
According to a recent survey by the HR technology company ESCRIBA, 49.0 percent of employees with computer-based jobs use AI tools several times a week, daily, or even several times a day. Given the ongoing AI boom, this comes as little surprise. However, a critical issue is that 47.8 percent of these employees use AI applications in their daily work without their employer’s approval. This leads to what is known as “shadow AI.” The cause often isn’t a lack of willingness on the part of employees to follow the rules. Rather, many companies lack clear guidelines, approved tools, and practical support for the safe use of AI.
Follow ESCRIBA on LinkedIn to stay up to date on HR digitization, AI transformation, and software solutions for human resources.
Estimated reading time: 13 minutes
Table of contents
- The use of AI in the workplace has long been a reality
- Why do employees use unauthorized AI tools?
- What AI risks arise in companies?
- What do employees want when it comes to AI use in companies?
- How Should Companies Approach AI Transformation?
- What role does HR play in AI transformation?
- Conclusion: Good AI employers close the support gap
- FAQ
The use of AI in the workplace has long been a reality
Artificial intelligence has evolved from a technology of the future to an everyday work tool in a short period of time. This is shown by a study conducted by the market research institute Bilendi on behalf of ESCRIBA. The study surveyed 1,037 employees in Germany, most of whom work at a desk. 60.3 percent of respondents say they use AI significantly more often in their daily work today than they did twelve months ago. This trend is therefore far from having plateaued. On the contrary, there are many indications that the use of AI in the workplace is continuing to accelerate.
Low-threshold applications are particularly widespread. 71.4 percent of employees use AI frequently or occasionally to research information. 65.5 percent use it to create or edit texts and documents. By contrast, only 28.5 percent currently use AI agents that can independently handle multiple process steps. For most people, therefore, the AI transformation in the workplace does not begin with complex automation, but with tasks where visible benefits can be achieved quickly.
The barrier to entry is low: all it takes is a browser, a freely accessible tool, and a quick input. But that is precisely where the problem lies. While employees can try out new possibilities right away, companies need time to review applications, clarify responsibilities, assess data protection requirements, and establish binding rules. This results in an AI transformation within companies that isn’t planned centrally but begins decentralized at many individual workstations.
Click here to go directly to the ESCRIBA study and the accompanying white paper,“The AI Support Gap.”
Why Do Employees Use Unauthorized AI Tools?
The survey did not directly ask about the personal motivations for using applications that were not provided. However, a plausible pattern can be deduced from the results: Employees recognize a specific benefit but often cannot find suitable official tools or sufficient guidance.
For 56.3 percent, AI saves time in their day-to-day work. 54.3 percent of respondents use it to complete routine tasks more quickly. When employees experience these benefits while the company is still debating responsibilities and approvals, there is a strong incentive to use freely available AI tools in the workplace. Shadow AI is therefore not automatically a sign of negligence or a deliberate violation of rules. It can just as easily indicate a sense of initiative, pressure to be productive, and a lack of corporate alternatives.
On top of that, the rules are unclear in many places. Only 45.2 percent of respondents report having guidelines on which AI tools may be used. 31.5 percent are unsure about the extent to which they are even allowed to use AI in a corporate setting. Where clear guidelines are lacking, employees must decide for themselves which applications and which data entries are still acceptable. However, they often lack the necessary understanding of data protection, information security, and potential contractual consequences.
The use of shadow AI is not limited to entry-level employees or roles requiring an academic background. According to the study, it is highest among 30- to 39-year-olds, at 59.7 percent. Among employees without a college degree, 43.0 percent use AI applications not provided by their employer; among college graduates, the figure is 52.6 percent. Companies must therefore tailor their measures to the entire workforce and must not assume that AI proficiency is limited to specific age or education groups. This is because unregulated AI use in the workplace is widespread across all sectors.
What AI risks arise in companies?
Unauthorized AI tools are particularly risky because companies cannot reliably control either the systems used or the information processed by them. Employees may unintentionally transmit personal data, customer information, internal knowledge, or trade secrets to external providers. Furthermore, the terms of use, storage locations, and potential further use of user input are not transparent to users for every service.
