The word “shadow” appears zero times in the AI Act. Not once in the consolidated text, not in a recital, not in a definition. Yet one European worker in three already uses artificial intelligence at work, and the single article that would force your company to know who they are only becomes enforceable in December 2027. The fine that hits you if one of them gets it wrong became enforceable this month.
That inversion is the whole story. Liability first, visibility sixteen months later.
What we are calling shadow AI
Shadow AI is the use of artificial intelligence tools inside a company that the company never chose, approved or mapped. An employee opens a browser, signs into the free tier of a well known service with a personal account, pastes in the text they are working on and asks for a rewrite. Nobody told them to. Nobody knows they did.
The name suggests something furtive, and that is the first misreading to clear away. In most cases there is no intention to go around the employer. There is a person with repetitive work to finish before the evening.
The number worth starting from, and what it does not say
The Joint Research Centre, the European Commission’s in-house science service, published the AIM-WORK survey in 2025: 70,316 workers aged 16 to 65, across all 27 Member States, fieldwork in 2024 and 2025. It is the widest picture available in Europe today, and it comes from an institution with nothing to sell you.
What it found:
- 30% of EU workers already use artificial intelligence for their own work;
- roughly 20% use it at least once a week;
- the most frequent use is writing, at 65% of all reported uses;
- then translation (59%), data analysis and discussing ideas (38%), transcription (28%), image generation (27%);
- highest usage: Denmark, Belgium, the Netherlands, Finland, Austria.
Now the honest part, which matters as much as the figure itself. The survey measures how many people use AI at work, not how many do it without authorisation. The split between personal initiative and company decision is not in that publication, and anyone who hands you that split with two decimal places is selling you something alongside it.
So the number does the work it can do, and the question it opens stays rhetorical: if 65% of uses are writing, which is precisely the act of pasting company text into a box, how many of those acts happen inside a tool your company selected?
First correction: the law already applies
You will often read that the phenomenon concerns “companies where the AI Act does not apply yet”. It does apply, and the sentence starts from a calendar error.
The AI Act (Regulation (EU) 2024/1689, the European regulation on artificial intelligence) entered into force on 1 August 2024 and applies in stages:
| Block of rules | Applies from |
|---|---|
| Chapters I and II (general provisions, prohibited practices) | 2 February 2025 |
| General purpose AI models | 2 August 2025 |
| General application, including Article 50 on transparency | 2 August 2026 |
| High risk obligations, Annex III (the list that includes staff recruitment) | 2 December 2027 |
| High risk obligations, Annex I | 2 August 2028 |
The last two rows were closer until a few weeks ago. Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July and in force since 27 July 2026, moved them.
The accurate sentence is therefore not “the AI Act does not apply yet”. It is: the law has been in force for two years, the company still has not moved, and the deadline that would have forced it to move has just been pushed back.
Second correction: shadow AI does not breach the AI Act
This has to be stated precisely, because it is the point on which an informed reader would dismantle any alarmist article. There is no dedicated provision, no prohibition, not even a line discouraging the practice.
Shadow AI is not a breach of the AI Act. On a closer reading it turns out to be something less comfortable: exposure that is already enforceable today, on a practice no rule obliges you to map.
That exposure comes in three separate pieces, and they are worth keeping apart because they run on three different clocks.
- Article 50, transparency. Applies from 2 August 2026 and falls directly on the deployer, meaning the organisation that uses the system rather than the one that built it. Anyone deploying a system that generates or manipulates images, audio or video resembling real ones (deep fakes) must disclose that the content has been artificially generated or manipulated. The same duty covers text published for the purpose of informing the public on matters of public interest. Penalties reach 15 million euro or 3% of worldwide annual turnover.
- GDPR (Regulation (EU) 2016/679 on the protection of personal data). No deferral, no phase-in: it applies today, and it applies to the personal data that ends up in a prompt.
