Shadow AI is a security problem, but the EU AI Act makes it a legal one
Employees at larger enterprises regularly feed corporate data into AI tools.
Organizations face a significant AI-related security risk not from external attackers, but from employees using unauthorized AI tools on company data. A recent survey found that nearly half of employees at larger enterprises regularly feed corporate information into unapproved AI tools, even when company-approved tools are available.
This practice increases the risk of data breaches, with unauthorized tools contributing to 43% of breaches in the past year, according to IBM's 2026 Cost of a Data Breach report. The EU AI Act adds legal requirements on managing AI use, requiring organizations to have full governance over how AI is deployed, governed, and monitored.
These obligations, which have rolled out in phases, include inventory management, data governance, audit logging, and transparency. Other deadlines will come into force later, covering high-risk AI usage in areas like recruitment, credit scoring, and biometric categorization. Any organization using AI systems now has compliance obligations, regardless of whether the systems were formally sanctioned.
Penalties for high-risk breaches can reach up to €15 million or 3% of global annual turnover. Existing security stacks may not be able to detect shadow AI, as it exploits blind spots between conventional security layers. Detection logic needs to match the reality of defending against a covert internal threat actor, intercepting sensitive data at the point of movement before it reaches an external AI system.
To comply with the EU AI Act, security and compliance teams should map the full AI estate, including unmanaged endpoints, personal devices, and AI embedded within SaaS. Data governance must move to the endpoint, and policies prohibiting sensitive data sharing with unapproved tools are crucial. Continuous discovery and granular interaction logs help demonstrate compliance with the Act's requirements.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.