AI Act in force across the EU
From 2 August 2024 the AI Act began to apply throughout the European Union. The regulation requires transparency and accountability when organisations deploy artificial intelligence models. Czech technology news outlet SystemOnLine reports that the new legal framework has drawn attention to a practice labelled “shadow AI”, the informal and often hidden use of public generative AI tools by employees.
How shadow AI creates data leakage
Shadow AI arises when staff insert internal know-how, trade secrets or personal data into publicly available models without authorisation. The data leaves the corporate environment, yet the organisation can still be held responsible for the breach. SystemOnLine describes this as a paradox: the employee initiates the transfer, but the employer bears the legal consequences.
Dual threat of cyber incidents and regulatory sanctions
The leakage creates a double exposure. First, it increases the risk of cyber security incidents because sensitive information enters systems the organisation does not control. Second, it exposes the company to penalties under both the AI Act and the General Data Protection Regulation (GDPR). An employer can be fined for failing to protect personal data and for insufficient transparency of AI systems, even when the leak originated with an internal user.
Governance and technical controls required
To mitigate these risks, organisations must establish clear policies for AI use, monitor access to external tools and ensure that every deployed model meets AI Act and GDPR requirements. Governance, auditability and control of input data are the key pillars for maintaining compliance.
Threat landscape evolving with AI
SystemOnLine notes that cyber threats are becoming faster, more extensive and more sophisticated because of artificial intelligence. Automated processes and human oversight alone are no longer sufficient. Organisations must re-evaluate their security models and integrate comprehensive defence strategies that account for the new attack surface created by generative AI.
What this means for non-Czech organisations
Although the reporting comes from a Czech source, the AI Act and GDPR are EU-wide regulations. Any organisation operating in the European market faces the same obligations and penalties. The shadow AI phenomenon is not specific to Czechia; it is a direct consequence of widely available generative tools meeting strict new regulatory requirements. Companies that do not bring public AI use under formal governance risk data loss, security breaches and financial sanctions across the Union.