EN

Inventory · vendor AI · consumer AI

Shadow AI: the AI risk your board may not yet know about

If you believe your institution does not use AI, you are probably wrong. AI components are now hidden in software that has been in use for years and in tools employees use without formal approval.

What shadow AI means

Shadow AI means the use of AI systems in an organisation without sufficient transparency, approval or governance. This may sound like deliberate rule-breaking by individual employees. In most cases, however, the risk arises from structural gaps.

Form 1: employee shadow AI

Employees use freely available AI tools such as ChatGPT, Claude or AI-supported translation services for work tasks, on private devices or in the office, without formal approval. Classic technical blocks only have limited effect because sensitive customer data or internal documents can also enter external systems via private devices.

Form 2: vendor AI

The more sensitive regulatory form is vendor AI: software your institution has used for years increasingly contains AI components introduced through regular updates. These systems were often not consciously classified as AI, yet duties under the EU AI Act may still arise.

Why shadow AI is particularly critical for financial institutions

The key difference from classic shadow IT: AI systems make or influence decisions. A loan applicant rejected by an insufficiently tested scoring model, an underwriting system calculating premiums based on a machine-learning model, or HR software automatically pre-sorting applications are not mere IT questions. They raise issues of governance, traceability, data protection, labour law and possible liability.

This is exactly why the connection to the AI inventory is central. Without a structured inventory, neither risk classification nor responsibility allocation is reliable.

CSRD / ESRS relevance

If shadow AI creates discriminatory effects in HR processes, employee monitoring or customer access processes, it can also become a sustainability and governance topic. CSRD / ESRS reports then need not only incidents, but also policies, remedy channels, measures and internal controls.

Typical vendor AI systems in Austrian financial institutions

AreaExamplesWhat AI may do there
Core bankingTemenos, Finastra, MambuAI copilot in credit processing, next-best-action recommendations
Credit scoringFICO, Moody's Analytics, SASML-based creditworthiness assessment of natural persons
AML / fraud detectionNICE Actimize, Oracle FCCMAnomaly detection in transactions, customer risk rating
UnderwritingGuidewire, Sapiens, Duck CreekRisk assessment and premium calculation with AI support
HR recruitingPersonio, SAP SuccessFactors, WorkdayCandidate matching and scoring through AI models
Chatbots / serviceGenesys, NICE CXone, Leena AINatural-language processing for customer communication
Why a complete inventory is harder than it sounds

The question "Which AI systems do we use?" sounds simple. Providers rarely label ML components explicitly as AI systems within the meaning of the EU AI Act. A reliable survey requires coordinated involvement of IT, procurement, compliance, HR and business units as well as technical and regulatory expertise.

Do you know which AI systems are actually in use?

A structured inventory is the first and often most difficult step toward EU AI Act compliance.

Arrange a first conversation
Notice: This page is for general information about regulatory developments and does not constitute legal advice. Content reflects the state of July 2026 and may change through new legislation, national implementation rules or regulatory interpretation.