Your staff use ChatGPT: how big is the risk?

Somewhere in your company, someone is pasting business data into ChatGPT right now. Not in secret, just to work faster. What it costs when it goes wrong, and how to prevent it without banning AI.

Terence
8 min read

Right now, someone in your company is probably using ChatGPT. Not to slack off, but to write an email faster, summarise a complaint, or translate a piece of text. Handy. The problem: you usually have no idea exactly what information goes in. And that is where the risk lives. When your staff use ChatGPT without any agreements, confidential business data can quietly end up on a system you do not control. This phenomenon has a name: Shadow AI. In this article you will read how big the risk really is, what the law says about it, and, more importantly, what you can do about it without banning AI entirely.

What is Shadow AI?

Shadow AI is AI use that happens out of the organisation's sight. Your staff discover that ChatGPT, Gemini or Claude makes their work faster and start using it, without anyone having agreed what may and may not go in. Dutch public broadcaster NOS covered it in June 2026: at organisations without clear agreements, employees start using ChatGPT on their own and feed it data containing personal or company details, without realising it.

The sting is in the good intentions. The employee who pastes a customer file into ChatGPT to quickly produce a tidy summary just wants to do their job well. But that file, with a name, an address, maybe an ID number or medical detail, now sits on a system you do not control. And with the free versions of many AI tools, that material may be used to train the model further.

11%

of what employees paste into ChatGPT is confidential

What can actually go wrong

This is not a doomsday story. It has simply already happened, close to home too.

  • The city of Eindhoven: a sample check revealed that in a single month staff had uploaded more than a thousand documents containing personal data to external AI tools, ID numbers, care records, financially sensitive data. That caused a data breach, reported to the Dutch data protection authority.
  • Amazon: after internal company information turned out to be leaking via an AI model, the tech company reined in employee AI use. Internal documentation was found inside ChatGPT.
  • Your business: a quote with your sharpest prices, a customer list, a deal not yet announced. Pasted once into the wrong tool and you have no idea where it ends up.

The Eindhoven example is the most instructive. Nobody meant any harm. There simply were no agreements. More than a thousand documents in one month, at one organisation. Multiply that across a year and you understand why this is not something to "look at later".

The bill: what does a data breach cost you?

A data breach is not only a privacy problem, it is a cost. Three kinds of costs add up.

  • Fines. If personal data leaks, you fall under the privacy law (GDPR). You must report it within 72 hours to the data protection authority. Fines run up to 20 million euros or 4% of your worldwide annual turnover, whichever is higher.
  • Recovery. Working out exactly what leaked, informing customers, legal advice, sealing your systems. That costs time and money you never budgeted for.
  • Trust. The hardest to win back. A customer who hears that their data has leaked thinks twice before leaving anything with you again.
€20m

or 4% of annual turnover, the maximum GDPR fine

Is it even allowed? What the law says

Two rules matter here, and both already apply today.

  • The privacy law (GDPR): personal data may not simply be sent to an external party. Put a customer file into a free AI tool and you are sharing that data with a company outside your control. In many cases that is simply not allowed.
  • The AI law (AI Act): since February 2025, as an employer you are obliged to ensure your people have sufficient "AI literacy", they must know how to work safely with AI. Doing nothing is therefore no longer a neutral choice; it clashes with a rule that is already in force.

From 2 August 2026 another rule joins them: if your customers are talking to an AI chatbot, you must clearly say so. If you build something with AI in it, you had better set that disclosure up properly from the start. We wrote about that separately in our article on the AI Act for small business.

Banning it does not work. This does.

It is tempting to just ban AI entirely. But that does not work. Your staff use it because it genuinely makes their work easier, ban it and they do it on their private phone, and you see even less. The ethical hacker NOS spoke to put it well: the best thing you can do is facilitate something, so that you can also see how it is being used.

In other words: remove the reason people sneak off to ChatGPT. Give them a safe way to do the same work, inside an environment you control.

  • Make agreements. Half a page is enough: what is allowed, what is not, which information never. People follow rules they understand.
  • Do not use free versions for work. Business versions of AI tools promise they will not use your data to train their model. That is the minimum.
  • Give your team one safe place. Instead of ten separate tools nobody has any view of: one environment you manage that does what your team needs.
  • Explain why. An employee who understands that a pasted customer file can become a data breach stops doing it. Fear does not work, understanding does.

Honestly: Socialo does not sell software that spies on your staff or blocks everything. That is a different trade. What we do is remove the cause, we build the safe place where the work happens, so nobody has a reason to colour outside the lines anymore.

How Socialo approaches this

Our approach does not start with "ban AI" or "roll out AI", but with the question: what is your team actually trying to do with ChatGPT? Often it is a handful of recurring chores, answering customer questions, drafting emails, summarising documents, translating. We rebuild exactly that work in a setup you manage yourself, so the data stays inside your company.

For your employee the difference is zero: the work still goes faster. For you the difference is huge: you know what goes in, your data stays yours, and you meet the rules straight away instead of putting out fires afterwards. Problem first, tool second, not AI for the sake of AI, but a solution to the reason your people are sneaking off to it now.

What you can do this week

Even without us, you can shrink the biggest risk today. Three steps.

  • Ask around. Not accusingly, just: "do you use ChatGPT for work, and what for?" You get honest answers and you immediately know where it pinches.
  • Agree one rule: never put personal data or confidential information into a free AI tool. Introduce it today, free of charge, and it covers the biggest risks.
  • Work out which chores your team hands to AI most often. That list is exactly the basis for a safe setup you can build later.

Ready to get started?

Request a free consultation. We look together at where you are losing time.

Schedule free call

Recognise this in your business?

Schedule a free consultation. We look together at where you lose time, and whether AI is the answer.

Schedule free call