The employee who is not on the payroll
The average mid-sized Polish company employs, according to its own records, a hundred and something people. According to the reality it actually operates in, it employs around two hundred. That difference is Shadow AI — dozens of artificial intelligence assistants that employees spin up on their own initiative, without the board's knowledge, without an entry in the record of processing activities, without a data processing agreement, without training, without a policy and without oversight.
Every day, in that very organisation, someone pastes a fragment of a client contract into the free version of ChatGPT with the request "summarise this for me in Polish". Someone else uploads a departmental salary table to Gemini in order to "format it for a presentation". The board's assistant pastes the content of supervisory board discussions into Claude to "write up the minutes". A developer drops database code containing a hard-coded production password into Copilot. Every one of them believes they are helping the company — and every one of them has just carried data over the wall that the board guards with hundreds of firewalls, VLAN segmentation, DLP policies and the whole machinery of information security.
We call this phenomenon Shadow AI. Unlike the classic insider threat — the deliberate exfiltration of data by a dishonest employee — there is no bad faith here. There is only ignorance. And that is precisely what makes Shadow AI one of the most underestimated risks facing Polish companies in 2026.
A scale that appears in no board report
International research, set alongside data from Fib.Code's own Polish audits, paints a painfully consistent picture. In organisations with no formal policy on the use of AI tools, between 60 and 80 per cent of knowledge workers use at least one generative AI tool for work purposes. In marketing departments that figure approaches a hundred per cent. In legal and HR departments — ostensibly conservative — it exceeds half the workforce.
Our audits reveal something more troubling still. When we ask a board to estimate the scale of the phenomenon in its own company, the estimates range between 5 and 15 per cent of the workforce. The reality we uncover in the course of our work is usually 60 per cent or more. A perception gap of forty percentage points is no accident — it follows from the fact that Shadow AI is by definition invisible to a board that has nothing with which to measure it.
What is more, the phenomenon is not confined to free consumer tools. Almost as often we find companies using paid individual subscriptions to ChatGPT Plus or Claude Pro, bought by employees on personal cards, with or without expensing them. Those subscriptions are covered by no B2B contract, no data processing agreement and no clause on the non-use of data for model training. From the AI provider's point of view, this is a consumer account. From the company's point of view, it is a leakage channel with a sign on it reading "they pay for it themselves".
This is not an IT problem. It is a board problem
Before we get into the substance, one thing needs to be said plainly. Shadow AI is not a technical problem to be solved by yet another DLP product or by adding three domains to a block list. Blocking ChatGPT at the firewall does not switch off an employee's smartphone — and the phenomenon bypasses the corporate network entirely the moment someone switches to mobile data.
Shadow AI is a problem of corporate governance — governance in the literal sense of the word. It comes down to the fact that the company has not decided how its employees are to use the most transformative technology of the decade. And until it does, that technology will be making more use of the company than the company makes of it.
Framing it this way matters for two reasons. First, it puts responsibility where it belongs: with the management body. Second, it opens the door to solutions that actually work — policies, training, procedures, contracts and an access architecture for sanctioned tools. In short, to the full range of instruments Fib.Code has been using for years in GDPR, ISO 27001 and NIS-2 projects.
Five layers of risk we usually only identify after an audit
When the Fib.Code team assesses an organisation's readiness for the AI era, it regularly identifies five categories of risk. They are different enough from one another to require different control instruments — and connected enough that they cannot be addressed in isolation.
Personal data leakage — a GDPR breach in real time
Pasting a customer list with contact details into the free version of ChatGPT is a transfer of personal data to a third party — usually one outside the European Economic Area — with no legal basis, no data processing agreement and no privacy notice for the data subjects. It is a classic, textbook breach of Articles 28 and 44 GDPR. A breach that occurs hundreds of times a day in the average Polish company, entirely off the radar of the board and the data protection officer (DPO).
The consequences come on five levels: financial penalties from Poland's data protection authority (UODO) of up to EUR 20 million or 4% of annual worldwide turnover; civil claims from data subjects; claims from clients for breach of DPA terms; contractual risk (a growing number of contracts contain clauses prohibiting the transfer of data to AI tools without the counterparty's consent); and finally reputational risk, which is never quantified in figures but is quite capable of destroying relationships built over years.
