Shadow AI and the EU AI Act: What Businesses Need to Know

Learn how Shadow AI creates EU AI Act compliance gaps, from high-risk uses and transparency duties to employee AI tools and AI literacy.

  • Aug 30, 2026
  • 10 min read
Shadow AI and EU AI Act compliance infographic showing business responsibilities, governance, and regulatory requirements.

AI compliance can look complete on paper while unapproved AI systems continue operating beyond the view of legal, compliance, security, and IT teams.

 

Shadow AI is the use of AI systems, applications, or features within an organization without formal approval, visibility, or appropriate organizational oversight.

 

It is what happens when employees bring AI into everyday workflows faster than the organization can identify and assess it. It is why the Shadow AI EU AI Act relationship matters: a business cannot determine its regulatory obligations for AI systems it does not know are being used.

 

The EU AI Act does not create a separate category called Shadow AI, nor does it automatically prohibit employees from using unapproved AI. The problem is that undiscovered AI may prevent a company from determining whether the Act applies, what risk category a use falls into, whether the organization is acting as a provider or deployer, and what transparency or other obligations must be met.

 

In this blog, you will learn how Shadow AI interacts with the EU AI Act, when employee AI use can create greater regulatory exposure, and what businesses should check to understand their obligations.

Key Takeaways

  • Shadow AI is not a defined risk category under the EU AI Act.

  • Unapproved AI can still fall within the Act when its conditions of application are met.

  • Businesses need visibility into AI use before they can classify systems correctly.

  • Certain employment and other sensitive AI uses may fall into high-risk categories.

  • Article 50 transparency obligations can affect customer-facing and content-generating AI uses.

  • AI literacy helps employees recognize when AI use needs disclosure, review, or escalation.

1. Does the EU AI Act Apply to Shadow AI?

The EU AI Act regulates AI systems and the organizations involved in providing, deploying, importing, or distributing them. Whether a system was formally approved by a company's IT department is not what determines whether the legislation applies.

 

The Act defines a deployer as, broadly, a person or organization using an AI system under its authority, except for personal, non-professional activities. The regulation also has territorial rules that can bring organizations outside the European Union within scope in certain circumstances, including where AI system outputs are used in the EU. The full scope is set out in the EU AI Act on EUR-Lex. This distinction matters for global businesses.

 

A company does not necessarily escape responsibility because an employee independently purchased access to an AI service. What matters is how the system is being used, where the regulated activity occurs, the organization's role, and whether the relevant provisions apply.

 

Skadden similarly highlights that businesses need to identify their AI systems, assess whether the Act applies, classify their systems, and determine their organizational role.

 

This makes Shadow AI a regulatory visibility issue rather than a separate regulatory category.

2. Why Shadow AI Makes EU AI Act Compliance Difficult

Shadow AI compliance sequence infographic showing discovery, scope, use case, risk class, role, and obligations under the EU AI Act.

EU AI Act compliance starts with knowing which AI systems exist.

 

Consider a multinational company that maintains an official register containing its enterprise chatbot, approved coding assistant, and customer-service automation platform. At the same time, individual departments are independently using AI meeting assistants, recruitment software, research tools, content generators, and browser extensions.

 

The company's AI register may look organized while still providing an incomplete view of its actual AI exposure.

 

This is not a remote concern. Codec cites Microsoft UK research reporting that 71% of employees had used unapproved AI tools at work, with more than half continuing to use them every week. Codec describes this growth in unauthorized AI usage as Shadow AI.

 

The regulatory problem follows a simple sequence:

 

Discover AI use → determine scope → identify the use case → classify risk → establish organizational role → apply the relevant obligations

 

Shadow AI disrupts that sequence at the beginning.

 

If a business does not know a tool is being used, it may not know whether that system falls within the Act, whether it performs a regulated function, whether transparency requirements apply, or whether a seemingly ordinary tool has been introduced into a sensitive decision-making process.

 

This is why an AI inventory should reflect actual use, not merely software that procurement has officially approved.

3. When Shadow AI Can Become a High-Risk AI Problem

Shadow AI EU AI Act risk infographic comparing internal writing, recruitment AI, employee evaluation, and credit decisions.

Not every unauthorized AI use carries the same regulatory significance.

 

An employee using generative AI to improve the wording of a routine internal note is very different from an HR department quietly introducing AI to rank job applicants.

 

The EU AI Act identifies specified uses in areas such as employment, education, essential services, law enforcement, migration, and biometrics as potentially high-risk, subject to the detailed conditions in Article 6 and Annex III. Employment-related systems can include AI intended for recruitment, selection, decisions affecting employment relationships, task allocation based on personal characteristics, and worker monitoring or evaluation.

 

A useful comparison is:

Shadow AI use

Potential EU AI Act significance

Rewriting routine internal text

Generally lower regulatory significance

Screening job applications

May fall within high-risk provisions

Ranking employees for promotion

May raise high-risk considerations

AI influencing certain credit decisions

Potential high-risk use

Customer-facing AI assistant

Transparency duties may apply

Synthetic public-facing media

Article 50 may become relevant

Suppose a recruitment manager begins using an AI candidate-screening service purchased directly with a department budget. The system starts ranking applicants before the company's compliance function even knows it exists.

 

The key question is no longer simply whether the employee broke an internal software policy. The company needs to determine what the system is intended to do, whether the use falls into a high-risk category, and which obligations attach to the organization's role.

 

That is where Shadow AI can turn an internal governance gap into a regulatory issue.

4. Shadow AI and Article 50 Transparency Requirements

Article 50 is one of the clearest places where undiscovered AI can create an immediate compliance blind spot.

