Back to blog
Compliance·Jun 15, 2026·4 min read

Shadow AI and the EU AI Act: why unmanaged AI is a compliance risk now

Shadow AI is the AI nobody signed off on. The EU AI Act does not care whether you signed off on it. Every AI system in use is in scope, sanctioned or not.

Most organisations are building their EU AI Act response around the AI tools they know about. The problem is the tools they do not. The unsanctioned models, copilots, and embedded AI features your teams adopted without review are still AI systems under the Act, and the obligations attach to them whether or not they are on anyone's list.

This is the link between shadow AI and EU AI Act compliance, and it is the gap most programmes miss. For the wider regulatory picture, see the EU AI Act explained.

What shadow AI is

Shadow AI is any AI tool used inside an organisation without going through review or approval. A team pasting customer data into a public chatbot, a department buying an AI writing tool on a personal card, an AI feature switched on inside software you already run: each is shadow AI, and together they usually outnumber the AI tools IT actually knows about.

Because unsanctioned tools are still in scope, Grasp helps you bring shadow AI into your EU AI Act picture before it becomes the gap.

It spreads because adopting an AI tool now takes a browser tab, not a procurement cycle. That is also why you cannot govern it by policy alone. You can read more in our guide to detecting shadow AI.

Why the EU AI Act makes this urgent

The Act assigns obligations by the risk tier of each AI system and by your role as a provider or deployer. None of that works if you cannot see the system. Three exposures follow directly from shadow AI.

Unclassified high-risk systems. An AI tool used in recruitment, credit, or another listed context carries the full high-risk obligations. If it entered as shadow AI, it is high-risk and unmanaged, which is the worst combination at audit. The risk classification guide shows where systems land.

Missing transparency disclosures. From 2 August 2026, systems that interact with people or generate content owe Article 50 transparency. A shadow chatbot with no disclosure is a live breach the day the obligation applies.

No inventory for the audit. The Act expects you to know and document your AI systems. An incomplete inventory is not a paperwork gap; it is the thing that makes every other obligation unprovable.

What to do about it

The sequence is the same one the Act rewards, and it starts before any policy. Discover every AI system actually in use, including the embedded and unsanctioned ones. Classify each by risk tier so you know which carry real obligations. Then govern them: disclosures where transparency applies, documentation where high-risk applies, and a fast review path so the next tool does not arrive as shadow AI. Building the list comes first, and the AI inventory guide covers how.

Frequently asked questions

Does the EU AI Act apply to shadow AI?

Yes. The Act applies to AI systems by their use and risk, not by whether they were formally approved. An unsanctioned tool used in a high-risk context carries the same obligations as an approved one, which is why undetected shadow AI is a compliance risk rather than just an IT one.

Why is shadow AI a bigger problem under the EU AI Act?

Because the Act's obligations depend on knowing and classifying every AI system. Shadow AI is by definition the AI you have not classified, so it sits outside your controls, your documentation, and your audit trail while still counting against you.

What is the first step to get shadow AI under control?

A complete inventory. You cannot classify, disclose, or document a tool you cannot see, so discovery comes before policy. Once you can see every AI system in use, the rest of the EU AI Act work becomes possible.

When do the relevant EU AI Act deadlines apply?

Transparency obligations under Article 50 apply from 2 August 2026, and standalone high-risk obligations from 2 December 2027 following the Digital Omnibus deferral. Shadow AI affects both, because an unseen system can sit in either tier.

Grasp discovers every AI tool in use across your organisation, classifies each by EU AI Act risk tier, and keeps the inventory current, so shadow AI stops being a blind spot. See the EU AI Act solution →