Your biggest AI risk is not the model your security team evaluated and signed off. It is the free ChatGPT account an employee opened this morning, the Copilot tab that logged into a personal environment, and the AI feature your CRM switched on last quarter without asking.
The AI that does the work in your organisation is not the one you approved
This is Shadow AI, and it is spreading faster than any policy can keep up with. Every organisation reading this uses SaaS tools that have deployed AI features in the last two years. Most of those features route data somewhere you have not inspected, under terms you have not read. Some of that data trains models you will never control, embedded there permanently.
And even the AI you did approve may not be as sovereign as you think. The compute behind your licensed models often sits outside Europe, so your prompts and responses can travel across the Atlantic for lower latency. Governments have already moved to cut off access to specific models. If your workflows depend on a single frontier model, this is not a hypothetical risk to your continuity. It is a real one.
This article explains what Shadow AI is, the three risks it creates, and the layered controls that bring it back under management. Then we tackle AI sovereignty: what it means and why the rise of open-weight models is one of the clearest opportunities Europe has.
What this article covers
- What is Shadow AI
- The three real risks
- The layered controls that work
- Why 100% protection does not exist
- What AI sovereignty means beyond data residency
- Why the ability to switch models matters most
- Why open-weight models are an opportunity
What Shadow AI is, and why it is not Shadow IT
You already understand Shadow IT. It is the devices and infrastructure running inside your organisation that you do not know about, and therefore cannot protect. Shadow AI is the same challenge, moved into a new layer.
We define it as the unsanctioned use of any AI. That includes the obvious case, an employee using ChatGPT on a personal account, and the far less obvious one, a Salesforce or HubSpot instance with AI features enabled that no one approved. The first is visible if you look. The second hides inside tools you already trust.
Video 1. Your data ends up in the model forever
The three risks Shadow AI creates
Data leaks and breaches
Some AI vendors use the data you type into the prompt to train their models. When this happens, your input, which may be sensitive, ends up embedded in the model itself, effectively forever. If you do not know which models your people use, you cannot know where your data ends up.
Reputational damage
AI models hallucinate. They also carry the guardrails, ethical standards, and cultural assumptions of whoever built them, and models now come from every regime and jurisdiction on earth.
Compliance exposure
For a European organisation, this is about trust and accountability. Frameworks like NIS2 require you to understand and stand behind your supply chain. Shadow AI is an unmanaged part of that supply chain by definition. If you cannot see it, you cannot govern it.
The controls that work
Video 2. Three layers to control Shadow AI in your organisation
There is no single tool that solves Shadow AI. This is a new field, and CISOs are managing it with a set of point solutions and a layered approach. Here is what Eye Security recommends, and what each layer does and does not cover.
DNS blocking
DNS is how a name like chatgpt.com resolves to an IP address. Larger organisations can block those requests so the name does not resolve, or redirects to a landing page explaining why access is blocked. It is the same mechanism schools once used to block gaming sites. It is effective, but it is relatively complex to set up correctly, so it is not realistic for every organisation.
Browser extensions
Most AI and agentic activity happens in the browser, which makes the browser the natural place to control it. Commercial extensions can block domains and add a useful layer of defence. They share one significant gap: mobile phones and tablets.
The personal-account problem
Here is a situation almost every organisation faces. You hold a commercial ChatGPT or Copilot licence, so you do not want to block the tool outright. But employees still use it on personal or unauthenticated accounts, where their data trains the models and they often do not even realise it. Many vendors serve free and corporate use from different domains, so you can block the free domain. ChatGPT currently does not, which means you cannot block personal, signed-out use by domain alone. Every CISO should investigate exactly how each of their AI vendors handles this.
This is the specific gap we built a tool to close. Our research team developed a free browser extension, AI Leak Block, after hearing this same question from customers repeatedly over six months. It deploys on Edge and Chrome, supports around twelve AI tools today, targets precisely the personal and free-tier use case, and guides the user to the properly governed AI tool your organisation has approved. It is available free in the Chrome Web Store, and you can start using it right away.

Microsoft Purview
Because browser extensions do not cover mobile, you need another layer. Purview, Microsoft's compliance centre, is widely used across Europe. With the right licences you can encrypt and label your Office documents, PDFs, and emails by default. An encrypted file is unreadable to any AI agent it is uploaded into, so it simply cannot be ingested. If a user decrypts files to get around this, that becomes an event you can detect and act on. The honest limitation: the same encryption also blocks the legitimate AI tools you do want to use, so this is one layer, not a complete answer.
SaaS governance
Assume every SaaS tool you run has added AI features. Vendors have a strong incentive to build them in. These features are usually disabled by default, but more vendors are enabling them by default on an opt-out basis. So list your SaaS tools, check the settings regularly, and challenge the vendor directly. Ask which models they use, where those models run, and whether that is inside Europe. Ask what guardrails you can control. If you are not satisfied, opt out. Most SaaS AI features allow it.
One quick win for identification
If you run Microsoft or Google Workspace, check your logs. Users who signed into an AI tool with their corporate account, even on a free tier, leave a trace. In Entra ID you can list many of those users in a few clicks. The point is not to shame anyone. It is to get in control of a new field with new risks.
