Shadow AI & the EU AI act: what changes
Shadow AI is already inside your organisation. The EU AI Act just made that a problem.
Banned ChatGPT at work? Chances are your team still uses it; on a personal account, on a phone, on data nobody logged. That's shadow AI: AI use that happens whether or not IT approved it, because the alternative someone was offered was slower than the tool they already knew.
For most organisations that's been a quiet compliance gap. From 2 August 2026, it stops being quiet.
What the EU AI act actually requires
The EU AI Act doesn't ban AI. It adds real obligations for high-risk use: logging of inputs & outputs, human oversight at the right points & auditability, being able to show, after the fact, what the system did & why.
That's hard to prove when the system in question is a colleague's personal ChatGPT tab. It's not much easier when it's a corporate AI subscription running on infrastructure you don't control either; you can see the invoice, not always the logs.
Local doesn't mean your own server room
The instinctive fix is "bring AI in-house." True, but it comes with a catch that stops a lot of organisations before they start: not everyone has a team to run GPU infrastructure, or the budget to buy it outright.
That's the part worth separating out. Sovereign AI means you control where your data goes, who can access it & what gets logged.
It doesn't require owning the hardware. A sovereign EU cloud environment such as Exoscale or IONOS gives you the same governance and the same jurisdiction, without the procurement cycle.
Either route, on your own infrastructure or on a managed EU cloud, gets you to the same place: logging, oversight & auditability you can actually demonstrate.