How to Find the Shadow AI Already in Your Company
Your staff are already using AI you did not approve. Here are four ways to find out what, without turning it into an investigation.

Erin Moore
Fractional Chief AI Officer
The fastest way to find shadow AI is to ask, having first made it safe to answer. Expense reports, browser telemetry and SSO logs will each find some of it, but the majority sits in free-tier consumer accounts that leave no trace in any system you administer — which means discovery is a trust problem before it is a technical one.
Why the technical methods only get you part way
Expense and card data finds paid subscriptions. It misses every free tier, which is where most shadow AI lives.
SSO and identity logs find tools people signed into with a work account. It misses anything signed up for with a personal email, which is exactly what someone does when they suspect the tool might not be approved.
Network or browser telemetry finds the most, and is also the method most likely to poison the conversation you actually need to have. If staff learn that the way you discovered their tool use was surveillance, the next tool moves to a personal phone and you have made your visibility worse.
Each of these is worth running. None of them is sufficient, and the last one carries a cost that is easy to underestimate.
The conversation that finds the rest
Ask, with a stated amnesty and a genuine reason. Something close to: we are building an approved list, nothing you tell us gets anyone in trouble, and we would rather buy you the paid version than have you use the free one with customer data.
That framing works because it is true and because it offers something. People adopt unsanctioned tools for good reasons — the sanctioned option is worse, or does not exist. Treating that as a discipline problem misreads it. How to get your team to use AI covers the same incentives from the adoption side.
Run it as a short survey or as ten minutes in each team's existing meeting. Ask what they use, what for, and what data goes into it. The third question is the one that matters.
What to do with the answer
Sort what you find into three buckets:
Approve and pay for it. If a tool is genuinely useful and the data handling is acceptable, buying the business tier usually costs less than the risk of the free one and immediately gives you an audit trail.
Replace it. If the need is real but the tool is not acceptable, provide an alternative before removing access. Removing without replacing sends the behaviour underground.
Prohibit it. Some tools should not touch your data at any price. Say which, say why, and write it down — this is the core of the one-page AI policy template.
Then keep a register of what is in use, who owns it and what data it touches. NIST's AI Risk Management Framework treats this kind of inventory as foundational, and it is the artifact you will want the first time a customer asks how their data is handled.
Doing this once is not enough
Shadow AI is not a backlog to clear; it regenerates every time a new tool launches and your approval route is slower than a signup form. The durable fix is a fast, visible path to getting something approved — measured in days, not weeks — plus a quarterly re-ask. If approval takes a month, you are manufacturing the next round yourself.
For the broader structure this fits into, see the AI governance framework and the fractional Chief AI Officer retainer, which usually owns this register in practice.
Frequently asked questions
How do I find shadow AI in my company? Combine expense data, SSO logs and a direct amnesty-backed ask. The technical sources find paid and work-account tools; the conversation finds the free-tier consumer accounts, which is where most of it lives.
Is monitoring employee browsers a good way to find shadow AI? It finds the most and costs the most. Once staff know discovery came from surveillance, the next tool moves to a personal device and your visibility gets worse. Use it as a backstop, not as the opening move.
What should I do with the shadow AI I find? Sort into approve-and-pay, replace, or prohibit. Never remove access without providing an alternative for a genuine need — that is what drove the behaviour underground in the first place.
How often should we look for shadow AI? Quarterly, and treat the result as a signal about your approval process. If new unsanctioned tools keep appearing, approval is too slow rather than staff being careless.
Further reading
Tagged with:
Ready to Automate Your Business?
Let's discuss how AI automation can deliver measurable ROI for your organization in 90 days or sooner.