Shadow AI · Policy vs. Reality

Your team uses AI tools you don't know about.

Shadow AI is the #1 compliance blind spot auditors find. Fencia detects every tool, checks it against your policy, and surfaces every gap — automatically.

The problem

What is Shadow AI?

Shadow AI refers to artificial intelligence tools, models and applications that employees use within an organization without the knowledge, approval or oversight of IT, legal or compliance teams. It happens because AI adoption is fast and frictionless — a developer installs an SDK, a marketer pastes data into ChatGPT, a designer uses an AI image generator — all without a formal review.

The problem isn't that employees want to break rules. The problem is that AI tools are now as easy to adopt as a browser extension, and the compliance review process hasn't caught up. By the time IT finds out, the tool has been in production use for months.

Shadow AI exposes your organization to serious regulatory risk. The EU AI Act, in force since August 2024, holds deployers accountable for every AI system in use — including the ones that were never officially approved. Auditors will ask for a complete AI inventory. If you can't produce one, that's a finding.

The EU AI Act holds you accountable for every AI system you deploy — including the ones you didn't officially approve.

Real examples we detect every week: ChatGPT used to summarize customer support tickets (personal data processed without consent mechanism), OpenAI SDK imported directly into production codebase (no security review), Perplexity used for competitive research on confidential product strategy.

Common

Employees often use AI tools that haven't been formally approved by their organization

Industry reporting
Art. 26

EU AI Act deployer obligations include using high-risk AI systems in line with instructions and maintaining oversight

EU AI Act
Growing

The number of unapproved AI tools active inside organizations grows as teams adopt new products

Observed across deployments

Policy vs. Reality

acceptable-use-policy.pdf
Your policy
1. Employees must not paste customer PII into
generative AI tools (ChatGPT, Claude, etc).
2. AI tools must be reviewed by Legal before
being used on production data.
3. Use of AI for code generation requires CTO
approval and a code-review attestation.
Detected by Fencia
Real usage
ChatGPT
14 mentions · #marketing
Policy gap
OpenAI SDK
openai in 3 repos · package.json
Policy gap
Perplexity
2 mentions · research-2026.docx
Policy gap
GitHub Copilot
8 mentions · #engineering
Approved
Cursor
.cursor/ in 4 repos
Policy gap

Left: what your AI policy says. Right: what Fencia found in Slack and GitHub.

How it works

Three steps from unknown to audit-ready.

01

Connect your sources

Link Slack, Google Drive and GitHub in one click. No agents installed, no IT tickets required. Read-only OAuth — Fencia never writes or deletes anything.

02

Automated, continuous scanning

Fencia scans every message, document and repository for AI tool mentions and usage patterns. Runs continuously on a schedule — not just when you remember to check.

03

Policy gap analysis

Every detected tool is cross-referenced against your uploaded AI policy. Unapproved tools become findings with article reference, severity rating and a concrete remediation step.

Detection sources

Where Fencia looks.

Slack

AI tool mentions in public channels, shared links, bot integrations and workflow automation.

ChatGPT, Claude, Midjourney, Perplexity, Notion AI…

Google Drive & Dropbox

AI tool names referenced in documents, contracts, meeting notes, spreadsheets and presentations.

Tool names in strategy docs, vendor agreements, product specs…

GitHub

SDK imports and dependencies in package.json, requirements.txt, Cargo.toml and direct API calls in source code.

openai, anthropic, langchain, huggingface, replicate…

What happens next

From detection to finding in seconds.

When Fencia detects a tool, it doesn't just log it. It classifies the tool (approved / unapproved / unknown), cross-references it against your uploaded AI policy, and generates a structured finding.

Each finding includes: the tool name and version, the source where it was found, the EU AI Act article it potentially violates, a severity rating (Critical, High, Medium, Low), and a recommended remediation action — not a generic suggestion, but a specific step you can take today.

Findings are grouped into your AI inventory automatically. New tools discovered after your last scan appear as new findings. The inventory stays current without any manual effort.

Example finding
High
ToolOpenAI SDK (openai@4.28)
SourceGitHub · package.json · 3 repos
ArticleEU AI Act Art. 26 — Deployer obligations
SeverityHigh
ActionAdd to AI policy and complete risk classification
Add to AI policy and complete risk classification

Regulatory context

Why Shadow AI is an EU AI Act problem.

Article 26 of the EU AI Act sets out the obligations for deployers of high-risk AI systems — the organizations that put those systems into use. Deployers must use the system in line with its instructions for use, ensure human oversight, monitor operation, and keep relevant records. Documenting the AI systems your organization deploys is the foundation for meeting these obligations.

The point is 'AI systems actually in use' — not just those your IT department approved. If your team uses a tool like ChatGPT to process customer data without documenting it, you can be exposed during an audit. The exact obligations that apply depend on the use case and should be confirmed with your legal advisor.

Auditors under the EU AI Act will request an AI inventory as one of their first steps. They want to see what you operate, how you classified each system, what oversight mechanisms you have in place, and what your AI use policy says. Shadow AI is the gap between what your policy says and what your inventory actually contains.

Build your AI inventory automatically →

Stop guessing what AI your team uses.

Fencia builds your AI inventory automatically and keeps it up to date — so you're ready when the auditor asks.