A survey of those who use AI tools not officially provided by their companies shows just how real this risk is. Of this subgroup, 42.7 percent have already entered drafts of internal emails. 15.7 percent have used strategic information about projects, products, or customers; 12.9 percent have used customer data; and 12.3 percent have used HR or applicant data. These figures refer specifically to users of “shadow AI” and not to all 1,037 respondents. According to the white paper, when extrapolated to internal email drafts, this still corresponds to about one-fifth of all surveyed desktop workers.
Another AI risk in companies is the quality of the results. 73.4 percent have already experienced AI providing incorrect information in a professional context. While 63.5 percent always or often verify the results from a technical perspective, However, more than a third do so only occasionally or never, and 47.8 percent accept AI outputs largely unchanged at least occasionally. In an effort to save time, this can lead to errors, unverified claims, and poor decisions.
Another risk is a lack of transparency. Only 23.3 percent typically disclose to colleagues or supervisors that they have used AI; 44.5 percent never do so. This makes it more difficult to trace the origins of work outputs, define responsibilities, and share best practices within the team. Sustainable AI use in companies therefore requires not only technical reliability but also an open culture of learning and accepting mistakes.
Save
for later
White paper on the use of AI in the workplace
White paper on the use of AI in the workplace ESCRIBA will shortly be publishing a comprehensive white paper on the use of AI in the workplace. We will then send you the white paper directly, free of charge.
What do employees want when it comes to the use of AI in companies?
Employees do not expect a single measure, but rather a comprehensive package that includes guidance, empowerment, protection, and participation. A majority of respondents approved of all ten support measures listed in the ESCRIBA survey. On average, there is a gap of about 22 percentage points between what employees want and the reality in the workplace.
The following are particularly important to the respondents:
- Clear rules for data entry: 62.4 percent want clear guidelines on what data may be entered into AI tools.
- Training when job responsibilities change: 62.1 percent expect support when AI changes their scope of work. In reality, only 32.2 percent receive it.
- Clear tool approvals: 60.9 percent want rules regarding which AI applications are permitted.
- Protection against performance monitoring: 60.4 percent want assurance that AI will not be used to monitor their performance. Only 33.0 percent experience such protection against monitoring.
- Practical training: 59.8 percent would like training on how to use AI in their own work environment.
- Communication and involvement: The majority also expects transparency regarding existing AI applications, opportunities for discussion, and involvement in the implementation of new systems.
The largest AI support gap relates to continuing education: there is a 29.9 percentage point gap between employees’ expectations and what is actually offered. The gap regarding protection against AI-based performance monitoring is nearly as large, at 27.4 percentage points. Companies should draw two conclusions from this.
- First, AI literacy is a corporate responsibility, not a personal obligation.
- Second, a successful AI transformation cannot be implemented against the will of employees.
How should companies approach AI transformation?
Safe and productive use of AI in the workplace does not result from a blanket ban. Bans may be necessary for particularly risky applications, but they eliminate neither the need nor the perceived benefits. In the absence of a viable alternative, the use of AI may simply become less visible. What is needed, therefore, is a coordinated approach that combines governance, technology, training, and change management.
Establish Clear AI Governance
Companies should first establish binding guidelines specifying which AI tools are approved for which tasks. A manageable “whitelist” is more helpful in day-to-day operations than a long list of abstract prohibitions. Equally important is a clear data classification system: Which publicly available, internal, confidential, or personal information may be entered into which system?
The rules must reflect specific work situations. These include, for example, handling job applications, customer inquiries, internal emails, draft contracts, source code, and strategic documents. In addition, it should be clarified when human review is required, how the use of AI is made transparent, and who makes the decision in cases of doubt.
Provide AI Tools That Comply with Data Protection Regulations
Rules are only effective if employees are provided with a viable alternative to freely available applications. Companies should therefore provide vetted AI tools that align with their security requirements and processes. Selection criteria include, among other things, data processing and storage, access and authorization policies, logging, deletion options, and integration with existing systems.
The greatest value is created when AI does not operate in isolation from the existing IT landscape. Integrated solutions can access approved data and clearly defined processes without requiring employees to manually copy sensitive content into a public chat window. For example, ESCRIBA’s NLC|AI platform supports rule-based review and approval processes, the orchestration of AI agents, and integration with HR systems such as SAP HCM, SAP SuccessFactors, and Workday.
