← All insights

Shadow AI: Why the Board Needs to Know This Risk

Published: 25 March 2026

Shadow AI: Why the Board Needs to Know This Risk

Your employees use AI. Daily. And, in all likelihood, without your knowledge. That is not an IT problem. It is a governance challenge, and the board is responsible for it.

What happens when no one is watching

Shadow AI refers to employees using AI tools without formal approval from IT, security, or compliance. The phenomenon is the next stage of the shadow IT problem organisations have known for years, but it differs in one essential way: while shadow IT is mainly about infrastructure and applications, shadow AI actively processes company data. Employees feed text, documents, source code, or financial data into external language models, without the organisation knowing about it or being able to control the data flows.

The numbers are an eye-opener. According to the IBM Cost of a Data Breach Report 2025, a global report covering multiple countries and sectors, one in five organisations surveyed had a security incident caused by shadow AI. The additional cost per incident averaged US $670,000. At the same time, only 37% of the organisations surveyed had policies in place even to detect uncontrolled AI use. In other words, most companies simply have no visibility into what is happening.

Why this concerns the board directly

Shadow AI is, first and foremost, a governance problem, and only secondarily an employee problem. When employees turn to unauthorised tools, they are not doing so out of bad intent, but because the organisation has not given them adequate alternatives. Efficiency pressure in day-to-day work, combined with the free availability of powerful AI tools, creates a situation in which employees weigh the perceived benefits more heavily than risks they are often not even aware of.

What many overlook: shadow AI is not confined to individual employees. Board members and executives can behave in much the same way, without being fully aware of the risk: anyone who feeds board papers, strategy documents, or confidential information into unapproved tools creates the same risk, at the highest level of confidentiality.

There is also a structural challenge that obscures the problem: AI functions are now embedded in standard software. Translation tools, design applications, or writing aids are not perceived as AI in everyday work, yet they process highly sensitive content through cloud services. In my own leadership roles, I have seen employees use such tools regularly even where the use of external cloud services was prohibited. Not through carelessness, but simply because they were unaware that a cloud service sat behind the familiar translation tool or design application. This creeping integration evades classic security mechanisms and makes a purely application-based blocking strategy ineffective.

Four risk dimensions the board needs to know

  • Data leakage: employees enter source code, strategy documents, or customer data into external AI models. That data can be reused by the provider for model training and is, in effect, beyond the organisation’s control. File uploads carry a particularly high risk, since they concentrate sensitive information.
  • Data protection and compliance: entering personal data into unapproved AI tools can breach the Swiss FADP and, depending on the situation, the GDPR too. Without a documented legal basis, purpose limitation, and information to the people concerned, a compliance risk arises that touches the board’s oversight duty directly.
  • Cybersecurity: unauthorised AI applications open up additional attack surfaces. Because they are not recorded anywhere, no risk assessment can take place either. The organisation is exposed to unknown risks that show up in neither the AI inventory nor the risk classification.
  • Liability: flawed AI outputs that feed into business decisions without human review, or the use of AI models of opaque origin, can give rise to personal liability for board and executive members. A board that fails to act despite a recognisable risk bears the consequences.

Why bans fail

The temptation to simply block AI platforms is understandable. Experience shows, however, that employees use these tools anyway, through personal devices or alternative access routes. That, in turn, creates shadow AI in the first place, and puts it entirely beyond established governance processes. The IBM report confirms this pattern: nearly 47% of generative AI users access the tools through personal accounts, bypassing all corporate controls in the process.

The strategic answer lies in controlled enablement, not in prohibition. The organisation must provide vetted, secure AI tools whose use is governed by clear policy and backed by technical controls. The risk is not the use of AI. The risk is uncontrolled use.

What the board must actually do

Within its duty of ultimate direction, the board has three levers:

  • Exercise policy authority: the board must ensure that a binding company policy on the use of generative AI exists. It must define which types of data may be processed with which tools. The executive team should be instructed to provide vetted, approved AI tools that meet data protection and information security requirements.
  • Orient oversight around data, not tools: it is not enough to monitor which tools are in use. What matters is which types of data flow into them. The board should require periodic reports that treat shadow AI as its own risk category within risk reporting.
  • Demand contractual protection: when procuring AI services, contractual terms must ensure that company data is not used to train external models. This requirement belongs in the executive team’s mandate.

The cost of doing nothing

Switzerland takes a sectoral and very liberal approach to AI regulation. There is, as yet, no overarching AI law. For the board, that means responsibility sits with the organisation itself; it must define its own rules, ones that satisfy general legal requirements, sector-specific regulation (for example FINMA), and data protection.

The reality: 63% of the organisations surveyed in the IBM report had no AI governance policy, or were still developing one. Only 34% run regular audits for unauthorised AI. These figures do not describe a purely American problem. They describe the state of affairs that prevails in Swiss companies too.

A board that does not steer AI use in its organisation today loses control of three things at once:

  • Data
  • Compliance
  • Liability

Shadow AI is not something IT can solve on its own. It is an issue the board must address at the strategic level, and the executive team at the operational level.


References