GuideArtificial Intelligence

Shadow AI: finding unapproved AI use and bringing it under governance

Shadow AI is any use of AI tools, features or automations at work that nobody has assessed or approved. It rarely starts from bad intent: people adopt what helps them get work done. This guide shows how to find that use without a witch hunt, tier tools by what they do with your data, tie an acceptable-use policy to your data classification and offer a sanctioned option people prefer to the workaround.

Reviewed 8 min read

On this page
  1. The five forms shadow AI usually takes
  2. Why bans fail, and what is really at risk
  3. Discovering shadow AI in five passes
  4. Tiering AI tools by what they do with your data
  5. An acceptable-use policy keyed to data classification
  6. Technical controls that back the policy
  7. A hypothetical professional services firm moves to a sanctioned assistant
  8. Folding discovered use into the AI inventory and risk register
  9. Questions and answers
  10. Sources

The five forms shadow AI usually takes

The term covers far more than chat tools. These five forms turn up in most organizations, and each is found by a different method.

Unapproved chat assistants
Consumer or free-tier AI assistants used in a browser with personal accounts, often to draft, summarize or translate work content.
AI browser extensions
Plug-ins that read web pages, email or documents in the browser to rewrite, summarize or autofill, frequently with broad permissions granted in a single click.
AI features inside approved software
Assistants switched on inside SaaS products you already license, sometimes by default after an update, under data terms that can differ from the core product.
Personal API keys
Developers or analysts calling model providers directly on personal or team cards, sending code, data or documents outside any agreed contract.
Unsanctioned agents and automations
Workflow tools and agents connected to company mailboxes, drives or CRM records through app consents, acting on data with no review.

Why bans fail, and what is really at risk

Blanket bans push use onto personal phones and home networks, where it becomes invisible, and they signal that the organization has nothing better to offer. Someone who found a tool that saves an hour a day will not stop because a policy says so. They stop when an approved tool does the same job with less friction.

The risks worth managing are specific. Confidential, personal or client data may be retained by a provider or used to train its models. Code and documents may leave the organization in breach of contracts or intellectual property terms. Unchecked outputs can slip into decisions, client deliverables or published material. Personal data sent to a provider without a processing contract can also breach GDPR (Regulation (EU) 2016/679), which requires a binding contract with any processor acting on your behalf1.

Discovering shadow AI in five passes

Run the passes in parallel where you can. Before analyzing anything at the level of named individuals, check employment law, works council agreements and your privacy notices.

  1. Review spend and expense claims

    Search card statements, expense claims and purchasing records for AI subscriptions and model provider charges. This finds paid tools quickly and shows which teams use them.

    Output
    Paid AI tools by team
    Owner
    Finance and procurement
  2. Audit single sign-on and app consents

    Export third-party app consents from your identity provider and productivity suite. Look for assistants, meeting recorders and automation tools that hold access to mail, files or calendars.

    Output
    Connected-app register
    Owner
    Identity and access team
  3. Read gateway and DNS logs

    Use secure web gateway, proxy or DNS logs to see traffic to AI services by volume and department. Look for patterns, not people, at this stage.

    Output
    Traffic map of AI services
    Owner
    Security operations
  4. Inventory extensions and in-app features

    Pull browser extension lists from managed devices, and check the admin consoles of your main SaaS products for AI features that are switched on.

    Output
    Extension and feature inventory
    Owner
    Endpoint and SaaS administrators
  5. Run an amnesty survey

    Ask staff which AI tools they use, for which tasks and with what data, with a clear promise of no disciplinary action for honest answers. The answers reveal the jobs people need done, which is what the sanctioned alternative must cover.

    Output
    Picture of use and unmet demand
    Owner
    CIO office with HR and internal communications

Tiering AI tools by what they do with your data

Judge each tool on the terms that govern your data. Popularity and brand say little about either.

