Ask a Dutch company how much AI it uses and you get one number. Ask its employees the same question and you get a much larger one. The space between those two answers has a name: shadow AI — the AI tools your people already use for work, without your IT, security or privacy officer knowing about it.

It is rarely rebellion. It is someone summarising a long report before a meeting, drafting a difficult email, or cleaning up a spreadsheet at half past four. The intent is good. The exposure is real.

The gap between what you run and what your people use

Start with the official picture. According to CBS figures published in 2026, 13.8% of Dutch micro-businesses (2 to 9 staff) used at least one of seven surveyed AI technologies in 2025, against 29.8% of SMEs (10 to 249 staff) and 66.2% of large companies. An earlier CBS AI monitor put adoption among companies with ten or more employees at 22.7% in 2024, a jump of almost nine percentage points in a single year. Those are numbers about organisations: what the company has decided to use.

Now the other picture. The NCSC reported on the Alert Online trend survey — carried out by Ipsos I&O for the Ministry of Economic Affairs — that around half of employees use generative AI at work: 35% occasionally and 14% structurally. In the same survey, only 26% of employees said their organisation has clear guidelines for managing the risks. Twenty-three per cent said there are none, and 38% could not say either way.

Put those side by side and the gap is hard to miss. Organisational adoption sits somewhere between one in seven and two in three, depending on size. Individual use sits at roughly one in two — everywhere. Most of that difference is not on anyone’s software list, in any contract, or in any risk assessment. And in the majority of organisations, the employee doing it has never been told where the line is, because no line was ever drawn.

What actually goes wrong

This is not a theoretical risk, and the Dutch regulator has been explicit about it. The Autoriteit Persoonsgegevens (AP) warned that it receives notifications of data breaches caused by employees sharing personal data with AI chatbots. In one reported case, an employee at a GP practice entered patients’ medical data into a chatbot, against the agreements in place — medical data being exactly the category the law protects most heavily. In another, an employee at a telecom company entered a file containing customer addresses.

The mechanism is simple, and worth spelling out for your team because most people have never thought it through. Most companies behind these chatbots store everything that is entered. That data ends up on their servers, usually without the person who pasted it realising, without them knowing what will be done with it, and certainly without the customer or patient whose data it is knowing anything at all. The AP draws a sharp distinction here: if an employee does this against internal agreements, you have a data breach on your hands. If it happens because it is your organisation’s policy, it is often simply not lawful in the first place. You need to prevent both.

The trend is moving the wrong way. By the end of 2025, Binnenlands Bestuur reported that the AP had already received dozens of notifications that year involving sensitive information shared through public AI tools. Separately, the AP has warned that AI is increasing the risk of cyberattacks, phishing in particular — so the same technology widens the entry point and the exit point at once.

Eindhoven: what it looks like when it surfaces

The clearest Dutch example so far is the municipality of Eindhoven, and it is worth reading closely because almost every detail transfers to a private company.

Eindhoven ran an internal sample of outbound data traffic over thirty days, from 23 September to 23 October 2025. It found files containing personal data of residents and staff uploaded to public AI websites including ChatGPT. As Omroep Brabant reported, the material included documents under the Youth Act (Jeugdwet), internal reports and CVs, coming mainly from departments providing care and support — in other words, data about vulnerable residents. The breach was reported to the AP on 23 October and made public in mid-December.

Two details deserve your attention. First, the municipality could not establish how large the leak was, because the AI platforms retain entered data for a maximum of thirty days — which also means it could not inform the individuals affected personally. A breach you cannot measure is a breach you cannot clean up. Second, this was a thirty-day sample at a single organisation that was already paying attention: Eindhoven had spent two years under enhanced AP supervision and was actively improving its privacy controls when it went looking. Most companies have never looked at all.

What Eindhoven did next is the part worth copying. It blocked public AI websites, gave staff one sanctioned tool inside the secured municipal environment, asked OpenAI to delete the uploaded files, and tightened monitoring of data traffic to external sites. Block plus alternative plus monitoring — not block alone.

Why a ban is not a plan

A prohibition without a usable alternative does not remove shadow AI; it relocates it to personal phones and private laptops, where you have no logging, no agreements and no visibility whatsoever. The employee still has the deadline. Meanwhile the survey data above suggests the more common failure is quieter: not a ban being circumvented, but no guidance existing at all, so people improvise in good faith.

A workable approach for most Dutch businesses looks like this:

  • Measure before you legislate. Look at outbound traffic, browser extensions, expense claims and subscriptions before writing rules. Eindhoven only knew because it sampled.
  • Ask, and make it safe to answer. A one-off amnesty — tell us what you use, nobody gets in trouble — surfaces more in a week than monitoring does in a quarter.
  • Offer something at least as good. A managed, contracted tool that people actually like is the only alternative that competes with the free one they already opened.
  • Write down what may and may not be entered. The AP’s advice is exactly this: make clear agreements about whether chatbots may be used and which data can go in — and, where possible, agree with the provider that entered data is not stored.
  • Train the people, not just the policy. Staff need to understand what happens to a document once it is pasted into a free tool.
  • Have a reporting route. Someone who realises they pasted the wrong thing must know where to go, and quickly: notifying the AP and the people affected is mandatory in many cases.

If you want a ready-made framework rather than a blank page, the Dutch government’s overheidsbrede handreiking voor de verantwoorde inzet van generatieve AI is public, free and written for organisations rather than lawyers. It is aimed at government bodies and is not binding, but the technical, organisational, ethical and legal conditions it sets out translate almost directly to a company.

Shadow AI is also an AI Act problem

There is a compliance dimension that is easy to miss. The EU AI Act asks you to know which AI systems you use and in what role, and since February 2025 it also requires organisations to ensure sufficient AI literacy (AI-geletterdheid) among the people working with AI — a duty the Dutch government explains in plain terms on Digitale Overheid. Both of those obligations rest on an inventory. If half your organisation is using tools that appear on no inventory, your classification is a guess and your literacy programme is training people on the wrong tools. We wrote about the wider picture in the EU AI Act in the Netherlands: what your business needs to know.

The encouraging part is that shadow AI is a demand signal, not just a risk. Half your staff have already decided AI helps them do their work. That is the hard part of adoption, and it is done. What is missing is a safe place to do it — the right tools, clear agreements, and someone who knows how to set both up. See how Baionic connects you to the right AI experts.

(This is general information, not legal advice.)