Shadow AI in the Public Sector: What the Försäkringskassan Case Shows

Shadow AI in the Public Sector: What the Försäkringskassan Case Shows

The Shadow AI Risk Inside the Organisation

Everybody is talking about AI as a new way into organisations including prompt injection, AI-assisted phishing, poisoned models and cloned voices. Those threats are real. But one of the most immediate risks from shadow AI in any organization, private as well as public sector, may be simpler; employees intentionally or accidentally putting confidential information into tools they use every day. That action can turn an ordinary productivity task into a GDPR incident, a confidentiality breach and a costly problem for the organisation. In some cases, the consequences can extend beyond the company itself and seriously impact the employees involved.

The Försäkringskassan case in Sweden shows exactly how this can happen. No attacker broke in. No system was hacked. Employees used an AI-powered tool during normal work and confidential information ended up where it should not have been.

What Happened at Försäkringskassan

Two caseworkers at Försäkringskassan’s department for international healthcare needed to translate clients’ medical certificates and case notes. They pasted the text into Google Translate without first removing the personal data. The incidents happened in February and April of this year.

Google Translate is permitted at the agency. Pasting unedited personal data into it is not. Because the material was covered by secrecy rules, the agency’s position was that the information had been disclosed the moment it left whatever happened to it afterwards.

Both cases went to Försäkringskassan’s personnel responsibility board, known as PAN, the internal body that handles disciplinary matters at larger Swedish authorities. At the end of August the board decided to refer both caseworkers to prosecutors. The agency’s press office told Publikt that the referral was made because there was reasonable suspicion of an offence against the duty of confidentiality. It added that neither employee was suspected of having acted deliberately.

Nobody attacked Försäkringskassan. Nothing was encrypted, no credentials were stolen and no ransom was demanded. The whole incident consisted of text moving from a case system into a browser tab.

The Agency Was Cleared. The Staff Were Not.

The detail that makes this case worth a board’s attention is one the coverage has largely passed over. Sweden’s data protection authority, IMY, examined one of the two cases and concluded that the agency itself could not be faulted, according to Arbetsvärlden. The second case remains under review. On the data protection track, in other words, the organisation came through without a finding against it.

The criminal track reached the opposite place. The agency’s own memo to the board pointed to the penal code noting that a person who discloses information they are obliged to keep secret can face a fine or imprisonment. Disclosure through negligence is enough to attract a fine. Försäkringskassan’s investigation found no intention to break any rule and put the cause down to workload and inattention. Its position was that the distinction matters less than the result. The information was disclosed either way.

Read those two outcomes together and the lesson is uncomfortable. An organisation can pass a data protection review and still watch two of its staff referred to prosecutors on exactly the same facts. Liability under GDPR sits with the controller which is the organisation. The duty of confidentiality sits with the person at the desk. A board that treats “we are GDPR compliant” as the complete answer to AI risk has answered only one of the two questions being asked. It is not the one that ends careers.

There is a further consequence that no apology can undo. Arbetsvärlden notes that once the material reached Google’s servers it sits where the company’s own AI assistant may process and train on it. Deleting a browser tab does not retrieve it. This is also why it helps to know in advance which of Sweden’s reporting clocks a given event starts because the answer determines what you owe, to whom and by when.

Why Shadow AI Starts with the Approved Tool

The most useful part of this story is the mechanism because it has very little to do with Swedish social insurance and a great deal to do with any organisation adopting AI under pressure.

Both caseworkers said in the investigation that roughly 90 percent of the documents they handle need translating. The agency does have an internal AI tool, one that keeps information on its own servers. That tool is still under development and cannot yet handle every language. That comes from Andreas Spång, the head of the department, speaking to Arbetsvärlden in general terms rather than about these two cases. The safe tool did not cover the language in front of them. The unsafe one did, instantly and at no cost.

Meanwhile the pressure ran in a single direction. The department has been working under a government catch-up mandate for two and a half years. Since 2025 Försäkringskassan has also carried a mandate to integrate AI into its operations, tightened for 2026 after the government expressed dissatisfaction with the pace. Thomas Åding, the ST union chair at the agency and a member of the board that made the referral, told Arbetsvärlden that at every meeting with government since 2024 the answer had been to become more efficient with AI. Asked in late 2025 about objections concerning the handling of sensitive information, Sweden’s minister for public administration Erik Slottner told Sveriges Radio’s P3 Nyheter that we would see “some mistakes and errors here and there”. The policy, in short, anticipated the failures. What it did not settle is who absorbs them. The answer so far is not the ministry, not the agency and not the vendor.

