80% of professionals in the Icelandic labour market use AI at work, but only 34% have received training from their employer (Viska 2025). The gap between those figures is called shadow AI: staff solving tasks with free AI tools nobody has approved, on accounts nobody has oversight of. The risk is not that your company will adopt AI. It is that it already has, without you.
What is shadow AI?
Shadow AI is when staff use AI tools at work without the company's knowledge or approval. It looks innocent: a sales rep pastes a customer's email into a free chatbot to get a better reply. A finance employee asks for a summary of an Excel file. An HR manager has a draft termination letter rewritten.
None of this is done with bad intentions. Quite the opposite: people are trying to work faster and better. The problem is that the free versions of many tools reserve the right to use entered data to train models, and the company has no way of knowing what went in, where it went or where it ends up.
This is not an edge case. When 80% use the tools but only 14% of Icelandic companies have an AI policy in place (Statistics Iceland 2025), shadow AI is the default state in most Icelandic workplaces. Including yours.
Why a ban does not work
The first reaction of many managers is to ban the tools. It sounds responsible but usually produces the opposite result. Staff do not stop using AI, they just stop talking about it. Usage moves to personal phones and personal accounts, where the company has even less oversight than before.
A ban has another cost too: the company forfeits the benefits. Research shows 25 to 56% faster completion of individual tasks among trained people (Harvard/BCG 2023). A company that bans the tools keeps the risk, just hidden, and loses the benefits along the way.
The realistic goal is not zero usage. It is managed usage: the right tools, the right settings, clear rules and people who know how to follow them.
What are you actually risking?
The risk of shadow AI is not theoretical. It comes down to four categories of data and incidents that most companies know well:
Personal data. example from daily work: National ID numbers, payroll data or health information pasted into a free chatbot · possible consequence: Breach of data protection law, a reportable security breach
Confidential data. example from daily work: Draft contracts, price quotes, customer lists entered for summarising · possible consequence: Confidential data outside the company's control
Wrong answers. example from daily work: An unverified AI answer goes straight into a proposal or report · possible consequence: Errors in decisions, damage to customer trust
No oversight. example from daily work: Each department uses its own tools on personal accounts · possible consequence: Impossible to answer where the company's data is
The fourth category is the most insidious. When a security incident, a customer enquiry or an audit comes up, the company needs to be able to answer a simple question: which data has gone into which tools? With shadow AI the answer is always the same: we do not know.
The solution is policy plus training, not one or the other
Shadow AI grows out of a vacuum. Staff see that the tools work, the company says nothing, and people fill in the gaps themselves. The solution has two parts, and neither is enough on its own.
The policy answers what is allowed: which tools are approved, which data may go where, which subscriptions guarantee that data is not used to train models. This does not need to be a 40-page document; one clear page that everyone understands beats most of what exists today.
The training answers how: how do you use the approved tools so that they deliver real results, and when should you not trust the answer. Policy without training becomes a document nobody reads. Training without policy leaves the same open questions about the data. Together they turn shadow AI into a competitive advantage: the same people, the same tools, but now with settings, rules and skills the company stands behind.
What you can do right now
- Ask, without punishing. Send a short anonymous survey or raise it at the next department meeting: which AI tools do people use today and for which tasks? Make it clear that the purpose is to learn, not to ban. You will not get honest answers if people fear the consequences.
- Set one interim rule today. Until a formal policy is ready: no personal data and no confidential data in free AI tools. One sentence in an email from a manager is enough to stop the biggest risk immediately.
- Check the settings of the tools already in use. In most chatbots you can turn off the use of your data for training, and company subscriptions usually offer stronger data protection than free versions. Thirty minutes in the settings reduces the risk considerably without costing a single króna.
[ Get in touch ]
Book a free assessment
90 minutes that pay off immediately: we map your AI usage, risks and 3 to 5 automatable workflows, and deliver a report within a week. No commitment.