In 2025, according to INE, Statistics Portugal, 38.7% of people aged 16 to 74 in Portugal used artificial intelligence tools, and 19.9% did so for work. In the same year, only 9.4% of small companies (10 to 49 people) reported using AI. The figures are not directly comparable, but they point to something I often see in the SMEs I work with: AI has already come into the company through the back door, on each employee's phone and laptop, long before the owner has decided anything about it. This is called "Shadow AI".
What Shadow AI is and why it is already in your company
Shadow AI is the use of AI tools such as ChatGPT, Gemini or Copilot on employees' own initiative, without the company's knowledge, approval or rules. It is not just a Portuguese phenomenon. The 2024 Work Trend Index by Microsoft and LinkedIn, which surveyed 31,000 people in 31 countries, found that 75% of knowledge workers already use AI at work and that 78% of those users bring their own tools. Only 39% had received training from their company. A Salesforce survey with YouGov of more than 14,000 workers in 14 countries found that more than half of those using generative AI at work do so without formal approval from their employer, and that nearly 7 in 10 workers had never received training on using these tools safely and ethically.
In my experience, this does not happen out of bad faith. It happens because people want to get their work done faster and have found a tool that helps them. The problem is not the use. It is use without direction.
The three risks the business owner does not see
- Client data and confidential information. When someone pastes a client list, a sales proposal or the company's figures into a free tool, that information leaves your control. Depending on the tool and the account settings, it may be stored or used to train models. And GDPR obligations do not disappear because it was "just a test".
- Errors that reach the client. AI writes with confidence, even when it is wrong. A quote with an invented figure, an email with a contractual condition that does not exist or a report with a false reference can be costly in credibility.
- Knowledge that does not stay in the company. If an employee has found a way to do in 20 minutes what used to take two hours, that gain stays with them alone. When they go on holiday or leave the company, the gain goes with them.
What the AI Act says about AI literacy
The European Artificial Intelligence Regulation, Regulation (EU) 2024/1689, contains in Article 4 an AI literacy obligation that has applied since 2 February 2025. In the original version, companies using AI systems had to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff, taking into account their technical knowledge, experience, education and training and the context in which the systems are used.
In July 2026 the Digital Omnibus package on AI came into force and softened this rule: companies are still required to take measures that support AI literacy in their teams, but no longer have to ensure a sufficient level of competence for each individual. The obligation has changed shape, but it has not gone away. This is not legal advice: for your specific case, especially if you use AI in sensitive processes, check with a lawyer. From a management point of view, the conclusion is simple: training your team and keeping a record of it is not optional.
How to turn hidden use into a company advantage
Banning it rarely works. People keep using it, just in secret. The approach I recommend has five steps.
- A one-page AI policy. What is allowed, what is not allowed and who decides when in doubt. For example: never paste clients' personal data or the company's financial information, and everything that goes to a client is reviewed by a person.
- Approved tools. Choose one or two, preferably business versions with contractual guarantees on data, and pay for them. It costs less than an incident.
- Sharing what works. Fifteen minutes in the weekly meeting for someone to show a use that saved them time. Keep the best requests (the so-called prompts) in a shared document.
- Short, practical training. One session on risks, checking results and internal rules, with an attendance record. It is also your evidence that you have taken measures.
- Measuring time saved. Ask each person to log, for one month, the tasks in which they used AI and the time they estimate they saved. Without numbers, it is just opinion.
A hypothetical example
Imagine, as a hypothetical example, a services company with 15 people. The sales manager uses ChatGPT on her personal account to prepare proposals and, without thinking about it, pastes in client names and contact details. The owner finds out by chance. Instead of banning it, he brings the team together, approves a paid tool, writes the one-page policy and asks the sales manager to show her colleagues how she prepares proposals, now without personal data. A month later, with the time log, he knows how many hours the team has gained and where to reinvest that time. What was a hidden risk has become a company process.
As an engineer, I see this like any other process: first you make it visible, then you standardise it, then you measure and improve it.
This week's action
This week, ask your team a simple question, without any tone of accusation: "Who uses AI tools at work, for what and how much time does it save?". Make sure no one will be penalised for their answer. With those answers, write the first version of your one-page AI policy and book 30 minutes to present it.
If you would like help organising this process and linking AI to your company's productivity goals, the ActionCOACH Porto team can help. A good way to start is our Free Business Analysis, where we look at your business and identify where the biggest opportunities are.