Your company almost certainly has an Acceptable Use Policy. It probably covers email, internet access, and perhaps even personal device usage. What it almost certainly does not cover is the wave of generative shadow AI tools quietly reshaping how your employees work - tools that bypass IT procurement, operate outside contracted data-processing agreements, and land your organisation squarely inside three overlapping regulatory frameworks at once.
Shadow AI - the unsanctioned use of AI tools by employees outside IT visibility, is not an edge case. It is the default state in most organisations. Yet most enterprise AI policies still contain no reference to GDPR data-processing obligations when personal data is pasted into a chatbot, no classification against the EU AI Act's risk tiers, and no DORA ICT register requirement for financial services firms, the three gaps that make shadow AI governance a regulatory exposure rather than just an IT housekeeping problem.
This guide walks you through every section a compliant shadow AI policy must contain, explains the regulatory mapping for each clause, and links to a free editable template you can deploy today.
78% | 38% | $4.63 |
What a Shadow AI Policy Must Cover
A shadow AI policy is not a generic AI usage guideline. It is a targeted instrument that addresses the specific legal and operational risks created when employees deploy shadow AI tools outside the organisation's governance perimeter. At minimum, it must contain six distinct sections.
01 Scope & Definitions Who is covered, what counts as an AI tool, and what shadow AI means in your organisation. | 02 Prohibited Practices EU AI Act Article 5 red lines - no employee may deploy or enable these systems, even via personal accounts. |
03 Permitted AI Tools The approved tool register. Only listed tools may be used for work purposes. | 04 Employee Obligations What employees must do: classify tools, report new use, and never input personal data without a DPA. |
05 Enforcement & Reporting How violations are handled - and how employees report new tools safely without fear. | 06 Review Cycle Quarterly policy review, annual regulatory alignment check, training completion tracking. |
1. Scope and Definitions
The policy must define what constitutes an 'AI tool' broadly enough to capture large language models, AI-powered productivity add-ins, image generators, code-completion engines, and AI-enhanced SaaS features. It must also define 'shadow AI' explicitly - any AI system or AI-enabled feature used in the context of work that has not been assessed and approved through the organisation's standard tool-onboarding process.
Scope should extend to all employees, contractors, and third parties acting on the organisation's behalf, regardless of whether they are using personal or corporate devices.
2. Prohibited AI Practices - Article 5, EU AI Act
This section is non-negotiable and must mirror the prohibited practices listed in Article 5 of the EU AI Act, which became enforceable in August 2025 with fines of up to €35 million or 7% of global annual turnover. No employee may deploy, enable, or interact with any AI system that:
- Uses subliminal or manipulative techniques to distort a person's behaviour (Article 5(1)(a))
- Exploits vulnerabilities of age, disability, or economic circumstances to cause harm (Article 5(1)(b))
- Performs social scoring based on personal behaviour or characteristics (Article 5(1)(c))
- Makes criminal risk assessments based solely on profiling (Article 5(1)(d))
- Scrapes facial images from the internet or CCTV to build recognition databases (Article 5(1)(e))
- Infers emotions in workplace or educational settings (Article 5(1)(f))
- Categorises individuals using biometric data to infer protected characteristics (Article 5(1)(g))
3. Permitted AI Tools - The Approved Register
The policy must create and reference a live Approved AI Tool Register. Only tools that appear on this register may be used for work purposes. The register records the tool name, vendor, risk classification under the EU AI Act, GDPR data-processing basis, whether a Data Processing Agreement is in place, and the date of last review, and it is the operational output of continuous AI tool discovery running against the live environment.
4. Employee Obligations
Employees who discover a new AI tool they wish to use must submit it for review before use. The policy must specify that employees must never input personal data, customer data, or proprietary information into any non-approved tool, and must report any AI tool they have previously used without approval through the amnesty process within a specified grace period.
