Montro
NIS2 & GDPR10 min read

How Shadow AI Discovery Supports GDPR RoPA: The Missing Entry Is Already the Breach

How Shadow AI Discovery Supports GDPR RoPA: The Missing Entry Is Already the Breach
AuthorAnkur Arora
Published on18 Sept 2026

Most conversations about shadow AI treat it as a risk waiting to happen - an unapproved tool that might leak data, might train on something it shouldn't, might cause a problem later. That framing is comforting, because it puts the harm in the future. For a Record of Processing Activities, it is also wrong.

 

Under GDPR, an AI tool processing personal data that is not in your RoPA is not a risk of non-compliance. It is non-compliance, already, the moment it exists. The record is supposed to account for every processing activity, and one it does not know about is a gap in the account - not a future event, a present fact.

 

Why the missing entry is the breach, not the risk

 

Two provisions make this true together.

 

Article 5(2) - the accountability principle, requires that a controller be able to demonstrate compliance at any time. Article 30 requires a record of all processing activities. Put those together and an undocumented processing activity is not a security exposure that may or may not turn into a problem. It is a standing failure to demonstrate compliance, present from the moment the processing begins.

 

This is a different kind of problem from a data breach. A breach is an event - something happens, and you respond. An incomplete RoPA is a condition: it sits there, quietly non-compliant, for as long as the undiscovered tool keeps processing. Nothing has to go wrong for it to be a breach; it already is one.

 

That distinction matters because it changes what "getting ahead of shadow AI" means. You are not trying to prevent a future incident. You are trying to close a gap that is already open.

 

Why it gets worse when someone looks

 

The cost of an incomplete RoPA is not fixed. It escalates sharply the moment a regulator is involved, and not in the way most people expect.

 

A supervisory authority investigating a complaint does not only examine the specific processing the complaint is about. It looks at the governance around it: the records, the accountability framework, whether the organisation is in control of its data generally.

 

An incomplete RoPA discovered at that moment does not read as one missing row. It reads as evidence that the organisation does not know what it does with personal data, which is exactly the conclusion an investigation is trying to reach.

 

So a single undiscovered AI tool can do disproportionate damage. It is not just one unrecorded activity; it is a demonstration, handed to a regulator, that the record cannot be trusted. The fine assessment for the original complaint is made in that light.


Why discovery is the part that makes the record true

 

Here is where discovery earns its place, and it is not as an add-on. A RoPA is only an accurate record if it contains every processing activity. Completeness is not a nice-to-have property of the record; it is the property that makes it a record at all rather than a partial guess.

 

For most processing, completeness is manageable - the activities came through procurement, they have owners, they are known. Shadow AI is the category that defeats it.

 

An AI feature switched on inside an existing platform, a model wired into a workflow, an automation a team built to save time, these process personal data without ever announcing themselves to whoever maintains the record. They are the activities most likely to be missing, precisely because nobody decided to add them.

 

Discovery is the mechanism that closes that gap. It finds the processing that did not come through the front door - the AI tools operating below the level of procurement, contracts and tickets, and surfaces each one so it can be assessed and recorded.

 

Without discovery, the RoPA documents the processing the organisation already knew about, which is the processing least likely to be the problem. With it, the record has a chance of being what Article 30 actually asks for: complete.

 

That is the real relationship between shadow AI discovery and the RoPA. Discovery does not "support" the record in the way a helpful tool supports a task. It is the difference between a record that is true and one that is merely tidy.

 

From discovered tool to defensible entry

 

Finding the tool is the start, not the finish. A discovered AI tool has to become a proper Article 30 entry: its purpose, the categories of data and data subjects, the recipients, the retention, the lawful basis it relies on.

 

That last one is where discovery pays off most, because an undiscovered tool is almost always operating with no lawful basis assessed at all - not the wrong basis, no basis, because no one ever asked the question.

 

This is also the honest limit. Discovery surfaces the tool; it does not decide, on its own, what the tool's lawful basis is or how long its data should be kept. That judgement is a person's work, informed by what discovery puts in front of them.

 

What discovery changes is that the judgement can be made at all, you cannot assess the lawful basis of a processing activity you have never seen. The record becomes true in two steps: discovery makes the activity visible, and judgement makes the entry defensible. Skip the first and the second never happens.


This is the gap I started Montro to close: the one that is already open before anyone notices it, and costs the most at the moment they do. 


Frequently asked questions

 

Is shadow AI a GDPR breach even if nothing goes wrong?

 

Montro's position is that it can be, independently of any incident. Under Article 5(2) a controller must be able to demonstrate compliance at any time, and under Article 30 must maintain a record of all processing activities.

 

An AI tool processing personal data outside the RoPA means the organisation cannot fully demonstrate compliance, which is a standing gap regardless of whether the tool ever causes a leak. The missing record is itself the problem.

 

How does shadow AI discovery help with a RoPA?

 

A RoPA is only accurate if it captures every processing activity, and shadow AI is the category most likely to be missing, tools that process personal data without going through procurement or review. Discovery finds those tools and surfaces them so each can be recorded as an Article 30 activity. Without it, the RoPA documents only the processing already known, leaving the least-visible and often highest-risk activities off the record entirely.

 

What happens if a regulator finds an incomplete RoPA?

 

An incomplete RoPA found during an investigation tends to be read as more than a single omission. A supervisory authority examines the governance around a complaint, not only the complaint itself, and a record shown to be inaccurate signals that the organisation may not be in control of its data generally.

 

This can weigh on the wider assessment, which is why a small documentation gap can carry a cost out of proportion to its size.

 

Does discovering a shadow AI tool make it compliant?

 

No. Discovery makes the tool visible, which is the precondition for compliance, not compliance itself. Once found, the tool still has to be assessed, its lawful basis established, its purpose and retention decided, its entry added to the RoPA. Discovery ensures that work can happen; it does not do the work. An undiscovered tool, by contrast, gets none of that assessment, because no one knows it is there to assess.

Ankur Arora

Ankur Arora

Co-founder

Fifteen years of enterprise digital transformation across telecoms, media, consumer goods, and agriculture - and a front-row seat to AI adoption outpacing governance at every organisation he worked in. He built Montro so the next firm doesn't have to learn that lesson the hard way.

Blog

Read next

Explore more from our library

View all

Stay informed on EU AI governance

Monthly updates on regulatory changes, compliance trends, and platform releases

By subscribing you agree to our Terms and Conditions and Privacy Policy

Montro AI governance dashboard showing tool risk tiers