Montro
Shadow AI18 min read

What is Shadow AI? A Practitioner's Guide For European Mid-market Security And Compliance Teams

What is Shadow AI? A Practitioner's Guide For European Mid-market Security And Compliance Teams
AuthorAnkur Arora
Published on24 Jun 2026

TL;DR. Shadow AI is the AI running in your organisation without security or compliance review. Most of it is not the rogue ChatGPT subscription you're worried about - it's the AI feature that turned on inside a SaaS tool you sanctioned three years ago. Each instance simultaneously creates exposure under the EU AI Act, GDPR, DORA, and NIS2. The discovery problem is the hard part; once you know what you have, the shadow AI governance work follows.


Shadow AI is the AI running in your organisation without security or compliance review. Most security teams think they have a shadow IT problem. They have a shadow AI problem too, and the second one is harder.


Shadow IT was a finite category, applications employees installed without IT approval. Shadow AI is something different. The CV-screening feature your recruiter switched on inside a tool IT approved years ago. The AI summarisation that defaulted on inside Notion last quarter. The Copilot button your finance team started clicking in Microsoft 365 yesterday. None of those tools are unauthorised. The AI inside them is.


This is a working definition for security and compliance teams trying to make sense of the category before they take it to a board.


A Working Definition


Shadow AI is any AI system in active use within your organisation that has not been classified, registered, or risk-assessed by the team accountable for shadow AI governance.


The definition does three things deliberately. It says in active use - not "approved" or "purchased", because most of the problem sits outside procurement. It says classified, registered, or risk-assessed because all three need to happen before an AI system is governed rather than tolerated. And it says the team accountable for AI governance, which in most mid-market firms doesn't yet exist as a named team, which is part of why shadow AI exists.


Three categories get conflated and shouldn't:


Sanctioned AI is AI you know about, have classified, and are operating under defined controls. ChatGPT Enterprise with a signed Data Processing Agreement, configured for your tenant, with a usage policy and audit logging - that is sanctioned.


Shadow IT is the older problem: software your team did not procure that is nonetheless in use. Some shadow IT contains AI; most still does not. The shadow IT problem and the shadow AI problem overlap, but treating them as identical is the most common analytical error in this space.


Shadow AI is AI in use that has not been through your classification process - whether or not the host application was sanctioned. This is the category that breaks the spreadsheet, because shadow AI is not only about discovering new applications. It is about discovering new AI features inside applications you have already mapped.


Why Shadow AI is Harder to Find Than Shadow IT


Shadow IT lives at the edges of your environment. New domains, unfamiliar logos in the SSO catalogue, charges on the corporate card from vendors no one remembers approving. The discovery patterns are well understood, the tools are mature, and the answers are visible if you know where to look.


Shadow AI lives inside applications you have already mapped.

The security teams that are furthest behind on shadow AI are not the ones who do not have a SaaS management tool. They are the ones who have one and believe it solved the problem. 


The SaaS management platform identifies Notion, but not Notion AI. It finds Slack, but not Slack AI. It finds Microsoft 365, but it does not find Copilot, or it identifies Copilot as a licence, not as an AI system processing your data in ways the original Microsoft 365 procurement did not anticipate. The tool that helped you solve the shadow IT problem was built to find applications, but shadow AI is not a new application. It is a new feature inside an application that you have already mapped. That distinction is why the security team with the most mature SaaS inventory can still have the worst shadow AI visibility, because they are looking in the right place for the wrong thing. - Ankur Arora, Co-Founder, Montro

Gartner predicts that by 2026, more than 80% of independent software vendors will have embedded GenAI capabilities in their enterprise applications, up from less than 5% today. Notion AI is on by default for paid Notion workspaces. Slack AI runs on plans you have already paid for. Microsoft Copilot is offered inside Microsoft 365. HubSpot Breeze sits on top of the same HubSpot you have used for years. Salesforce Einstein. Atlassian Intelligence. Zendesk AI. Zoom AI Companion. Each was a SaaS application before it was an AI application. Each went from a known tool to an unknown AI surface in a single product release, often without an admin-level configuration change to mark the moment.


The free-tier problem compounds it. ChatGPT's free tier, Claude.ai's free tier, Perplexity, the public versions of image generators, GitHub Copilot personal, Cursor - these are AI tools your employees use without expense, without procurement, without admin visibility. Free-tier adoption does not show up in your finance system. It often does not show up in your SSO. It shows up in browser traffic and in the work that gets produced, but only if you are looking.


And the third pattern - what we call evaluation creep, is the most insidious. A team starts evaluating a new AI tool. The evaluation extends. The tool quietly becomes the way real work gets done. A purchase order eventually appears, or it does not. By the time anyone notices, the tool is processing customer data in production.


