Eversheds Sutherland warns of Shadow AI business risk in media
Eversheds Sutherland partner Laura Fannin discusses the legal and operational risks of 'Shadow AI' in corporate environments, emphasizing the need for rigorous due diligence and human oversight. The guidance highlights compliance requirements under the EU AI Act and Digital Services Act for businesses integrating AI tools.
Key Takeaways
- Eversheds Sutherland partner Laura Fannin identifies advertising and media as early adopters now facing significant IP and copyright uncertainty.
- The EU AI Act and Digital Services Act now require strict transparency for AI-driven chatbots and employee monitoring systems.
- Shadow AI occurs when staff input confidential client data or protected IP into external models without understanding data retention policies.
- Eversheds Sutherland has deployed Harvey, a specialized legal AI tool, to automate due diligence and document discovery with human oversight.
Why It Matters
The rise of unauthorized AI usage creates immediate legal exposure for streaming and media firms regarding copyright ownership of generated assets. As the EU AI Act enforces stricter transparency, companies must move beyond simple device blocking to establish formal governance structures that ring-fence sensitive data. In the broader ecosystem, this shift necessitates a transition from experimental tool usage to audited, enterprise-grade platforms to protect intellectual property. The industry must now reconcile the efficiency gains of automation with the non-negotiable requirement for human review to prevent algorithmic hallucinations. Watch for upcoming court rulings on whether AI-generated branding and advertising content qualifies for standard copyright protections.
Additional Context
The EU AI Act's phased enforcement timeline is forcing media and entertainment companies to formalize their AI governance structures well before full compliance deadlines arrive. In August 2025, the European Commission published its first set of guidelines on prohibited AI practices under the EU AI Act, clarifying that social scoring, emotion recognition in workplaces, and manipulative AI systems face outright bans. For streaming companies and content studios, the practical implication is that any employee using unauthorized generative tools to produce marketing copy, script drafts, or visual assets could inadvertently trigger compliance obligations that the organization has not yet mapped. Eversheds Sutherland's warning about Shadow AI sits directly within this regulatory window, where the gap between informal tool adoption and formal compliance frameworks creates measurable legal exposure.
Harvey, the AI legal platform mentioned in the source discussion, has become a reference point for how enterprise-grade AI tools differ from consumer alternatives in governance design. In early 2025, Harvey raised $300 million in a Series D round led by Sequoia Capital at a $3 billion valuation, signaling investor confidence that regulated industries will pay premiums for AI platforms with built-in audit trails, data isolation, and compliance logging. The contrast is stark: consumer tools like ChatGPT or Midjourney offer no enterprise data governance by default, while platforms like Harvey embed access controls and retention policies from the start. For media companies evaluating Shadow AI risk, the investment thesis around Harvey and similar vertical AI platforms suggests that the market is pricing in exactly the governance gap that Fannin describes.
Technical benchmarks and independent assessments are beginning to quantify the scale of unauthorized AI usage in corporate environments. A 2025 report from Gartner estimated that by 2027, 40% of enterprise AI projects will be canceled due to inadequate governance and risk management, citing unclear accountability, poor data quality controls, and escalating costs as primary failure modes. The Digital Services Act compounds this for streaming platforms specifically, since algorithmic recommendation systems used in content discovery fall under its transparency and risk-assessment requirements. Companies that allow Shadow AI tools to influence content metadata, thumbnail generation, or recommendation logic without formal oversight face dual exposure under both the AI Act and DSA, making Eversheds Sutherland's call for rigorous due diligence a practical necessity rather than theoretical caution.
Read full article at image.ie
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source