AI governance · Switzerland
Shadow AI, Swiss FADP and EU AI Act: A Guide for Swiss Companies
Updated 21 July 2026 · 18 min read
Artificial intelligence rarely enters a company through a single door. An employee uses a personal chatbot to summarise a contract. A sales team installs an extension that analyses calls. A developer pastes source code into an assistant. A manager generates a briefing from a document that contains staff information.
Taken one by one, each use may look harmless. Together they create an environment the organisation can no longer fully inventory, secure or document: Shadow AI — the extension of Shadow IT into generative models and autonomous agents.
For a Swiss organisation the issue is not only cybersecurity. As soon as an AI tool processes personal data, the Federal Act on Data Protection may apply. The EU AI Act adds another layer depending on the system, the organisation’s role and its connection to the European market.
This guide explains how to distinguish Shadow IT from Shadow AI, how to articulate Swiss FADP duties and EU AI Act requirements, how to assess the riskiest uses, and how to build governance that protects data without freezing the productivity gains teams expect.
The goal is not to promise automatic compliance. It is to answer four essential questions: which tools are used, which data they receive, which obligations may apply, and which evidence the company can produce.
This content is for information only and does not constitute legal advice. Any concrete situation should be reviewed with qualified counsel.
In brief: what leaders should remember
- Shadow AI is not an autonomous legal category.
- An unsanctioned use can still create personal-data processing subject to the Swiss FADP.
- The AI Act applies based on role, system, use and territorial connection to the EU market.
- Blocking every tool does not necessarily solve the business need.
- The first step is to inventory uses, data, providers and influenced decisions.
- TrustAI must not be presented as “automatic compliance”.
What is Shadow AI?
| Dimension | Shadow IT | Shadow AI |
|---|---|---|
| Object | Unsanctioned software or service | Unsanctioned AI model, assistant or feature |
| Data | Storage and processing | Prompts, files, context, outputs and inferences |
| Additional risk | IT fragmentation | Incorrect answers, opaque decisions, uncontrolled reuse |
| Examples | Personal SaaS, cloud storage | Public chatbot, AI extension, autonomous agent |
Definition of Shadow AI
Shadow AI is the use of applications, models, extensions, APIs or AI agents without sufficient organisational visibility, validation or governance. The tool may be public, embedded in office suites, installed locally or accessed through a personal account.
How does Shadow AI differ from Shadow IT?
Shadow IT mainly concerns unsanctioned software or services. Shadow AI adds a generative-model dimension: prompts, supplied context, model outputs and the decisions they inform can create risks beyond simple IT fragmentation.
Examples of relevant uses
- summarising a contract in a personal account;
- analysing a customer file in a public assistant;
- generating code from an internal repository excerpt;
- drafting a named HR assessment;
- using a browser extension with access to visited pages;
- connecting an agent to messaging or a CRM without approval.
DONNÉE À VÉRIFIER – SOURCE REQUISE: actual frequency and impact for a given organisation.
Why does Shadow AI appear?
Unmet business needs
Employees often adopt AI to reduce friction: drafting, summarising, researching or automating repetitive work. When the official offer does not cover the need, personal tools fill the gap.
Approval processes that are too slow
Governance based only on bans or long homologation cycles encourages workarounds. Teams then prioritise speed over traceability.
An official offer seen as insufficient
Restricted access, limited usability, missing integrations or lack of training can make the approved solution less attractive than a public tool.
A blurred boundary
AI features are now embedded in browsers, office suites, CRMs and SaaS tools. Staff may not realise they are using a generative model or an agent.
What risks does Shadow AI create?
Disclosure of personal data
- customer and prospect data;
- employee data;
- sensitive data;
- metadata;
- attachments and conversation histories.
Disclosure of confidential information
- contracts;
- source code;
- strategies;
- trade secrets;
- non-public financial information.
Lack of traceability
Core question: can the organisation determine who used which tool, with which data, to produce which output?
Decisions based on unverified answers
Risk increases when outputs influence hiring, customer relationships, financial decisions or public communication without documented human review.
