
Shadow AI becomes a legal exposure under the EU AI Act
TechRadar reports that nearly half of employees at large enterprises are feeding corporate data into unsanctioned AI tools, and that 85% continue even when official tools exist. Under the EU AI Act, this ‘shadow AI’ is no longer just a security issue but a compliance and liability problem, since unapproved tools can fall outside documented risk assessments, DPIAs, and AI registers.
Position your firm as a partner that helps clients surface, contain, and regularize shadow AI—combining discovery, policy, and technical controls—as a defined advisory offering aligned to the EU AI Act and sector regulations.
highIf you cannot show boards and regulators where client data might be flowing into public or consumer‑grade AI tools, you risk privilege issues, contractual breaches, and loss of trust in your handling of sensitive matters.
high