Shadow AI is the use of AI tools a company has not reviewed, approved, or noticed, often with company or customer data typed straight into them. The fix is not a policy memo. It is finding out what people already use, then writing rules that match reality. A ban written before discovery bans tools nobody admits to using and misses every tool actually in play.

The National Institute of Standards and Technology frames AI governance as a continuous cycle of mapping, measuring, and managing risk, not a one-time document. Its AI Risk Management Framework treats “map” as the first step, because you cannot manage what you have not found. Skipping straight to policy without a map produces rules that go unenforced.

On this page

What shadow AI actually is

Shadow AI is the AI version of shadow IT. It is any AI tool an employee uses for work without IT or security’s knowledge. That includes free chatbots used to draft emails, browser extensions that summarize documents, coding assistants added without a ticket, and AI features switched on inside licensed tools.

The risk is not the tool itself. It is what goes into it. An employee pasting a customer contract into a public chatbot for a quick summary has moved that data outside the company’s control, often without realizing it.

  • Free or personal-account AI chatbots used for drafting, summarizing, or coding.
  • Browser extensions and plugins that add AI features to existing workflows.
  • AI features built into SaaS tools that get switched on by default.

Why policy before discovery fails

A policy written before anyone checks actual usage is a guess dressed up as governance. It names the two or three AI tools everyone has heard of, bans them, and stops there. Meanwhile marketing uses a transcription tool nobody mentioned, and a developer has a code assistant installed that nobody logged.

Worse, a policy built on guesswork gives leadership false confidence. The company believes it has addressed AI risk because a document exists, without checking whether it reflects what happens on real laptops and accounts.

  • Bans list only the well-known tools, missing niche or embedded ones.
  • Staff assume the policy does not apply to tools not named in it.
  • Leadership treats a written policy as proof of control it does not have.

Discovery method: network and DNS traffic review

Reviewing DNS logs and network traffic for known AI service domains is one of the fastest ways to see what is actually used. Most AI tools call out to recognizable domains, and firewall or proxy logs already capture this traffic. The data usually exists and just needs to be read with AI usage in mind.

This method catches usage on company networks and devices, a meaningful slice of shadow AI activity. It will not catch use on personal devices or networks, so pair it with other methods rather than treating it as complete on its own.

  • Pull existing DNS and proxy logs rather than deploying new monitoring first.
  • Match traffic against a list of known AI domains.
  • Flag volume and frequency, not just presence, to find heavy users.

Discovery method: browser extension audits

Browser extensions are a quiet entry point for shadow AI. Many AI writing assistants, summarizers, and research tools install as extensions rather than standalone apps, easy to add and easy to miss. An audit across managed devices, run through the browser’s management console, surfaces these quickly.

This is worth doing on a schedule, not just once. New extensions appear constantly, and a yearly audit will miss most of what shows up in between.

  • Pull an extension inventory from the browser management console on managed devices.
  • Cross-reference extension names against known AI tool categories.
  • Repeat the audit on a regular cadence, not as a one-time sweep.

Discovery method: procurement and expense records

Finance records tell a story IT logs miss. Expense reports and card statements show subscriptions to AI tools an employee or team paid for directly, without going through procurement. A line item for a monthly AI subscription is a clear signal, sitting in a system most companies already review.

This method does not depend on technical detection. It works off paperwork that already gets generated and, in most companies, reviewed.

  • Search expense and card statements for recurring AI vendor charges.
  • Review procurement requests that were denied or never submitted.
  • Cross-check departmental software budgets against approved vendor lists.

Discovery method: employee surveys done right

Asking employees directly works, but only if the framing removes fear. A survey opening with a warning about consequences gets silence. One that says the goal is understanding real workflows, with no penalty for past use, gets honest responses.

Anonymity helps. So does asking about tasks rather than tools. Asking what someone uses to draft first versions of documents surfaces more than asking whether they use AI tools.

  • Frame the survey around understanding workflows, not catching rule breakers.
  • Offer anonymity so people answer honestly about past use.
  • Ask about tasks and workflows, not just tool names.

