Artificial intelligence has now become part of businesses’ day-to-day operations. It is not limited to major technology projects or complex systems developed in-house: it is often already embedded in the tools used daily by employees, external collaborators, and corporate departments.
The starting point should not be the question of whether AI ought to be prohibited, but rather how it can be adopted, governed, and used responsibly.
Which AI Tools Are Actually Being Used?
When a company is asked which artificial intelligence tools it uses, the initial response is often uncertain: silence, hesitation, or sometimes the claim, “We do not use any.”
However, further investigation often reveals a different reality: translation tools, chatbots, generative AI assistants, applications integrated into corporate software, free services, or business accounts. This is the phenomenon known as “shadow AI”: tools that have not been formally adopted by the company but are used independently by employees.
In the workplace, AI may be used to screen candidates, manage attendance, monitor productivity, support logistics processes, or assess employee performance.
What Should a Company Do Before Adopting AI Systems?
A sound approach should begin with several essential activities: mapping the tools being used, assessing providers, distinguishing between public or free tools from business accounts, defining privacy roles and contractual responsibilities, and clarifying which data may be entered and which data must not be disclosed.
The company should also review the service settings, terms of use, purposes of processing, security measures, data storage locations, and any potential reuse of uploaded content.
Internal procedures, policies, and guidelines are effective only when they are understood, communicated, and properly implemented. When workers receive clear instructions on the use of AI tools, the company reduces the risk of unauthorized conduct and strengthens its governance framework. In more sensitive cases, it is also necessary to assess the impact on fundamental rights and, where personal data processing is likely to result in high risks, to coordinate this analysis with the data protection impact assessment (DPIA).
Article 27 of the AI Act requires certain deployers of high-risk AI systems to carry out a fundamental rights impact assessment, which complements the DPIA where applicable.
Roberta De Giusti, Country Manager of Privacy Desk Suisse, explored these topics during the Ticino Digital Day event held on 5 May 2026.



