Compliance & Regulation

Shadow AI: the security risk of uncontrolled AI use

76 percent of data leaders confirm: governance has not kept pace with AI usage. Learn what risks Shadow AI creates, why three regulations are striking simultaneously, and how to regain control in five steps.

By SIMO GmbH

AI usage in German companies has doubled within a year: 36 percent of firms now deploy artificial intelligence—twice as many as in 2024. But while adoption is exploding, governance is lagging behind. 76 percent of data leaders confirm in a current survey from March 2026: internal control structures have not kept pace with AI usage. The result is a phenomenon that IT security experts call Shadow AI—and it has developed into the biggest security risk of 2026.

What is shadow AI and why is the problem exploding in 2026

Shadow AI describes the use of AI tools and services by employees without the knowledge, approval, or oversight of the IT department. The term goes beyond the familiar Shadow IT concept: while traditional shadow IT is limited to unauthorized software and hardware, Shadow AI adds a critical factor—the mass transfer of unstructured corporate data to external systems.

A sales representative who copies a customer list into a free AI tool to create form letters. A project manager who hands internal calculations to an AI assistant to prepare a presentation. A developer who feeds proprietary source code into an unauthorized code assistant. All of this happens daily, in companies of every size, and usually without malicious intent.

Three drivers of escalation in 2026

First: Availability has reached a new threshold. Generative AI tools are accessible for free or for a few euros per month. A browser tab is all it takes. No installation, no IT approval, no technical expertise needed. The entry barrier has dropped to zero.

Second: Productivity pressure is growing faster than budgets. The Horvath study shows that midsize companies spent only 0.35 percent of revenue on AI in 2025—down from 0.41 percent the prior year. The Mittelstand (privately held midsize companies) invests 30 percent less than the market average. When companies do not provide approved AI tools, employees find their own solutions.

Third, the governance gap has not closed; it has widened. 69 percent of organizations with more than €500 million in revenue now use generative AI, up from 48 percent the year before. This jump of 21 percentage points within a year has pushed already overstretched compliance structures to their limits. That is why 74 percent of chief data officers are urgently calling for AI literacy training in their organizations.

The three regulations that make shadow AI a compliance nightmare

What makes Shadow AI particularly explosive in 2026 is the convergence of three regulatory frameworks. Each on its own poses significant requirements for companies. In combination, they create a triple compliance burden that escalates uncontrolled AI usage from a security risk to an existential business risk.

EU AI Act

The EU AI Act requires companies to keep a risk-based AI inventory. Every AI system in use must be classified, documented, and monitored. Article 4 on AI literacy has also applied since February 2025; as amended in July 2026, it requires measures that support the AI literacy of everyone who works with AI systems on the company’s behalf (as of October 2026 · not legal advice).

For Shadow AI, this means: if employees use AI tools not listed in the company’s AI inventory, a compliance violation exists—regardless of whether the company knew about it. The obligations for high-risk AI systems, such as in HR or credit decisions, have been postponed to December 2027. But the basic obligations already apply now.

The penalties are substantial: up to €35 million or 7 percent of global annual revenue for prohibited AI practices, and up to €15 million or 3 percent of revenue for other violations. In Germany, the KI-Marktüberwachungs-und-Innovationsförderungs-Gesetz (KI-MIG, AI Market Surveillance and Innovation Promotion Act), in force since July 29, 2026, implements the EU AI Act. The Federal Network Agency is the central market surveillance authority.

NIS2 directive

The NIS2 directive extends European cybersecurity obligations to approximately 30,000 German companies. Initial NIS2 compliance requires investments in the six-figure range—a sum that represents a significant hurdle especially for midsize companies.

The connection to Shadow AI is direct: third-party AI tools belong to the digital supply chain and must be included in risk analyses. Uncontrolled AI usage by employees creates attack surfaces that count as security gaps under the NIS2 framework. AI-related security incidents must be reported within 24 hours. And particularly grave: personal liability of management for violations is tightened.

Anyone who tolerates Shadow AI in their company—even unknowingly—risks not only corporate penalties but personal liability claims.

GDPR

The General Data Protection Regulation remains the foundation of European data protection and is the most common stumbling block with Shadow AI. When employees enter personal data—customer lists, employee information, applicant data—into unauthorized AI tools, the legal basis for this data processing is typically missing entirely. There is no consent from the data subjects, no data processing agreement with the AI provider, no data protection impact assessment.