5. Enforcement and Reporting
The policy must draw a clear line between employees who were unaware and those who acted despite knowing. A graduated, non-punitive model works best: self-disclosure is rewarded, good-faith tool requests are processed within five business days, and disciplinary action is reserved only for wilful or repeat violations. Three minimum requirements apply:
Amnesty Window | 30–60 days from policy publication during which past shadow AI use can be self-disclosed without disciplinary consequence. Disclosures trigger a tool review, not a HR process. |
Tool Request | A simple form (tool name, proposed use, data types involved) reviewed by IT and DPO within 5 business days. If denied, a compliant alternative must be suggested. |
Graduated Response | Informal awareness conversation → Formal written warning → HR referral. Serious cases (Article 5 violations or GDPR breaches involving personal data) skip straight to formal action. |
6. Review Cycle
Given the pace of AI development and evolving regulatory guidance, the policy must be reviewed quarterly for tool additions and annually for full regulatory alignment. Every employee must complete AI awareness training upon policy publication and at each major revision.
The GDPR Section - What to Include
GDPR is the silent risk inside every shadow AI incident. When an employee pastes a customer's name, email address, performance review, or medical record into a public AI tool, they have triggered a data-processing event. The organisation is the data controller. The AI vendor is the processor. Unless a Data Processing Agreement (DPA) is in place, that processing is unlawful.
GDPR Clause - Mandatory Policy Language |
No employee may input personal data - as defined under Article 4(1) GDPR - into any AI tool, AI-enabled application, or generative AI interface that is not listed on the Approved AI Tool Register. Where an approved AI tool processes personal data on behalf of the organisation, the DPO must confirm that a valid Data Processing Agreement (DPA) compliant with Article 28 GDPR is in place with the AI vendor before first use. Any AI system used to make automated decisions about individuals that produce legal or similarly significant effects must be assessed under Article 22 GDPR. Employees may not use AI to generate automated employment decisions, credit decisions, or health-related determinations without explicit DPO sign-off and confirmation that Article 22 safeguards (right to human review, right to contest) are implemented. |
Article 22 GDPR - Automated Decision-Making
Article 22 is particularly relevant to HR and finance use cases. If your organisation's employees are using AI tools to screen CVs, score loan applications, evaluate employee performance, or generate customer risk ratings, and if those outputs produce decisions with legal or significant effect, Article 22 applies. The policy must prohibit unapproved automated decision-making and establish a clear process for obtaining DPO authorisation where AI-assisted decisions are operationally necessary.
The GDPR section of the policy should also address data subject rights: employees must not use AI in ways that would make it impossible to respond to subject access requests, erasure requests, or rectification requests within statutory timeframes.
GDPR Article | Policy Obligation |
Article 4(1) - Personal Data | Define personal data in policy scope; prohibit input into unapproved tools |
Article 28 - Processor Agreements | Require DPA before any AI tool processes personal data |
Article 22 - Automated Decisions | Prohibit AI-only decisions with legal effect; mandate human review |
Article 13/14 - Transparency | Ensure AI use is disclosed in privacy notices where applicable |
Article 32 - Security | Require IT security assessment of any tool that handles personal data |
The EU AI Act Section
The EU AI Act (Regulation EU 2024/1689) introduced a risk-based classification framework for AI systems. For the purposes of a shadow AI policy, the most operationally critical requirement is that every AI tool an employee wishes to use must be classified against the Act's four risk tiers before first use. This is not optional - deployers of AI systems in the EU have legal obligations under the Act.
PROHIBITED | Article 5 practices - banned outright. No use permitted under any circumstances. |
HIGH RISK | Annex III systems (HR, credit, law enforcement support). Require registration, conformity assessment, human oversight, and DPA. |
LIMITED RISK | Chatbots & synthetic media. Transparency disclosure to users required. |
MINIMAL RISK | Spam filters, recommendation engines. Follow internal guidelines; no mandatory regulatory obligations. |
Classification Before Use - The Policy Requirement
The policy must require that any AI tool a business unit wishes to adopt is submitted to IT and the DPO for classification before any employee uses it. The classification determines whether a DPA is required (any tier above minimal risk), whether a Data Protection Impact Assessment is required (high-risk), and whether use is simply prohibited (Article 5), and that determination is the AI risk assessment that every tool must go through before it reaches employees.
