According to the Microsoft Work Trend Index 2024, 75 % of knowledge workers use generative AI at work, and 78 % of them bring their own tools, without their employer's knowledge. This phenomenon, sometimes called shadow AI, creates concrete risks for companies in five key areas. Let us go through them and show how to address each one.
1. Leakage of Confidential Data and Trade Secrets
This is the most serious and most immediate risk. When an employee pastes a company contract, a financial statement, a strategy document or clients' personal data into ChatGPT, that data leaves your control. With the free and the paid personal versions of ChatGPT (Free, Plus, Pro) and most other public AI tools, the provider uses your inputs to train the model by default unless the user switches this off. Your trade secrets may thus become part of a knowledge base available to anyone.
The solution is twofold. First, set clear rules on what types of information must never be entered into AI tools: at a minimum personal data, trade secrets, protected know-how and internal financial data. Second, consider deploying business versions of AI tools (ChatGPT Business, formerly Team, ChatGPT Enterprise, Microsoft 365 Copilot, Azure OpenAI), where the provider contractually guarantees that data is not used for training and stays in a controlled environment. The price difference is negligible compared with the risk of a data leak.
2. GDPR Compliance: Personal Data in AI
Entering personal data into an AI tool constitutes processing of personal data under the GDPR. That brings a number of obligations. You need a lawful basis for the processing (Article 6 GDPR). You must inform data subjects that you process their data using AI. When transferring data outside the EU, you must ensure adequate protection under Chapter V GDPR. OpenAI is certified under the EU-US Data Privacy Framework and offers business customers EU data residency, but with the free and personal versions of ChatGPT you have no data processing agreement under Article 28 GDPR and the data is used for training by default.
A concrete example: your company's accountant pastes an invoice containing a client's personal data into ChatGPT to have the AI summarise it. You have just transferred personal data to a third party (OpenAI) without a processing agreement under Article 28 GDPR, without informing the data subject and probably without a data protection impact assessment (DPIA). Under the GDPR accountability principle (Articles 5(2) and 24), the employer as controller is responsible for this processing whether or not management knew about it, and the fine from the supervisory authority can reach 20 million euros or 4 % of worldwide annual turnover.
Solution: carry out a DPIA for the deployment of AI tools. Conclude a data processing agreement (DPA) with the processor (OpenAI, Microsoft). Define processes ensuring that personal data is entered into AI only by authorised persons and only in authorised cases.
3. An Internal AI Policy: Rules for Using AI
Without clear rules, using AI in a company is like driving without a highway code; sooner or later there will be an accident. An AI policy (AI Use Policy) is an internal document setting out which AI tools are approved, which types of data may and may not be entered, who is responsible for overseeing AI use, how AI outputs are handled (quality control, fact-checking) and what the sanctions for breaches are.
This document does not need 50 pages. A short, comprehensible guide of 3 to 5 pages covering the key scenarios is enough. What matters is that employees actually read and sign it. An AI policy is also the most practical way to demonstrate compliance with the AI literacy obligation under Article 4 of the AI Act, which has applied since 2 February 2025; a written policy is not expressly required, but the European Commission recommends keeping internal records of training and rules.
4. Employee Training: AI Literacy as an Obligation
Article 4 of the EU AI Act (Regulation (EU) 2024/1689) requires providers and deployers of AI systems to take measures to support the development of AI literacy among their staff and other persons using AI on their behalf. The obligation has applied since 2 February 2025. The amendment to the AI Act (the so-called Digital Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026) softened it in that a company need not guarantee a specific level of knowledge for every individual, but it must demonstrably take steps (training, rules). The postponement of high-risk obligations to December 2027 does not affect this duty, and since 3 August 2026 it has been supervised by national market surveillance authorities; in the Czech Republic this is expected, under the adaptation act currently in preparation, to be primarily the Czech Telecommunication Office.
In practice this means training employees in the basics of how AI works (what it can and cannot do), the risks of using AI at work, the company's AI policy and rules, and the practical, effective use of the approved tools. Training need not be complicated. We recommend combining a short e-learning module (30 to 60 minutes) with a hands-on workshop focused on the company's specific use cases. It is important to document the training, because in the event of an inspection you must show what measures you have taken.
5. Output Quality and Liability: Who Is Responsible for AI Errors?
AI tools such as ChatGPT generate outputs that may contain factual errors (so-called hallucinations), outdated information, copyright infringements (reproduction of protected content) or bias. If an employee uses a flawed AI output in client material, a legal document or a financial analysis, the company bears the liability, not the AI.
Solution: introduce mandatory human review (human-in-the-loop) for all AI outputs that leave the company or serve as a basis for decisions. Define which types of output require review by an experienced colleague. Prohibit presenting unreviewed AI outputs as one's own work. And above all, educate employees about the limits of AI so that they do not accept outputs uncritically.
What to Do Tomorrow
If you have not yet addressed AI in your company, we recommend starting with the following steps. Run an anonymous survey among employees to find out who uses AI and how. Identify the riskiest scenarios (work with personal data and trade secrets). Prepare a basic AI policy; simple but clear rules are enough. Schedule AI literacy training, which you are required to provide by law. And consider deploying business versions of AI tools with guaranteed data security.
How We Can Help
At Surman s.r.o. we deal with exactly these questions. Mgr. Jaroslav Surman has hands-on experience implementing AI and AI governance in organisations of various sizes. We offer an AI policy tailored to your company, a GDPR assessment for AI tools, AI literacy training for staff and management, the selection and deployment of secure AI tools and complete preparation for the AI Act. In cooperation with the law office of Mgr. Barbora Surmanová we also cover the legal aspects: contracts with AI providers, DPIAs and liability questions.
Want to keep AI in your company under control? Contact us for a non-binding initial consultation. Find out more on our AI Consulting page.
Updated August 2026.