It becomes particularly critical with data outflows to providers outside the EU. Without standard contractual clauses or an adequacy decision, a violation of Chapter V of the GDPR exists. The fines: up to €20 million or 4 percent of global annual revenue.

The double-extortion scenario described by security experts further exacerbates the situation: attackers not only encrypt corporate data but simultaneously threaten to publish exfiltrated information. If Shadow AI usage has led to sensitive data residing on poorly secured external servers, the extortion potential becomes considerably greater.

Concrete risks for midsize companies

Germany leads the EU in AI investment readiness at 52 percent—the European average is only 38 percent according to the BCG AI Radar 2026. But readiness alone does not protect against risks. 70 percent of AI projects fail. The combination of high ambition and patchy governance makes Germany’s Mittelstand particularly vulnerable.

Real-world example: machine builder with 120 employees

A midsize machine builder in Baden-Wuerttemberg with annual revenue of €28 million. The design team—eight engineers—has been using various AI tools for months to optimize CAD drawings, analyze material tables, and calculate manufacturing tolerances. The IT department knows nothing about it.

What is actually happening: design data for a patented special machine—the core of the competitive advantage—regularly flows to servers of external AI providers. Purchase prices and supplier terms are uploaded to free analysis tools. Manufacturing parameters optimized over years reside on servers whose location and security level are unknown.

The financial risks in numbers:

  • GDPR fine (with personal data in the uploads): up to €1.12 million (4 percent of €28 million revenue)
  • EU AI Act sanction (missing AI inventory, no documentation): up to €840,000 (3 percent of revenue)
  • NIS2 violation (missing risk analysis of the AI supply chain): up to €560,000 (2 percent of revenue)
  • Know-how loss (if competitors access design data): unquantifiable, potentially existentially threatening
  • Forensics and legal counsel after an incident: typically €150,000 to €300,000
  • Reputational damage if it becomes public: customer loss in the seven-figure range

The total exposure of this single company is conservatively estimated at over €2.5 million—almost 9 percent of annual revenue. For a company of this size, that is existentially threatening.

Risk comparison: shadow AI versus controlled AI usage

  • Criterion: Data location | Shadow AI (uncontrolled): Unknown, often US servers without GDPR protection | Controlled AI usage: Defined, German or EU servers
  • Criterion: Legal basis | Shadow AI (uncontrolled): None—neither consent nor DPA present | Controlled AI usage: DPA with AI provider, GDPR-compliant
  • Criterion: AI inventory (EU AI Act) | Shadow AI (uncontrolled): Not recorded, documentation obligation violated | Controlled AI usage: Inventoried, risk-classified
  • Criterion: AI competence (Art. 4) | Shadow AI (uncontrolled): No training, no evidence | Controlled AI usage: Training documented, competence demonstrable
  • Criterion: NIS2 compliance | Shadow AI (uncontrolled): Not included in risk analysis | Controlled AI usage: Integrated into supply chain risk analysis
  • Criterion: Cumulative fine risk | Shadow AI (uncontrolled): Up to €35M (EU AI Act) + €20M (GDPR) + €10M (NIS2) | Controlled AI usage: Minimized through documented compliance
  • Criterion: Incident response | Shadow AI (uncontrolled): No detection, no reporting chain | Controlled AI usage: Monitoring, real-time detection, 24h reporting
  • Criterion: Executive liability | Shadow AI (uncontrolled): Personal liability for failure to act | Controlled AI usage: Discharge through documented due diligence
  • Criterion: Cost per incident | Shadow AI (uncontrolled): Average $4.63M (IBM) | Controlled AI usage: Drastically reduced through prevention
  • Criterion: Productivity effect | Shadow AI (uncontrolled): Short-term gain, long-term risk | Controlled AI usage: Sustainable productivity increase

Five steps to controlling shadow AI

Bans do not work. Years of experience fighting Shadow IT demonstrates this. Employees switch to personal devices and mobile networks. Usage becomes more invisible, the risk greater. Instead, companies need a strategic approach that combines control with productivity.

Step 1: conduct a shadow AI audit

Before you can take measures, you must know the current state. Conduct an anonymous employee survey: What AI tools are being used? For what tasks? How often? Supplement the survey with an analysis of network logs—which AI services are being called from the corporate network?

The result will probably surprise you. Experience shows that actual Shadow AI usage in most companies is two to three times higher than management assumes.