- Articles 26 and 27, the duties of an organisation deploying a high risk system. Deferred to 2 December 2027, and materially impossible to perform if you do not know what is running in your own house.
Here is the inversion the whole argument rests on. An employee who publishes generated content today without disclosing it exposes the company to a penalty that is already enforceable, while the duty to know they are doing it arrives in December 2027. Nobody would design that order on purpose.
Third correction: the audit is missing partly because the law never asks for one
Anyone working on this reaches the same diagnosis: what is missing is the audit, the map of what is actually running inside the organisation. The diagnosis is right. The reason is usually told badly.
It is not only corporate timidity. The word “inventory” never appears in the AI Act, and no provision imposes a general census of AI systems in use. Registration in the EU database under Article 49 falls on providers; deployers register only when they are public authorities. An inventory is the factual precondition of Articles 26 and 27, not a standalone duty anyone can hold against you today.
And there is more, on exactly the ground where shadow AI grows. Article 4 is the only provision in the Regulation that addresses AI literacy, meaning how much the people in an organisation actually understand about the systems they operate. It has been rewritten: where it used to require organisations to “ensure a sufficient level”, it now asks them to “take measures to support the development” of that literacy, with an added sentence stating that the obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual. In the list of penalised obligations under Article 99(4), Article 4 does not appear.
One line, then: the only article covering staff competence, which is exactly the ground shadow AI grows on, carries no penalty and has just been softened.
Stated that way the argument gets stronger, not weaker. The problem is not that your company is breaking something. The problem is that nobody is asking it to look, so it does not look.
The grey area, declared rather than hidden
There is a point where lawyers disagree, and hiding it to make the article more dramatic would be dishonest.
Article 3(4) defines a deployer as anyone using an AI system under its authority, excluding purely personal non-professional use. If a company merely tolerates an employee using a free browser service on a personal account, you can argue that the “authority” is absent, and therefore that the company is not the obligated party. Doctrine is split, there is no case law yet, and the Commission has issued no guidance.
Lawyers will keep arguing about this for a long while. While they argue, your team is already pasting data into the prompt.
Why employees do it, in five steps
When a person is pushed into behaving this way, there is almost always the residue of a problem nobody solved. The sequence runs like this, and each step produces the next.
- The people who push innovation started before the law did. Every company has staff who experiment by temperament. They began in 2023, when the first conversational tools had been public for a few months and the AI Act did not exist, since it only entered into force on 1 August 2024. They were not circumventing a rule: there was no rule.
- Employees are ahead of the company. Not more capable, faster: one person switches tools in an afternoon, an organisation takes a year.
- The company adopts AI as a technology, not as a method. It buys licences, rolls them out, announces the programme. Nobody redesigns how the work is done, so the tool lands on top of a process that never changed.
- Consequently AI arrives as an imposition, and whoever receives it treats it as one more compliance task.
- When the needs of the people doing the work go unheard, those people build their own way to automate the repetitive part. That is the moment shadow AI is born.
From which the thesis follows, and the phenomenon changes sign: shadow AI is not the cause, it is the symptom of a company whose employees have been more innovative than its decision making structures.
The tension to keep, not to resolve
At this point it sounds like two contradictory claims. Shadow AI is a negative phenomenon, because like every do-it-yourself practice it produces exposure. And at the same time it is the best signal the company has.
Both are true, and the contradiction is only apparent:
- the practice produces exposure, and has to be governed;
- the signal that generates it is the sharpest internal research on processes the company has ever had, and nobody paid for it.
Every time someone automates part of their own job, they are pointing with surgical precision at where the corporate process wastes time. It is a map of inefficiencies drawn by the people who live with them.
Punish the practice and discard the signal, and you lose twice: the exposure stays, because the behaviour moves rather than disappears, and the information is gone.
