Guide 13 min read

Shadow AI Discovery: Find Every AI Tool Staff Use

J

Jared Clark

September 04, 2026

I have never walked into a company, at any size, where the honest answer to "which AI tools does your team use" matched the official list. There is always a gap. Someone in accounts payable is running invoice text through ChatGPT to summarize it. A marketing associate has a Claude account she pays for herself because it writes better than the tool IT approved. A sales rep pastes call notes into an AI note-taker nobody in the company selected or reviewed. None of this shows up in the software asset inventory. All of it touches company data.

That gap has a name now: shadow AI. It is shadow IT's successor, and in most organizations it is bigger and harder to see than the problem it descended from, because the tools are free, browser-based, and require no procurement approval to start using. You don't install shadow AI. You just sign in.

This article is about finding it for real — not guessing, not surveying your way to a rough estimate, but building an actual inventory of the generative AI tools already running inside your business. I'll cover what counts as shadow AI, why finding it has become a compliance floor rather than a nice-to-have, the discovery methods that work, and what to do with the list once you have it.

What Counts as Shadow AI

Shadow AI is any generative AI tool an employee uses for work that IT and compliance never approved, never inventoried, and in most cases never heard of. That includes the obvious case — a free ChatGPT account used to draft client emails — and the less obvious ones: an AI feature quietly switched on inside a SaaS tool your company already pays for, a browser extension that summarizes web pages by sending their contents to a third-party model, an AI meeting bot that joined a client call because a calendar invite included it by default.

The unifying trait isn't the tool. It's the absence of a decision. Nobody weighed the risk, checked the vendor's data-handling terms, or decided whether client information belongs in that tool's training pipeline. The tool got adopted the way habits get adopted: because it worked, and nobody said no.

This also covers tools your company already licenses in a different form. Microsoft 365 Copilot, Google's Gemini in Workspace, and Salesforce's Einstein Copilot all ship as add-ons or embedded features inside platforms most companies already run. A team that turns one of these on without telling compliance has created shadow AI inside a sanctioned tool — which is exactly the blind spot a software-license inventory won't catch, because the license for the parent product was already approved.

Why This Has Stopped Being Optional

For a few years, shadow AI discovery was a "good governance" recommendation. It is now closer to a compliance floor, for three reasons.

The standards world caught up. ISO/IEC 42001:2023, the AI management system standard, requires under clause 4.3 that an organization determine the scope of its AI management system. You cannot scope what you haven't found. Clause 6.1.2 goes further, requiring a documented AI risk assessment, which is impossible to perform honestly against tools sitting outside the inventory used to write it. An organization pursuing ISO 42001 certification with an undocumented shadow AI footprint isn't behind on paperwork — it's certifying a system that doesn't describe its own operations.

The regulatory deadlines arrived, though not the ones most articles describe. The EU AI Act, Regulation (EU) 2024/1689, entered into force on August 1, 2024. Its obligations phase in over several years: the prohibited-practices list and the Article 4 AI-literacy duty took effect February 2, 2025, general-purpose AI model obligations followed on August 2, 2025, and the high-risk system obligations for the Annex III use cases — employment decisions, credit scoring, biometric identification, critical infrastructure — became enforceable August 2, 2026. High-risk systems embedded as safety components in Annex I–regulated products (machinery, medical devices, and similar) get an extra year, until August 2, 2027.

None of that makes an employee's ChatGPT account for drafting emails a "high-risk AI system" under the Act. It almost never is: the high-risk category is narrow and enumerated, and a general-purpose chatbot used for correspondence doesn't fall inside it. What actually bites on ordinary shadow AI use is Article 4. Since February 2, 2025, any organization deploying or using an AI system has been required to ensure its staff have a sufficient level of AI literacy for the context in which the system is used. You cannot demonstrate that duty is met for tools your compliance team doesn't know exist. Article 50's transparency duties — disclosing AI interactions, labeling AI-generated content — layer onto that for EU-facing companies. Shadow AI doesn't usually pull a company into the high-risk regime. It puts a company in the position of being unable to show it met the literacy and transparency duties that already apply today.

NIST's framework put discovery first. The AI Risk Management Framework (NIST AI 100-1, published January 26, 2023) organizes AI governance around four functions — Govern, Map, Measure, Manage — and the Map function's opening move is cataloging the AI systems an organization actually has. Every downstream control depends on that catalog being complete. A partial map isn't a smaller version of AI governance. It's a governance program confidently managing the wrong risk.

