It usually surfaces by accident. An MD at a 60-person consultancy reviews a junior consultant's handover and discovers that, for the past six months, client financials have been going into a free AI summariser — pasted into a browser tab, summarised, pasted back into deliverables. No malicious intent. No security review. No contract with the vendor, no data processing agreement, no logging. Nothing on any register.
That's shadow AI. Not a rogue department skunkworks project — just ordinary people adopting extraordinary tools faster than governance can see them. And under the EU AI Act, it sits in the gap between your AI policy and your team's actual behaviour. This page is about that gap: why it's now a compliance exposure, where it hides, and how to close it. It sits within our full guide to the EU AI Act for UK and Irish businesses — and it matters whether or not you think the Act applies to you, because the behaviour it describes is already happening on your network.
Why shadow AI is a compliance problem now
Three exposure vectors, in ascending order of how badly they can go:
- AI literacy (Article 4). The Act makes you responsible for ensuring staff use AI competently — the staff AI literacy obligation has applied since February 2025. Ungoverned use is the precise opposite of competent use. A team pasting client data into unvetted tools isn't a training gap you can quietly fix later; it's evidence the duty isn't being met.
- Transparency and classification. If a team switches on an AI feature that interacts with clients or shapes decisions — a candidate-screening plugin in an ATS, AI scoring in a CRM — transparency duties and possibly high-risk obligations already apply. You never classified them because you never knew they existed. "We weren't aware" is not a compliance position; it's a confession.
- Data spill-over. Client data going into third-party models is a GDPR and business-confidentiality exposure that lands on the MD's desk, not the intern's. No processing basis, no vendor contract, no idea which data went where. When that surfaces — in a client audit, a breach, an exit interview — it's a boardroom problem within the hour.
Notice what all three share: the obligation attaches to what your business actually does, not to what it has approved. A perfectly governed approved-tool list next to an unexamined shadow layer isn't compliance. It's theatre.
Where shadow AI hides
The realistic list, from the audit work we've done — five places, none of them exotic:
Hiding place 1
Free chatbots and "AI assistants"
The obvious one, and still the biggest. Staff paste contracts, decks, code and client emails into consumer chatbots daily. Free tiers typically mean your data trains someone else's model unless someone found the opt-out — and nobody did, because nobody was looking.
Hiding place 2
Browser extensions and PDF/AI add-ons
One-click installs with broad page-access permissions. Half summarise, half "help write", several quietly ship the page content elsewhere. IT never sees them; they ride in on personal accounts and sync across devices.
Hiding place 3
AI features quietly shipped inside existing SaaS
The default-on wave. Microsoft 365 Copilot toggles, CRM "smart" fields, ATS matching, helpdesk reply suggestions — vendors ship AI into tools you already pay for and switch it on for you. Approved-by-procurement doesn't mean reviewed-for-AI.
Hiding place 4
Meeting note-takers and transcription bots
An AI notetaker joins the call, records everyone, emails a summary — including the part where a client discussed confidential terms. Often invited by the most junior person in the room, with the most enthusiasm for productivity.
Hiding place 5
Personal API keys and no-code automations
A personal GPT API key inside a Zapier or n8n workflow, built by one capable operator, now quietly processing leads or CVs or support tickets. The most dangerous kind: it's load-bearing infrastructure nobody else can see or maintain.
The six warning signs
Book this list. If two or more land, you have shadow AI at a scale worth measuring:
- No AI tool list exists. Nobody in the business can produce, in one document, every AI tool currently in use. The absence of the list is the finding.
- M365/Google AI toggles default-on, never reviewed. Copilot or Gemini features were enabled by the vendor's rollout calendar, not by a decision anyone remembers making.
- Procurement doesn't ask "does this have AI in it?". New SaaS is bought on features and price; the AI embedded in it never surfaces as a question.
- Exit interviews mention tools nobody approved. Leavers name AI tools in handovers that appear on no register — the cheapest discovery channel you have, and the most ignored.
- DPO/legal has never seen your AI usage. Whoever owns data protection in your business has never been shown, or asked for, a picture of actual AI use.
- The shadow AI policy is a blank page. There is no AI usage policy, or the one that exists predates the AI your team actually uses — a 2019 acceptable-use policy with one clause about "automation" doesn't count.
What you can't do about it — and what you can
Two responses that reliably fail. Banning AI outright feels decisive and drives usage further underground — the tools are free, they're one tab away, and staff who've built their workflow around them don't stop, they just stop mentioning it. Pretending the old policy covers it is worse, because it combines the comfort of having acted with the exposure of having done nothing.
What works is a sequence: find it, name it, train it out. Find it — an audit of what's actually running, which is what the Shadow AI Audit exists to do. Name it — log every tool in an AI inventory and back it with a usage policy that says what's approved, restricted, and banned. Train it out — turn the Article 4 literacy duty into actual staff competence instead of a checkbox.
The frame that makes this workable: the goal isn't zero shadow AI — it's zero unknown AI. Some of what your team has adopted is genuinely good and should be approved, not amputated. You can't make that call tool by tool until you can see the full list.
How a Shadow AI Audit works
Three steps, deliberately unglamorous:
- Scan and discovery. Technical discovery — browser extension audits, SaaS admin reviews, M365/Google Workspace AI toggles, expense trawls for AI subscriptions — combined with interviews and an anonymous staff survey. The survey matters: people tell you about tools when asking is clearly not a trap.
- Risk classification. Every tool found gets sorted into its AI Act risk class — prohibited, high, limited, minimal — using the four sorting questions. Most tools fall to minimal in under a minute; a short, load-bearing list doesn't.
- Report and remediation plan. A classified inventory plus a decision list: approve, restrict, or replace — sequenced so the scary items are actioned first and the harmless ones are simply documented.
Speed is the point. Done properly this is one afternoon to two days of work, not a consultancy quarter — the deliverable is a register you can show a client, an auditor, or your own board, and a remediation list short enough to actually finish. If you'd rather start softer, take the AI Act quiz — two minutes, six questions, and it flags where the gaps in a setup like yours tend to hide.
The takeaway
Shadow AI isn't a staff discipline problem; it's a visibility problem. Your team adopted AI because it works, and the behaviour isn't going away. What changes under the AI Act is the cost of not looking: literacy duties, unclassified deployments, data exposure that lands on the MD's desk. The fix is the same at any company size — see the full list, classify it, decide tool by tool, then write the decisions down.
Start by finding out what's actually running: book a Shadow AI Audit — or, if you're still mapping where the Act touches your business, read up on AI Act Readiness first and let the audit follow. Either direction, the blind spot closes. (Practical guidance throughout, not legal advice.)