Shadow AI has a new problem: The law
EU AI Act enforcement is less than two weeks away, increasing the stakes for shadow AI detection.
Subscribe to FILED Newsletter
Hi there,
Welcome to FILED Newsletter, your round-up of the latest news and views at the intersection of data privacy, data security, and governance.
This month:
- The EU AI Act reaches full enforcement on August 2, 2026
- A publicly exposed database holding 24 billion stolen credentials was found online
- The UN held its first ever Global Dialogue on AI Governance in Geneva
But first, shadow AI is still growing, it's getting riskier, and with the EU AI Act arriving on August 2, it's now a legal liability too.
If you only read one thing
Shadow AI has a new problem: The Law
Shadow AI has been a security risk, with an estimated 60-70% of enterprises exposed to shadow AI, and another 20% having had a breach linked to unauthorized AI use. But with less than two weeks until August 2, when the EU AI Act reaches full enforcement, shadow AI is increasingly a legal risk too.
Among the obligations taking effect is Article 10, which sets data governance requirements for high-risk AI systems: the data used to build and run them must be relevant, representative, well-documented, and subject to proper governance.
Patchwork of US state regulations emerge
If the EU is at the forefront, the US is catching up. A 42-state attorney general coalition is coordinating AI enforcement, Colorado's AI regulations take effect this year, and Connecticut's broad new AI and online safety statute came into force in June.
The federal government may be deregulating, but the states are moving in the opposite direction.
For organizations operating across jurisdictions, shadow AI now creates simultaneous exposure on multiple regulatory fronts. The window to get ahead of it is closing.
Visibility and governance are the same problem
Here's a hard truth: When it comes to AI, too often, what leadership believes is going on, and what is actually happening are very different — From the tools in use, to what exactly employees are building in their off time.
And much of the problem stems from the very simple idea that we've repeated a time or two: You can't govern what you can't see.
The stats back up the idea that governance is lagging. A study released just last week found that, among today's enterprises, only 26% have governance frameworks that are keeping pace with AI deployments.
With regulatory stakes rising, the instinct is to adopt draconian policies: Block AI use. But that can have the opposite effect — Pushing use underground, and onto personal devices where the risks are even harder to detect.
In our recent FILED Talks conversation, Chief AI Officer Rob Williams offers a better approach: Bring it into the open. Find employees already using AI, understand what they're solving for, and give them sanctioned tools that meet those needs — backed by policy people understand.
What this means practically
While there’s a whole lot more to compliance than visibility, with the August 2 deadline bearing down, we’d bet big that the organizations most at risk aren’t the ones with sophisticated AI deployments. The risk lives in the gap between what employees are doing, and what leadership thinks they are.
[Image: How Mentorloop Got Started with AI Gov: https://www.recordpoint.com/webinar/filed-talks-mentorloop-ai-governance]
🔎 Privacy and governance
The European Data Protection Board has announced that the right to erasure under Article 17 of the GDPR will be enforced in 2026, signaling that organizations need robust, documented processes for handling deletion requests.
Cumulative GDPR fines have now surpassed EUR 7.1 billion, with more than 2,800 fines issued to date.
The White House issued a new Executive Order on AI innovation and security in June, continuing the administration's deregulatory approach while adding national security guardrails. Meanwhile, 19 new AI laws have emerged across 11 US states in just two weeks.
🛡️ Security
A publicly exposed Elasticsearch database containing 24 billion stolen credential records was found online in June, holding more than 8.3TB of data including usernames, email addresses, plaintext passwords, and login URLs.
Market intelligence firm Klue confirmed a supply chain breach affecting close to 200 companies, including cybersecurity firms Jamf, HackerOne, and LastPass. Attackers used compromised legacy credentials to the company's Salesforce CRM integration environment.
TechCrunch's mid-year breach roundup shows that 2026 is already a record year for major incidents, with attacks spanning pharmaceuticals, higher education, government, and critical utilities.
🤖 AI governance
The EU AI Act reaches full enforcement on August 2, 2026, including transparency obligations under Article 50, conformity assessment requirements for high-risk systems, and the data governance rules under Article 10. Penalties for the most serious violations reach EUR 35 million or 7% of global turnover.
The UN held its first Global Dialogue on AI Governance in Geneva on July 6 and 7, bringing together all 193 UN member states alongside the private sector, civil society, and academia. The Secretary-General used the occasion to warn of the risk of "catastrophic harm" if international coordination fails to keep pace with AI capability.
A TELUS Digital report finds that 86% of organizations have experienced AI-related security incidents, with privacy exploitation and fraud as the top risks.
The latest from RecordPoint
🎧 Watch: In this upcoming FILED Talks episode, RecordPoint CEO Anthony Woodward talks with MentorLoop CTO Tracy Bongiorno about how a lean team developed a practical, people-first approach to AI governance, including managing shadow AI, navigating the EU AI Act, managing sensitive personal data in an AI-driven matching algorithm.
📖 Read: Forrester's Responsible AI Solutions Landscape is out for Q2 2026, and it covers 30 vendors and reinforces the importance of data governance in responsible AI. Get the full report here.
