Shadow AI is a security problem, but the EU AI Act makes it a legal one (www.techradar.com)

🤖 AI Summary
A recent analysis highlights a growing concern in the realm of AI security: Shadow AI, where employees use unauthorized AI tools to handle sensitive corporate data. Research shows that nearly half of employees in larger organizations routinely input proprietary information into unapproved AI applications, with a staggering 85% of this user base continuing to do so even when sanctioned alternatives are available. This behavior poses significant risks, amplified by the EU AI Act, which imposes legal obligations on organizations regarding AI use. As of August 2026, companies must ensure governance, data management, and auditing capabilities over their AI deployments, raising the stakes for compliance amidst the threats posed by Shadow AI. The implications are twofold: organizations not only face potential security breaches stemming from Shadow AI—responsible for an estimated 43% of data breaches—but also face hefty fines of up to €15 million or 3% of annual turnover for non-compliance with the EU AI Act. Traditional security measures are often ill-equipped to detect unauthorized AI usage, as they typically overlook data that flows through secure channels, leaving a significant visibility gap. To tackle these issues, organizations must improve their AI governance strategies, implement robust endpoint protection, and enhance AI literacy amongst employees to prevent data leakage and ensure adherence to regulatory demands.
Loading comments...
loading comments...