EU AI Act
Shadow AI and the EU AI Act: what organisations need to know
The EU AI Act does not use “shadow AI” as a legal category. The connection is practical: an organisation cannot reliably identify its role, risk class, or obligations for an AI system it does not know is being used. Discovery and an accurate AI inventory are therefore foundations for compliance.
Classification begins with use, not brand name
The same general-purpose tool can support low-impact drafting in one context and contribute to a consequential decision in another. Assessment should capture the system's intended purpose, how the organisation actually uses it, the people affected, the data involved, and whether the organisation is a provider, deployer, importer, distributor, or product manufacturer under the Act.
Where an unknown tool creates gaps
- Role: the organisation may not know which legal role it performs.
- Risk: a use connected to recruitment, education, essential services, critical infrastructure, law enforcement, or migration may require closer classification.
- Transparency: people may need to know they are interacting with AI or viewing synthetic content.
- AI literacy: staff need knowledge appropriate to the systems they operate and the context of use.
- Evidence: owners, instructions, oversight, logs, vendor documents, and review decisions may be missing.
What to record before classifying a use
KISYN's free AI Act assessment explains the terms in ordinary language and links each legal concept to the official regulation. It is an orientation tool, not a substitute for legal advice.
- The AI system or feature and its provider.
- The business purpose and actual workflow.
- The organisation's legal role in making or using it.
- People affected and possible consequences.
- Input data, output data, integrations, and human oversight.
- The initial risk classification, supporting evidence, owner, and review date.
Frequently asked questions
Does the EU AI Act ban shadow AI?
No. It prohibits certain AI practices and regulates other systems according to role, purpose, and risk. “Shadow AI” describes a governance condition in which use is not visible or approved; the legal analysis concerns the underlying practice and system.
Can a general-purpose chatbot be high-risk AI?
A chatbot is not automatically high-risk. How an AI system is placed on the market or put into service, its intended purpose, and how it is used all matter. A general-purpose model can also be integrated into another system whose use requires a separate classification.
Where can I read the official EU AI Act?
The authoritative text is Regulation (EU) 2024/1689 on EUR-Lex. The European Commission's AI Act Service Desk also provides an accessible regulation explorer and implementation information.
Free orientation tool
Understand how the EU AI Act may apply
Answer plain-language questions, get explanations as you go, and see the official legal basis behind your result.
Start the AI Act assessment