Skip to content
SimpleAct Logo

AI Act and GDPR · Practice

As of 9 October 2026, after the Digital Omnibus

Shadow AI in companies

Shadow AI means AI tools that employees use without the company having reviewed or approved them: a chatbot in the browser, a transcription service, an add-on in the office suite. This page explains which obligations are affected, how to find such tools and how to govern their use instead of just banning it.

Short answer

Shadow AI is not a legal term, but it is a compliance risk. What nobody in the company knows about cannot be classified: neither as a prohibited practice (Art. 5 AI Act) nor as a high-risk system with deployer obligations (Art. 26 AI Act). If personal data reaches unvetted services, there is usually no data processing agreement (Art. 28 GDPR), no entry in the records of processing (Art. 30 GDPR) and no appropriate safeguards (Art. 32 GDPR). The first step is a complete AI inventory, the second an AI policy with approved alternatives.

Obligations affected

What shadow AI touches legally

Which obligations apply depends on the tool, the purpose and the data processed. These provisions are affected most often.

  • Art. 4 AI Act as amended

    AI literacy

    Deployers take measures to support the AI literacy of their staff. That presupposes knowing which AI systems are in use.

  • Art. 5, Art. 26 AI Act

    Classification and deployer obligations

    If a tool is used for a purpose listed in Annex III, such as pre-screening job applications, the company can be the deployer of a high-risk AI system without knowing it.

  • Art. 50 AI Act

    Transparency

    Content generated or manipulated with AI can trigger labelling obligations, for example for deepfakes or for text published to inform the public on matters of public interest.

  • Art. 28, 30 GDPR

    Processing agreement and records

    If an external AI service processes personal data on behalf of the company, a contract under Art. 28 and an entry in the records of processing are required.

  • Art. 5(1)(f), Art. 32 GDPR

    Confidentiality and security

    Customer data, HR files or trade secrets in an unvetted service put confidentiality and integrity at risk. Depending on the case, a notification duty under Art. 33 GDPR can arise.

  • Art. 35 GDPR

    Data protection impact assessment

    New technologies likely to result in a high risk to data subjects require a DPIA beforehand. For unknown tools it does not happen.

Detect

Where to find shadow AI

  • Consents in Microsoft 365 or Google Workspace: which apps did employees grant access to company data via OAuth?
  • Proxy, firewall or DNS logs: which domains of known AI vendors are being called?
  • Device management (e.g. Intune): which AI apps and browser extensions are installed?
  • Invoices and company credit cards: which AI subscriptions run through expenses?
  • Asking business units: what is AI already used for, and what is missing?

Analysing logs can itself involve employees’ personal data. Define purpose, scope and retention beforehand and involve the works council where there is one (to be checked case by case).

Govern instead of ban

How companies get shadow AI under control

A blanket ban usually just moves usage to private devices and accounts. It works better to offer approved tools that meet the need and to set clear rules for everything else.

An AI policy defines which tools are allowed for which purposes, which data must not go into AI services, how new tools are requested and who reviews them. Tools that are found go into the AI inventory and are classified like any other AI system.

Training under Art. 4 AI Act explains why the rules apply. People who understand the risks are more likely to report new tools than to use them secretly.

Implementation

How SimpleAct makes shadow AI visible

  • AI Discovery

    Three discovery sources

    OAuth consent grants from Microsoft Entra ID, optionally the app landscape from Intune, and uploaded network logs (CSV). No endpoint agent is required.

  • Vendor catalogue

    Category and risk hint

    Every finding is matched against a catalogue of known AI vendors. Unknown domains are collected rather than discarded.

  • Art. 4, Art. 26 AI Act

    From finding to inventory

    Findings can be promoted into the AI inventory, classified and given owners, obligations and evidence.

FAQ

Frequently asked questions about shadow AI

AI tools that employees use at work without the company having reviewed or approved them. The term is borrowed from “shadow IT” and is not a legal term.
The AI Act does not prohibit shadow AI as such. The risk is that obligations go unnoticed, such as deployer obligations for high-risk AI (Art. 26 AI Act) or processing agreements and security under Art. 28 and 32 GDPR.
That is the company’s decision. An AI policy that defines which tools are allowed with which data makes sense. Processing personal data requires a suitable contractual basis with the provider.
Through OAuth consents in Microsoft 365 or Google Workspace, proxy and DNS logs, device management, invoices and asking business units. Respect employee data protection when analysing logs.
Usually not. Bans often move usage to private devices. Approved alternatives, clear rules and AI literacy training under Art. 4 AI Act work better.

More questions? We're happy to help. Send email · Get started

Sources and status

As of · SimpleAct editorial team

Editorial information, not legal advice. The text published in the Official Journal is authoritative; interpretation and national implementation can differ in individual cases. For specific questions, seek legal advice.

Make shadow AI visible

Find out which AI tools are used in your company and move them into the AI inventory with classification and owners. We will show you how this looks in SimpleAct.