Shadow AI is the use of AI tools by employees without internal validation. This phenomenon exposes the company to compliance risks regarding the AI Act and GDPR. Discover how to identify and manage these practices using a 5-step inventory method.
Shadow AI refers to the use of artificial intelligence tools by employees without prior validation from the IT department or the DPO. This practice encompasses chatbots like ChatGPT, image generators, writing assistants, or coding solutions such as GitHub Copilot. These tools are accessible in a few clicks, often via personal accounts or free versions. Recent studies estimate that Shadow AI affects between 41% and 78% of companies, with a marked incidence in large corporations.
Far from being marginal, Shadow AI reflects the speed at which business units adopt new tools, sometimes bypassing traditional IT channels. This dynamic raises serious challenges regarding data governance and regulatory compliance.
Why is Shadow AI growing so rapidly?
Consumer AI solutions are designed for instant adoption: an email address is all it takes to access ChatGPT or Gemini, and freemium offers further lower the barriers. The pressure for efficiency drives employees to seek out these tools to save time—for writing, analysis, code generation, etc. Business units, often more agile than IT departments, do not always wait for official approval to adopt these technologies.
The lack of simple internal alternatives also fuels this phenomenon. When a company does not offer validated and easily accessible AI solutions, teams spontaneously turn to external tools. This pattern is particularly visible in sectors where AI is an emerging issue, such as legal or communications.
Shadow AI and Compliance: What are the risks regarding the AI Act and GDPR?
The AI Act imposes strict requirements regarding transparency, documentation, and control. An unlisted tool cannot be audited, nor can it be included in a compliant register. Article 26 of the regulation requires that every high-risk AI system be subject to a register and logs—a requirement impossible to meet if the tool escapes the inventory.
Operational risks are also significant. Consumer AI tools are not designed for professional constraints: they may process confidential information (clients, HR, finance) without guarantees of confidentiality. Prompts sent to external APIs may contain personal data, exposing the company to GDPR violations.
For example, sending client data to a non-EU API may constitute an illicit transfer, even if the intent is professional. Furthermore, Shadow AI introduces uncontrolled biases into business processes: a text generation or analysis tool can produce biased results, with legal consequences, particularly in recruitment or risk management.
How to conduct an inventory of undeclared AI tools: 5 key steps
To map unvalidated AI usage, it is essential to combine several methods, blending human inquiry with technical analysis. Here is a five-step process:
1. **Anonymous employee questionnaire**: Distribute a form to identify the tools used, the use cases, frequency, and account type (professional/personal).
2. **IT expenditure analysis**: Examine corporate card statements and invoices to spot subscriptions to AI services, often purchased outside of IT channels.
3. **Network and log inspection**: Use monitoring tools to detect connections to AI APIs (e.g., api.openai.com, generativelanguage.googleapis.com) via proxy or firewall logs.
4. **Interviews with business teams**: Organize workshops to understand operational needs and reveal usage unknown to the IT department.
5. **Voluntary declaration via form**: Provide a simple and confidential channel allowing employees to report their AI usage without fear of sanction.
The synergy of these approaches ensures an exhaustive inventory and a better understanding of actual practices.
Example form for declaring an AI tool
An effective form must be simple, neutral, and reassuring. It can be deployed via Google Forms, Microsoft Forms, or an internal tool. Recommended fields include:
- **Name of the AI tool** (e.g., ChatGPT, Copilot, Midjourney, Perplexity)
- **Primary use case** (writing, data analysis, code generation, image generation, other)
- **Frequency of use** (daily, weekly, occasional)
- **Types of data processed** (no sensitive data, client data, employee data, financial data, other)
- **Type of account used** (professional account, personal account, freemium version)
- **Free comments**
Explain the purpose of the form: to secure AI usage, not to punish. The response rate will depend on the climate of trust established.
Managing Shadow AI: Repression or Collaboration?
Strictly prohibiting Shadow AI without offering alternatives is ineffective. The needs persist, and employees find other ways to access tools. A sustainable approach relies on awareness, the provision of official solutions, and a clear framework for use.
Why repression alone does not work
Blocking access to AI tools or sanctioning users does not solve the problem. Teams bypass restrictions via their mobile phones, VPNs, or other undetected tools. This approach generates distrust and makes the phenomenon invisible instead of resolving it.
Three levers for collaborative management
An effective strategy combines:
- **Awareness**: Train teams on the risks (data leakage, GDPR, individual liability). Short, concrete modules are more effective than long charters. Article 4 of the AI Act requires AI literacy for all operators as of February 2, 2025.
- **Official solutions**: Offer validated, contractually secure alternatives. Professional versions of consumer AI tools are now available.
- **Clear usage policy**: Publish an AI Acceptable Use Policy specifying authorized tools, permitted use cases, and accepted data types. The compaia.eu tool helps structure this policy according to your context.
The goal is to channel AI usage to turn it into a competitive advantage while mastering regulatory risks.
Regulatory references to know
- **AI Act – Art. 4**: Obligation of AI literacy for all operators, in force since February 2, 2025
- **AI Act – Art. 26**: Mandatory register and logs for high-risk AI systems
- **AI Act – Art. 50**: Transparency required for systems interacting with natural persons, applicable in November 2026
- **GDPR – Art. 25**: Privacy by design, documentation, and data processing management from the design stage
- **GDPR – Art. 44**: Conditions for data transfers outside the EU, particularly via non-European AI APIs