Discovery isn't the first step in AI governance. It's the floor everything else stands on.

Why Shadow AI Is Worse Than Shadow IT

Shadow IT — the unsanctioned SaaS tools employees signed up for on a company card — was a budget and security problem. Shadow AI carries that same risk plus one shadow IT never had. The data doesn't just sit in an unapproved database; it gets processed by a model, and depending on the vendor's terms, it may get used to improve that model. A leaked spreadsheet is a breach with a fixed set of contents. Data fed into a free-tier AI tool with permissive training terms can resurface, in some form, in someone else's output months later.

Shadow IT also had natural chokepoints: a login screen requiring a corporate email domain, a credit card that showed up on an expense report, an IT ticket when the tool needed to talk to another system. Shadow AI has none of those. A personal Gmail account and a free tier is enough. That's why discovery has to be deliberate. The tool leaves almost no trail unless you go looking for the specific trails it does leave.

How to Actually Find Shadow AI Tools

There is no single source that reveals everything. Each method below has a specific blind spot, which is why a real inventory comes from running two or three of them together and reconciling what they turn up.

  1. Audit your SSO and OAuth admin console. If your company runs Google Workspace or Microsoft 365 / Entra ID, the admin console already lists every third-party app employees have granted access to via "Sign in with Google" or "Sign in with Microsoft." This is free, immediate, and catches every AI tool where someone used SSO instead of a fresh password — a large share of tools adopted through a work account. It will also show licensed Copilot activations sitting alongside unsanctioned ChatGPT and Claude access granted the same way. Run this report first.

  2. Pull network and DNS logs against a maintained list of AI domains. Your firewall or web gateway already logs outbound traffic. Cross-referencing it against known AI domains — chatgpt.com, claude.ai, gemini.google.com, perplexity.ai, and the growing list of AI writing, coding, and note-taking tools — surfaces usage that never touched an SSO screen, including tools accessed with a personal email and password from a company laptop.

  3. Audit expense reports and procurement cards for AI subscriptions. This only catches paid tools, a minority of shadow AI, but often the highest-risk minority: a paid subscription means sustained, habitual use rather than a one-off experiment.

  4. Inventory browser extensions on managed devices. If you run mobile device management or an endpoint platform, pull the installed extension list across the fleet. AI writing assistants, summarizers, and meeting bots increasingly ship as browser extensions rather than standalone apps, and extensions are the most commonly missed category in a first-pass inventory.

  5. Run an anonymous amnesty survey. After the technical passes, ask staff directly what AI tools they use for work, with an explicit promise that disclosure carries no penalty. People will tell you things logs won't show, particularly personal-device use that never touches the corporate network. A punitive framing gets you a survey full of "none," and you already know that's not the honest number.

  6. Add a Cloud Access Security Broker (CASB) or AI-aware secure web gateway. If none of the above infrastructure exists yet, tools like Cloudflare Gateway maintain categorized application signatures that flag generative AI traffic in real time, turning discovery from a periodic audit into an ongoing control. This is more setup than the other methods, but it's the only one that keeps working after the first inventory is built.

Discovery Methods Compared

Method What It Catches Relative Effort Main Blind Spot
SSO / OAuth app audit (Google Workspace, Microsoft Entra ID) AI tools accessed via "Sign in with Google/Microsoft," including licensed Copilot activations Low — built into existing admin console Tools accessed with a personal email, no SSO
Network / DNS log review AI domains visited from the corporate network Medium — needs log access and a maintained domain list Off-network use on personal phones or home laptops
Expense report / procurement card audit Paid individual or team AI subscriptions Medium — needs finance cooperation Free-tier tools, which is most of shadow AI
Browser extension inventory (via MDM) AI extensions and meeting bots on managed devices Low-to-medium if MDM already deployed Unmanaged personal (BYOD) devices
Anonymous staff survey / amnesty Tools staff will admit to using, including on personal devices Low cost, high dependence on trust Understates use; people underreport habitual behavior
CASB / secure web gateway with AI signatures Real-time, ongoing visibility across cloud app traffic Higher — new tooling or configuration Cost and deployment time; traffic-level, not content-level

No single row gets you to a complete picture. Run the SSO audit and the network log review together and you'll catch most sanctioned-account and network-visible use within a week. Layer the survey on top and you'll catch the personal-device use neither technical method can see. That three-method combination is where I tell clients to start, because it's achievable without new procurement, and each method closes the blind spot the other two leave open.