This is how shadow AI or skugg-AI as it is known in Sweden, actually begins in most organisations. Not in defiance and rarely in ignorance of the policy. It begins in the gap between what the sanctioned tool can do and what the job in front of someone actually requires. That gap widens every time leadership asks for more output without closing it. The same pattern is already visible in engineering where developers reach for public models to unblock themselves and the organisation quietly inherits the risks that come with AI-generated code. Ask which of your teams are currently being told to go faster with AI while the approved tool does not yet do what they need. That list is your exposure.

The Incident Your Security Stack Cannot See

It is worth pausing on what this incident did not generate. No malware executed. No unusual login appeared. No large outbound file transfer registered. No data loss prevention rule fired because nothing was ever attached to anything. Text moved from a case management system into a browser tab on a permitted website which is a sequence most security stacks record as a visit to a translation service and nothing more.

The reporting does not say how either incident came to light. That silence deserves attention. If you cannot describe in one sentence how your organisation would learn that a member of staff pasted a patient record or a personnel file into a public model this morning, then you would not learn it. You would learn it the way this board learned it, later and from somebody else.

Detecting this class of event is a different problem from detecting intrusion. It requires visibility over which AI services your people actually use, what leaves the organisation through them and which of those accounts are corporate rather than personal. Very little of that appears in a traditional endpoint or perimeter view.

Sweden Already Published the Rulebook

None of this happened in a regulatory vacuum. On 21 January 2025, Digg and IMY published national guidelines for the use of generative AI in public administration, produced on a government mandate issued in July 2024. At launch there were 18 guidelines covering leadership and accountability, information security, copyright, data protection, ethics, employment law and procurement. They are public, free and written for exactly this situation.

IMY has since named AI in the public sector as one of its three supervision and guidance priorities for 2026, alongside children and young people and law enforcement processing. For a kommun or a region, that is not a distant signal. The authority has said in advance where it intends to look. Försäkringskassan and Skatteverket are simultaneously building AI-verkstaden, a shared national environment meant to help agencies, municipalities and regions develop and test AI safely which tells you the state itself recognises how widespread the capability gap has become.

At EU level, the obligation most often missed is Article 4 of the AI Act. It has applied since 2 February 2025 to every deployer of an AI system, public authorities included. It requires measures to build AI literacy among the staff operating those systems. The Digital Omnibus on AI, in force since late July 2026, deferred the heavier high-risk obligations for Annex III systems to December 2027 and softened Article 4’s wording from ensuring a sufficient level of literacy to supporting its development. It did not move the date. For an organisation that has taken no measures at all, that softening changes nothing because the question a supervisory authority asks is what measures you took.

One precision point is worth making, because it is frequently confused. This is not a NIS2 incident in the ordinary sense. No service was disrupted and no network was intruded so the reporting duties under Cybersäkerhetslagen are not the ones in play. What is in play is data protection law and the secrecy rules which run on their own timetable. Whether your organisation sits inside Sweden’s NIS2 scope is a separate question and worth settling separately.

Questions Worth Putting to Your Own Organisation

None of the useful questions here require a budget cycle to answer. The first is whether the sanctioned tool actually handles the work. For every task where staff currently reach for a public AI service, someone should be able to name the languages, file types and document formats the approved alternative cannot process today. That list is where the next incident comes from.

The second is a detection question. If someone pasted a case file into a browser tab this morning which log would show it? Who reads that log? The third is a governance question, duller but no less important, who signs the confidentiality assessment for each AI use case? When was the most recent one written? An assessment that exists but is two years old covers a tool that no longer behaves the same way.

The fourth question decides the other three. When an investigation concludes that the guidance was clear, ask how long that guidance takes to read and when your staff last had that time. Thomas Åding’s answer to Publikt was that the rules are clear enough if you read every document closely and that very little time is left for reading when almost all of it goes to clearing cases faster. A policy nobody has time to read is not a control. It is a record of what you intended.

Careful Was Not the Missing Control

Both caseworkers were described by their own managers as careful. The investigation found no intention to break any rule. What it found was workload and inattention, in an organisation that had written the right policy, permitted the right tool and told its staff clearly what the rules were. Careful people, written rules and an approved tool still produced a criminal referral because none of those three things closed the gap between the work that had to be done and the tools available to do it. If your own AI governance rests on the same three things, it rests on precisely what failed here.

This post is also available in: Svenska