This article provides general informational guidance. See the Legal disclaimer .
- Shadow AI, employees using AI tools the company never approved, reviewed, or knows about, has moved from IT nuisance to compliance liability. Under the AI Act , your company is a "deployer" the moment staff use AI tools professionally, whether or not procurement signed off.
- UpGuard's November 2025 research puts unapproved AI tool use among employees above 80%. Pacific AI's 2025 survey found fewer than four in ten companies have a formal AI governance framework in place.
- A ban doesn't survive contact with a deadline. Visibility comes first: you need to know what's in use before you can govern any of it.
Shadow AI in brief: any AI tool an employee uses for work without company review. A personal ChatGPT account, a browser extension that summarizes documents, an AI feature turned on inside another SaaS product your company already pays for. None of it shows up in an IT asset list built for software licenses. All of it can process company or customer data.
Key takeaways
- The AI Act doesn't require you to have chosen or approved an AI tool for it to trigger deployer obligations. Informal, unauthorized use counts.
- Most organizations that have looked have found unsanctioned AI use somewhere in the building. The honest starting assumption for any SME is "we have some," not "do we have any."
- A tool ban without a sanctioned alternative fails: employees route around it. A documented inventory and an approved-tools list works instead.
Why this became urgent in 2026, not 2023
Shadow IT, unapproved software, has existed for as long as companies have had IT departments. Shadow AI is a different problem. The tools are easy to start using, useful the moment you do, and they process data in ways an employee can't see and can't audit. Signing up for a personal ChatGPT account takes thirty seconds. Understanding what happens to the data pasted into it takes far longer, and almost nobody does that second part before the first.
Picture a marketing coordinator at a 40-person industrial supplier. She's behind on a product catalog rewrite, finds a free AI writing tool through a LinkedIn ad, and pastes in three years of client testimonials to speed up the drafting. Nobody told her not to. Nobody told her to, either. Her manager finds out about the tool six months later, by accident, while asking why the catalog copy suddenly sounds different.
The scale involved isn't marginal. UpGuard's research puts unapproved AI use above 80% of workers, with security professionals using unsanctioned tools at rates just as high. Meanwhile, only around a third of companies report having a formal AI governance framework at all. That gap, high usage paired with low governance, is where compliance failures happen.
Why this is a compliance problem, not just a security one
Two regulatory facts make shadow AI a compliance exposure specifically, not only an IT hygiene issue.
First, deployer status doesn't require approval. Under the EU AI Act , any organization whose staff use an AI system professionally is a "deployer," subject to obligations including AI literacy (Article 4, in force since 2 February 2025) and, for higher-risk use cases, additional duties under Article 26. The Act does not exempt tools that IT never signed off on. If your marketing team uses an unapproved AI tool to screen job candidates informally, your company carries deployer obligations for that use, whether or not compliance knew it was happening.
Second, GDPR exposure follows the data, not the procurement process. An employee pasting a customer list into an AI summarization tool is a data processing event under GDPR regardless of who authorized the tool. Shadow AI use is, by definition, use nobody reviewed for a lawful basis, a DPA, or data minimization: the exact gaps a GDPR audit is built to find. See our analysis in our ChatGPT & Copilot GDPR compliance guide and our practical GDPR checklist for SMEs .
What shadow AI actually looks like inside an SME
It's rarely one dramatic case. It's usually five or six small, individually reasonable decisions that add up to an ungoverned processing footprint.
| Pattern | Example | Why it's missed |
|---|---|---|
| Personal-account chatbot use | An employee uses their own ChatGPT/Gemini account for work tasks | No corporate account, no IT visibility |
| Embedded AI features | An AI "smart summary" or "auto-draft" feature quietly enabled inside an existing SaaS tool | Nobody re-reviews a tool's terms after a feature update |
| Browser extensions | A "summarize this page" or "rewrite this email" extension installed without IT review | Extensions rarely go through procurement |
| Freelancer/contractor tools | An external collaborator uses their own AI tools on your data | Outside your device management entirely |
| Department-level pilots | A team adopts a tool to move faster, loops in compliance later, if at all | Speed gets rewarded, documentation doesn't |
Building visibility: the first, non-negotiable step
You can't govern what you can't see. Before writing a policy, running training, or classifying risk, an SME needs an honest, current answer to one question: what AI tools are actually touching our data today?
- Ask, don't assume. Send a short survey to every team: what AI tools do you use for work, even occasionally? Frame it as fact-finding, not an audit of wrongdoing. People underreport when they think they'll be blamed.
- Check your existing SaaS stack for embedded AI. Many tools you already pay for have quietly added AI features. Review recent release notes and settings pages for tools handling customer or employee data.
- Look at expense reports and card statements. Personal subscriptions to AI tools sometimes get expensed, a useful, underused signal.
- Document what you find, even the messy parts. An incomplete inventory that's honest is more useful, and more defensible to a regulator, than a clean one that's fiction.
What to do once you have visibility
A ban rarely survives a deadline. If a tool is useful and gets banned outright, the realistic outcome is that employees keep using it, just less visibly. The approach that holds up:
- Approve a short list of sanctioned tools on enterprise/API tiers with a Data Processing Agreement in place. Giving people a legitimate, fast alternative removes most of the incentive to go around it.
- Write a one-page acceptable-use policy stating what can and can't go into a prompt, in plain language, not a legal document nobody reads.
- Run baseline AI literacy training to satisfy Article 4 and, more practically, to make the risk legible to the people creating it. Follow our actionable roadmap in How to Comply with the EU AI Act in 5 Steps .
- Re-run the discovery exercise quarterly. Shadow AI isn't a one-time cleanup. New tools appear constantly, and the inventory goes stale within months if it isn't revisited.
Frequently Asked Questions
Is my company liable for AI Act obligations if employees use tools we never approved?
Should we just block AI tools at the network level?
How do we find out what AI tools our team is actually using?
Is this really a compliance issue, or is it an IT problem?
Themio.ai maps your EU AI Act deployer obligations and GDPR exposure for tools in use across your organization, identifying required governance policies, inventories, and compliance steps in under 2 minutes, with every finding traceable to the source article. See how it works →
This article provides general information to help you understand compliance obligations regarding shadow AI and the EU AI Act. It does not constitute legal advice and does not replace review by a qualified lawyer, DPO, or compliance specialist familiar with your organization's specific situation. Regulatory requirements can change — always verify current obligations against official texts. Last reviewed: September 4, 2026.