EU AI Act update, 8 May 2026: current law remains the baseline. The Digital Omnibus provisional agreement would move many high-risk AI obligations to 2 Dec 2027 and product-integrated high-risk AI rules to 2 Aug 2028 if formally adopted. Track status EU AI Act update: current law remains the baseline. Digital Omnibus dates apply only if formally adopted. Track status
Shadow AI evidence starter

Shadow AI Discovery Questionnaire and Remediation Tracker

You cannot govern AI tools you have not found. Use this questionnaire and tracker to identify unsanctioned AI use, map data exposure, record vendor status, and assign remediation owners.

Free XLSX workbook · No login · Review-only page

Download the Shadow AI tracker

Professional XLSX worksheet with dashboard, working tabs, lookups, sources, and review notes.

Use it before approval

This is designed to create the first structured evidence file before legal, privacy, risk, security, or management review.

What is inside the workbook

When to use it

  • quarterly shadow AI discovery
  • business-unit interviews
  • procurement cleanup
  • AI inventory preparation

Boundary

This is a practical starter. It is not legal advice, a certification, or a guarantee of EU AI Act compliance. Treat the output as a structured evidence file for qualified review.

Related EU AI Compass tools and guides

FAQ

Is this an employee monitoring template?

No. It is designed for governance discovery. Use lawful, proportionate methods and involve HR or legal before any employee-monitoring activity.

Should discovered tools be blocked immediately?

Not always. Some tools should be blocked; others may need controlled approval, migration, or vendor due diligence. The tracker is built to record the decision path.

Source basis

Source basis: Regulation (EU) 2024/1689; European Commission AI Act resources and Service Desk timeline; and official European Commission, European Parliament, and Council Digital Omnibus communications where relevant.

Use note: This page is educational only and is not legal advice, a conformity assessment, or a compliance guarantee.