Trade secret leakage — the Samsung case and what follows from it
In 2023, Samsung engineers pasted fragments of proprietary semiconductor code into ChatGPT while looking for advice on a bug. In 2024, an employee of a European law firm pasted the defence strategy in a high-profile commercial case into a chatbot in order to "check the reasoning". Both cases ended identically: the data went into the AI provider's infrastructure with no realistic way of getting it back.
Under Poland's Act on Combating Unfair Competition, such conduct constitutes disclosure of a trade secret. Liability does not rest with the employee alone — the company is also liable, for having failed to protect the secret with appropriate organisational measures. And "appropriate measures" begin with a written policy that the company can demonstrate was effectively communicated and enforced.
Hallucinations as the basis for business decisions
Generative artificial intelligence does not say "I don't know". It states, with complete conviction, things it does not know. And until someone gets used to that characteristic, they will treat its answers as facts. So when a junior lawyer asks ChatGPT for citations from Supreme Court case law, she gets magnificent-sounding case references that never existed. When a financial analyst asks for a comparison of sector benchmarks, he gets numbers that look real but whose sources cannot be verified.
In 2023 an American law firm was fined and its lawyers were disciplined for filing a pleading full of case law fabricated by ChatGPT. Similar cases are beginning to appear in Poland. This is not a technological curiosity. It is an operational risk that strikes at everything the company produces — from analyses, through contracts, to investment decisions.
Shadow training — when company data becomes part of the model
In their terms of use for free and individual accounts, most generative AI providers reserve the right to use the content of prompts and responses for further training of the model. This is not about literal memorisation of content — the models are far too large to work that way. It is about the fact that every fragment of pasted data increases the chance that future versions of the model will begin generating content of that kind for other users too.
In practice, this means a scenario in which a competitor, entering a specific query with the same AI provider, receives an answer based on data extracted a month earlier from someone else's company. Verifiable cases of company identifiers "leaking" from one user's prompts into another user's answers were documented in 2024. They are not common, but they exist — and for a board that signs data protection declarations, the risk alone should be enough.
Inconsistency with the AI Act — the deployer role nobody talks about
The Artificial Intelligence Act (EU Regulation 2024/1689) comes into full application in stages, and from August 2026 it covers the last and strictest requirements for high-risk AI systems. What matters most for Polish companies is the status of the deployer — the entity putting an AI system to use in its own activities. It is the deployer who is accountable for how AI is used inside the organisation.
Article 4 of the regulation introduces an obligation to ensure AI literacy among everyone dealing with AI systems on the deployer's behalf. Article 26 imposes specific obligations on deployers: from documentation, through human oversight, to monitoring and logging of use. An organisation that allows its employees to use AI tools without any rules meets, by definition, not one of those requirements. This is not a matter of interpretation — it follows directly from the text of the regulation.
What exactly needs to be done — and in what order
The good news is this: although the risk is serious, getting it under control does not require a revolution. It requires a method. Fib.Code has developed a nine-step sequence, tested in organisations across a range of sectors — from law firms, through manufacturing companies, to local authorities. The order of the steps matters.
Step one — inventory. Before we prohibit or permit anything, we need to know what is going on. An anonymous survey, an audit of network traffic and interviews with department heads together usually produce a surprisingly complete picture. The first truth about Shadow AI is that there is far more of it than the board expects.
Step two — data classification. An AI policy cannot read "you may not use ChatGPT". It has to read: "for work with category A data you may use only tool X in enterprise mode; for work with category B data you may use tools Y and Z; for category C data you may use any tool, but you may not paste in any customer identifiers". Without data classification there is no good AI policy.
Step three — classification of AI tools. In parallel: a review of the available tools against three criteria — GDPR compliance, AI Act compliance, and the provider's contractual terms (does it use data for training, where does it process it, what security measures does it have). The result is a list of permitted, conditionally permitted and prohibited tools, updated quarterly.
Step four — an AI usage policy. A document drafted according to the logic of GDPR and ISO 27001:2022, integrated with the existing Information Security Management System. Not a set of rules in the style of "keep well away from this", but a living working instrument that specifies what is allowed, what is not, who is responsible for what, and what to do if something happens anyway.