QuestionApprovedLimited useBlocked
Training on your inputsExcluded by contractOff through a setting the organization controlsInputs may be used to train provider models
Retention of prompts and outputsDefined and configurable, with deletion on requestDefined but not configurableUnclear or indefinite
Data location and transfersProcessing locations stated and acceptableStated, with transfer safeguards still to reviewNot stated
Enterprise controlsSingle sign-on, admin console, audit logsSome controls but no audit logPersonal accounts only
Sub-processorsPublished list with notice of changesPublished list, changes not notifiedNo list
ContractData processing agreement signedStandard business terms reviewed by legalConsumer terms of service

Tier names are illustrative. If you already run vendor risk categories, add these questions to them rather than creating a parallel scheme.

An acceptable-use policy keyed to data classification

Most organizations already classify data. Map each class to the tool tiers it may enter instead of writing a separate AI rulebook.

  • If

    The content is public or already published.

    Then

    Approved and limited-use tools may be used; outputs still get a human check before anything is published.

    The data risk is low, but the accuracy and attribution risk of the output is not.

  • If

    The content is internal but not confidential, such as notes on routine work.

    Then

    Approved tools only, through company accounts.

    Company accounts keep the audit trail and end access when someone leaves.

  • If

    The content is confidential, client-owned or under a non-disclosure agreement.

    Then

    Only approved tools cleared for that class, and only where the client contract allows it.

    Client terms can forbid third-party processing even when your own policy would permit it.

  • If

    The content includes personal data, health or financial records, or other regulated information.

    Then

    Only systems assessed for that specific purpose, with a processing agreement and, where required, a data protection impact assessment.

    Regulated data needs a lawful basis and safeguards for each use, not a general approval of the tool.

  • If

    Someone needs a tool that has not been approved yet.

    Then

    Route the request through a fast assessment with a published turnaround.

    When asking is slower than working around, people work around.

Technical controls that back the policy

0 of 6 checked

A hypothetical professional services firm moves to a sanctioned assistant

Folding discovered use into the AI inventory and risk register

Discovery pays off only if it feeds records you already keep. Each tool found becomes an inventory entry with an owner, the data classes it touches, its tier and its business purpose. Uses that shape decisions about people, such as screening job candidates, also belong in the risk register with a review date, because they can carry duties of their own for deployers under the EU AI Act.

The same entries become evidence for an ISO/IEC 42001 management system, and the survey shows where AI literacy training is most needed. Where the sanctioned option is a private deployment or a platform assistant, the enterprise AI and Microsoft Copilot development pages cover those routes. ColdAI's AI governance and safety work builds this kind of framework together with the controls behind it2.

Questions and answers

How is shadow AI different from shadow IT?

Shadow AI is a subset of shadow IT with three extra problems. Data sent to a model may be retained or used for training, outputs can feed straight into decisions and documents without review, and AI features appear inside software you already approved, so procurement never sees them. Traditional shadow IT controls catch new subscriptions but often miss features switched on in existing tools.

Can we monitor which AI tools employees use?

Generally yes at an aggregate level, through gateway logs, app consent records and spend data, provided the monitoring is proportionate and disclosed. Analysis of named individuals raises employment and data protection questions, and in many countries a works council must be consulted first. Start with patterns by team, and involve legal and HR before going further.

Should we block all public AI chat tools?

Block the tools that fail your tiering, but only once a sanctioned alternative is live and easy to reach. Blocking without an alternative moves the same use onto personal devices, where you cannot see it or protect the data. A short, published list of approved tools with a fast route for requests tends to hold better than a broad block.

Who should own shadow AI governance?

Ownership is usually split. Security or the CIO office runs discovery and technical controls, legal and privacy own the policy and contract terms, and a business-facing owner runs the sanctioned alternative so it keeps meeting real needs. Whoever holds the AI inventory, often an AI governance lead or committee, should receive every finding so nothing stays outside the register.

Sources

  1. Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026
  2. Artificial Intelligence capability: AI Governance and Safety offering — ColdAI

More in Artificial Intelligence

Back to Artificial Intelligence

Next step

Tell us what your shadow AI discovery has turned up

Share what you have found, or suspect, and which data classes worry you most. We will suggest the order of discovery passes and controls, and where a sanctioned option would remove the need for a workaround.

Discuss shadow AI governance