Shadow AI Is Now a Proof Problem, Not Just a Security One
Under the AI Act, using AI in a business decision without being able to show how isn't a compliance footnote anymore. It's a liability.
The decision nobody can reconstruct
A sales director used an AI tool to draft a discount recommendation for a key account. The recommendation was approved, the deal closed, everyone moved on. Six months later, a client dispute lands, and someone asks: how was that pricing decision made? Who reviewed the AI output? What data did the model see? Nobody remembers. There's no log, no version of the prompt, no record of who approved what. The tool worked fine. The problem is that nobody can prove it worked fine.
This is the shift most companies haven't registered yet. For the past few years, the conversation about employees using AI tools without IT's knowledge was framed as a security issue: data leaking into a public model, sensitive documents pasted into a chat window, credentials exposed. That risk hasn't gone away. But it's no longer the main one. The new risk is that a regulator, an auditor, or a client asks you to demonstrate how an AI-assisted decision was made, and you have nothing to show.
Why "we use AI responsibly" is no longer enough
Under the AI Act, AI systems used in contexts that affect people's rights, employment, credit, insurance, or similar high-stakes decisions are subject to documentation and traceability obligations. But the practical effect reaches further than the legal text suggests, because the burden of proof sits with the company, not the regulator. It's not enough to have a sensible internal policy about AI use. You need to be able to produce, on request, a record of what system was used, on what data, with what human oversight, and what the outcome was.
That's a different discipline than "managing AI risk." Managing risk means having guardrails so things don't go wrong. Managing proof means having a paper trail so that when something is questioned, you can answer in minutes instead of weeks. Most PMEs have the first, informally. Almost none have the second.
The gap shows up fastest in shadow AI use: the AI-generated email drafts feeding into HR decisions, the AI-assisted risk scoring in a spreadsheet nobody labeled as a model, the AI summary that shaped a board recommendation. None of it was hidden maliciously. It just wasn't treated as something that needed a record, because until now, nobody asked for one.
What impact documentation actually means in practice
Impact documentation isn't a compliance binder gathering dust. Done right, it's a lightweight, repeatable log attached to any AI-assisted decision that could be scrutinized later: hiring, pricing, credit, performance evaluation, content published under your name. For each one, you want to be able to answer four questions without digging: which system was used, what input it received, what human validated the output, and what the final decision was based on.
The mistake most companies make is trying to solve this with a policy document instead of a workflow. A policy says "employees must disclose AI use." A workflow makes disclosure the path of least resistance, built into the tool or the approval step, so it happens by default rather than by memory.
Where to start this month
- Map where AI currently touches decisions with real consequences — hiring, pricing, credit, contracts, performance reviews — not every use of a chatbot for drafting an email.
- For each of those, define the minimum record: system used, input data, human reviewer, date, and final decision. Keep it to one line if you can.
- Assign ownership of the log to the person who already owns the decision, not to a separate compliance function nobody consults in real time.
- Test it by picking one closed decision from last month and trying to reconstruct it. If you can't, the gap is real and it's where you start.
- Set a review cadence — quarterly is enough for most PMEs — to check the log is actually being filled, not just designed.
What to watch to know it's working
The test isn't whether you have a policy on paper. It's whether you can pull up, for any AI-assisted decision from the last quarter, a record of what happened and who signed off on it — in under ten minutes, without asking three people to remember. If that reconstruction takes a search through Slack messages and someone's memory, the documentation isn't working yet, regardless of what the policy says. Track how long that reconstruction takes each time you test it. When it drops to minutes and stays there, you've turned a compliance obligation into an operational habit — which is the only version of it that survives contact with a real audit.
Find Where Your Decision Trail Fails
ArkonLabs designs the logging and approval steps that make AI-assisted decisions traceable by default, built into your existing tools rather than bolted on as a separate compliance layer. If you want to know where your own decision trail would fail a reconstruction test, reach out at www.arkon-labs.com.