Previous Article Back to Blog
September 4, 2026 Nicolas Pinault (Co-founder & Product Development) 7 min read AI Act

Shadow AI in European SMEs: The Compliance Risk Hiding in Your Team’s Browser Tabs

Executive summary
  • Shadow AI, employees using AI tools the company never approved, reviewed, or knows about, has moved from IT nuisance to compliance liability. Under the AI Act , your company is a "deployer" the moment staff use AI tools professionally, whether or not procurement signed off.
  • UpGuard's November 2025 research puts unapproved AI tool use among employees above 80%. Pacific AI's 2025 survey found fewer than four in ten companies have a formal AI governance framework in place.
  • A ban doesn't survive contact with a deadline. Visibility comes first: you need to know what's in use before you can govern any of it.
80%+
Employees Using Unapproved AI Tools

at work, per UpGuard's 2025 State of Shadow AI report .

36%
Companies With a Formal AI Governance Framework

leaving a majority managing AI risk with no documented process at all, per Pacific AI's 2025 Governance Survey .

Shadow AI in brief: any AI tool an employee uses for work without company review. A personal ChatGPT account, a browser extension that summarizes documents, an AI feature turned on inside another SaaS product your company already pays for. None of it shows up in an IT asset list built for software licenses. All of it can process company or customer data.

Key takeaways

  • The AI Act doesn't require you to have chosen or approved an AI tool for it to trigger deployer obligations. Informal, unauthorized use counts.
  • Most organizations that have looked have found unsanctioned AI use somewhere in the building. The honest starting assumption for any SME is "we have some," not "do we have any."
  • A tool ban without a sanctioned alternative fails: employees route around it. A documented inventory and an approved-tools list works instead.

Why this became urgent in 2026, not 2023

Shadow IT, unapproved software, has existed for as long as companies have had IT departments. Shadow AI is a different problem. The tools are easy to start using, useful the moment you do, and they process data in ways an employee can't see and can't audit. Signing up for a personal ChatGPT account takes thirty seconds. Understanding what happens to the data pasted into it takes far longer, and almost nobody does that second part before the first.

Picture a marketing coordinator at a 40-person industrial supplier. She's behind on a product catalog rewrite, finds a free AI writing tool through a LinkedIn ad, and pastes in three years of client testimonials to speed up the drafting. Nobody told her not to. Nobody told her to, either. Her manager finds out about the tool six months later, by accident, while asking why the catalog copy suddenly sounds different.

The scale involved isn't marginal. UpGuard's research puts unapproved AI use above 80% of workers, with security professionals using unsanctioned tools at rates just as high. Meanwhile, only around a third of companies report having a formal AI governance framework at all. That gap, high usage paired with low governance, is where compliance failures happen.

Why this is a compliance problem, not just a security one

Two regulatory facts make shadow AI a compliance exposure specifically, not only an IT hygiene issue.

First, deployer status doesn't require approval. Under the EU AI Act , any organization whose staff use an AI system professionally is a "deployer," subject to obligations including AI literacy (Article 4, in force since 2 February 2025) and, for higher-risk use cases, additional duties under Article 26. The Act does not exempt tools that IT never signed off on. If your marketing team uses an unapproved AI tool to screen job candidates informally, your company carries deployer obligations for that use, whether or not compliance knew it was happening.

Second, GDPR exposure follows the data, not the procurement process. An employee pasting a customer list into an AI summarization tool is a data processing event under GDPR regardless of who authorized the tool. Shadow AI use is, by definition, use nobody reviewed for a lawful basis, a DPA, or data minimization: the exact gaps a GDPR audit is built to find. See our analysis in our ChatGPT & Copilot GDPR compliance guide and our practical GDPR checklist for SMEs .

What shadow AI actually looks like inside an SME

It's rarely one dramatic case. It's usually five or six small, individually reasonable decisions that add up to an ungoverned processing footprint.

