Many organisations believe they are not yet using artificial intelligence. In reality, they are often already using it without having identified it. This article explains why AI is frequently present without being named, why this is a risky blind spot, and how to address it through a simple first step: an inventory of uses.
Because AI almost never comes with a label.
It installs itself inside tools that we use for something else: an advertising platform, recruitment software, customer service, a spreadsheet enhanced with automated functions. The organisation buys a feature, not «AI», and does not always realise that this feature relies on a machine learning model.
Online advertising is the most striking example. Audience targeting, automated bidding, segment creation or campaign optimisation frequently rely on predictive models. An organisation that is «simply doing advertising» is therefore, in many cases, using AI without having explicitly decided to do so.
The same observation can be applied to many professions:
AI has thus integrated into everyday tools without always becoming visible in internal governance processes.
An unidentified AI system risks bypassing standard assessment, compliance and safety processes.
Those responsible for data protection, cybersecurity, risk or compliance can only intervene effectively if they know where and how AI is being used.
In the absence of visibility, several questions may remain unanswered:
These questions may fall under the General Data Protection Regulation (GDPR), the European Artificial Intelligence Act (AI Act), contractual requirements or, more broadly, the organisation's risk management.
Not all uses of AI present the same level of risk or are subject to the same obligations. However, no serious analysis is possible until the systems in question have been identified.
Blind spots often appear at the time of an incident, a claim, an audit or an inspection. At this stage, the organisation sometimes discovers that a system has long been influencing decisions or processing data without having been integrated into its governance arrangements.
No, and that is a frequent source of confusion.
A tool that applies a predefined rule, a model that produces a prediction and a system capable of triggering an action do not work in the same way. Nor do they present the same risks.
It is therefore important to distinguish in particular between:
Using the term «AI» vaguely in a contract, audit or internal policy gives the impression of addressing the subject without specifying what one is actually trying to control.
Before it can govern AI, an organisation must therefore define the scope of its analysis and distinguish uses according to how they operate, their purpose and their impact.
This clarification is not a purely theoretical exercise. It makes it possible to concentrate compliance, security and control efforts on the uses that genuinely create new risks.
The first step of a serious approach is not to write a charter or buy a new tool. It is to carry out an honest inventory of the AI uses already present in the organisation. Concretely, this inventory answers a few simple questions for each system:
Which tools or processes rely on AI models, including within software purchased for other functions?
What data do these systems rely on, and does this data include personal data?
What decisions do these systems make or influence, and do these decisions affect people?
How far can these systems act without human validation?
Who in the organisation is responsible for this?
Answering these questions reveals the reality of usage, including that which was previously invisible, such as shadow AI (AI tools used by teams without approval) or AI embedded in suppliers' services. It is from this mapping that everything else becomes possible: assessing risks, checking compliance, and clarifying responsibilities.
Two categories of usage deserve particular attention.
The first is the Shadow AI, that is to say the use of AI tools by employees or teams without official validation from the organisation. This can include, for example, the use of a public generative service to process professional information.
The second is the’Edge AI in supplier products. In this case, the tool was indeed purchased or authorised, but some of its AI-based functions were not listed separately.
These two situations create different blind spots. Shadow AI raises issues regarding authorisation, confidentiality and security in particular. Embedded AI raises more questions about supplier transparency, contractual responsibilities and the evolution of the proposed features.
A useful inventory must cover both.
An unidentified AI system risks bypassing standard assessment, compliance and safety processes.
Those responsible for data protection, cybersecurity, risk or compliance can only intervene effectively if they know where and how AI is being used.
In the absence of visibility, several questions may remain unanswered:
These questions may fall under the General Data Protection Regulation (GDPR), the European Artificial Intelligence Act (AI Act), contractual requirements or, more broadly, the organisation's risk management.
Not all uses of AI present the same level of risk or are subject to the same obligations. However, no serious analysis is possible until the systems in question have been identified.
Blind spots often appear at the time of an incident, a claim, an audit or an inspection. At this stage, the organisation sometimes discovers that a system has long been influencing decisions or processing data without having been integrated into its governance arrangements.
The risk is not simply using AI. It is using it without knowing precisely where it intervenes, what data it processes, what decisions it influences and who is accountable for it.
Organisations that map their usage give themselves the means to act in an informed manner. They can better protect their data, comply with their obligations, clarify responsibilities and detect situations that require enhanced monitoring.
The first step is not necessarily technical or costly. It consists of looking honestly at what the organisation is already using and naming it precisely.
For you cannot control what you have not defined.
By carrying out an inventory of use cases. AI is often integrated into tools bought for other functions: advertising platforms, recruitment software, customer services, analysis tools. Reviewing these tools and asking their suppliers if they rely on AI models makes it possible to reveal previously invisible uses.
Because unrecognised usage escapes all evaluation: its risks, its biases, its compliance with the GDPR and the AI Act are not verified. It may process personal data or influence decisions without oversight. These blind spots often come to light at the time of an incident or an audit, which is too late.
Frequently. Audience targeting, automated bidding, segment creation and campaign optimisation often rely on predictive models and machine learning systems. An organisation that advertises online is therefore likely to be using AI, even without having explicitly decided to do so.
It is a structured inventory of the AI systems present within an organisation. For each one, it specifies the tools involved, the data used, the decisions made or influenced, the degree of autonomy of the system and the person responsible. It forms the basis of any AI governance initiative.
Shadow AI refers to AI tools used by teams without official authorisation from the organisation. These practices bypass compliance and security controls, and can expose the organisation to unmanaged risks – particularly regarding the processing of personal data.
Yes. The term «AI» covers very different realities, from simple automation tools to systems capable of acting autonomously. Without a clear definition, it is impossible to concentrate compliance efforts where the risks are real.
Through a structured inventory of existing use cases. This involves identifying the tools concerned, the data they process, the decisions they influence, their level of autonomy and the people responsible for them. This inventory forms the basis of any AI governance approach.
We use cookies to improve your experience. Some features may not work without them. Manage your preferences.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper functioning of the website.
You will find more information in our...Cookie Policy and Terms & Conditions of Sale.