Compliance / EU AI Act

The EU AI Act assumes you know your AI. Shadow AI says otherwise.

Every obligation in the AI Act, risk classification, transparency, literacy, oversight, starts from one implicit premise: the organization can list the AI systems it uses. Shadow AI is the gap between that premise and your network. Closing it is step zero, and it is the step a log audit does.

This page describes how audit evidence supports your own compliance work. It is not legal advice, and the report does not certify AI Act compliance; your counsel owns the legal analysis.
The premise gap

You cannot classify what you have not inventoried

The Act's architecture is risk-based: obligations follow from what each AI system is and does. That machinery has an input requirement nobody advertises.

Classification needs a list

Risk-classifying your AI systems presumes a complete list of them. An unknown chatbot processing HR text is unclassified by definition, and unclassified is not a category the Act offers.

Literacy needs a scope

AI literacy duties cover staff using AI systems. If usage is shadow, you cannot even say who is in scope, let alone train them appropriately.

Deployer duties need a trigger

Organizations carry obligations as deployers of AI systems. Shadow adoption means becoming a deployer without noticing, which is how obligations get missed rather than breached deliberately.

The uncomfortable summary: for most organizations the binding constraint on AI Act readiness is not legal interpretation. It is that nobody can produce the list.

Step zero

The audit as the inventory step

A log-based audit produces the list the Act's machinery consumes, with properties that matter to the people doing the downstream work.

What legal gets from it

  • A defensible starting universe: "these systems, observed on our network in this window".
  • Vendor training verdicts with check dates, feeding the provider-versus-deployer questions counsel actually litigates internally.

What IT gets from it

  • A worklist instead of a mandate: sanction, control or block per tool, with the ordering argument already made.
  • A quarterly rhythm that keeps the inventory alive rather than a one-off binder.
Mapping

Where audit evidence plugs into Act workstreams

Generic-safe mapping: your advisors decide the legal weight; the report supplies the observed facts each workstream starts from.

AI Act workstreamThe question it starts withWhat the report contributes
System inventoryWhich AI systems are in use at all?The tool table: every matched system, dated, per network scope.
Risk classificationWhat does each system do, for whom?Category and subcategory per tool, plus risk and abusive flags as triage order.
Prohibited-practice screeningIs anything in a banned category in use?Abusive-purpose flags surface the candidates for counsel's review immediately.
AI literacy scopingWho uses AI systems, and which?The per-user breakdown, team by team.
Vendor diligenceWhat do providers say about data and training?Dated training verdicts from 13,000+ terms reviews, per tool found.
Ongoing governanceIs the inventory current?Quarterly re-runs with deltas; changed verdicts flagged between runs.

Evidence handling suits the exercise: uploads are read once and discarded, only hostnames and identities feed the report, and reports are deletable before their 90-day expiry.

The EU angle

Evidence produced inside the jurisdiction

For EU organizations, where the audit itself runs is part of the diligence story.

An EU company

Shadow AI Tools is a product of Alpha Quantum, Munich, Germany. The vendor answering your AI-inventory question sits under the same regulatory sky you do.

Minimal data movement

The audit consumes hostnames, identities and timestamps, discards the upload after the run, and retains only the report you keep. That description fits comfortably inside a DPIA paragraph.

Sovereignty flags built in

Each matched tool carries a data-sovereignty flag, so the systems processing under jurisdictions you exclude surface in the first read, not the third workshop.

Timeline reality

Why step zero is urgent even where deadlines feel far

Whatever your reading of the Act's phase-in dates, three practical clocks are already running.

The procurement clock

Enterprise customers and public tenders increasingly ask AI-governance questions now, citing the Act. "Here is our dated inventory and process" wins deals before any enforcement exists.

The accumulation clock

Every quarter of unmeasured shadow adoption grows the eventual classification backlog. Inventorying now means triaging dozens of tools; later means hundreds.

The evidence clock

Governance narratives need history. A file of quarterly reports starting today reads very differently in two years than a scramble started under a deadline.

The cadence is the control: quarterly audits, same window, deltas reviewed. Plans that include monthly audits are on the pricing page.

The inventory your counsel keeps asking for

The sample report shows the document: systems, categories, flags, dated verdicts. Hand it to legal and watch the workshop agenda write itself.

Open the sample report
First moves

A four-week step-zero plan

FAQ

EU AI Act questions

Does the AI Act require an AI inventory?

Its obligations presuppose one: you cannot classify, screen or train around systems you have not listed. The inventory is the practical prerequisite, whatever the formal wording.

Does the audit make us AI Act compliant?

No, and nothing that runs on logs could. It produces the observed-usage evidence your compliance workstreams start from; the legal analysis is yours and your counsel's.

Are shadow AI tools our responsibility under the Act?

Discuss specifics with counsel, but as a rule organizations do not escape deployer questions by not knowing a system was in use. Not knowing is the risk, not the defense.

How often should the inventory refresh?

Quarterly as a floor. Between staff adoption and vendors changing terms, an annual inventory misstates the present for most of its life.

Does this help with GDPR too?

Substantially; the same findings feed processing analysis and DPIAs. The GDPR-specific angle has its own page: GDPR and shadow AI.

Where does the audit run and what does it keep?

It is operated by an EU company; uploads are read once and discarded, and only the report remains, deletable before its 90-day expiry.

Step zero takes an afternoon

Every AI Act workstream starts from the list. Produce it this week, from logs you already have.

Run the free audit