AI Act and GDPR · Practice
As of 9 October 2026, after the Digital Omnibus
Shadow AI in companies
Shadow AI means AI tools that employees use without the company having reviewed or approved them: a chatbot in the browser, a transcription service, an add-on in the office suite. This page explains which obligations are affected, how to find such tools and how to govern their use instead of just banning it.
Short answer
Shadow AI is not a legal term, but it is a compliance risk. What nobody in the company knows about cannot be classified: neither as a prohibited practice (Art. 5 AI Act) nor as a high-risk system with deployer obligations (Art. 26 AI Act). If personal data reaches unvetted services, there is usually no data processing agreement (Art. 28 GDPR), no entry in the records of processing (Art. 30 GDPR) and no appropriate safeguards (Art. 32 GDPR). The first step is a complete AI inventory, the second an AI policy with approved alternatives.
Obligations affected
What shadow AI touches legally
Which obligations apply depends on the tool, the purpose and the data processed. These provisions are affected most often.
Art. 4 AI Act as amended
AI literacy
Deployers take measures to support the AI literacy of their staff. That presupposes knowing which AI systems are in use.
Art. 5, Art. 26 AI Act
Classification and deployer obligations
If a tool is used for a purpose listed in Annex III, such as pre-screening job applications, the company can be the deployer of a high-risk AI system without knowing it.
Art. 50 AI Act
Transparency
Content generated or manipulated with AI can trigger labelling obligations, for example for deepfakes or for text published to inform the public on matters of public interest.
Art. 28, 30 GDPR
Processing agreement and records
If an external AI service processes personal data on behalf of the company, a contract under Art. 28 and an entry in the records of processing are required.
Art. 5(1)(f), Art. 32 GDPR
Confidentiality and security
Customer data, HR files or trade secrets in an unvetted service put confidentiality and integrity at risk. Depending on the case, a notification duty under Art. 33 GDPR can arise.
Art. 35 GDPR
Data protection impact assessment
New technologies likely to result in a high risk to data subjects require a DPIA beforehand. For unknown tools it does not happen.
Detect
Where to find shadow AI
- Consents in Microsoft 365 or Google Workspace: which apps did employees grant access to company data via OAuth?
- Proxy, firewall or DNS logs: which domains of known AI vendors are being called?
- Device management (e.g. Intune): which AI apps and browser extensions are installed?
- Invoices and company credit cards: which AI subscriptions run through expenses?
- Asking business units: what is AI already used for, and what is missing?
Analysing logs can itself involve employees’ personal data. Define purpose, scope and retention beforehand and involve the works council where there is one (to be checked case by case).
Govern instead of ban
How companies get shadow AI under control
A blanket ban usually just moves usage to private devices and accounts. It works better to offer approved tools that meet the need and to set clear rules for everything else.
An AI policy defines which tools are allowed for which purposes, which data must not go into AI services, how new tools are requested and who reviews them. Tools that are found go into the AI inventory and are classified like any other AI system.
Training under Art. 4 AI Act explains why the rules apply. People who understand the risks are more likely to report new tools than to use them secretly.
Implementation
How SimpleAct makes shadow AI visible
AI Discovery
Three discovery sources
OAuth consent grants from Microsoft Entra ID, optionally the app landscape from Intune, and uploaded network logs (CSV). No endpoint agent is required.
Vendor catalogue
Category and risk hint
Every finding is matched against a catalogue of known AI vendors. Unknown domains are collected rather than discarded.
Art. 4, Art. 26 AI Act
From finding to inventory
Findings can be promoted into the AI inventory, classified and given owners, obligations and evidence.
FAQ
Frequently asked questions about shadow AI
More questions? We're happy to help. Send email · Get started
Sources and status
As of · SimpleAct editorial team
- Regulation (EU) 2024/1689 (AI Act), Official Journal
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal
Editorial information, not legal advice. The text published in the Official Journal is authoritative; interpretation and national implementation can differ in individual cases. For specific questions, seek legal advice.
Make shadow AI visible
Find out which AI tools are used in your company and move them into the AI inventory with classification and owners. We will show you how this looks in SimpleAct.