Pattern Example Why it's missed
Personal-account chatbot use An employee uses their own ChatGPT/Gemini account for work tasks No corporate account, no IT visibility
Embedded AI features An AI "smart summary" or "auto-draft" feature quietly enabled inside an existing SaaS tool Nobody re-reviews a tool's terms after a feature update
Browser extensions A "summarize this page" or "rewrite this email" extension installed without IT review Extensions rarely go through procurement
Freelancer/contractor tools An external collaborator uses their own AI tools on your data Outside your device management entirely
Department-level pilots A team adopts a tool to move faster, loops in compliance later, if at all Speed gets rewarded, documentation doesn't

Building visibility: the first, non-negotiable step

You can't govern what you can't see. Before writing a policy, running training, or classifying risk, an SME needs an honest, current answer to one question: what AI tools are actually touching our data today?

  • Ask, don't assume. Send a short survey to every team: what AI tools do you use for work, even occasionally? Frame it as fact-finding, not an audit of wrongdoing. People underreport when they think they'll be blamed.
  • Check your existing SaaS stack for embedded AI. Many tools you already pay for have quietly added AI features. Review recent release notes and settings pages for tools handling customer or employee data.
  • Look at expense reports and card statements. Personal subscriptions to AI tools sometimes get expensed, a useful, underused signal.
  • Document what you find, even the messy parts. An incomplete inventory that's honest is more useful, and more defensible to a regulator, than a clean one that's fiction.

What to do once you have visibility

A ban rarely survives a deadline. If a tool is useful and gets banned outright, the realistic outcome is that employees keep using it, just less visibly. The approach that holds up:

  1. Approve a short list of sanctioned tools on enterprise/API tiers with a Data Processing Agreement in place. Giving people a legitimate, fast alternative removes most of the incentive to go around it.
  2. Write a one-page acceptable-use policy stating what can and can't go into a prompt, in plain language, not a legal document nobody reads.
  3. Run baseline AI literacy training to satisfy Article 4 and, more practically, to make the risk legible to the people creating it. Follow our actionable roadmap in How to Comply with the EU AI Act in 5 Steps .
  4. Re-run the discovery exercise quarterly. Shadow AI isn't a one-time cleanup. New tools appear constantly, and the inventory goes stale within months if it isn't revisited.

Frequently Asked Questions

Is my company liable for AI Act obligations if employees use tools we never approved?
Yes, potentially. AI Act deployer status attaches to professional use of an AI system, not to whether the company formally selected or purchased it. Unauthorized, employee-initiated use of an AI tool for work purposes can still trigger deployer obligations, including the Article 4 AI literacy requirement.
Should we just block AI tools at the network level?
Blocking access to specific known tools can be part of a response, but as a standalone strategy it tends to fail. Employees switch to personal devices or unblocked alternatives, and you lose visibility rather than gaining control. A sanctioned-tools list paired with a usable policy holds up better than a block list alone.
How do we find out what AI tools our team is actually using?
Start with a direct, non-punitive survey of every team, cross-reference it against your existing SaaS subscriptions for embedded AI features, and check expense reports for individually subscribed tools. No single method catches everything; the combination gets you most of the way.
Is this really a compliance issue, or is it an IT problem?
Both, but the compliance exposure is the part most companies underestimate. IT cares about security and cost. Compliance cares about lawful basis for data processing, AI Act deployer obligations, and what happens if a regulator asks what AI tools process personal data in your company: a question shadow AI, by definition, leaves unanswered.
Nicolas Pinault

Nicolas Pinault is Co-founder & Product Development at Themio. With over 20 years of SaaS architecture experience, he designs the deterministic rules engines and compliance infrastructure for European enterprises.

Themio.ai maps your EU AI Act deployer obligations and GDPR exposure for tools in use across your organization, identifying required governance policies, inventories, and compliance steps in under 2 minutes, with every finding traceable to the source article. See how it works →