SurfingBear ToolsSurfingBearTools
Skip to content

Home › Blog › Finding shadow AI

Finding shadow AI — locating unapproved AI use

Shadow AI is less a staff failing than a signal that your approval process is slow. So the response has to start with the process, not with sanctions.

How to find it Response order Limits of banning

The short answer

The risk in shadow AI is not the tool but the terms. Personal accounts frequently default to training on your data, have no audit log, and cannot be reclaimed when someone leaves.

And banning does not remove it. People use it because the work needs it, so with no approved alternative it simply hides better. The order is find, then provide, then regulate.

How to find it — imperfect, but it catches most

Network and proxy logs — Check which AI service domains are reached from the corporate network. The widest net, but personal devices and mobile escape it.
Expense claims — Find personal card purchases that were reimbursed. Look for small recurring charges.
SSO logs — Catches tools connected with organisational accounts, but not personal-email sign-ups.
A survey — The only way to fill the gaps. Be explicit that the purpose is improving approvals, not sanctions. Anonymous surveys get better response rates.
Work output — Documents and code sometimes carry the signature of a particular tool. But using that to identify individuals destroys trust.

What the real risks are

Risk Why it matters
Training on your data Personal tiers frequently default to it
No audit log After an incident you cannot establish what was entered
No deprovisioning Company data stays in a leaver’s account
No data export The company cannot retrieve work accumulated in a personal account
Unverified terms Nobody checked storage location or retention

Response order

Provide company accounts first. Contracting organisational tiers for the most-used tools reduces shadow use sharply — far more than a prohibition notice does.

Then build a request route: where to ask for a new tool, and how quickly an answer comes. If the answer takes two weeks, people stop asking. A lightweight approval is the whole point.

Regulation comes last. State data classes and prohibited actions, and include the reporting route. A policy that is only sanctions lowers the reporting rate — and the unreported incident is the expensive one.

Frequently asked questions

Why not just block it?

Blocking on the corporate network moves usage to personal devices and mobile, at which point you cannot see it at all. Blocking should be a supporting measure after an approved alternative exists.

Will people answer a survey honestly?

They will if they believe the purpose is not punishment. Take it anonymously, and approve real tools based on the results — the next survey’s response rate goes up.

Company data is already in personal accounts.

Confirm that tool’s deletion process and retention period, and document the blast radius. If personal data is involved, notification obligations need review. Process repair comes after.

How much is realistic to allow?

Splitting by data class is realistic: allow public information broadly, and restrict internal, confidential and personal data to approved company accounts. That generally works.

Organisational readiness

Find which axis is the problem

The AX readiness assessment scores policy, ownership and process on the organisation axis, showing whether shadow AI is a policy problem or a process one.

Check readiness