Shadow AI: finding unapproved AI use and bringing it under governance
Shadow AI is any use of AI tools, features or automations at work that nobody has assessed or approved. It rarely starts from bad intent: people adopt what helps them get work done. This guide shows how to find that use without a witch hunt, tier tools by what they do with your data, tie an acceptable-use policy to your data classification and offer a sanctioned option people prefer to the workaround.
On this page
- The five forms shadow AI usually takes
- Why bans fail, and what is really at risk
- Discovering shadow AI in five passes
- Tiering AI tools by what they do with your data
- An acceptable-use policy keyed to data classification
- Technical controls that back the policy
- A hypothetical professional services firm moves to a sanctioned assistant
- Folding discovered use into the AI inventory and risk register
- Questions and answers
- Sources
The five forms shadow AI usually takes
The term covers far more than chat tools. These five forms turn up in most organizations, and each is found by a different method.
- Unapproved chat assistants
- Consumer or free-tier AI assistants used in a browser with personal accounts, often to draft, summarize or translate work content.
- AI browser extensions
- Plug-ins that read web pages, email or documents in the browser to rewrite, summarize or autofill, frequently with broad permissions granted in a single click.
- AI features inside approved software
- Assistants switched on inside SaaS products you already license, sometimes by default after an update, under data terms that can differ from the core product.
- Personal API keys
- Developers or analysts calling model providers directly on personal or team cards, sending code, data or documents outside any agreed contract.
- Unsanctioned agents and automations
- Workflow tools and agents connected to company mailboxes, drives or CRM records through app consents, acting on data with no review.
Why bans fail, and what is really at risk
Blanket bans push use onto personal phones and home networks, where it becomes invisible, and they signal that the organization has nothing better to offer. Someone who found a tool that saves an hour a day will not stop because a policy says so. They stop when an approved tool does the same job with less friction.
The risks worth managing are specific. Confidential, personal or client data may be retained by a provider or used to train its models. Code and documents may leave the organization in breach of contracts or intellectual property terms. Unchecked outputs can slip into decisions, client deliverables or published material. Personal data sent to a provider without a processing contract can also breach GDPR (Regulation (EU) 2016/679), which requires a binding contract with any processor acting on your behalf1.
Discovering shadow AI in five passes
Run the passes in parallel where you can. Before analyzing anything at the level of named individuals, check employment law, works council agreements and your privacy notices.
Review spend and expense claims
Search card statements, expense claims and purchasing records for AI subscriptions and model provider charges. This finds paid tools quickly and shows which teams use them.
Audit single sign-on and app consents
Export third-party app consents from your identity provider and productivity suite. Look for assistants, meeting recorders and automation tools that hold access to mail, files or calendars.
Read gateway and DNS logs
Use secure web gateway, proxy or DNS logs to see traffic to AI services by volume and department. Look for patterns, not people, at this stage.
Inventory extensions and in-app features
Pull browser extension lists from managed devices, and check the admin consoles of your main SaaS products for AI features that are switched on.
Run an amnesty survey
Ask staff which AI tools they use, for which tasks and with what data, with a clear promise of no disciplinary action for honest answers. The answers reveal the jobs people need done, which is what the sanctioned alternative must cover.
Tiering AI tools by what they do with your data
Judge each tool on the terms that govern your data. Popularity and brand say little about either.
| Question | Approved | Limited use | Blocked |
|---|---|---|---|
| Training on your inputs | Excluded by contract | Off through a setting the organization controls | Inputs may be used to train provider models |
| Retention of prompts and outputs | Defined and configurable, with deletion on request | Defined but not configurable | Unclear or indefinite |
| Data location and transfers | Processing locations stated and acceptable | Stated, with transfer safeguards still to review | Not stated |
| Enterprise controls | Single sign-on, admin console, audit logs | Some controls but no audit log | Personal accounts only |
| Sub-processors | Published list with notice of changes | Published list, changes not notified | No list |
| Contract | Data processing agreement signed | Standard business terms reviewed by legal | Consumer terms of service |
Tier names are illustrative. If you already run vendor risk categories, add these questions to them rather than creating a parallel scheme.
An acceptable-use policy keyed to data classification
Most organizations already classify data. Map each class to the tool tiers it may enter instead of writing a separate AI rulebook.
- If
The content is public or already published.
ThenApproved and limited-use tools may be used; outputs still get a human check before anything is published.
The data risk is low, but the accuracy and attribution risk of the output is not.
- If
The content is internal but not confidential, such as notes on routine work.
ThenApproved tools only, through company accounts.
Company accounts keep the audit trail and end access when someone leaves.
- If
The content is confidential, client-owned or under a non-disclosure agreement.
ThenOnly approved tools cleared for that class, and only where the client contract allows it.
Client terms can forbid third-party processing even when your own policy would permit it.
- If
The content includes personal data, health or financial records, or other regulated information.
ThenOnly systems assessed for that specific purpose, with a processing agreement and, where required, a data protection impact assessment.
Regulated data needs a lawful basis and safeguards for each use, not a general approval of the tool.
- If
Someone needs a tool that has not been approved yet.
ThenRoute the request through a fast assessment with a published turnaround.
When asking is slower than working around, people work around.
Technical controls that back the policy
A hypothetical professional services firm moves to a sanctioned assistant
Folding discovered use into the AI inventory and risk register
Discovery pays off only if it feeds records you already keep. Each tool found becomes an inventory entry with an owner, the data classes it touches, its tier and its business purpose. Uses that shape decisions about people, such as screening job candidates, also belong in the risk register with a review date, because they can carry duties of their own for deployers under the EU AI Act.
The same entries become evidence for an ISO/IEC 42001 management system, and the survey shows where AI literacy training is most needed. Where the sanctioned option is a private deployment or a platform assistant, the enterprise AI and Microsoft Copilot development pages cover those routes. ColdAI's AI governance and safety work builds this kind of framework together with the controls behind it2.
Questions and answers
How is shadow AI different from shadow IT?
Shadow AI is a subset of shadow IT with three extra problems. Data sent to a model may be retained or used for training, outputs can feed straight into decisions and documents without review, and AI features appear inside software you already approved, so procurement never sees them. Traditional shadow IT controls catch new subscriptions but often miss features switched on in existing tools.
Can we monitor which AI tools employees use?
Generally yes at an aggregate level, through gateway logs, app consent records and spend data, provided the monitoring is proportionate and disclosed. Analysis of named individuals raises employment and data protection questions, and in many countries a works council must be consulted first. Start with patterns by team, and involve legal and HR before going further.
Should we block all public AI chat tools?
Block the tools that fail your tiering, but only once a sanctioned alternative is live and easy to reach. Blocking without an alternative moves the same use onto personal devices, where you cannot see it or protect the data. A short, published list of approved tools with a fast route for requests tends to hold better than a broad block.
Who should own shadow AI governance?
Ownership is usually split. Security or the CIO office runs discovery and technical controls, legal and privacy own the policy and contract terms, and a business-facing owner runs the sanctioned alternative so it keeps meeting real needs. Whoever holds the AI inventory, often an AI governance lead or committee, should receive every finding so nothing stays outside the register.
Sources
- Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026
- Artificial Intelligence capability: AI Governance and Safety offering — ColdAI