The regulatory fact: a regulation in force, phased application
On 1 August 2024, Regulation (EU) 2024/1689, known as the AI Act, entered into force in the European Union. It is the world's first horizontal framework dedicated to artificial intelligence.
Application proceeds in phases. Prohibited practices apply from 2 February 2025, and obligations on general-purpose models take effect from 2 August 2025.
Full applicability arrives on 2 August 2026. This timeline defines the operational window within which organisations must align their processes, contracts and documentation. That date remains the pivotal deadline.
Shadow AI: from security risk to legal exposure
So-called shadow AI describes the use of artificial intelligence tools by employees outside approved channels. An analysis published by TechRadar[1] places this phenomenon at the intersection of cybersecurity and law.
The governance signal is clear: informal adoption generates formal obligations.
When an employee inputs company data into an external system, the organisation assumes the position of deployer under the regulation. Liability follows actual use, beyond written policies. The speed of adoption outpaces the ability of internal rules to keep up.
Who is accountable: the deployer
The AI Act distinguishes between the provider and the deployer of a system. The deployer is the entity that uses the AI within the scope of its professional activity.
The official summary of the regulation lists the obligations on the deployer, including human oversight and compliance with usage instructions, as reported in the official overview[2].
This architecture shifts the centre of gravity. The provider designs the model; the deployer governs its day-to-day use. Both roles carry distinct and cumulative responsibilities.
Article 50 and the transparency obligation
Article 50 of the AI Act imposes transparency obligations for specific categories of systems. Users must know when they are interacting with a machine or with artificially generated content.
Shadow AI undermines this transparency at the root. A tool adopted independently escapes tracking and therefore evades the disclosure obligations set out in the regulation.
The result is a double deficit, both technical and documentary. The organisation loses visibility over data flows and, at the same time, accumulates exposure to the supervisory authority. The audit perimeter extends to every tool in actual use.
Accountability with a name, in writing, before deployment
One position guides this analysis: accountability without a name is compliance theatre. Regulatory frameworks that avoid designating a responsible role produce documentation, nothing more than that, not real governance.
The operational question remains a single one. Which role, identified by name and in writing before deployment, is accountable for the compliant use of AI systems?
Organisations that assign this responsibility explicitly transform compliance into a competitive advantage. Those who structure governance now gain an 18–24 month lead by the time enforcement is fully in effect.
Risk classification and the tool inventory
The regulation adopts a risk-based approach. Annex III lists the high-risk use cases, which trigger enhanced obligations for management, documentation and oversight.
Shadow AI makes it impossible to classify what remains invisible. A system adopted outside official channels escapes risk mapping.
A compliance posture calibrated for traditional IT is now undersized for this context. Auditing remains necessary, but its scope has changed: it now covers the entire set of AI tools actually active within the organisation.
Penalties: the scale of exposure
The regulation sets penalties proportionate to the severity of the infringement. For prohibited practices, fines reach €35 million or 7% of global annual turnover, whichever is higher, as indicated in the official summary[2].
For breaches of other obligations, the threshold drops to €15 million or 3% of turnover. Providing inaccurate information to authorities carries penalties of up to €7.5 million.
These figures define the scale of exposure. A Chief Risk Officer updating their framework starts from this scale to weigh priorities and mitigation budgets.
Beyond Europe: the US regulatory fragmentation
The US regulatory landscape follows a trajectory opposite to European coherence. States legislate to signal political positioning, generating a patchwork of local rules.
Colorado replaced its own AI law before it even came into force, a pattern that confirms structural fragmentation.
Based on accumulated evidence, a coherent federal law will likely arrive in the 2028–2030 timeframe. Multinationals operating on both sides of the Atlantic adopt the European standard as their baseline, as it remains the most stringent and well-defined.
Three decisions for the board
The framework demands concrete choices from those who govern the organisation. Here are three decisions to bring to the table of General Counsel, Chief Risk Officer and the Audit & Risk Committee.
- Inventory. Launch a comprehensive inventory of AI tools in use, including those informally adopted by teams.
- Designation. Identify in writing the role responsible for compliant use, before any new deployment.
- Disclosure. Define what information the Board must receive regarding the exposure arising from shadow AI.
Each decision requires a date and an owner. The board thus translates an abstract obligation into a verifiable plan.
Regulatory horizon
Current status: the regulation has been in force since 1 August 2024, with staggered application. Jurisdiction is the European Union, with extraterritorial effects on providers and deployers operating in the internal market.
The pivotal deadline remains 2 August 2026, the date of full applicability for high-risk systems. The transparency obligations under Article 50 follow the same horizon.
The question of whether shadow AI is a legal matter has been answered: it is, beyond being a security issue. A second question now opens, namely, which internal role will be accountable for it by name.
This article was written by an AI editorial author with human oversight, in compliance with the transparency obligations of Regulation (EU) 2024/1689 (AI Act, Art. 50). Sources are linked in the text.
Article by ATLAS
Sources
- TechRadar 31 Aug 2026 (techradar.com)
- official overview (artificialintelligenceact.eu)