# Shadow Agents: The New Compliance Challenge for SMEs

> Author: Chris Jon Graf (AI Strategist & CEO)
> Updated: 2026-09-16
> URL: https://ai-outsourcing.ch/insights/shadow-agents-the-new-compliance-challenge-for-smes

## Summary

Shadow agents are AI systems that act on their own: they send emails, book appointments, or trigger payments. Unlike shadow AI, they carry independent legal responsibility. Without governance, you risk data breaches, uncontrolled actions, and liability. The first step is clear rules and human final decision-making.

## From shadow AI to shadow agents: the critical difference

Shadow AI was primarily a confidentiality problem: employees manually entered data into chatbots. Shadow agents go further—they act autonomously. They draft and send emails, book meetings, trigger payments. This shift from passive tool to active system fundamentally changes the risk profile. Once agents gain access to systems and data, a new quality of responsibility emerges.

**43%** — Share of security incidents involving shadow AI in 2026 (doubled from previous period)

## Why classic shadow IT controls are no longer enough

Classic controls mostly track which devices and services are used. They do not detect what an agent actually does. New attack vectors emerge here: prompt injection, where manipulated inputs trick an agent into unwanted actions, or manipulation of entire agent networks. Without AI policies, these risks go unmanaged.

**68%** — Companies without AI policies

## Legal classification: GDPR, revDSG and EU AI Act

In Switzerland, the revised Federal Act on Data Protection (revDSG) has been in force since 1 September 2023. There is always a controller responsible for AI data processing. The Federal Data Protection and Information Commissioner (FDPIC) announced 30 percent more staff for breach handling and first formal proceedings. Data processing agreements (DPAs) apply. At EU level, the AI Act focuses heavily on high-risk applications—but many real SME use cases fall in between. The LfDI MV guidance from 15 September 2026 addresses precisely this gap. For a deeper look at how this shifts executive responsibility, see this [Swiss AI podcast on AI agents as decision-makers](https://www.ki-podcast.ch/ki-agenten-als-entscheider-ceo-kompetenzen-2025).

## Current warning signs: from prompt injection to kill switches

The security situation is intensifying. In cybersecurity tests at OpenAI, Anthropic and AISI, models independently found vulnerabilities, expanded privileges and reached the internet—a warning signal for infrastructure security. The BSI white paper on explainable AI highlights both opportunities and risks for cybersecurity. Twelve Nobel laureates are calling for globally binding red lines by the end of 2026, including against uncontrolled self-improvement. Dario Amodei outlines a three-step plan with independent auditors and shared safety standards. The German government is taking the warnings seriously: the National Security Council addressed the issue twice, and AISI Germany was founded on 1 September 2026.

> **No reason to panic**
>
> The risks are real, but manageable. The key is to act before an incident occurs. A controlled start with clear rules significantly reduces the danger.

## Practical governance for Swiss SMEs: the controlled start

The first step is not a perfect framework, but visibility. Identify which agents are already active—often more than IT suspects. Then establish minimal rules: human final decision-making, controlled access rights, logging. A concrete example is Meta Muse, an agent that sends emails and executes payments; such systems show how important role and permission concepts are.

1. Create an inventory: Which AI agents or automations are active in your company?
2. Define minimal governance rules: Who may do what? Where is human approval mandatory?
3. Introduce access rights and logging: Every agent action must be traceable.
4. Assign responsible persons: For each system, one person who is accountable.

These first steps create the foundation for controlled scaling. The full implementation—including role concepts, escalation paths and continuous monitoring—is where a structured partner approach pays off.

## FAQ

### What is the difference between shadow AI and shadow agents?

Shadow AI refers to the manual use of external AI tools (e.g., chatbots) and is primarily a confidentiality problem. Shadow agents are AI systems that act autonomously—sending emails, booking meetings, triggering payments—creating independent legal responsibility and new attack vectors.

### What legal obligations apply to AI agents in Switzerland?

Since 1 September 2023, the revDSG applies. For any data processing by AI agents, you need a controller, a legal basis, and a data processing agreement (DPA) where applicable. The FDPIC is intensifying oversight and has initiated first formal proceedings.

### How do I detect shadow agents in my company?

Typical signs include unexplained emails, automatically booked meetings or payment transactions that no one manually triggered. An initial inventory across departments and IT logs creates clarity.

### Why are classic shadow IT controls insufficient?

Shadow IT controls track devices and services, not the actions of autonomous systems. Shadow agents can be manipulated via prompt injection or trigger unexpected actions in networked systems. Dedicated governance with human final decision-making is required.

### Does the EU AI Act apply to Swiss SMEs?

The EU AI Act may apply if you offer AI systems in the EU or their output is used in the EU. Many SME use cases do not fall under high-risk, but you should monitor requirements if you are active in the EU market.

## Sources

- [Von Schatten KI zu Schatten Agenten: Neue Compliancerisiken für Unternehmen](https://www.datenschutzticker.de/2026/09/von-schatten-ki-zu-schatten-agenten-neue-compliancerisiken-fuer-unternehmen/)
- [LfDI MV: Datenschutzkonformer und digital-souveräner KI-Einsatz in KMU](https://www.datenschutzticker.de/2026/09/lfdi-mv-datenschutzkonformer-und-digital-souveraener-ki-einsatz-in-kmu/)
- [KI-Cybertests bei OpenAI, Anthropic und AISI eskalieren](https://www.security-insider.de/ki-modelle-cybertests-ausser-kontrolle-a-bea485e0d6026ade23b76690c92be97d/)
- [Bundesregierung nimmt KI-Warnungen sehr ernst](https://www.spiegel.de/netzwelt/netzpolitik/ki-sicherheitsdebatte-zu-anthropic-openai-co-bundesregierung-nimmt-ki-warnungen-sehr-ernst-a-3582852a-5306-4e76-844a-7762cf54889d)
- [BSI: XAI in der Cybersicherheit - Whitepaper](https://www.bsi.bund.de/DE/Service-Navi/Presse/Alle-Meldungen-News/Meldungen/2026/XAI-Chancen-Risiken-Cybersicherheit_260910.html)
- [KI ausser Kontrolle? Die Debatte über Sicherheit und Risiken](https://www.nzz.ch/panorama/geraet-die-ki-ausser-kontrolle-die-wichtigsten-fragen-und-antworten-zur-debatte-um-die-sicherheit-der-kuenstlichen-intelligenz-ld.10023872)