The result, across the AI tool discovery audits we have run at European mid-market firms in the 200–2,000 employee range, is consistent. When a security team estimates their AI footprint, they typically name nine to fourteen tools. A structured discovery process surfaces thirty-eight to fifty-two. The gap is widest for firms in the 500–1,200 employee band, where headcount is high enough to drive distributed adoption but governance is rarely yet centralised.


The Four Regulatory Exposures


What makes shadow AI a higher-stakes problem than shadow IT is that every shadow AI tool simultaneously creates exposure under four EU regulatory regimes. Same tool. Different obligations. Different supervisors. Different deadlines.


The EU AI Act, Regulation (EU) 2024/1689, became binding on prohibited practices on 2 February 2025. The bulk of high-risk obligations apply from 2 August 2026; existing high-risk AI systems already in market get an additional year, until 2 August 2027. For most mid-market firms, the question is which AI systems are high-risk. Article 6 of the Act answers that two ways: AI used as a safety component of a product covered by listed Union harmonisation legislation is automatically high-risk, and AI used in any of the use cases enumerated in Annex III is high-risk. The Annex III category that catches mid-market firms most often is employment, the AI-driven CV screening that almost every recruiter platform now offers. The fines are sized to draw attention: Article 99 sets penalties up to €35 million or 7% of global annual turnover for prohibited-practice violations, and up to €15 million or 3% for most other obligations.


Every shadow AI system that processes personal data triggers obligations under GDPR, Regulation (EU) 2016/679. The Article 30 record of processing activities, the RoPA - is supposed to capture the purposes, the data categories, the recipients, and the international transfers for every processing activity in your organisation. When a new AI feature turns on inside a sanctioned tool, the purposes change, the data categories may change, and the recipients almost certainly change. Beyond Article 30, Article 35 requires a Data Protection Impact Assessment for processing likely to result in high risk to data subjects' rights, and the European Data Protection Board has been clear that this includes most AI processing involving personal data.


For financial services firms, the Digital Operational Resilience Act, Regulation (EU) 2022/2554, has been operationally binding since 17 January 2025. Article 8 requires a register of all ICT third-party service providers, capturing concentration risk, criticality, contractual arrangements, and exit strategies. AI tools - whether procured directly or activated inside an existing SaaS, are ICT third-party services. They belong on the register; in most firms, they are not. The register is not a snapshot you produce in January. It is a live document. The supervisor will not accept "we had not updated it yet" as a defence when an AI feature that has been running for six months is missing.


And NIS2, Directive (EU) 2022/2555, has been transposed across most of the EU since the 17 October 2024 deadline (with several member states transposing late). Article 21 requires essential and important entities to address supply chain security, including direct suppliers and service providers. AI features inside SaaS, and the AI providers behind them, are part of that supply chain. NIS2 also introduces accountability for management bodies under Article 20: the AI inventory you cannot produce is not only an organisational risk; it is a personal one for the people who certified the firm's cyber risk position.


Four regimes. Four supervisors. One AI tool that the security team did not know about until last Tuesday.


What Shadow AI Looks Like in Practice


Three composite scenarios from real audits, anonymised.


Marketing. A 700-person SaaS company. Marketing has been using a free-tier image generator to produce campaign assets for six months. The prompts include the company's customer logos, occasionally with the customer name and segment alongside. The free-tier terms allow the vendor to retain prompts for training. The DPO did not know. The CISO did not know. The customer logos are now somewhere in a foundation model's training pipeline; the path to remediation is opaque.

HR. A 1,100-person professional services firm. The recruiting team turned on Phenom's AI-driven candidate matching last quarter. Phenom is now deciding which CVs reach the human reviewer. Under GDPR Article 22, candidates are entitled to human intervention in significant automated decisions; under EU AI Act Annex III, the system is high-risk; under DORA, Phenom is an ICT third party that should be on the register. None of those documents have been updated. The supervisor inquiry has not happened yet. It will.


Finance. A 500-person fintech. The CFO has been using ChatGPT free tier to summarise board materials for the last two months. The board materials include unaudited financials, M&A pipeline, and key personnel decisions. The CFO assumed the chat history was private. It is, for the user. It is not, for the model - OpenAI's free-tier terms permit use of inputs for training improvements, with opt-outs that the CFO did not configure.


In none of these scenarios was a person acting in bad faith. In all of them, the shadow AI exposure is real, contemporaneous, and in two of three cases compounding.


How To Find It


AI tool discovery is the work that has to happen before any of the rest of the work can. Without an inventory, every governance, classification, and reporting activity is theoretical.


In practice, no single discovery method finds all shadow AI. Each method finds a partial picture; combined, they approach completeness. Four layers, each with different strengths.


Identity and SSO. Your identity provider - Okta, Microsoft Entra ID, Google Workspace, OneLogin - has logs of every authenticated SaaS access. This finds sanctioned tools and most paid shadow tools. It misses free-tier and personal-account access entirely.


