Most mid-size companies that have started paying attention to AI tool sprawl are thinking about it as a cost problem. Tools purchased outside procurement. Duplicate subscriptions. Licences nobody is using. Budget leaking through expense accounts faster than finance can track it.

The cost problem is real. But the compliance exposure that sits underneath it is larger, harder to see, and accumulates faster than the spend.

Every unsanctioned AI tool in a mid-size portfolio is not just an unbudgeted line item. It is a third-party tool processing company data under terms the company has never reviewed, in jurisdictions the company may never have considered, with no contract giving the company any rights if something goes wrong. In 2026, with AI-specific regulation now actively applying to SMEs and enforcement intensifying across data protection frameworks, that exposure has moved from theoretical to operational.

What Makes AI Tools a Distinct Compliance Risk

AI tools create a different compliance profile than standard SaaS tools, and the difference matters for how risk accumulates.

A standard SaaS tool is typically procured through a process that includes a contract, a data processing agreement, and at minimum some review of what data the tool will access. The procurement process itself is the compliance checkpoint, even if it is a lightweight one. When the tool arrives without that process, someone notices.

AI tools routinely bypass this checkpoint entirely. They arrive through personal expense accounts, free tiers, browser extensions, and API integrations that no procurement system is watching. And they carry a data handling characteristic that most SaaS tools do not: many AI tools use inputs to train or improve their models. When an employee pastes client data, financial projections, or source code into an AI tool to get a faster output, that data may be processed, stored, and used in ways that the company has no contractual visibility into and no right to control.

The absence of a data processing agreement is not a technicality. Under GDPR, any processing of personal data by a third party requires a DPA. Without one, the company has no documented record of what the vendor does with the data, no right to request deletion, and no notification obligation from the vendor if a breach occurs. That is the compliance baseline exposure on every unsanctioned AI tool in the portfolio.

Three Compliance Exposures Mid-Size Companies Are Carrying Right Now

GDPR and data processing agreements. The most widespread exposure is the simplest: AI tools in active use with no reviewed data processing agreement. Under GDPR, this is non-compliant by default for any tool processing personal data. IBM's 2025 Cost of a Data Breach Report found that incidents involving unsanctioned AI tools cost an average of $670,000 more than standard data breaches, and that one in five organisations has already experienced a breach tied to unsanctioned AI tool usage. The DPA gap is not a future risk; it is a current one.

EU AI Act applicability. The EU AI Act classifies AI systems by risk level, and many of the AI tools already common in mid-size company operations sit in the high-risk category: AI tools used in HR decisions, financial risk assessment, medical diagnosis support, and similar functions carry conformity assessment, transparency, and human oversight obligations. The Act now applies to SMEs operating within the EU or processing EU citizen data. Mid-size companies in software, healthcare, and financial services need to assess whether their current AI tool deployments trigger these obligations, because the Act does not exempt companies based on size.

Sector-specific frameworks. HIPAA applies to any AI tool that processes protected health information. A clinician using an AI summarisation tool to draft patient notes is potentially creating HIPAA exposure if that tool has not been assessed and contracted. PCI DSS applies to tools that access or store payment card data. In each regulated sector, the AI tool enters the compliance scope the moment it touches regulated data, regardless of whether anyone intended it to.

Why AI Tools Move Faster Than Compliance Processes

The compliance gap is not primarily a policy failure. It is a speed mismatch.

According to UpGuard's 2025 State of Unsanctioned AI Tools Report, 81% of workers now use AI tools their organisation has not approved. IBM's research found that only 37% of organisations have any policy in place to manage or detect unsanctioned AI tool usage. These figures reflect a structural problem: the pace at which employees adopt AI tools for legitimate work purposes has outrun the pace at which compliance processes were designed to operate.

A standard SaaS procurement review takes weeks. An employee can adopt an AI tool, start using it for client-facing work, and be processing sensitive data through it within a day. Free tiers that convert to paid plans after a usage threshold do not generate a purchase order. API integrations that pull company data into an AI tool may not generate any visible event at all.

The result is a compliance exposure that accumulates continuously, invisibly, and without any of the usual signals that trigger a review. Tools are not assessed at onboarding because they were never onboarded. They are not reviewed at renewal because they were never contracted. And they are not caught by expense management reviews until the spend is already large enough to notice, well after the compliance clock started running.

The Governance Gap Is Widest at Mid-Market Scale

Mid-size companies are not simply smaller versions of enterprises with the same governance infrastructure at reduced scale. The governance gap between mid-market and enterprise in the AI tool category is structural.

Grant Thornton's 2026 mid-market research found that 19% of mid-market companies have no formal AI governance approach at all, compared to 8% at enterprise level. Enterprise organisations with dedicated GRC functions, legal teams, and security operations centres have the infrastructure to detect and respond to ungoverned AI tool adoption as it happens. Mid-size companies typically do not.