And that is the right expectation to set. You cannot fix Shadow AI completely. 100% protection does not exist, just as 100% security never has. What you can do is implement layered defences that match your risk appetite and bring Shadow AI under the same kind of management you already apply to Shadow IT.
AI sovereignty is not what you probably think it is
Video 3. AI sovereignty means the ability to switch
Sovereignty is as new a discipline as Shadow AI, and it is widely misunderstood. Most people reduce it to data residency, the question of where your data sits. This matters, and keeping models, chats, prompts, and agentic flows inside Europe is relatively straightforward. But it is not the whole picture.
The harder challenge is compute. Frontier models need enormous amounts of it, which is why data centres full of expensive GPUs are being built worldwide. Limiting all of that compute to a single region like Europe is difficult for the vendors and hosters involved. So even under the ChatGPT or Claude licences you hold today, a great deal of compute probably still happens outside Europe.
The reason is latency. Every AI vendor wants to be the fastest, and the US simply has the most compute. So there is a fair chance that both your prompts and the model's responses are processed in the US. Restricting yourself to European servers can increase latency, which is exactly the trade-off buried in the contracts.
The capability that matters: the ability to switch
Here is our core position. Sovereignty is the ability to switch models when you need to, ideally within minutes.
Being locked into a single AI model or vendor can hurt you eventually. As you adopt AI across your organisation, more of your workflows and agents come to depend on a specific model running on a specific vendor's tokens. If that model moves to a different jurisdiction, changes its terms, or gets banned tomorrow, your continuity is at risk. This is not theoretical. We have already seen administrations move to cut off access to specific models. An organisation that has wired all of its workflows into one frontier model has no answer to that.
The good news is that switching is already possible. At Eye Security, we use frontier models ourselves, in a sovereign way, inside Europe. What makes it sovereign is not avoiding those models. It is that we can switch away from them within months if a ban or another change forces our hand, and we continuously monitor the alternatives so we are ready.
Why open-weight models are Europe's opportunity
Video 4. Being locked into one model will hurt you eventually
Today, the best models are commercial, driven mainly by OpenAI and Anthropic, with Microsoft's Copilot alongside them and Mistral flying the European flag. This will not stay fixed.
The clearest shift is the rapid rise in quality of open-weight models. These are effectively open-source models that anyone can download and run on their own infrastructure, with no licence fee. Models like Kimi are improving fast, and our assessment is that within six months they will rival the frontier models. They are not there yet, for several reasons, but they are improving faster than the alternatives.
This is an opportunity. Anyone can run these models without limits, and crucially, no data leaves for another environment or jurisdiction. Hosting an open-weight model yourself is fundamentally different from using a hosted DeepSeek endpoint. For European hyperscalers that own the infrastructure and the GPUs, running open-weight models here, properly segmented, is the path to sovereignty. When a foreign government wants access to a model or wants it banned, they have none. This is significant because, under the US Cloud Act, US companies can always be compelled to hand over access or data. You do not want your defences to depend on that.
The takeaways
Two conclusions. First, you cannot fix Shadow AI completely, but you can bring it under control with layered defences. And you can start today, including with our free browser extension. Second, AI sovereignty is not a setting you switch on in a year. It is a capability you build now. Use frontier models if they serve you, but do not wire your entire organisation into a single one. Stay ready to switch, for cost reasons, or security reasons, or the next ban. This readiness is one of the strongest positions any European organisation can hold.
Frequently asked questions
What is Shadow AI?
Shadow AI is the unsanctioned use of any AI inside your organisation. It ranges from employees using ChatGPT on personal accounts to AI features quietly enabled in SaaS tools like your CRM. Like Shadow IT, it is a risk precisely because you cannot see it.
Why is Shadow AI a risk?
It creates three main risks. Data leaks, because some vendors train their models on what you type in. Reputational damage, because models hallucinate and carry the assumptions of whoever built them. And compliance exposure, because unmanaged AI is an ungoverned part of your supply chain under frameworks like NIS2.
Can I block employees from using AI on personal accounts?
Sometimes. Many vendors serve free and corporate use from different domains, so you can block the free domain. ChatGPT currently does not, so you cannot block signed-out personal use by domain alone. A browser extension such as our free AI Leak Block is designed to close this specific gap.
Can I stop Shadow AI completely?
No. 100% percent protection does not exist, just as complete security never has. The realistic goal is layered defence: DNS blocking, browser extensions, encryption through Purview, and active SaaS governance, matched to your risk appetite.
What is AI sovereignty?
It goes beyond where your data is stored. True sovereignty is the ability to switch models quickly when cost, security, or a jurisdictional change requires it, without your workflows collapsing because they were locked into a single vendor.
Why do open-weight models matter for Europe?
They can be downloaded and run on your own infrastructure with no data leaving your environment and no licence lock-in. As their quality catches up with the frontier models, they give European hyperscalers a genuine path to sovereignty, outside the reach of foreign governments and the US Cloud Act, under which US companies can be compelled to hand over access or data.