Email and calendar metadata. Every SaaS the organisation uses sends transactional email; every account creation produces a confirmation. Mining email metadata for vendor patterns surfaces tools your SSO does not, including most personal-account adoption.


Browser and endpoint telemetry. Where consented and configured, browser and endpoint data shows actual usage of AI tools, including the ones that do not require a login. This is where free-tier ChatGPT use surfaces.


Finance and expense data. The expense management system, the accounts payable system, the corporate card statements: these find the paid tools your IT and security systems missed because someone in marketing put the subscription on a personal card and expensed it.


The four together, run against a current catalogue of SaaS tools with AI feature flags and against the integrations your firm already uses, surface ninety per cent of the footprint within thirty days at most firms. The remaining ten per cent is where the qualitative work happens - interviewing department heads, examining workflow documentation, looking at the work product itself for AI-generated patterns.


This is the high-level picture. The full method runs longer, and the operational version of it is what we run during a Montro Discovery Audit.


What To Do Once You Have Found It


Discovery is the start, not the end. Once you have an inventory, the governance pipeline is roughly:

Classify each tool by risk. Apply the EU AI Act risk tiers - prohibited, high-risk, limited-risk, minimal-risk - and identify the deployer-versus-provider role as part of a structured AI risk assessment. For each high-risk tool, identify the Annex III category that puts it there.


Map regulatory obligations. For each tool, capture which of the four regimes apply and which Articles within each. The same tool will typically generate three to seven distinct documentary obligations.

Apply controls proportionate to risk. Transparency notices for limited-risk systems, human oversight processes for high-risk, logging and retention controls across the board, and an exception register for tools that cannot yet be brought into governance.


Produce evidence. Audit-ready output formats, a reporting cadence to the executive committee, a clear path from inventory to register to controls to evidence. The supervisor's eventual question is: show me. The evidence pipeline determines whether that's a Tuesday or a six-week scramble.


The Thirty-Day Audit Pattern


The structured way to do this is a thirty-day audit.


Week one is data integration: connecting to SSO, email, finance and procurement, and where appropriate browser telemetry. By the end of week one, the first complete shadow AI tools inventory exists.


Week two layers classification - the EU AI Act risk tiers, the Annex III categories, the GDPR processor mapping, where applicable the DORA register and NIS2 supply chain assessment.


Weeks three and four cover the documentation pipeline: register population, control assignments, evidence formats.


The output at day thirty is an audit-ready inventory and classification register, not a complete governance programme, that is a longer build. But day thirty is the point at which the board question becomes answerable: how many AI tools do we have, what are they doing, and what regulatory regimes do they cross?


Frequently Asked Questions


Is shadow AI a real category, or just rebranded shadow IT?


It overlaps with shadow IT and shares some of the same discovery patterns, but it is not the same problem. The embedded-AI dimension, features turning on inside applications you have already mapped, has no analogue in shadow IT. And the regulatory exposure profile is different: a shadow IT tool typically creates one or two regulatory issues; a shadow AI tool routinely creates four.


Does open-source AI count?


If your team is running an open-source model on your own infrastructure, that is still an AI system you deploy, and the EU AI Act and GDPR obligations attach. The provider obligations may differ; the deployer obligations are largely the same. Article 2 of the EU AI Act has carve-outs for AI released under free and open-source licences in some circumstances, but the carve-outs narrow when the system is used in a high-risk context.


Does this apply to non-EU companies?


The EU AI Act applies to providers placing AI systems on the EU market and to deployers established in the EU - and, the part US firms often miss, to providers and deployers outside the EU when the output is used in the EU. Most non-EU firms with European customers are in scope for at least some of their AI systems.


Does using OpenAI or Anthropic in our product make us a provider?


Probably not, by itself. Calling a general-purpose AI API to power a feature in your own product typically makes you a deployer of that AI, not a provider. Provider obligations attach when you place an AI system on the market under your own name. The line is more nuanced when fine-tuning is involved.


Should we just ban free-tier AI tools?


Bans do not stop usage; they stop visible usage. Every organisation we have worked with that banned ChatGPT discovered, six weeks in, that ChatGPT use had moved to phones and personal devices. The governance question is not whether to allow these tools - it is on which tier, with which controls, with which retention agreements. The answer that scales is shadow AI governance, not prohibition.

Ankur Arora

Ankur Arora

Co-founder

Fifteen years of enterprise digital transformation across telecoms, media, consumer goods, and agriculture - and a front-row seat to AI adoption outpacing governance at every organisation he worked in. He built Montro so the next firm doesn't have to learn that lesson the hard way.

Blog

Read next

Explore more from our library

View all

Stay informed on EU AI governance

Monthly updates on regulatory changes, compliance trends, and platform releases

By subscribing you agree to our Terms and Conditions and Privacy Policy

Montro AI governance dashboard showing tool risk tiers