At the same time, mid-size companies face the same regulatory obligations. The EU AI Act does not scale its requirements to company size for high-risk AI systems. GDPR fines are proportional to revenue, which means a mid-size company faces proportionally equivalent financial exposure to an enterprise for the same DPA failure. And Gartner projects that AI regulation will cover 75% of global economies by 2030, meaning the regulatory environment will continue tightening regardless of company size.

The gap between governance infrastructure and regulatory obligation is the specific risk mid-size companies carry that enterprises have already begun to close.

See What AI Tools Are Running Without a Reviewed Contract in Your Organisation

CostRoom maps every active AI, SaaS, and cloud tool across your portfolio, identifies what is processing company data without a formal contract or DPA, and delivers a prioritised action plan for compliance and spend.

Book a Demo

What Compliance-Ready AI Tool Management Looks Like

Reducing AI tool compliance risk does not require a dedicated compliance officer or a multi-month governance programme. The baseline that closes the most critical exposures is achievable in three steps.

Step 1: Build the AI tool inventory. Compliance starts with knowing what is in use. Reconciling finance, IT, and expense management data surfaces every active AI tool, including the ones that arrived without any procurement process. The inventory immediately identifies which tools are processing sensitive data without a DPA on record. These are the highest-priority items for remediation. For how to structure this reconciliation and what it typically surfaces, see AI Tool Governance for Mid-Size Companies: Managing Spend, Risk, and Compliance Together.

Step 2: Review data processing agreements for active tools. For every AI tool processing personal data, confirm whether a reviewed DPA exists. Where it does not, the options are to obtain and review one, restrict the tool's data access until a DPA is in place, or discontinue the tool. The review does not need to be exhaustive for every tool simultaneously. Tiering by data sensitivity and usage volume makes the remediation workload manageable.

Step 3: Communicate an acceptable use policy. Employees using AI tools for legitimate work purposes are not acting in bad faith. They are acting without guidance. A one-page policy that defines what data can and cannot be input into AI tools, which tools are currently approved, and how to request approval for a new tool closes the most common source of ongoing exposure. IBM's research found only 37% of organisations have any such policy. Having one places a company in the better-governed minority immediately.

For how vendor risk assessment connects to the DPA review process, see What Is a SaaS Vendor Risk Assessment and How Does It Work?. For the full AI tool governance framework that these three steps feed into, see AI Tool Governance for Mid-Size Companies. For the cost management side of the same AI tool portfolio, see Why AI Tools Are Becoming Mid-Size Companies' Fastest-Growing Unmanaged Spend.

CostRoom's Spend Analysis and Optimisation delivers the AI software inventory and contract compliance review as an integrated engagement, covering both the spend and the compliance dimension of an ungoverned AI portfolio simultaneously.

Find Out Where Your AI Compliance Exposure Sits

CostRoom identifies every active AI tool in your portfolio, maps the DPA and contract gaps, and delivers a prioritised remediation plan for spend and compliance together.

Book a Demo

Frequently Asked Questions

What is AI tool compliance risk?

AI tool compliance risk is the regulatory and legal exposure a company carries when AI tools in active use have not been formally reviewed, contracted, or assessed for data handling compliance. The primary exposures are: data processing agreements missing for tools handling personal data (a GDPR requirement), AI tools that may fall into high-risk categories under the EU AI Act, and sector-specific obligations under HIPAA or PCI DSS for tools processing regulated data. The risk accumulates for every AI tool that enters through expense accounts or department budgets without a formal review process.

Does the EU AI Act apply to mid-size companies?

Yes. The EU AI Act applies to any company operating within the EU or processing EU citizen data that uses AI systems classified as high-risk. High-risk categories include AI tools used in HR decisions, financial risk assessment, medical diagnosis support, and critical infrastructure management. The Act does not provide a blanket exemption for SMEs using high-risk systems. Mid-size companies in software, healthcare, and financial services should assess their current AI tool portfolios against the high-risk classification criteria, as obligations include conformity assessments, transparency requirements, and human oversight mechanisms.

What happens if an employee uses an AI tool without a contract in place?

When an employee uses an AI tool without a formal contract, the company typically has no data processing agreement in place, meaning there is no documented record of how the vendor handles company data, no right to request deletion, and no vendor notification obligation if a breach occurs. IBM's 2025 research found that incidents involving unsanctioned AI tools cost an average of $670,000 more than standard data breaches. Under GDPR, using a third-party tool to process personal data without a DPA is non-compliant by default, regardless of whether the tool was adopted intentionally or informally.

How do you reduce AI tool compliance risk without a dedicated compliance team?

The baseline reduction is achievable in three steps: build an AI software inventory by reconciling finance, IT, and expense management data; review data processing agreements for every active tool processing personal data, starting with the highest-risk items; and communicate a one-page acceptable use policy defining what data can be shared with AI tools and how to request approval for new ones. This three-step baseline closes the most critical exposures without requiring a dedicated compliance function. For the full governance framework these steps feed into, see the guide on AI Tool Governance for Mid-Size Companies.