Building the Inventory, Not Just the List

A spreadsheet of tool names is not an inventory. A usable AI inventory records, for every tool found: who uses it, what data category it touches (customer PII, financial data, source code, general correspondence), whether the vendor's terms permit using inputs for model training, and whether a paid or enterprise tier with better data-handling terms exists. That last field matters more than people expect. A large share of shadow AI risk disappears the moment a free-tier tool gets upgraded to its enterprise plan, because the training-data terms usually change with the tier.

This inventory is also the artifact that NIST's Map function and ISO 42001's clause 6.1.2 risk assessment both assume exists before either framework can do anything useful. Discovery isn't a side project you run once before an audit. It's the input every subsequent governance decision depends on, and it goes stale the moment a new AI feature ships inside a tool you already use.

What to Do Once You Find It

Finding shadow AI isn't the point. The point is deciding, tool by tool, whether to sanction it, replace it with a governed alternative, or shut it down — and then telling staff why. A ban with no explanation just pushes the behavior further underground.

In my experience, the tools worth sanctioning outnumber the tools worth banning. Staff generally found these tools because they solved a real problem faster than the approved alternative did. The fix is usually a proper enterprise agreement for the tool that's already working, not forcing everyone back onto a slower tool nobody was using anyway.

That triage is a judgment call, not a checklist. Every industry's data sensitivity and regulatory exposure changes where the line sits, which is the kind of thing worth talking through directly rather than reducing to a generic rule. If you want a structured starting point before that conversation, our AI readiness assessment builds the inventory and risk triage in one pass. If you're sequencing this alongside a broader NIST AI RMF rollout, I've written a step-by-step version for a 200-person company in this implementation guide.

Shadow AI discovery never really finishes. New tools ship weekly, existing SaaS platforms bolt AI features onto products you already licensed, and staff turnover brings in people with different habits than the ones you just accounted for. Treat the first inventory as a baseline, not a project with an end date, and build the SSO audit and network log review into a recurring quarterly check rather than a one-time sweep. The companies that get burned by shadow AI aren't usually the ones that never looked. They're the ones that looked once, found less than they expected, and assumed the problem was smaller than it actually was.

FAQ

What exactly counts as shadow AI? Any generative AI tool an employee uses for work-related tasks that wasn't vetted, approved, or inventoried by IT or compliance — including free browser tools, AI features embedded in already-licensed software like Microsoft 365 or Google Workspace, and AI browser extensions, regardless of whether any company money was spent on them.

Is using shadow AI illegal? Not inherently, but it creates real legal exposure fast. Pasting customer PII, protected health information, or contract terms into a consumer-tier AI tool can violate the company's own data processing agreements and privacy commitments, and for EU-connected companies, it can leave the organization unable to demonstrate the Article 4 AI-literacy duty under Regulation (EU) 2024/1689. The tool itself isn't illegal. The uncontrolled data flow through it usually is the problem.

How is shadow AI different from shadow IT? Shadow IT is an unsanctioned software purchase; shadow AI is unsanctioned data processing by a model. Shadow IT risk is largely about security and cost. Shadow AI adds the risk that submitted data may be retained or used to improve the vendor's model, a category of exposure shadow IT never had.

Can I find shadow AI without buying new tools? Yes, for a first pass. The SSO/OAuth admin console audit, network log review, and an anonymous staff survey use infrastructure most companies already have, and together catch the majority of usage. A Cloud Access Security Broker or AI-aware secure web gateway becomes worth the investment once you want ongoing, real-time visibility rather than a periodic snapshot.

How often should we re-run shadow AI discovery? Quarterly, at minimum, and after any major SaaS platform adds AI features to a product you already use — which is now a routine vendor update, not a rare event. Treat the inventory as a living document tied to your AI risk assessment, not a one-time audit deliverable.

Last updated: 2026-09-04

J

Jared Clark

AI Strategy Consultant, AI Strategies Consulting

Jared Clark is the founder of AI Strategies Consulting, helping organizations design and implement practical AI systems that integrate with existing operations.