Shadow AI and Hidden Subprocessors: The Compliance Blind Spot Putting Organizations at Risk

Table of Contents

As organizations race to mature their AI governance programs, a quiet but serious gap is opening between the vendors they trust and the actual data processing happening behind the scenes. New research reveals that a majority of technology providers are failing to fully disclose the AI systems and subprocessors operating within their stacks—creating compliance exposure that many privacy and legal teams may not even see coming. The findings, paint a clear picture of an industry struggling to keep contractual transparency in step with the speed of AI adoption.

The Numbers That Should Worry Privacy Leaders

Examined data protection assessments from 2,400 popular business software providers that market AI capabilities. The results were striking:
  • 63.6% of third-party technology vendors failed to disclose subprocessing activity performed by another AI provider.
  • 32.8% of AI systems self-reported that they engage in high-risk processing of sensitive data or enable automated decision-making.
These are not edge cases. They represent the majority of the market. For organizations that treat data protection assessments as reliable sources of truth during vendor onboarding, the report raises an uncomfortable question: how much of what appears in a DPA can actually be trusted?

When Technology Moves Faster Than Legal Documents

A structural problem that is accelerating. Vendors are shipping new features and integrating additional AI capabilities at a pace that outstrips the ability of legal and product security teams to update contractual disclosures. In many cases, the primary vendor itself may not have full visibility into what its own downstream partners are doing with data. “Technology is moving very quickly and may be moving faster than the legal documents can keep up,” Barber explained. “Businesses are moving much faster than they were even 12 months ago. This is very challenging for product security teams and legal teams to keep up with the speed at which engineering can advance individual products.” The result is a growing inventory of “hidden” AI processing that never appears in the documents used for risk assessment and due diligence.

Shadow AI: From One-to-One to One-to-Many

Martin Woodward, Global Legal Director and Global Responsible AI Officer at Randstad, frames the issue as the natural evolution of shadow IT. Where traditional shadow IT typically involved a single unapproved tool, shadow AI introduces a more complex dynamic: a single employee or vendor relationship can quietly connect an organization to multiple AI systems. “In most IT relationships, it’s essentially a one-to-one relationship, whereas with shadow AI it can be a one-to-many relationship,” Woodward noted. That multiplicity makes detection and control significantly harder. Unlike cloud services, which can often be identified through network traffic analysis, AI components are frequently embedded, containerized, or accessed through APIs in ways that resist simple discovery. Under the EU AI Act, the distinction between provider and deployer carries different obligations. Organizations that unknowingly onboard AI systems through vendors or employee experimentation can find themselves in the deployer role—and subject to transparency and risk management requirements they never anticipated.

Legal Exposure Under GDPR and Beyond

Vincent Rezzouk-Hammachi, Partner at Bird & Bird and CIPP/US, highlighted the GDPR implications. In many cases, a third-party technology vendor’s processing activities can qualify it as a controller. Incomplete disclosure of subprocessors can therefore expose the vendor to enforcement risk before the customer organization faces penalties—provided the customer can demonstrate reasonable due diligence at the time of onboarding. Incomplete visibility also undermines the practical ability to fulfill data subject rights. Deletion and access requests become far more difficult to execute when organizations do not know every system that holds or processes personal data further down the chain. Rezzouk-Hammachi observed that many organizations still struggle to assign clear ownership of AI governance. Because AI touches so many functions, accountability can become fragmented and political, slowing the development of consistent review processes before contracts are signed.

Practical Controls That Actually Work

Experts interviewed for the original reporting outlined several approaches that organizations are using to reduce exposure:
  • Access controls and acceptable use policies that contractually restrict employees from using unauthorized AI tools.
  • Controlled experimentation environments that allow employees to test AI tools under defined safeguards rather than in the open corporate environment.
  • Screening and detection tooling capable of identifying non-mainstream or unauthorized AI processes running inside the organization.
  • Updated system inventories that capture not only direct vendors but also the subprocessors those vendors rely on.
John Bowman, AIGP, CIPP/E, CIPM, FIP, noted that mature organizations have had success by guiding employees toward approved tools inside secured environments rather than attempting to block every external option. Elena Maran, founder of Alethesis AI and AIGP, emphasized that smaller, more agile companies often find it easier to encourage structured experimentation, while larger enterprises with long vendor due-diligence cycles face greater inertia. Barber returned to a foundational recommendation: organizations need a living inventory of systems that reflects reality, not just the paperwork. “The historical method of scanning the DPA is not sufficient in 2026 if we know 63.6% of DPAs are not actually accurate. We need another mechanism to populate your inventory of systems in a better way.”

AI Compliance Teams Subprocessor Classification Issue

The combination of rapid AI feature releases, incomplete contractual disclosure, and the one-to-many nature of modern AI tooling creates a compliance environment that is more opaque than many organizations realize. Relying solely on vendor-provided data protection assessments is no longer a defensible posture. Privacy and legal teams that want to stay ahead of regulatory expectations—whether under the EU AI Act, the CCPA’s risk assessment requirements, or GDPR controller-processor rules—will need to treat subprocessor visibility as an active, ongoing process rather than a one-time contractual checkbox. The organizations that adapt fastest will be those that pair stronger contractual demands with technical discovery capabilities and clearer internal ownership of AI risk. Those that continue to treat DPAs as complete and reliable sources of truth are likely to discover the gaps only after a regulator, a data subject request, or a security incident forces the issue into the open.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.