survol

← All articles · Analysis

Analysis

Shadow AI in the public sector: a symptom of being ahead, not behind

More than one public servant in two already uses ChatGPT quietly to do their job. Seen from the risk side - data outside the EU, the Cloud Act, a growing cyber threat - it is worrying. Seen from the usage side, it is a tremendous signal of appetite. The right answer is neither prohibition nor waiting: it is sovereign governance that sees and frames without punishing.

A
Adrien Torris 26 June 20269 min read
From clandestine ChatGPT (shadow AI) to sovereign, governed AI in local government

The figure landed on 5 April in La Tribune Dimanche, and it deserved an earthquake: in a survey of 2,000 public servants across nine French administrations, more than one in two says they use ChatGPT or an equivalent in the course of their duties. With no framework, no supervision, no formalised code of conduct. Better still: 73% report a productivity gain, and 80% want to go further. As Étienne Delouvrier (Avanoo) describes in InformatiqueNews, "shadow AI" is no longer a hypothesis: it is already inside town halls.

Let us start with what is rarely said: this is not a collective professional failing. The officer who has a memo rewritten in plain language, a resident's letter translated into Ukrainian, or a draft council resolution produced from rough notes, is doing exactly what we expect from a public service: faster, better, with less. They are inventing, on their own, the use cases that doctrine has not had time to write down.

Shadow AI is not the symptom of a public service left behind. It is the symptom of a public service ahead of its own governance.

The real problem: asymmetry

So the problem is not enthusiasm. It is the asymmetry between that enthusiasm and how exposed public bodies are. And there, the numbers are chilling. In its 2025 cyber threat overview, France's ANSSI reports that ministries and local authorities account for 24% of the incidents it handled - the second most targeted sector in the country. That same year, 144 municipalities were hit by a cyberattack, 25 of them by a confirmed ransomware. The bill is real and documented: €1M for Lille, €230,000 for Mitry-Mory, entire services halted in Gravelines.

On top of that already strained ground comes shadow AI: HR files, council meeting minutes, draft by-laws, citizen data travelling through servers outside the EU, subject to the Cloud Act, sometimes reused to train models whose value chain nobody in the organisation controls. Minister David Amiel sums up the risk bluntly: a "clandestine AI spreading" at the expense of "our data and our independence".

A structural situation, not negligence

To be fair: the responsibility does not lie with local authorities. A town of 8,000 inhabitants typically has a part-time IT manager - sometimes none at all. An inter-municipal body often shares one security officer across twenty entities. Meanwhile the French state is rolling out a sovereign assistant based on Mistral (Mistral Medium 3, hosted in France at Outscale on SecNumCloud) for at least 10,000 ministry staff… but access is not yet open to local government. Seventy authorities are negotiating their way into Albert API. The others are waiting. And while they wait, they do what they can: they open a ChatGPT tab.

Here is the tension: AI is too useful to ban, too risky to leave unattended, and too fast to wait for negotiations. Banning it would only push shadow AI deeper into the shadows.

The right answer: see and frame, without punishing

If prohibition does not work and waiting does not either, what is left? Framing. And the good news, too rarely highlighted, is that the answer to shadow AI will not necessarily come from the American giants who are its root cause. A French and European ecosystem is emerging that offers exactly what public bodies are looking for: the ability to see, understand and frame AI usage - without killing the momentum or rebuilding a ten-million-euro information system. Map real usage, steer people towards compliant tools, protect sensitive data at source. Without banning. Without punishing. By supporting.

Three principles emerge, and they hold well beyond town halls - for any organisation adopting AI:

Where Survol does its part

Let us be precise about our scope: Survol is not a firewall that stops someone pasting an HR memo into ChatGPT. But on the ground where we operate - designing and steering digital products with a coding AI - we apply exactly those three principles. In other words: we prevent the shadow AI of development, right where a public body (or any organisation) builds its online services.

At our scale, that is the same philosophy public bodies are asking for: a French answer, simple to deploy, that respects sovereignty and locks nobody in. Survol supervises - it owns nothing.

From clandestine ChatGPT (shadow AI) to sovereign, governed AI in local government

The takeaway

  1. Shadow AI is first of all proof of usefulness: public servants did not wait for a circular to save time.
  2. The risk is real - data outside the EU, the Cloud Act, cyber threats - and banning would only make it worse.
  3. The answer is sovereign governance: see, frame, trace, without punishing. A French ecosystem is emerging for exactly that.
  4. The same reflex applies to building software: govern and trace your development AI, rather than discovering it after the fact.

"It is up to us, French players, to close the gap. Fast", writes Étienne Delouvrier. We share the call - and the urgency. Shadow AI is not a fatality: it is an invitation to finally give the enthusiasm that created it a framework worthy of it.

#shadow-ai #sovereignty #public-sector #governance
A

Adrien Torris

Founder of Survol

A developer turned agent orchestrator. I write about steering products in the age of agentic development, and about the making of Survol.

Don't miss the next article

One email a month, our best field notes on agentic development and what's new in Survol.