The delay in the rollout of part of the EU's AI Act has put many companies at ease — but experts warn that so-called "Shadow AI" means firms are already breaking the law today. The issue arises when employees use publicly available AI tools — ChatGPT, Gemini or Claude — to handle confidential information without their employer's knowledge or consent.
Employees' motives are usually innocent enough: they simply want to get through routine tasks faster or boost their productivity. But the consequences can be serious, as trade secrets, margin data, source code, and personal information about clients and staff end up in chatbots with no oversight whatsoever.
According to a November 2025 study by UpGuard, up to 80% of employees use AI tools that haven't been approved by management. A KPMG study from the same year found that 57% of workers deliberately hide their use of such tools from their bosses. Companies in IT, software development, marketing, legal and tax services, and consulting are most at risk.
The EU's Digital Omnibus package, which received final approval from the European Parliament and the Council of the EU in June, pushed back the effective date for part of the rules governing high-risk AI systems. Lawyers, however, say this is no reason for companies to let their guard down.
"After the June delay to part of the AI Act's rules, companies breathed a sigh of relief. But they shouldn't lose sight of the fact that any firm where people are secretly using AI tools with no rules in place is already breaking the law today," says Michal Nulíček, attorney and partner at ROWAN LEGAL specializing in data protection, commenting on this paradoxical situation. He notes that most of the remaining AI Act provisions have already been in force since August 2 of this year.
The trouble is that even when a specific employee is behind a leak of commercial information, legal liability falls on the company itself — as the data controller under GDPR, a party to confidentiality agreements, and an entity bound by the AI Act.
"The insidious thing about Shadow AI is that a company ends up being both victim and offender at once. It's the employee who just wanted to save time who leaks the trade secret, but it's the employer who pays the fine for the personal data breach or the breach of a non-disclosure agreement," Nulíček explains.
Companies risk facing penalties under both the AI Act and GDPR simultaneously, and regulated entities — financial institutions, for instance — could face additional fines under sector-specific rules on top of that.
Incidents like this are already cropping up in practice, both in Czechia and abroad. Last December, the Czech Constitutional Court fined a lawyer 25,000 crowns for a complaint that relied heavily on nonexistent case law generated by artificial intelligence. Most such incidents are handled internally, so the cases that make headlines are just the tip of the iceberg.
The case that drew the most attention was South Korea's Samsung back in 2023, when the company's engineers uploaded confidential source code to the free version of ChatGPT, which subsequently slipped beyond the firm's control. Samsung responded by banning employees from using public AI services, under threat of dismissal.
"This isn't a theoretical risk. Many companies' knee-jerk reaction is to impose a blanket ban on AI tools, but that's not the best solution. A ban is practically impossible to enforce, and it just pushes users deeper into the grey zone. The only approach that actually works is to give people an approved, secure tool and teach them how to use it," says Filip Beneš, a lawyer at ROWAN LEGAL.
He notes that many companies will need to roll out commercial AI services backed by contractual data-processing guarantees, adopt internal AI-use policies that clearly define what data cannot be uploaded to AI systems, and train their staff accordingly. Nulíček recommends starting with an anonymous audit to give management a real picture of which tools employees are actually using.
Regulatory pressure in Czechia is only set to increase: the country is currently working through the legislative process for an adaptation law on artificial intelligence, under which oversight of compliance will fall mainly to the Czech Telecommunication Office, with the Office for Personal Data Protection handling the data-protection side. Experts advise companies that haven't yet tackled the Shadow AI issue to act now — before a regulator or a client spots the non-compliance first.
Source: prazskypatriot.cz