[{"data":1,"prerenderedAt":84},["ShallowReactive",2],{"news-doc-en-/news/2026-04-20-shadow-ai-at-work":3},{"id":4,"title":5,"author":6,"body":7,"category":64,"date":65,"datePosted":66,"department":66,"description":67,"employmentType":66,"extension":68,"image":69,"linkedinUrl":66,"location":66,"meta":70,"navigation":71,"path":72,"readTime":73,"seo":74,"stem":75,"tags":76,"translationId":82,"validThrough":66,"__hash__":83},"content/news/2026-04-20-shadow-ai-at-work.md","Shadow AI at work: one third of incidents linked to generative AI","Johan Holmström",{"type":8,"value":9,"toc":57},"minimark",[10,14,17,20,25,28,31,34,37,41,44,47,50,54],[11,12,13],"p",{},"I meet IT managers and security officers every week. Over the past year, one question has come up in almost every meeting: \"How do we know what our employees are doing with AI?\"",[11,15,16],{},"The question is justified. Microsoft's Data Security Index 2026 shows that 32% of organisations' data security incidents are linked to the use of generative AI tools. Over 70% of employees bring their own AI tools to work. 58% use personal devices to access GenAI at work.",[11,18,19],{},"The numbers don't surprise me. They confirm what I hear in the conversations.",[21,22,24],"h2",{"id":23},"the-problem-is-called-shadow-ai","The problem is called shadow AI",[11,26,27],{},"Employees use ChatGPT, Copilot or other tools without the company knowing. They log in with personal accounts. They paste in customer data, contract texts, internal communications. Not out of malice, but because the tools actually help them work faster.",[11,29,30],{},"But every time someone pastes a customer list into an uncontrolled AI tool, data leaves the company's firewall. Nobody knows where it ends up. Nobody can trace it.",[11,32,33],{},"IDC's Frontier Firms study (November 2025, 4,000 organisations globally) confirms this isn't just a Swedish problem. 31% of all organisations cite security and privacy as the biggest barrier to implementing GenAI. 29% highlight governance, sovereignty and quality. The problem grows as more tools reach the market.",[11,35,36],{},"In the security industry, where I've worked for over 30 years, this is a direct business risk. Our customers handle CCTV surveillance, access control systems, alarm data. The information is sensitive by definition.",[21,38,40],{"id":39},"the-solution-is-not-to-ban-ai","The solution is not to ban AI",[11,42,43],{},"35% of organisations expect more incidents next year, but the answer isn't to shut things down. The answer is to give employees approved tools that are at least as good as the uncontrolled alternatives.",[11,45,46],{},"That's exactly what we do at Walma. We build AI assistants that run in the customer's own, isolated environment in Azure Sweden. All data stays in Sweden. Each customer has their own database, their own URL, their own access controls. Employees get an AI that actually answers their questions, with source references to internal documents. And the IT department can see exactly what's happening.",[11,48,49],{},"47% of organisations are now implementing specific GenAI controls, an increase of 8 percentage points since 2024. The trend is clear. Those who succeed best are those who give employees better alternatives, not more bans.",[21,51,53],{"id":52},"what-are-you-doing","What are you doing?",[11,55,56],{},"Next time you hear that an employee is using ChatGPT to search your policy documents, ask yourself: why don't we have an internal tool that does the same thing, but securely?",{"title":58,"searchDepth":59,"depth":59,"links":60},"",2,[61,62,63],{"id":23,"depth":59,"text":24},{"id":39,"depth":59,"text":40},{"id":52,"depth":59,"text":53},"Insight","2026-04-20",null,"32% of organisations' data security incidents are linked to generative AI tools. Over 70% of employees bring their own AI tools to work. Here's the reality, and how we solve it.","md","/images/news/shadow-ai.jpg",{},true,"/news/2026-04-20-shadow-ai-at-work","5 min read",{"title":5,"description":67},"news/2026-04-20-shadow-ai-at-work",[77,78,79,80,81],"AI","data security","shadow AI","GenAI","enterprise AI","shadow-ai-at-work","btjK0MK05bR-9AurhC1CEGOPlSUsroC1OvqD7ISx8eE",1777879044224]