News
Over Half of Polish Employees Use AI Without Telling Employers, New App Aims to Fix That

54 percent of employees who paste data into AI tools don't tell their employer, Poland's data protection authority warns. Polish developers have built Anonimizer, an app that masks personal data before it reaches a chatbot.
Contents
More than half of employees in Poland paste company data into public AI tools without telling anyone at work. The deputy president of Poland's Personal Data Protection Office (UODO) warns that the problem is spiraling out of control faster than companies can keep up with policy. The answer, according to its developers, is a Polish app called Anonimizer, which masks sensitive data before a document ever leaves the employee's computer.
Scale of Uncontrolled Use
The phenomenon known as shadow AI describes employees turning to chatbots and generators without the knowledge of IT departments or managers. They paste in fragments of contracts, partner data, candidate CVs or internal correspondence, hoping for a quicker analysis or a ready-made text. The problem is that no one inside the organization knows where that data goes next or whether it's used to train the models.
UODO deputy president Konrad Komornicki cites data showing that 54 percent of employees who use AI tools don't inform their employers about it. That means that in most companies, decisions about what data gets sent to external systems are effectively made at the level of a single desk, not as part of an organization-wide security policy.
Why It's a GDPR Problem
Pasting an unredacted document into a public AI model can amount to transferring personal data to a party the company has no data processing agreement with, as required under GDPR. If the document contains customer data, employee data or trade secrets, the organization loses control over it the moment the send button is clicked. The consequences go beyond reputational damage: GDPR allows fines of up to 20 million euros or 4 percent of a company's global annual turnover, whichever is higher.
If an unredacted contract, legal document or correspondence containing personal data and trade secrets is fed into the tool, the organization can lose control over that information - Paweł Sokołowski, attorney, IT Legal law firm
75 Percent of Firms Lack an Expert
Data cited in the report shows that 75 percent of organizations have no one prepared to talk to the regulator about AI use, and 89 percent of companies have no real insight into how employees use these tools day to day. As much as 70 percent of AI interactions take place on company hardware, but through private accounts the company doesn't control.
Among Polish small and medium-sized businesses, 42 percent say they plan to invest in AI, but exactly the same share, also 42 percent, names data security as their main concern. Those two numbers show that companies want to use AI but don't know how to do it safely, so employees usually end up resolving that dilemma on their own, quietly.
How Anonimizer Works
The answer to this problem is meant to be Anonimizer, a Polish app built by Wojciech Chmiel and Jakub Dolata. The tool runs locally on the user's computer, before a document is ever sent to an external AI model. The system automatically detects sensitive data in the text, masks it, and shows the user the flagged fragments, which can be approved, rejected or edited by hand.
The key difference from typical corporate filters is that the original file never leaves the device in unprocessed form, and reconstructing the masked data, meaning de-anonymizing the AI's response, also happens locally. Only a version stripped of personal data and trade secrets ever reaches the model.
Lawyers stress that the technical tool alone won't replace an internal policy. Karol Sikorski, president of the Greater Poland Chamber of Commerce and Industry (Wielkopolska Izba Gospodarcza), notes that companies need clear rules of conduct, not just software.
Companies need simple rules: what must never be pasted into AI, which data has to be removed, who is responsible for checking the output, and when legal or technical consultation is required - Karol Sikorski, president of the Greater Poland Chamber of Commerce and Industry
What It Means for Polish Companies
For legal and IT departments in Poland, the message is clear: banning AI use in workplace policy doesn't solve the problem, since more than half of employees use these tools anyway without asking permission. What works better is combining technical safeguards, like masking data before it's sent out, with a simple, clear procedure that spells out exactly which documents are off-limits.
UODO also plans to put more emphasis on education, since 91 percent of survey respondents said they wanted the regulator to provide materials explaining the rules for using AI in the context of data protection. That suggests the office intends to publish more industry guidance in the coming months, rather than waiting for the first inspections and fines.
