Shadow AI is a security problem, but the EU AI Act makes it a legal one
The most damaging AI-related security incident your organization faces this year probably won't originate from external attackers using sophisticated new models.
It's far more likely to begin with an employee pasting a client contract, a financial forecast, or a set of HR records into an AI tool because it makes their job easier and nobody has told them why it matters.
Shadow AI is a growing problem, and our research found that nearly half of employees at larger enterprises regularly feed corporate data into AI tools that nobody in IT has approved or governs.
More striking still, 85% of employees continue doing so even when company-sanctioned tools are available, pointing to a governance failure that runs all the way to the executive suite.
With shadow AI, sensitive data can move silently outward through channels most security stacks were never designed to intercept.
Adding to the security risk of this unmonitored data flow, the advent of the EU AI Act also means organizations now face specific legal demands on managing AI use.
The ability to have full governance over how AI is deployed, governed and monitored, is becoming a regulatory, as well as a security, imperative.
Why the EU AI Act makes this a board-level problem Shadow AI represents a serious security issue, with IBM's 2026 Cost of a Data Breach report estimating that unauthorized tools contributed to 43% of breaches over the last year Now, the EU AI Act is adding significant regulatory requirements on top of these risks.
The Act's obligations have rolled out in phases; most recently, organizations classified as general deployers of AI have new inventory, data governance, audit logging and transparency obligations as of 2nd August 2026.
Other deadlines have shifted further ahead, with controls over high-risk AI usage, covering areas like recruitment, credit scoring and biometric categorization, set to come into force from 2nd December 2027.
AI embedded in regulated products will be covered from 2nd August 2028.
Any organization whose employees use AI systems now has compliance obligations as a deployer, regardless of whether those systems were formally sanctioned.
All organizations using AI should be aware that the AI literacy obligation under Article 4 has been enforceable since February 2025, meaning organizations are on the hook for ensuring their employees are aware of safe and sanctioned AI use.
Rules around high-risk AI usage will also apply to more operations than it may seem at first, including an employee using an unapproved consumer tool for tasks like screening CVs, assessing creditworthiness, and evaluating performance.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.