Step five — permitted tools in enterprise versions. Without this step, the whole policy collapses. Employees use AI tools because they are useful, not because they want to break the rules. If the company does not give them a sanctioned alternative (ChatGPT Enterprise, Copilot for Microsoft 365, Gemini Enterprise, Claude for Work — depending on profile and budget), they will use private ones. A policy without an alternative is a fiction.
Step six — a DPIA for high-risk use cases. A data protection impact assessment within the meaning of Article 35 GDPR, supplemented with AI Act requirements. A separate DPIA for every serious AI use case — recruitment, customer scoring, complaint handling, automated decisions. This is not bureaucracy. It is the document that, in the event of an inspection, shows that the company thought the risk through.
Step seven — training. An obligation under Article 4 of the AI Act, but also plain information security. Training on the use of AI must cover three things: what is allowed; how the technology works (where hallucinations come from, what prompt injection is, why the model "lies with conviction"); and how to recognise an attempt at AI-enabled manipulation (CEO deepfakes, AI-generated forged emails).
Step eight — monitoring and DLP. Next-generation DLP tools now recognise Shadow AI specifically: they detect attempts to paste personal data or code into known AI provider domains, log such events and ask the user to confirm. This is not a substitute for a policy — it is what gives the policy teeth.
Step nine — review and iteration. The AI tools market changes every few weeks. A policy that was state of the art six months ago may be out of date today. Quarterly review, updates to the list of permitted tools, updates to training. Without this, each of the previous eight steps loses its force over time.
Why it is worth doing this with Fib.Code
A corporate AI policy is not a document to be generated from ChatGPT in fifteen minutes. It weaves together at least five areas: GDPR, the AI Act, ISO 27001:2022, NIS-2 (where the company is in scope) and the internal culture of the organisation, without which even the best policy remains a dead letter. The Fib.Code team has worked across all five for years — and for the past two has specialised in integrating them around AI governance and preparing organisations for the AI Act.
Our approach is built on what we have learned in more than a dozen AI governance projects over the past year. First, every AI policy has to fit how the company actually works — generic templates from the internet do not survive first contact with the sales department. Second, there is no prohibition without a clear alternative — which is why every project includes a specific stack of permitted tools, matched to the budget and business profile. Third, a policy lives through training, not through publication on the intranet — which is why every project closes with a dedicated series of workshops designed for senior management, risk functions and knowledge workers.
The outcome of the engagement is a package you can put in front of the board, an inspector, a client and a certification auditor: a coherent policy, an approved classification of data and tools, delivered training with a knowledge assessment, DPIAs for key use cases, and a review plan. All of it harmonised with the existing Information Security Management System, where the organisation has one.
Thirty, sixty, ninety days
If your board is wondering where to start, we suggest a simple time horizon.
The first thirty days: inventory and preliminary data classification. During this period we establish the scale of Shadow AI in your organisation, learn its key use cases and assess the maturity of your existing information security policies.
The next thirty: the AI policy, tool classification, rollout of the sanctioned enterprise stack, and DPIAs for high-risk use cases. This is the stage of intensive documentation and decision-making work.
The final thirty: a cycle of training for all levels of the organisation, deployment of AI-focused DLP monitoring, and the first review iteration. After the ninetieth day, the organisation reaches a state it can present without reservation in a regulatory inspection and — just as importantly for many clients — in response to the increasingly frequent questions counterparties ask about AI policy in the supply chain.
A summary worth pinning above your desk
Shadow AI will not disappear. Regulation will not make it disappear. Technical blocks will not make it disappear. It will disappear only in those organisations that consciously, and in full compliance with the law, replace it with controlled use of AI — with policies, with tools, with contracts, with training. In the rest it will keep growing until it ends in the first serious UODO inspection, the first leak of data to a competitor, or the first prominent article in the trade press.
The best moment to get Shadow AI under control was a year ago. The second best moment is now. Not because the regulator is knocking at the door — although it is — but because well-designed AI governance is becoming, in 2026, one of the most cost-effective investments a mid-sized Polish company can make in security and efficiency alike.
Fib.Code would be glad to take your company along that road. We start with a free diagnostic conversation in which, within an hour, we can identify where you are today — and how far you are from the point at which Shadow AI stops being a problem and starts being a competitive advantage.
Get in touch: l.grabowski@fibcode.com | fibcode.com/en/contact. We have written on related themes in The AI Act and information security — what the new regulations have in common and Outsourcing the information security officer role — both connect directly to AI governance.