The real risks, measured rather than inflated
This is where most articles on the subject overreach, and overreaching has a price: one technical inaccuracy is enough for a competent reader to stop believing the true parts too. So each risk below carries the mechanism that produces it and the rule that touches it.
| Risk | The mechanism, stated precisely | Rule and timing |
|---|---|---|
| Loss of trade secret protection | A secret loses its legal protection the moment it stops being secret, which is when you disclose it to a third party without a confidentiality obligation. Nobody has to steal it: telling is enough | Directive (EU) 2016/943 and national implementing law. Applies today |
| Personal data outside the perimeter | Client names, assessments of staff, contact details pasted into a service nobody selected, with no legal basis and no processing agreement | GDPR. Applies today |
| Generated content published without disclosure | An image, an audio file or a text published without stating that it was artificially generated or manipulated. This is the only AI Act duty that hits an ordinary company today because of shadow AI | AI Act Article 50, from 2 August 2026. Up to 15 million euro or 3% of worldwide turnover |
| Automated decisions about people | Candidate screening run on a personal tool produces effects on individuals with no oversight and no audit trail | GDPR Article 22 and national anti-discrimination law: today. AI Act Annex III: from 2 December 2027 |
| Training data resurfacing | This does not work the way it is usually told: your prompt does not reappear in a stranger’s chat. The documented risk is that content used for training can be extracted from the model under particular conditions. It is rarer and more technical, and it deserves that measure | No dedicated rule. A technical risk, not an offence |
Two clarifications that are usually missing.
On free tiers. Many free versions do use conversations to train their models by default, but this is not a law of nature: it depends on the provider and on the settings, and it changes over time. Check the current terms of the service your people are actually using, not the ones you remember reading last year.
On network blocking. Blocking domains on the corporate network does not shrink the phenomenon: it moves it to the personal phone, where no company log can see it. Anything can be done from a private handset. A company that blocks and then declares itself safe has not solved the problem, it has stopped measuring it.
What to do, in order
The remedy is not the memo that forbids. The sequence is this.
- Map what is already happening, before regulating it. Ask people which tasks they have automated and with what. If you get silence, you already have your first answer about the internal climate.
- Read that map as process research, not as a list of infringements. Every line marks a point where the work loses time.
- Design the method with the people who do the work, and only then equip it with tools. The order matters: method first, technology second, because the reverse order is precisely what produced the phenomenon.
- Govern the exposure with the rules that exist today, meaning transparency on published content and lawful handling of personal data, without waiting for December 2027.
One clarification is necessary, because this is the easiest point to read backwards. Bottom-up is the signal, not the governing model. If the phenomenon stays at the bottom and nobody collects it, it produces exposure and nothing else. The job of the leadership is to collect that signal and build the method on top of it, instead of imposing one nobody asked for.
Think of a water main. On the surface everything works: water arrives, nobody complains, every indicator looks fine. Then at year end 40% of the water is missing, and it had been missing all along, in underground joints nobody inspected. Shadow AI is one of those joints, with a difference worth exploring: here the water leaking out is also telling you where the pipe runs.
If this is your situation
If serious work on integrating artificial intelligence has not started inside your company, your people have already started it on their own, and having blocked it on the network does not change the picture.
Contact me, and tell me your priorities and where the lag hurts: we will decode the signal your team is already sending you. If the timing is wrong, that is fine and we stop here.
Sources
- Regulation (EU) 2024/1689 (AI Act), consolidated text: https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- Regulation (EU) 2026/1744 of 8 July 2026: https://eur-lex.europa.eu/eli/reg/2026/1744/oj
- Gonzalez-Vazquez, I., Mariscal-de-Gante, A., Hemmert, G., Digital monitoring, algorithmic management and the platformisation of work in the EU: Data from the AIM-WORK survey, European Commission, Seville, 2025, JRC144330
- JRC release on the AIM-WORK findings: https://joint-research-centre.ec.europa.eu/jrc-news-and-updates/impact-digitalisation-30-eu-workers-use-ai-2025-10-21_en
- JRC publications repository: https://publications.jrc.ec.europa.eu/repository/handle/JRC143072