Proliferation of providers and transfers
- the provider;
- sub-processors;
- processing locations;
- retention periods;
- possible use of data to improve a service.
DONNÉE À VÉRIFIER – SOURCE REQUISE: exact provider terms at publication time.
Shadow AI and the Swiss FADP: which duties?
The Swiss Federal Data Protection and Information Commissioner notes that the FADP applies to personal-data processing that relies on artificial intelligence. Where risk is high, a data protection impact assessment may be required.
Does the FADP apply to foreign AI tools?
The decisive question is not only the provider’s nationality, but whether personal data is processed and what role the Swiss company plays as controller or processor.
Which FADP principles are relevant?
- lawfulness;
- good faith;
- transparency;
- proportionality;
- purpose limitation;
- accuracy;
- security;
- data protection by design and by default.
When is an impact assessment needed?
Do not assert that a specific use automatically requires an impact assessment without legal review of the case.
- Is personal data being processed?
- Is the processing likely to create a high risk?
- Are sensitive data, profiling or significant decisions involved?
- Can risks be reduced through documented measures?
- Is specialist consultation required?
What should be documented?
- purpose;
- data categories;
- users;
- provider;
- recipients;
- transfers;
- retention;
- security measures;
- risks;
- decisions and approvals.
Monitoring uses and employee data
In Switzerland, processing of employee data must respect proportionality, transparency and labour-law rules. AI-use monitoring cannot be improvised: purposes and modalities must be clear, and people should be informed in advance where monitoring is introduced.
Shadow AI and the EU AI Act: the real link
Is Shadow AI banned by the AI Act?
No. “Shadow AI” is not in itself an automatically prohibited practice. However, an uninventoried use can prevent the organisation from knowing which duties apply or from demonstrating compliance.
Can a Swiss company be in scope?
- presence or activity in the European Union;
- placing a system on the EU market;
- deploying a covered system;
- system output used in the EU;
- role as provider, deployer, importer or distributor.
DONNÉE À VÉRIFIER – SOURCE REQUISE: conclusion for a specific company after legal analysis.
What is the applicable timeline in 2026?
Editorial last check: 21 July 2026. Timelines evolve with implementing acts; revise this section before major updates.
- entry into force on 1 August 2024;
- prohibitions and AI literacy duties applying from 2 February 2025;
- general-purpose AI model duties applying from 2 August 2025;
- additional duties applying from 2 August 2026;
- specific or extended timelines for certain high-risk systems.
Which duties can Shadow AI make impossible?
- system inventory;
- role identification;
- risk classification;
- documentation;
- AI literacy;
- transparency;
- human oversight;
- evidence retention;
- incident management.
FADP and AI Act: do not confuse the two frameworks
The Swiss FADP primarily protects personal data. The AI Act regulates placing AI systems on the market and their use. The same practice may fall under both frameworks without making them interchangeable.
| Question | Swiss FADP | EU AI Act |
|---|---|---|
| Primary object | Protection of personal data | Placing AI systems on the market and their use |
| Trigger | Processing of personal data | System, role, risk and territorial connection |
| Actors | Controller and processor | Provider, deployer, importer, distributor |
| Controls | Purpose, proportionality, security, transparency | Classification, documentation, oversight, transparency |
| Shadow AI | Uncontrolled data flows | Uninventoried systems or uses |
The same use may fall under the FADP, the AI Act, labour law, cybersecurity and contractual commitments.
How to assess your Shadow AI exposure
Step 1: inventory tools
Include applications, embedded features, APIs, extensions, local models and agents.
Step 2: inventory use cases
Do not stop at the tool name. Document the actual task performed.
Step 3: map data
Classify information by sensitivity and purpose.
Step 4: identify influenced decisions
Spot outputs that may affect employees, customers, candidates or partners.
Step 5: assign an owner
Each use case needs a business owner and a control counterpart.
Step 6: classify and prioritise
This internal ranking does not replace AI Act legal classification.
- allowed;
- allowed under conditions;
- prohibited or suspended.
