An approval process is not bureaucracy. It is the opposite of it: one rule replacing a hundred separate decisions. It is also the only effective remedy for shadow AI — provided it is faster than the route around it.
By Patrick de Kathen, Founder of KlarComply · Reviewed on
Many companies start with a list of permitted tools. That works for about four weeks. Then a new tool appears that somebody needs for their work, it is not on the list, and they use it anyway — because nobody knows who they would have asked.
A process answers three questions permanently. Who asks whom? On what basis is it decided? And how long does it take? Miss any one of those answers and shadow AI appears. The third is the one most often forgotten, and it is the most important.
Commit to a response time and keep to it. Ten working days is a workable figure; five is better. Anyone who waits more than three weeks for an answer will not submit a request next time. They will quietly open a personal account.
A process with no stated turnaround behaves, in practice, exactly like a ban — with the difference that you believe yourself to be covered.
A single full assessment for every tool creates a queue. Sort the requests first instead.
| Lane | What goes in it | Procedure |
|---|---|---|
| Blanket approval | AI features inside software already assessed, where no new data flows arise — for example drafting help inside the office suite you already run | a single decision in principle, an entry in the inventory, no individual requests |
| Short assessment | Tools with no personal data and no confidential content, for example image generators used for illustrations | steps 1, 2, 5 and 7 of the checklist, usually under thirty minutes |
| Full assessment | Anything involving personal data, customer records, pricing, applications, or a connection to internal systems | all seven steps, with data protection consulted |
What exactly is the tool for, and is there already an approved tool that does it? The second part resolves a surprising share of requests on its own. In many companies three tools run for the same task, because three departments went looking independently.
What data are to go in? Do not answer “text”. Answer in categories: customer names, contract data, application documents, pricing calculations, source code, health data. That answer determines whether lane two or lane three applies, and whether data protection has to be involved.
Is there a business tier? Is a data processing agreement offered? Who is the counterparty? Are inputs used to improve models, and can that be switched off? Where are the data held? The data protection side is set out on ChatGPT at work.
Can trade secrets end up in it? If so, confidentiality has to be assured contractually — otherwise you put at risk the requirement in Directive (EU) 2016/943 that the information be subject to reasonable steps under the circumstances to keep it secret. Check as well whether your customer contracts prohibit disclosure to third parties without consent. That clause appears in more contracts than most companies expect.
Prohibited practice, high-risk, transparency duty or minimal risk? What decides it is the purpose of use, not the tool. The same language model can be unremarkable for drafting text and high-risk for pre-sorting job applications. The method is on classifying AI risk. Record the class and the reasoning — the reasoning is the evidence.
Does the tool produce content that goes out into the world? Images, voices, video, chat replies? Then settle before approval who applies the disclosure and what it says. Ready-made labels in three languages are free on our AI labels page. The scope and the limits of the duty are on labelling under Article 50.
Who administers the accounts? What does it cost? What happens to the data if you cancel — and how do you get your content out? The exit part is almost always skipped and almost always surfaces eventually.
Clear allocation prevents endless loops. A model that holds up in companies between twenty and two hundred and fifty people:
| Role | Task in the approval process |
|---|---|
| Requester | completes the form, describes the purpose and the data categories |
| AI lead | runs the assessment, decides, records — see appointing an AI lead |
| Data protection | consulted in lane three, may object, does not decide |
| IT | checks integration, accounts, access rights |
| Management | decides where cost exceeds a defined threshold and on any high-risk classification |
| Employee representatives | involved where the tool is capable of monitoring conduct or performance — see AI and employee representation |
Any longer and it does not get filled in. One page, ideally a form on the intranet.
Field 5. Asking whether an approved tool already exists disposes of a substantial share of requests before any assessment is needed — and it saves licence costs that otherwise nobody notices.
Every decision goes into the AI inventory: tool, purpose, class, reasoning, date, decision-maker. Refused tools go in as well — otherwise the same request arrives again in six months and is assessed again from scratch.
Marketing wants to generate imagery. No personal data are involved and no confidential content. Lane two, short assessment. Only two points matter here: the rights of use in the generated images under the provider's terms, and the disclosure obligation as soon as the imagery becomes photorealistic. Approved on condition that every published image carries a disclosure. Processing time: half an hour.
Sales wants to record and summarise conversations. This is squarely lane three: personal data, recording of conversations, and the possibility of evaluating how someone conducts a call. To settle: the processor contract, the legal basis, consent of the other party to the recording, the retention period — and involvement of the employee representatives, where a body exists, because performance data can be derived from such recordings. Realistic processing time: two to four weeks. Tell the requester that on day one, not on day twenty.
A program you already run acquires an AI feature. The decisive point is not the feature. It is the question: does a new data flow to a different provider arise? If processing stays with the existing counterparty and within the existing terms, a decision in principle with an inventory entry is enough. If data now flow to a third-party model, it is a new tool and needs the full assessment — even though nobody installed anything.
Record the outcome in exactly this form. It is simultaneously your inventory entry and your answer in the next supplier questionnaire.
Approvals are not permanent. Consider withdrawing one where the provider changes its terms to your detriment, where a security incident becomes known, where the contractual basis falls away, or where the tool is simply no longer being used. The last of those is the most common and the easiest: unused licences cost money and enlarge the attack surface.
A withdrawal needs the same care as an approval: reasons, a date, notice to the users, and a statement of what they should use instead.
Whether the foundations for it are in place takes two minutes to check with the free quick check.
Add a single field to the form: will the output of this tool be seen by, sent to or acted on by people in the Union? Under Article 2 of the AI Act that is what brings a third-country deployer into scope, and it is the question you would otherwise have to reconstruct months later from memory. Asking it at the point of approval costs nothing and answers itself.
Not expressly. It is the most practical way to implement the deployer duties in the AI Act and the organisational measures required by Article 32 GDPR, and it is the most effective remedy for shadow AI. Supplier questionnaires now ask for it by name.
Commit to a turnaround and keep to it. Ten working days is workable, five is better. If it takes more than three weeks, people route around the process and open personal accounts. At that point you have moved the problem, not solved it.
No. Where an application already assessed acquires an AI feature and no new data flows arise, a single decision in principle with an inventory entry is enough. Where data now flow to a different provider, it is a new tool.
One named individual, normally the AI lead. Data protection and IT are consulted and may object but do not co-decide. Management decides on high cost and on any high-risk classification, and employee representatives are involved where the tool is capable of monitoring performance.
Send them back through the assessment retrospectively, with an express amnesty for the past. Without that assurance nothing gets reported and your stocktake stays incomplete. From a clearly stated date, the process applies.
In most companies, no. A one-page form and a spreadsheet carry you well past a hundred employees. A tool does not replace a clear allocation of responsibility or a turnaround you have committed to — and those are what processes fail on.
Tool, provider and contracting entity; the purpose in one sentence; the lane; data categories; whether a processor contract exists and from when; whether training use is disabled; the risk class with reasoning; whether a disclosure is required and who applies it; the decision with conditions, date and decision-maker; and the date of the next review.
The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.
Start the quick check — free