Managed IT · 5 min read

Shadow AI: finding and managing the AI tools your staff already use

Employees adopt AI tools faster than policies can keep up. How to discover shadow AI, reduce the data risk and give people approved alternatives they will actually use.

· Bhargava Group

Your staff are using AI tools you have not approved. They are not doing it to cause trouble. They are doing it because the tools save time. The risk is what goes into them: customer lists pasted into a free chatbot, contracts uploaded to a summariser, source code shared with a browser extension.

Banning AI outright rarely works. It pushes usage onto personal phones and accounts, where you have no visibility at all. A better approach is to see it, steer it and supply something better.

See it: discover what is in use

  • Network and endpoint telemetry. Secure web gateways, DNS filtering and endpoint tools can report traffic to AI services by user and volume.
  • Identity logs. Look for sign-ins to third-party apps with company accounts, and for OAuth consents that grant AI tools access to mail or files.
  • Browser extensions. Inventory extensions on managed browsers. Many “AI assistants” request permission to read every page.
  • Ask. A short, non-punitive survey often surfaces more than the logs do.

Steer it: set clear, short rules

A one-page policy people can remember beats a long one nobody reads:

  1. Use approved tools for company work.
  2. Never enter personal information, customer data, credentials or unreleased financials into unapproved tools.
  3. You are responsible for checking AI output before you use it.
  4. Ask IT if you need a tool that is not on the list, and expect an answer within a week.

That last point matters. If approval takes months, shadow AI wins.

Supply it: give people something better

The most effective control is an approved alternative that is as good as the tool it replaces. For many organisations that means an enterprise AI assistant tied to company identity, with data protection commitments, logging and administrative controls. Approve a short list of specialist tools with reviewed terms for the teams that need them.

Enforce proportionately

Once approved options exist:

  • Block the highest-risk categories, such as unknown AI services that accept file uploads.
  • Use data loss prevention to warn on, or stop, sensitive data being pasted into AI sites.
  • Review OAuth app consents regularly and revoke those that are not needed.

Keep the register current

Every tool you approve goes into your AI register with an owner and a review date. Shadow AI becomes visible AI, and visible AI can be governed.

Our Managed IT & Cybersecurity practice can run a discovery, draft the policy and put the technical controls in place in a few weeks.

All insights

Talk to us

Talk to Managed IT & Cybersecurity.

A 30-minute consultation with a senior consultant. You leave with a clear next step — whether or not it involves us.

Privacy choices

Choose which optional technologies we may use. You can change this at any time from “Privacy choices” in the footer.

Strictly necessary

Security, spam protection (Cloudflare Turnstile) and remembering these choices. Always on.

Always on