Action plan: regain control without freezing innovation
Publish an interim rule immediately
Define what must never be sent to a public tool: personal data, secrets, credentials and strategic information.
Provide an approved entry point
Without a simple alternative, bans strengthen Shadow AI. A controlled workspace reduces friction while keeping a framework.
Mask or block sensitive data
Before data reaches a model, sensitive elements can be detected, masked or blocked. No system replaces human judgement and business policy.
Maintain an AI-use register
- tool;
- owner;
- purpose;
- data;
- provider;
- risk;
- approval;
- review date.
Train teams by function
Role-based training links AI literacy duties to concrete situations.
Implement proportionate logs and evidence
Evidence should support decision and incident reconstruction without abusive surveillance.
Reassess tools and contracts
Periodically review terms, integrations, sub-processors and new features.
How TrustAI can support this approach
Shadow AI assessment
TrustAI offers an indicative assessment of exposure to poorly governed AI uses, to identify risk areas and prioritise actions.
Approved AI entry point
TrustAI’s workspace aims to provide a governed AI work environment, reducing reliance on personal accounts for professional tasks.
Features described from public product documentation; exact scope depends on plan and configuration.
Masking and minimisation
TrustAI Vault is designed to detect and mask certain sensitive data before it reaches a model, in a minimisation logic.
Features described from public product documentation; exact scope depends on plan and configuration.
Policies, budgets, logs and evidence
Depending on the plan, TrustAI highlights usage policies, budgets, logs and evidence elements to document activity.
Features described from public product documentation; exact scope depends on plan and configuration.
What TrustAI does not replace
TrustAI is not a law firm and does not provide personalised legal advice or compliance certification. Contract review, labour law and governance decisions remain the responsibility of the organisation and its advisors.
Shadow AI, FADP and AI Act checklist
Local checklist only — no data is stored on the server.
Frequently asked questions
What is Shadow AI?
Shadow AI is the use of AI tools or features without sufficient organisational approval, visibility or governance. It extends Shadow IT into generative models and agents. Risk covers both data entrusted to the model and decisions based on its outputs.
What is the difference between Shadow IT and Shadow AI?
Shadow IT mainly concerns unsanctioned software or services. Shadow AI also covers prompts, context, outputs and inferences. A public chatbot can create confidentiality, accuracy and evidence risks even if it does not look like classic business software.
Does the Swiss FADP apply to ChatGPT and other AI tools?
As soon as an AI tool processes personal data for a Swiss company, the FADP may apply regardless of the provider’s nationality. Analysis covers the company’s role, purpose, proportionality, security and documentation of processing.
Is Shadow AI banned by the AI Act?
No. The AI Act does not ban the label “Shadow AI”. However, uninventoried use can prevent an organisation from identifying its role, classifying a system or demonstrating documentation, transparency or human-oversight duties.
Can the AI Act apply to a Swiss company?
Yes, depending on activity, market and role. A Swiss company may be in scope if it places a system on the EU market, deploys one, or if outputs are used in the Union. Each case requires legal review.
Can a company monitor employee AI use?
Monitoring is only possible within a proportionate, transparent framework compliant with labour law and data protection. Purposes, duration and methods must be clear. Opaque or excessive monitoring creates legal risk of its own.
Should all public AI tools be banned?
Not necessarily. A pure ban can increase workarounds if no approved entry point exists. A more durable approach combines clear rules, a controlled alternative, sensitive-data masking, training and proportionate evidence.
Where should we start to reduce Shadow AI?
Start by inventorying tools and use cases, mapping data, identifying influenced decisions, publishing an interim rule and providing an approved workspace. Then prioritise high-risk uses and document approvals.
Official resources and update method
This page should be revised when the FADP, the AI Act, FDPIC guidance or EU implementing acts change. Editorial last check: 21 July 2026.
Related reading
Do you know which AI tools are actually being used across your organisation?
Start with the TrustAI Shadow AI assessment to identify your main exposure areas and the actions that should be prioritised.
Assess my Shadow AI exposureIndicative assessment only. It does not constitute legal advice or a compliance certification.