Shadow AI is when someone in your business uses an AI tool that nobody in IT, security, or leadership has looked at or approved. It shows up as free accounts, browser extensions, and features already built into other software that people just switch on themselves, usually to get an everyday task done faster.
If someone in your business is using an AI system for a task, that use brings legal obligations with it, whether or not anyone signed off on the tool first. That's how deployer duties work under the EU AI Act.[1] So when one of your staff starts using a free tool to draft client emails or screen CVs, they've effectively made an AI decision for the whole business, whether they meant to or not. Most Irish businesses have already had this happen more than once, and don't know it yet.
An AI Readiness Assessment is the fastest way to find out which of these tools are already running in your business, before you decide what to do about any of them.
What is shadow AI?
Shadow AI is any AI tool, feature, or account your business is actively using that hasn't been through whatever review and approval process you actually run.
People sometimes call this shadow IT, the older term for software nobody approved. Shadow AI is the same idea, but there's a lot more on the line. A spreadsheet macro someone built without asking IT usually stays on one laptop, and nobody outside that team ever sees it. Text you type into a free AI tool doesn't stay put like that. It can leave your computer altogether and end up on someone else's server, and depending on the tool, it might get kept and used to train the model further. Once you've typed a client's name, a contract term, or a staff performance note into a tool like that, you can't get it back.
There are three ways shadow AI usually gets into a business. One of your staff signs up for a free tool on their own, using a personal or work email. A feature already built into software your team uses every day, like a browser or a CRM, gets turned on by someone who never saw an announcement about it. Or a team starts using something informally, simply because it's faster than waiting for an approved option to arrive.
In summary
Assume shadow AI already exists in your business before you spend a day trying to prove it.
Why does shadow AI happen in Irish SMEs specifically?
Shadow AI happens fastest in smaller businesses because the two things that usually slow it down in a bigger company, a security team watching network traffic and a formal approval process for new software, are things you probably don't have.
If you checked your company card statement today, there's a good chance you'd find at least one AI subscription nobody requested through any approval process. Someone signed up for it because they needed to solve a problem and didn't want to wait for it to be approved. That happens all the time, quietly, and nobody involved means any harm by it. The productivity gain is real. A tool that turns a two-hour first draft into a fifteen-minute one gets used straight away, whether it's approved or not.
This is a supply gap. An approved option didn't exist yet, so people reached for whatever got the job done.
In summary
What's already solving a problem for someone on your team? That's where shadow AI lives.
Does shadow AI break the EU AI Act or GDPR?
Shadow AI creates real exposure for your business under both, and it's rarely down to one dramatic breach.
If you're using AI systems in your business, you're supposed to help the staff who operate or use them actually understand what they're working with. That's the AI literacy duty under Article 4 of the EU AI Act, in force since 2 February 2025. A Digital Omnibus amendment that took effect on 27 July 2026 changed the wording of that duty, moving it away from one fixed standard everyone had to meet and focusing instead on the actual steps you take.[3][4] Staff quietly trying out new tools on their own falls well short of that standard. AI Literacy Training: What Article 4 Requires of Irish SMEs explains what meeting Article 4 actually involves, including the training and paperwork you need, in more depth than this article goes into.
It doesn't matter whether anyone at your business formally picked the tool. If someone is actually using an AI system for a task, the legal duties land on them anyway. That's Article 26. It puts deployer duties on whoever is actually using the system, whatever their intentions, and whatever tool you picked or never got around to picking.[1] Those duties shift depending on who's affected by the output, and they apply just as much to a tool your staff found on their own as to one you formally signed off on.
Then there's GDPR. Personal data can only be collected for a specific purpose, and it has to be kept to that purpose. That's Article 5.[5] When a client's name and query get typed into a free AI tool with no data processing agreement in place, that data has usually just gone well beyond its original purpose, often straight into a model's training data, with the client none the wiser. The Data Protection Commission has said plainly that you need to know where personal data actually goes once a third-party AI product is involved, whether the provider keeps it or reuses it some other way.[6]
In summary
An unapproved tool can still leave your business holding obligations nobody assigned.
Why doesn't banning AI tools work?
Prohibition sounds decisive and does almost nothing.
Tell your staff to stop using a tool that already saves them real time, and they mostly don't stop. They stop telling you about it, and the behaviour carries on regardless. Whatever visibility you had, and it wasn't much, disappears completely. A policy meant to cut risk ends up raising it instead, because you can't manage a risk you can't see.
Most businesses holding the line know this is happening under their own roof, and yours is probably no different. AI Governance for Irish SMEs makes the wider case, beyond shadow AI specifically, that governance built for safe use moves a business faster than a wall built to stop use outright. The same logic applies here. An AI acceptable use policy, which is a practical template and plain English guide to what to include, names an approved tool and takes away your staff's reason to go looking for one that isn't.
In summary
Give your staff a fast yes before they find their own way to a tool.
How do you find out if your business has shadow AI?
Start with a short, honest conversation.
Ask each of your teams what they actually used AI for this week, whatever the policy says is allowed. Most staff will tell you plainly once the question feels like information gathering rather than an audit. Ten specific answers on a page, drafting emails, tidying a spreadsheet, summarising a contract, prepping a client update, will tell you more than a policy document nobody has ever tested against reality. If the tools your team is using are agent-style, wired into email, a calendar, or a CRM, where to check AI agent settings walks through the exact settings screens across Microsoft 365, Zapier, and n8n where that kind of activity tends to hide, which this article only touches on.
Once you have that list, the next decision is what to offer instead. Choosing the right AI tools gives you a short filter for picking an approved option your staff will actually want to use, including how to check a vendor's data handling, which goes further than this article does.
In summary
A ten-minute conversation with each of your teams beats a six-month audit you never finish.
What's actually running across your business probably hasn't been mapped yet, and that's the specific problem the AI Policy and Governance Pack is built to solve. Get in touch and your business's AI use can be mapped properly, tool by tool, instead of guesswork.