Operating rule: Do not write an AI usage policy until you have run at least one discovery method across network logs, procurement records, and employee input. A policy based on assumption is not a policy. It is a hope.

Why outright bans push usage underground

A flat ban on AI tools rarely stops usage. It stops reporting of it. Employees who find a tool genuinely useful keep using it, more quietly, often switching to a personal device. That is worse for the company than open use, because it removes visibility entirely.

The Cybersecurity and Infrastructure Security Agency’s joint guidance on deploying AI systems securely stresses that organizations need visibility into how AI is used to manage the risk. A ban that drives usage underground removes that visibility.

  • Employees move to personal devices to keep using a valued tool.
  • Reporting drops even as actual usage continues or grows.
  • Security teams lose the visibility they need to manage real risk.
Approach Effect on visibility Effect on actual usage
Flat ban, no alternative Drops sharply as use moves underground Continues, often on personal devices
Discovery first, then policy Rises as usage patterns become known Shifts toward approved, monitored tools
Approved alternative offered Stays high because there is no reason to hide Consolidates around one supported tool

Why an approved alternative beats a ban alone

Employees turn to AI tools because they solve a real problem, whether drafting faster, summarizing documents, or getting past a coding block. Removing the tool without addressing the need just sends the employee looking for a replacement, often one less secure than the first.

Offering a vetted, approved AI tool that does the same job removes the reason to go around the rules. This is the lesson security teams learned from shadow IT years ago. Blocking a tool without a sanctioned equivalent rarely closes the gap. It relocates it.

  • Identify the task the unapproved tool was solving before removing it.
  • Offer an approved tool that covers the same task.
  • Make the approved tool as easy to access as the unapproved one.

Treating findings as inventory, not just discipline

When shadow AI use turns up during discovery, some organizations treat it as a violation to punish. That instinct discourages honesty and wastes useful information. Every discovered tool is a data point about what the workforce needs, and that point belongs in the AI inventory alongside approved tools.

An inventory built this way reflects the organization as it actually operates, not as policy assumed. That is a stronger foundation for security controls and tool decisions than a list built entirely from top-down approvals.

  • Log every discovered tool in the AI inventory, approved or not.
  • Use discovery findings to inform which tools get evaluated next.
  • Reserve disciplinary action for clear, repeated violations after a policy exists.

FAQ

What is the difference between shadow AI and shadow IT?

Shadow IT covers any unapproved technology, from hardware to software. Shadow AI is the subset involving AI tools, and it carries added risk because these tools often process and retain typed data in ways users do not expect.

Is shadow AI always a security incident?

Not always. Many cases involve an employee trying to work faster with no intent to cause harm. Treating it as discovery and inventory gets better results than treating every case as an incident.

How do we find shadow AI use that happens off the company network?

Network and browser methods miss activity on personal devices and networks. Procurement reviews catch some of this if the employee expenses a subscription. Honest, non-punitive surveys surface the rest.

Should IT block all unapproved AI domains immediately?

Blocking before discovery risks the same problem as a written ban. Discovery first, followed by an approved alternative, produces better outcomes.

How often should shadow AI discovery be repeated?

AI tools and browser extensions change quickly, so a single sweep goes stale fast. Repeating network reviews and extension audits quarterly keeps the inventory current.

Does an approved AI tool eliminate shadow AI entirely?

No single control eliminates it. An approved alternative reduces the incentive to go around policy, but ongoing discovery is still needed as new tools appear and preferences vary.

Who should own shadow AI discovery inside a company?

It works best as a joint effort between IT, security, and finance, since each holds a different piece of the picture. No single team has full visibility on its own.

Related reading

Conclusion

Shadow AI cannot be governed by a policy written in the dark. Discovery through network review, browser audits, procurement records, and honest surveys gives a company the real picture before it writes a single rule. Bans without alternatives push usage underground and destroy the visibility security teams need most. The stronger path treats every discovered tool as part of the AI inventory, offers a sanctioned alternative where needed, and saves discipline for clear violations of a policy built on evidence.

Sources

Previous post AI Incident Response Needs a Model-Specific Playbook
Next post AI Access Logging Needs Prompt-Level Detail