Home › Blog › Finding shadow AI
Finding shadow AI — locating unapproved AI use
Shadow AI is less a staff failing than a signal that your approval process is slow. So the response has to start with the process, not with sanctions.
How to find it Response order Limits of banning
The short answer
The risk in shadow AI is not the tool but the terms. Personal accounts frequently default to training on your data, have no audit log, and cannot be reclaimed when someone leaves.
And banning does not remove it. People use it because the work needs it, so with no approved alternative it simply hides better. The order is find, then provide, then regulate.
How to find it — imperfect, but it catches most
What the real risks are
| Risk | Why it matters |
|---|---|
| Training on your data | Personal tiers frequently default to it |
| No audit log | After an incident you cannot establish what was entered |
| No deprovisioning | Company data stays in a leaver’s account |
| No data export | The company cannot retrieve work accumulated in a personal account |
| Unverified terms | Nobody checked storage location or retention |
Response order
Provide company accounts first. Contracting organisational tiers for the most-used tools reduces shadow use sharply — far more than a prohibition notice does.
Then build a request route: where to ask for a new tool, and how quickly an answer comes. If the answer takes two weeks, people stop asking. A lightweight approval is the whole point.
Regulation comes last. State data classes and prohibited actions, and include the reporting route. A policy that is only sanctions lowers the reporting rate — and the unreported incident is the expensive one.
Frequently asked questions
Why not just block it?
Blocking on the corporate network moves usage to personal devices and mobile, at which point you cannot see it at all. Blocking should be a supporting measure after an approved alternative exists.
Will people answer a survey honestly?
They will if they believe the purpose is not punishment. Take it anonymously, and approve real tools based on the results — the next survey’s response rate goes up.
Company data is already in personal accounts.
Confirm that tool’s deletion process and retention period, and document the blast radius. If personal data is involved, notification obligations need review. Process repair comes after.
How much is realistic to allow?
Splitting by data class is realistic: allow public information broadly, and restrict internal, confidential and personal data to approved company accounts. That generally works.
Organisational readiness
Find which axis is the problem
The AX readiness assessment scores policy, ownership and process on the organisation axis, showing whether shadow AI is a policy problem or a process one.
SurfingBear