Document the results as a baseline. This current state is also your first step toward fulfilling the EU AI Act obligation to maintain an AI inventory.

Step 2: create and communicate an AI policy

Create an AI usage policy that clearly defines: what data may be entered into which AI tools? What use cases are permitted, which are prohibited? Who approves new AI tools? How are violations handled?

The tone is critical: the policy must be communicated as enablement, not prohibition. Show employees that the company supports AI usage—but on a secure path. Maximum five pages, in understandable language, with concrete examples.

At the same time, you meet Article 4 of the EU AI Act on AI literacy: train all employees on the policy and document the training. 74 percent of CDOs are calling for exactly this kind of training, so put it in place.

Step 3: provide an approved AI platform

The most important step: give your employees an official AI solution that is at least as powerful and easy to use as the shadow alternatives. If the approved solution is worse than ChatGPT in a private browser, Shadow AI will continue to flourish.

Focus on three core criteria: GDPR-compliant hosting on German or European servers, a data processing agreement with the provider, and the ability to configure access rights and data flow rules.

86 percent of CDOs want to increase their investments in data management between 2026 and 2027 according to the current LinkedIn AI Digest survey. Use this tailwind to convince management of the investment in a controlled AI platform.

Step 4: establish monitoring and reporting

Implement AI usage monitoring—not to surveil individual employees but to detect risks and steer the AI strategy. Which AI tools are being called in the network? How high is adoption of the approved platform? Is there still significant Shadow AI usage?

Define KPIs: Shadow AI rate (target: below 10 percent), adoption rate of the approved platform (target: above 80 percent), number of AI-related security incidents (target: zero). Report monthly to management.

This simultaneously fulfills NIS2 requirements for risk management and incident detection.

Step 5: ensure documentation and audit readiness

Document your entire AI deployment so that you can demonstrate to supervisory authorities at any time: which AI systems are used, for what purposes, with what protective measures, with what risk classification.

Schedule quarterly internal audits. Update the AI inventory with every new tool or change. Keep training records current.

This documentation serves not only compliance—it is also your best defense in an emergency. Companies that can demonstrate they exercised appropriate due diligence are treated significantly more leniently in fines than those that cannot show any structures.

Frequently asked questions

How do I recognize whether shadow AI is a problem in my company?

Ask yourself three questions: Do you have a formal AI usage policy? Do you provide your employees with approved AI tools? Can you name which AI systems are used in your company? If you answer any of these questions with no, Shadow AI is very likely an active risk. Experience shows: in companies without an AI policy, over 60 percent of knowledge workers use unauthorized AI tools.

What does it cost to bring shadow AI under control?

Costs vary by company size and current state. For a midsize company with 50 to 150 employees, a realistic budget plan is: €5,000 to €15,000 for the initial audit and policy creation, €500 to €3,000 monthly for a GDPR-compliant AI platform, and €2,000 to €5,000 for employee training. Set against average incident costs of $4.63 million, the investment in prevention amounts to less than one percent of the potential damage.

My company has under 50 employees. does this even affect me?

Yes. GDPR applies from the first employee. The EU AI Act does provide reduced fine frameworks for midsize companies, but the basic obligations—AI inventory, AI competence, transparency—apply to everyone. Smaller companies in particular often have fewer reserves to financially survive a data breach. A lean, pragmatic AI governance is not a luxury for midsize companies but a survival necessity.

What role does management play in shadow AI?

A central one. Under NIS2, management is personally liable for violations of cybersecurity obligations. If Shadow AI leads to a security incident and management has not taken appropriate measures, personal liability looms. Management must recognize Shadow AI as a strategic risk and provide the necessary resources for countermeasures. AI governance is a matter for the C-suite.

How long does it take to build AI governance?

With a structured approach, the basics are achievable in four to eight weeks: audit, policy, approved platform, initial training. A complete, audit-proof implementation with monitoring, reporting, and documented processes takes three to six months. The most important step is to begin now—regulatory deadlines are running, and the earlier you start, the more orderly the transition.

References

How our articles are created and who is accountable for them is set out in our editorial standards.

Tags

  • Midsize companies
  • AI Governance
  • GDPR
  • EU AI Act
  • AI Literacy

Back to the overview

Next step

Business data strategy for your company

From the target state to supervised delivery. We advise you and enable your organization.

Book an initial call

45 minutes, by video, free of charge.

Start the check

How ready is your decision? Check it in 3 minutes.

Call +49 6021 625 63 40