Shadow AI Is Now a Compliance Problem, Not Just an IT One

Employees are running unsanctioned AI assistants by the handful. Regulators are starting to ask who approved them, and under which control framework.

ThreatVectr Newsdesk· 3 min read
Shadow AI Is Now a Compliance Problem, Not Just an IT One
Share

The average knowledge worker is now using three to five generative AI tools on any given workday, most of them never reviewed by an internal security team, and a meaningful share connected directly to corporate data stores through OAuth scopes or browser extensions. That is the shape of the shadow AI problem in late 2025, and it is the reason compliance officers, not just CISOs, are being pulled into the conversation.

The pattern is familiar. An employee installs a writing assistant. A developer wires a coding copilot into the IDE. A product manager piggybacks a meeting-summarization plugin onto Zoom. Each individual decision looks rational. The aggregate exposure, measured against frameworks such as the NIST AI Risk Management Framework (AI RMF) 1.0 and the obligations now flowing out of the EU Artificial Intelligence Act, is not.

Under Article 4 of the AI Act, which entered into application on 2 February 2025, providers and deployers of AI systems are required to ensure a sufficient level of AI literacy among staff operating those systems. That obligation does not distinguish between procured tools and ones an employee installed last Tuesday. The European Commission has been explicit on this point. "AI literacy is a precondition, not an optional add-on," said Lucilla Sioli, Director for Artificial Intelligence and Digital Industry at the Commission, in published guidance accompanying the rollout.

Domestically, the picture is messier. The Cybersecurity and Infrastructure Security Agency (CISA) has issued non-binding guidance on generative AI use in federal environments, and the Office of Management and Budget (OMB) Memorandum M-24-10 requires federal agencies to inventory AI use cases. Private-sector firms have no equivalent single rule, but sectoral regulators are filling the gap. The Securities and Exchange Commission (SEC) has indicated through recent enforcement that material AI-related risks fall within the disclosure obligations under Item 1C of Form 10-K.

The practical question is what a defensible program looks like. Five elements are emerging as the consensus baseline: a maintained inventory of AI tools in use, a tiered approval workflow keyed to data sensitivity, contractual review of vendor data-handling terms (particularly training-data reuse), logging at the network or browser layer, and recurring literacy training tied to job role.

None of that requires blocking employees from the tools. It requires knowing which tools, holding which data, under which terms.

But the window for voluntary action is narrowing. The next set of AI Act obligations, covering general-purpose AI models, applied from 2 August 2025, and the high-risk system provisions in Annex III take effect on 2 August 2026. National competent authorities under the Act must be designated by member states by 2 August 2025, with enforcement powers following. Firms operating in the EU should expect their first information requests within that window. The compliance clock is already running.

© 2026 Threat Vectr