Align Continuing Education with Job Responsibilities and Skill Levels
A one-time general AI webinar is not enough. Employees need to learn the basics of secure data entry, identifying incorrect outputs, and responsibly reviewing results. In addition, they should learn how AI can support their specific tasks.
The offerings must take different starting points into account. A team formulating prompts for the first time needs different content than process managers integrating an AI agent into an HCM system. Practical exercises, consultation sessions, and internal best-practice formats help to permanently embed knowledge within the organization.
Organize human oversight on a risk-based basis
Not every AI application requires the same level of oversight. A spell-checker should be evaluated differently than a recommendation regarding job applicants or an automatically triggered HR process. Companies should therefore determine for each use case what the consequences of an error would be and at what point a human must review, approve, or intervene.
This also reflects the views of many employees. While 62.2 percent have a high or somewhat high level of trust in AI for spelling and grammar, only 30.1 percent feel the same way about automation without direct human review. Visible control mechanisms can therefore not only reduce errors but also increase acceptance of new AI systems.
Involve Employees and Protect Them from Surveillance
Introducing AI tools in the workplace often changes tasks, roles, and how people work together. Companies should therefore involve employees and employee representative bodies early on. This improves the quality of use cases because employees have a particularly good understanding of their processes and day-to-day challenges.
At the same time, there needs to be clear boundaries for AI-driven analyses of behavior and performance. Companies should disclose what data is being processed, for what purpose, and what is explicitly not intended. Such transparency builds trust and prevents the AI transformation in the workplace from being perceived as a covert surveillance project.
What role does HR play in the AI transformation?
HR is particularly important for the AI transformation in companies because it is where technology, organization, training, and corporate culture converge. The HR department should therefore not wait until new systems have been technically selected before taking action. Together with IT, data protection, information security, the legal department, and the works council, it can define how humans and AI will collaborate in the future.
At the same time, the HR department offers numerous suitable use cases. These include classifying incoming inquiries, reviewing documents, assisting with document creation, and automating clearly defined workflows. ESCRIBA recommends a step-by-step approach for this: prioritize processes based on frequency, error susceptibility, and resource requirements; start with one or two clearly defined pilot areas; and then expand successful approaches in a targeted manner.
The key is not to stop at prompting. Individual chat requests can save time, but they do not yet transform an end-to-end process. Sustainable productivity gains are achieved when approved AI features are securely embedded into digital workflows and existing data systems. This, in particular, requires a combination of process knowledge, technical expertise, and responsible governance.
Conclusion: Good AI employers close the support gap
The use of AI in the workplace can no longer be treated as a topic for the future. Employees are already using AI today, often on their own initiative and, in some cases, outside the company’s controlled environment. Companies that simply wait and see or impose bans are leaving their AI transformation to chance and increasing risks to data protection, information security, and the quality of their results.
Taking the right approach means providing clear rules and secure AI tools, offering practical training to employees, establishing risk-based human oversight, and actively involving the workforce. This transforms uncontrolled “shadow AI” into transparent, productive, and responsible AI use within companies. The crucial step is not to centrally prevent every instance of use, but to provide employees with a safe and useful framework within which they can competently utilize artificial intelligence.
FAQ
“Shadow AI” refers to AI applications used for work purposes that have not been officially provided or authorized by the employer. These may include freely available chatbots, translation services, writing assistants, or other generative AI tools.
With untested tools, it is often unclear how input data is stored, processed, or reused. As a result, personal data, customer information, internal documents, or trade secrets may leave the controlled IT environment. In addition, untested AI results can lead to technical errors and incorrect decisions.
No. A ban may make sense for specific applications or categories of data, but it does not eliminate employees’ needs. A more effective approach is a combination of clear rules, approved alternatives, training, and mandatory review processes.
An AI policy should specify permitted tools and use cases, prohibited data inputs, responsibilities, audit and labeling requirements, and reporting procedures for errors or security incidents. It should be easy to understand, easy to find, and explained using concrete examples from everyday work.
Companies should first assess current usage and specific needs. This should be followed by clear governance rules, the selection of secure applications, and a limited pilot project with measurable goals. Training, employee feedback, and a controlled rollout ensure that the pilot evolves into a sustainable AI practice.