 

The European Commission's Article 50 transparency obligations apply from August 2, 2026. The Commission published dedicated guidelines on transparency obligations shortly before those rules began applying.

 

The requirements vary according to the system and the organization's role.

 

Providers of certain interactive AI systems must ensure people are informed that they are interacting with AI unless that fact is already obvious. Providers also face requirements relating to machine-readable marking of qualifying AI-generated or manipulated content.

 

Deployers have specific disclosure duties concerning uses such as deepfakes, emotion recognition, biometric categorization, and certain AI-generated text on matters of public interest without the required human review or editorial responsibility. The Commission summarizes these responsibilities in its transparency guidance for AI systems.

 

Now consider a customer-service department independently launching an AI-powered virtual agent without informing the central AI governance team.

 

Or a communications team starts using synthetic video tools for external campaigns without determining whether disclosure requirements apply.

 

The technology may be operating publicly before anyone responsible for compliance has classified the use.

 

Codec's recent discussion of the EU AI Act makes the same connection between everyday workplace AI adoption and transparency obligations, particularly around chatbots, virtual assistants, AI-generated material, and human editorial involvement.

 

The lesson is straightforward: Article 50 compliance depends on knowing where qualifying AI interactions and content uses are happening.

5. Can Employees Create EU AI Act Obligations by Using Third-Party AI?

EU AI Act provider and deployer roles infographic showing employee AI use, compliance duties, and use-case approval.

Using technology developed by another company does not mean every regulatory responsibility remains with the vendor.

 

Businesses can themselves be deployers of AI systems.

 

That distinction becomes important when employees introduce external AI tools into corporate workflows. A company needs to understand not only who developed the technology but also what its own people are doing with it.

 

The issue can become more complicated when an organization substantially modifies an AI system or changes its intended purpose. Under specified circumstances, an actor that substantially modifies a high-risk AI system or changes its intended purpose can become subject to provider responsibilities. Skadden discusses this distinction in its analysis of what businesses need to know about the EU AI Act.

 

This creates an important distinction for businesses:

 

Tool approval is not the same as use-case approval.

 

An approved generative AI platform might be acceptable for routine productivity tasks but later be incorporated by a department into a sensitive workflow that was never assessed.

 

Organizations therefore need visibility into both which AI is being used and what it is being used to do.

6. What Should Businesses Check for EU AI Act Compliance?

 

Businesses do not need to repeat an entire Shadow AI governance program every time they assess EU AI Act exposure. They do, however, need enough information to make the required regulatory decisions.

 

The first question is what AI systems and AI-enabled functions are actually being used across the organization. That review should include centrally procured technology as well as independently adopted tools.

 

The business should then determine whether each relevant system falls within the Act, document its intended and actual use, establish the organization's regulatory role, and assess whether the use could fall within prohibited practices, high-risk categories, Article 50 transparency requirements, or other applicable provisions.

 

This approach aligns with Skadden's recommended sequence of identifying systems, assessing scope, classifying them, determining organizational roles, and building appropriate compliance measures.

 

Current enforcement also makes visibility more important. The European Commission announced that enforcement of relevant AI Act rules and the new transparency requirements began on August 2, 2026. Its AI Act enforcement update confirms that national authorities and the AI Office now have active enforcement roles within their respective areas of competence.

 

The goal is therefore not an inventory that sits untouched. Businesses need a current picture of AI use that supports regulatory classification and accountability.

7. How Does AI Literacy Fit Into Shadow AI Compliance?

AI literacy decision process showing recognize, check, disclose, and escalate before using a new AI tool.

Employees are often the first people to decide whether a new AI tool enters a workflow. That makes AI literacy relevant to controlling Shadow AI under the EU regulatory environment.

 

Article 4 addresses AI literacy for providers and deployers. The European Commission explains that organizations should support appropriate AI literacy among staff and other people dealing with AI systems on their behalf, taking into account factors such as their technical knowledge, experience, education, training, and the context in which AI is used. Its AI literacy guidance provides further information.

 

For Shadow AI, this matters because employees need to recognize when AI usage should be disclosed or reviewed.

 

The purpose is not to turn every employee into an AI lawyer. It is to help people understand that adopting an AI tool can create responsibilities beyond productivity and convenience.

Conclusion: Shadow AI Is an EU AI Act Visibility Problem

Shadow AI is not automatically a violation of the EU AI Act, and the regulation does not classify it as its own prohibited or high-risk category.

 

Its importance comes from what undiscovered AI can hide.

 

An organization cannot reliably determine whether an AI system is in scope, classify a sensitive use, identify its role as a deployer or provider, or comply with applicable transparency duties if nobody responsible for governance knows that the system is operating.

 

Businesses should therefore treat EU AI Act compliance as more than a review of approved AI vendors. They need visibility into real AI use across departments, including independently adopted tools and unexpected use cases.

 

The core compliance sequence remains simple:

 

Know where AI is being used, understand what it does, determine the organization's role, and apply the requirements that follow.

 

For organizations that need a structured approach to identifying and managing unauthorized AI use, the Shadow AI Risk Management & Governance Course provides focused training on Shadow AI risks, oversight, and responsible governance.

Frequently Asked Questions

No. Shadow AI is not a separate prohibited category under the EU AI Act. However, an undiscovered AI use may involve prohibited practices, high-risk systems, transparency requirements, or other obligations depending on what the technology does and how it is used.

Potentially. Internal approval status does not by itself determine whether EU AI Act obligations apply. A business may still be acting as a deployer or another regulated actor depending on the circumstances and use of the system.

No. The EU AI Act uses a risk-based structure, and only specified systems and uses meet the conditions for high-risk classification. Businesses still need enough visibility into their AI use to determine which category and obligations apply.