The High-Risk Notification Requirement is particularly important: if any business unit is already using, or proposes to use, an AI system that falls within the categories listed in Annex III of the EU AI Act - including AI in employment, education, credit, law enforcement, or essential services - this must be notified to the DPO and documented in the organisation's AI register. From August 2026, providers of such systems face additional conformity assessment obligations.
Article 5 - Non-Negotiable Red Lines (Effective August 2025) |
Non-compliance with Article 5 prohibited practices carries fines of up to €35 million or 7% of global annual turnover - whichever is higher. These are the highest penalty thresholds in the EU AI Act. As a deployer organisation, if an employee uses a prohibited AI system - even via a personal subscription - the organisation may bear regulatory liability. Your shadow AI policy must explicitly prohibit all Article 5 practices and include a training requirement so employees can recognise them. |
The DORA Section (For Financial Services Firms)
If your organisation is a bank, insurer, investment firm, payment institution, crypto-asset service provider, or any other entity within DORA's scope (Regulation EU 2022/2554, effective January 2025), shadow AI creates a specific and enforceable compliance gap: your ICT Register.
DORA - ICT Register Obligation |
DORA requires financial entities to maintain a detailed register of all ICT third-party service providers. Every AI tool your employees use to perform work functions is, in regulatory terms, an ICT service provider - regardless of how it was procured. An AI tool used by employees but absent from the ICT register is a DORA breach. The employee-facing policy consequence must be clear: Any employee who becomes aware of an AI tool being used for work purposes that does not appear in the organisation's ICT Third-Party Register must report this to their line manager and the IT risk team within 5 business days. Failure to report constitutes a breach of this policy and a potential breach of DORA Article 28 obligations on third-party risk management. DORA penalties can reach 2% of global annual turnover for financial entities. |
For financial services organisations, the shadow AI policy should also require that any AI tool classified as supporting a critical or important function under DORA undergoes a full Third-Party Risk Management (TPRM) assessment before approval, including exit strategy documentation, audit rights verification, and incident reporting obligations.
Enforcement Without Creating a Culture of Fear
The most common failure mode in AI policy is not weak enforcement - it is enforcement that is so punitive that employees stop reporting problems. When people fear disciplinary action for disclosing that they have been using an unapproved tool, shadow AI goes deeper underground. The policy ceases to function as a governance instrument and becomes a liability.
A shadow AI policy does not change the calculation an employee makes at 5pm on a Thursday when they have a deadline to complete a task and they find an AI tool that would solve the problem in ten minutes. The organisation has an existing policy, and the employees are trained. But the approved tool register does not have what they need; the unapproved tool does. This is a design failure, not a compliance failure. The policy was built around what employees should do, not around what they will do. The approved tool register needs to be good enough that employees would not go for an unapproved alternative. That is the governance outcome the policy is actually trying to achieve. - Namita Razdan, Co-Founder, Montro |
45% of workers used unsanctioned AI tools in the past 30 days, and 36% did so with confidential data | 46% would continue using banned tools even if explicitly prohibited |
This data should reframe how CISOs and DPOs approach enforcement. The goal is not to eliminate AI use; it is to make it visible, so it can be assessed, approved, and managed.
The Approved Tool Request Process
The policy must include a fast, frictionless process for employees to request approval of a new AI tool. A form-based submission - name of tool, proposed use case, type of data involved - reviewed by IT and the DPO within five business days is standard good practice. When the answer is no, the policy should require IT to suggest a compliant alternative.
Step 1 Employee discovers new AI tool | Step 2 Submits Tool Request Form (< 5 min) | Step 3 IT/DPO reviews within 5 business days | Step 5 Approved→Added to register | Denied→Alternative suggested |
Amnesty Window
For employees who have already been using unapproved tools, an amnesty window - typically 30 to 60 days from policy publication - during which past use can be disclosed without disciplinary consequence is highly effective at surfacing the true scope of shadow AI in an organisation. Disclosures made during the amnesty period should trigger a tool review, not a performance management process, and they are the most reliable AI tool discovery mechanism available for surfacing shadow AI tools that have been in use for months without IT visibility.
