Your employees have been using AI for a long time. It's just that you don't always see where.
Two statistics often stand out in this context: 78% of employees use personal AI tools that their employer isn’t aware of, and 50% of Dutch organizations lack an AI policy.
Together, these figures are representative of the situation in many Dutch organizations.
People are working with AI, and nowhere is it written down what is permitted and
responsible use. There is no list of approved tools, no agreement regarding the use of customer data, and no one has a clear answer to the question of whether you’re allowed to, no one has a clear answer. What results is shadow AI: AI use that the organization is unaware of and therefore has no oversight over. That is exactly what that initial 78% figure measures. It rarely stems from a lack of willingness. Someone is looking for a solution for their own work and uses whatever’s available.
How this goes wrong has now become all too clear. The city of Eindhoven reported a data breach in late 2025 after employees had entered youth welfare files and citizen service numbers into ChatGPT, using accounts that the municipality did not manage itself. Shadow AI. No malicious intent, by the way, just people who work.
A simple ban won’t solve that problem. The use won’t disappear; it just shifts: to a personal phone, to a personal account, to a document that someone sends to their own email address to continue working on it at. We’ve seen all three of these examples come up in our daily practice, by the way. From that moment on, there’s absolutely no way of knowing what’s is happening.
Organizations that do have this under control have typically put three things in place.
They know which AI tools are in use, they’ve documented what data is and isn’t allowed to be included, and they provide an environment that is robust enough to make that workaround unnecessary.
Six Questions for Every AI Vendor
The range of models and tools changes every month, and the major tech companies, take turns as market leaders. Every provider claims to be secure, and the details are buried in terms and conditions that no one reads. With the six questions below, you can still figure out where you stand. A starting point for getting things better organized.
1. Where is my data stored?
On servers in the Netherlands or the EU, or in the United States, out of your sight? And
in which countries are the companies that host it located? The location determines which
laws apply and who is allowed to access it.
2. Is my data being used for training?
Free tools and consumer versions often use your input to improve models. For business data, you want a firm “no” in writing, in a data processing agreement. Don’t assume everything is fine just because you have a business license.
3. Who does what, and can I see that?
Without centralized user management and logging, you won’t be able to answer the simplest audit question: who shared what, using which tool, and when?
4. Will everything remain mine?
This goes beyond your assistants and prompts. It concerns the entire infrastructure surrounding them: the skills and agents you’ve created, the integrations with your own
systems, the department-specific fine-tuning, and the work that’s gone into each use case. Together, this forms the operating system through which your organization works with AI. Switching providers shouldn’t mean you have to rebuild all of that from scratch.
5. Can I demonstrate that we’re compliant?
You must comply with the GDPR and the EU AI Act. You can only demonstrate this if you
know who is using which tool for what purpose, and where your data is going.
6. Are access, logging, and integrations set up?
Without roles, permissions, and insight into usage, you remain dependent on what people
tell you on their own. The same applies to the connections between your own systems and AI platforms. A connection to your CRM or document management system is easy to set up, and
in many organizations, no one keeps track of which ones are currently in place or what data is flowing through them.
You may notice that none of these six questions is about how good the model itself is. That’s intentional. Which provider is leading the way changes a few times a year, so your team’s preferred model changes just as often.
You build the framework around it once, and how you do that determines how much flexibility you’ll have to adapt to the market.
The investment lies in the infrastructure
This brings us to the second question, and to a common misconception we often see.
The biggest investment in AI isn’t in the model or the platform, but in the infrastructure surrounding it and in how you train people to work with it. That takes months, if not years.
With many platforms, that entire infrastructure depends on a single vendor. If the vendor’s
policy, pricing, or availability changes, it’s not just a tool that grinds to a halt—it’s an
way of working that you’ve spent a year building.
That this is not a theoretical risk became clear this past spring. On June 12, 2026, Anthropic suddenly took its latest model, Fable, offline, following a U.S. export order. The model is now up and running again, but that day revealed something that most organizations had not included in their risk analysis: a foreign government can determine that you lose access to an AI model. Het Financieele Dagblad wrote about this on June 16, noting that you should always be able to switch to a different model.
It’s difficult to avoid the American models at the moment, as they are the market leaders. That is, assuming your regulator allows you that choice.
The question of which model to choose is therefore less important than the question of what it
costs to switch if the need ever arises. That moment could arise, for example, due to geopolitical factors, new regulations, or simply because the cost structure changes.
Ensuring Continuity
Availability is also a security issue, although organizations rarely treat it as such. Regulations do, however, and not just in the financial sector.
DORA is the most explicit on this point and considers the loss of a provider to be a risk that must be managed, including contingency plans. NIS2 requires organizations in designated sectors to ensure the security of their supply chain and to be able to continue operations in the event of an outage. Since 2022, ISO 27001 has included a separate control measure for cloud services, which also addresses what you agree upon for the moment you decide to discontinue the service.
These frameworks don’t ask whether you’ve chosen a good provider. They ask whether you’ve
thought through what to do when you want to part ways with them. An environment where your data is secure but from which you can no longer exit is therefore only half the solution, and the same applies the other way around. Taking control of AI requires both: knowing where your data ends up, and knowing what it costs to switch when necessary.
So what now?
Here are three steps you can take today if you haven’t already got this in order:
Request the data processing agreement
From every AI provider you use, and look for two things in it: where the data is stored, and whether it’s being used for training. If it’s not stated explicitly enough in the accounts, request it in writing.
Ask which AI tools your employees actually use
Do this anonymously and without repercussions, otherwise you won’t get an honest answer. The list usually turns out to be longer than expected, and the order is often the biggest surprise. In our baseline measurements, ChatGPT regularly emerges as the most widely used platform, even among organizations that have a Copilot license for every employee.
Ask this switch question out loud
During your next meeting. If, in a year, we want to switch to a different model or a
different provider, what would that entail and how much time would it take? If no one can answer that question, you’ve immediately identified your first action item to address.
This blog post is a contribution from AIStudio. AIStudio is a single, secure AI work environment for your entire organization. Want to learn more? Visit AIStudio at booth 92 during Data Expo on September 9 and 10.
![]()