Guides
How to find shadow AI, and what to do once you have
Harriet Team · · 4 min read
Every company that has looked has found it. Personal ChatGPT and Claude accounts used for work. A browser extension that reads every page. An API key someone put on their own card because procurement was slow. AI features switched on inside the CRM that nobody reviewed.
It is called shadow AI, and in a 300-person company it is usually two to three times bigger than anyone in IT guessed. Here is how to measure it in a week, and what to do about it without a ban nobody will follow.
Why it is everywhere
The tools are free or nearly free, they live in a browser tab, and they work. A person who gets an hour back from a personal account is not going to wait for a policy. They will keep using it and not mention it, because mentioning it sounds like asking permission.
Add the SaaS layer. Half the tools your company already pays for have shipped an AI feature in the last year, each with its own terms about where your data goes and whether it trains on it. Those never went through security review because nothing was bought.
Finding it in a week
You do not need a discovery tool to get a good first picture. Three sources will do, starting with the cheapest.
Expenses and cards. Search the last six months for AI subscriptions. OpenAI, Anthropic, Perplexity, Cursor, Otter and the rest. This finds the paid tail and tells you who the heavy users are, which is useful later.
Network or DNS logs. If you have any visibility at the network edge, count requests to the main AI provider domains by device. This finds the free tier, which is most of it.
A blame-free survey. One question per team, asked by a manager rather than IT. Which AI tools do you actually use for work, and for what. Make it clear the answer will not get anyone in trouble. This finds the workflows, and the workflows are what you want to keep.
Put the three together and you have a map. It is normally lopsided, with a handful of teams doing serious work on personal accounts and a long tail of occasional use.
What to do once you have the map
Do not ban it
A ban stops the people who were doing the most useful work and teaches everyone else to hide it better. The companies that ban personal accounts without offering something at least as good end up with the same shadow AI and no survey data.
Make the sanctioned route the easy route
The one thing that reliably reduces shadow AI is an approved assistant that is better than the personal one. Better means the models people want, on every device without a ticket, with the company’s documents and tools connected so it has context a personal account never will.
Provisioning does the heavy lifting here. When the assistant arrives through your identity provider and device management, it is on every laptop before anyone thinks to sign up for something else.
Keep the workflows, retire the accounts
The survey found people doing real work. That work is the seed of your official rollout. Rebuild the three or four best personal workflows as shared, reviewed skills inside the sanctioned assistant, credit the people who invented them, and then ask them to close the personal account. Most will, because the approved version is now better.
Put a policy behind it that people can read
A one-page AI usage policy that says what is approved, what data can go where, and who to ask does more than a twenty-page one nobody opens. Write it after the map, not before, so it describes real use.
The governance you get for free
Once AI use runs through one route, the questions that were unanswerable become reports. Which teams use what, where data is processed, what each tool call did. That audit trail is what a security review or a regulator asks for, and you get it as a by-product of doing the rollout properly rather than as a separate project.
Your people found value before the company caught up. Catch up in a way that keeps it. Book a call and we will walk through the map with you.
Common questions
What is shadow AI?
Shadow AI is any AI use inside a company that IT and security cannot see or govern. Personal ChatGPT or Claude accounts used for work, AI browser extensions, API keys on a personal card, and AI features switched on inside SaaS tools nobody reviewed. It is the AI equivalent of shadow IT, and it grows faster because the tools are free and a browser tab away.
How do you detect shadow AI in a company?
Three sources, in order of effort. Expense and card data for AI subscriptions. Network or DNS logs for traffic to AI provider domains. A short, blame-free survey asking each team which AI tools they actually use. Most companies find two to three times the AI use they expected, mostly through personal accounts.
Should we ban personal AI accounts at work?
Bans rarely work and push use further underground. What works is giving people a sanctioned assistant that is at least as good as what they were using, provisioned to every device, with the models they want. Once the approved route is the easy route, shadow use drops on its own.
Why is shadow AI a risk?
Company data leaves through accounts with consumer terms, sometimes with training on your content switched on. Nobody can answer where the data went if a regulator or a customer asks. And the spend is invisible, spread across dozens of personal cards. The risk is rarely one dramatic leak. It is being unable to say what happened.