Training Requirement
Every employee must complete AI awareness training within 30 days of policy publication. This training should cover what shadow AI is, what the Article 5 prohibited practices look like in practice, how to submit a tool request, and what to do if they have already used an unapproved tool, the four components that make shadow AI governance training actionable rather than theoretical. Completion must be tracked and reported to the DPO and CISO quarterly.
Graduated Response for Wilful Non-Compliance
For employees who knowingly use prohibited AI tools - particularly those that process personal data in breach of GDPR or that fall within Article 5's prohibited practices - a graduated disciplinary framework is appropriate: informal warning, formal warning, and in serious cases, referral to HR. The key distinction in the policy is between employees who did not know and employees who acted despite knowing.
Enforcement Principle - Policy Language Suggestion |
This organisation treats the unauthorised use of AI tools as a governance and risk issue, not primarily as a disciplinary matter. Employees who disclose past use through the Amnesty Process or who submit Tool Requests in good faith will not face disciplinary action for that use alone. Disciplinary action is reserved for employees who knowingly use AI tools that have been explicitly prohibited under this policy, who deliberately conceal AI use when asked to disclose, or who cause harm to the organisation or to third parties through reckless AI use. |
Quick-Reference: Policy Sections vs. Regulation
Policy Section | Regulatory Basis & Key Obligation |
Prohibited AI Practices | EU AI Act Article 5 - Eight banned use cases, enforceable August 2025, fines to €35M / 7% turnover |
Data Processing Clause | GDPR Article 28 - DPA required before any AI tool processes personal data |
Automated Decisions | GDPR Article 22 - Human oversight mandatory for legal/significant AI decisions |
AI Tool Classification | EU AI Act Articles 6 & 50 - All tools must be risk-tiered before deployment |
ICT Register Notification | DORA Article 28 - All AI tools used for work = ICT third-party providers in register |
Training Requirement | EU AI Act Article 4 - Deployers must ensure sufficient AI literacy |
Enforcement & Amnesty | Best practice - Culture of reporting over punishment |
Review Cycle | Best practice - Quarterly tool review, annual regulatory alignment |
Frequently Asked Questions
Does a shadow AI policy need to be a separate document or can it be added to our existing acceptable use policy?
Either works, what matters is that the regulatory mapping is explicit. An updated AUP is sufficient if it addresses GDPR data-processing obligations, EU AI Act risk classification, and DORA ICT register notification specifically. A generic "use AI responsibly" clause satisfies none of these. If the existing policy is already complex, a standalone shadow AI policy with a cross-reference from the main AUP is often easier to maintain and communicate.
How does the amnesty window work in practice, and what should we do with the disclosures we receive?
Many organisations find a 30 to 60 day window practical, during which employees can disclose AI tools they have been using without facing disciplinary action. Each disclosure should trigger a tool review, not an HR process. The review assesses the tool against EU AI Act risk tiers and checks whether a GDPR Data Processing Agreement exists. Disclosures should be treated as governance intelligence, not admissions of wrongdoing.
What happens if an employee uses a prohibited AI practice without knowing it was prohibited?
The regulatory liability sits with the organisation regardless of employee awareness. Where AI is used under the organisation's authority and for its business purposes, it may be treated as the deployer, whether or not the use was sanctioned. An employee using an emotion recognition tool in a video interview platform may have no idea Article 5 applies. The exposure sits with the organisation. This is why the policy must include practical examples, not just legal references.
How should the policy address AI features embedded in tools we have already approved?
A tool approved twelve months ago may now have AI features activated by a vendor product update that were not there at approval. The policy should require that vendor AI feature activations trigger a re-review, even if the underlying platform is already on the approved register. Without a monitoring mechanism that surfaces new AI capabilities in existing tools, continuous AI tool discovery applied to the sanctioned stack, not just to unknown tools, the approved register reflects what tools looked like at approval, not what they are doing today.





