technical measures.
  • Check coverage of data types relevant to your sector (health data, financial data, judicial data).

Pro tip: Pseudonymization in accordance with Article 4(5) of the GDPR reduces the level of residual risk of a processing operation, which may reduce the requirements of a DPIA or modify its conclusions. Systematically document this measure in your register.


What legal checklist should be validated before authorizing an AI tool in business?

Before any validation of an AI tool by the DPO, seven checks are necessary. The CNIL and the EDPS converge on these minimum requirements.

Documentary obligations:

  • DPA complies with Article 28 GDPR: the subcontracting contract must specify the purposes, retention periods, security measures and commitments not to reuse data for training purposes.
  • Processing register: each validated AI use must appear in the register with its legal basis, its data categories and its recipients.
  • AIPD (DPIA) for high-risk uses: automated CV sorting, customer scoring, employee monitoring, profiling. The AI ​​Act strengthens this obligation for systems classified as high risk.

Contractual verifications:

  • Explicit commitment to non-reuse of data for model training (to be distinguished from general public CGU which often authorize this reuse).
  • Proof of accommodation in the EU or equivalent guarantees (standard contractual clauses, adequacy decision) for suppliers outside the EU.
  • Logging SLA: the supplier must be able to produce access logs in the event of an incident.

Special cases to watch out for:

  • CV sorting and customer scoring are high-risk uses within the meaning of the AI Act: prior AIPD is mandatory, and the final decision cannot be entirely automated without the right to human appeal.
  • Audio transcription tools processing health or union data fall under Article 9 of the GDPR: reinforced legal basis required.

The CNIL reminds that the GDPR compliance of an AI tool is not limited to the supplier's confidentiality policy. The data controller remains solely responsible for the lawfulness of the processing, the legal basis chosen and the security measures implemented. Consulting the CNIL resources on AI and data protection allows you to anticipate priority control points.

For contracts and DPA clauses, guide to contract confidentiality and artificial intelligence details the wording to be required.


How to deploy AI governance that lasts over time?

An AI policy only lives if it is supported by identified people and measured by concrete indicators. Ban without structure erodes in a matter of weeks; shared governance lasts for 18 months.

The four operational pillars:

1. Executive sponsor (DG or CIO): signs the AI charter, validates the budget for approved alternatives, arbitrates conflicts between productivity and compliance.

2. AI referent (DSI or RSSI): manages the Shadow AI register, coordinates technical controls, reports to the board on quarterly KPIs.

3. DPO: validates the AIPD, signs the DPA, liaises with the CNIL in the event of an incident.

4. AI Ambassadors (one per department): relay policy, collect business needs, report undeclared uses without stigmatizing.

KPIs to follow quarterly:

  • Percentage of LLM traffic routed via approved gateway (target: > 80% on D+90).
  • Number of incidents linked to prompts containing sensitive data detected by DLP.
  • Adoption rate of approved tools vs. unauthorized tools (measured by proxy logs).
  • Results of the quarterly employee survey on knowledge of the IA charter.

Training plan:

  • 30-minute awareness session for all employees: what is Shadow AI, what risks, what tools to use.
  • 90-minute business workshops for high-risk teams (HR, legal, finance): practical cases, demonstration of approved alternatives.
  • Quarterly reminder by email with an example of a recent incident (anonymized) to maintain vigilance.

The technical governance combining continuous discovery, prompt inspection and identity control is essential for French SMEs, where unregulated use remains frequent and where the pure ban has regularly demonstrated its limits.


Why the ban alone does not work in French SMEs and ETIs

Companies that have tried to block access to LLMs without offering an alternative have observed the same phenomenon: uses are moving towards personal devices, 4G/5G connections and consumer VPNs, out of any visibility. The risk does not disappear; he becomes invisible.

The approach that works combines three elements in this precise order: first attractive and efficient alternatives (employees must prefer the approved tool to general public ChatGPT), then technical controls which make unauthorized uses visible without making them impossible, and finally a culture of accountability supported by AI ambassadors. Compliance is not an objective in itself for business teams; productivity, yes. Aligning the two is the only sustainable strategy.

Field feedback in SMEs/ETIs confirms that organizations which involved the professions from the mapping phase obtained significantly faster adoption of the approved tools than those which imposed the policy from top to bottom. Employees who participated in defining the rules respect them better, and report problematic uses more readily.


Safe-doc: pseudonymize your documents before each LLM call

Your teams already use LLMs. The question is no longer to prevent it, but to ensure that sensitive data never passes unencrypted. Safe-doc fits as a layer of protection between your documents and any AI tool: real-time pseudonymization, zero storage, detection of more than 90 types of PII and confidential data.

Safe-doc

Concretely, Safe-doc integrates into your LLM gateway via REST API or MCP connector, or directly into your employees' browsers. Each pseudonymized document generates a PDF audit report, which can be used immediately during a CNIL check or a DPA review. The restoration mapping remains under your control, on the business side.

For legal departments and DPOs seeking a documentable technical response, Safe-doc offers proof that appropriate measures have been taken within the meaning of Article 32 of the GDPR. Visit the page dedicated to DPOs to see how to integrate Safe-doc into your compliance system or request a quick audit of your current AI uses.


Sources

The references below cover the regulatory, technical and operational dimensions addressed in this article. They constitute a solid starting point for documenting your approach during an audit.

Recommendation