Shadow AI: the AI your company already uses without knowing it
Someone on your team pasted an internal text into a free chatbot this week. Someone else connected an extension that summarises meetings. Marketing is trying out an image generator on the department card. None of it went through IT, or procurement, or the DPO. That is shadow AI: the use of artificial-intelligence tools in your company without anyone having assessed them, signed them off or put them on record.
Why it is not a discipline problem
Shadow AI does not appear because your team is reckless, but because these tools are useful, free or nearly free, and one click away. Banning them outright does not work: it pushes the use onto personal phones and leaves you with no visibility. The problem is not that they are used; it is that you do not know which ones, for what, or with which data.
What the law says — without inventing obligations
“Shadow AI” appears in no regulation. What does appear:
- EU AI Act, Art. 3, point 4: a deployer is whoever uses an AI system “under its authority”, with the sole exception of personal, non-professional activity. Professional use of these tools by your staff points straight at that definition — and the Regulation assigns its obligations per system, whether you know about it or not.
- EU AI Act, Art. 4: the AI literacy measures, in force since 2 February 2025, reach your staff “and other persons dealing on their behalf” with the use of AI systems. Hard to take measures on tools you do not know exist.
- GDPR: if an employee feeds personal data of clients or staff into a tool with no contract and no safeguards, your company remains the controller. In practice, this is the most immediate exposure.
And the pressure does not arrive on a legal deadline: it arrives earlier, by email — a large client asking for evidence, a procurement questionnaire, a board asking “how do we use AI?”.
Regaining control, in six steps
- Discover. A short, honest team survey — no retroactive penalties — plus a review of expenses and browser extensions. The goal is the real list, not the comfortable one.
- Inventory. Every tool with its record: who uses it, for what, since when. Download the inventory template →
- Review vendors. What each vendor says about your data: where it is processed, whether they train on it, what contract they offer.
- Classify. Place each use within the framework of the AI Act and the GDPR. Most will be minimal risk; what matters is being able to show why. Guide to the EU AI Act →
- Decide and write the policy. What is allowed, what needs approval and what stays out — with the rationale in writing, not as a list of bans.
- Keep the register alive. New tools will arrive next month. Without an intake process, the inventory goes stale in weeks.
Doing it by hand and keeping it alive are two different problems
A spreadsheet solves the first inventory. What it does not solve is showing, six months later, since when each tool has been on record, who decided its classification and what was there before. Alethexis M1 · Visibility is exactly that layer: the governed inventory, with the history, author and date of every change, and exportable evidence.
Dates under Art. 113 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (OJEU of 24 July 2026, in force since 27 July 2026). This content is informational and is not legal advice.