Shadow AI detection finds the unapproved AI tools your team already uses, from expense records, logins, browser extensions, and meeting bots, then flags the ones touching client data. Live in two to three weeks.
AI Governance & Security
Quick answer
Shadow AI detection finds the unapproved AI tools your team already uses, from signals you already have: expense and subscription records, login logs, browser extensions, and meeting-bot attendance. You get one inventory of every AI tool in use, the risky ones flagged, and a clear approved-or-blocked list. No single signal catches everything, so a human judges the edge cases. Live in two to three weeks.
The problem
AI tools show up everywhere and belong to no one. Someone expensed a ChatGPT Plus subscription on the company card. Someone else installed a browser extension that reads every page they open. An AI notetaker has been quietly joining client calls for months, recording and storing transcripts in an account nobody vetted. Because no one owns the list, most companies genuinely cannot say which AI tools their people use, or what data those tools see.
Put a number on it. In the 2024 "Oh, Behave!" Annual Cybersecurity Attitudes and Behaviors Report from CybSafe and the National Cybersecurity Alliance, 38 percent of workers admitted to sharing sensitive information with AI tools without their employer knowing. For a 40-person company, that is around 15 people feeding company or client information into tools nobody approved. Most leaders assume the number is a handful. It rarely is.
The hours are not the real cost here. The real cost is a client contract that says their data stays in named systems, quietly broken because someone pasted a deliverable into a free chatbot to summarize it. It is a confidential call recorded by a notetaker you did not know was in the room. It is finding out during a security review, or a client's own audit, instead of on your own terms. None of that shows up until it does, and by then it is a conversation you did not choose to have.
How the automation works
1Step 1
Pull the signals you already have.
The system reads the sources a small company already keeps: expense and subscription records, single sign-on and login logs, a browser and extension inventory, which meeting bots joined which calls, and network or domain-lookup (DNS) signals where they exist.
2Step 2
Match the signals to real AI tools and score the risk.
Each signal gets checked against a directory of known AI tools, then flagged by what it can touch. A grammar helper is low risk. A free chatbot that staff paste client documents into, or an unvetted notetaker sitting on confidential calls, is not.
3Step 3
Turn it into one approved-or-blocked list.
You get a single inventory: every AI tool actually in use, ranked by risk, with a recommended action for each. Approve it, replace it with a safer option, or block it.
The pieces are proven: parsing expenses and subscriptions, reading login and network logs, taking a browser extension inventory, and matching all of it against a directory of known AI tools. The real work is the wiring. No single signal catches everything, so it combines several imperfect sources and still needs a person to judge which tools genuinely put data at risk. And it has to run as an open business inventory, not secret surveillance of individuals. The main way this goes wrong is running it as a gotcha: the moment people feel hunted, they move their AI use somewhere you cannot see it, and you are more blind than when you started. That framing, and the judgment on the edge cases, is what gets set up and handed over during implementation.
What this looks like in practice
Worked example
A 45-person professional services firm handling client documents.
Leadership assumed AI use was limited to "a couple of people on ChatGPT."
Before
No one could name the AI tools in use. The working guess was maybe 3 tools; the real number turned out to be 14.
An AI notetaker had been silently joining client calls for months, storing full transcripts in a free personal account.
Two staff routinely pasted client documents into a free chatbot to summarize them, against what the client contract allowed.
After
One inventory listing all 14 AI tools actually in use, with 4 flagged as touching client or confidential data.
The unvetted notetaker was caught, removed from client calls, and replaced with an approved tool covered by a business data agreement.
The two chatbot habits moved to an approved tool that keeps company data out of training, closing the contract exposure.
Net effect: the firm went from "we think a few people use AI" to a known, risk-ranked list, with the highest-risk client-data leaks closed in the first pass, and a simple approved list people can actually follow.
Typical impact
3x or moreAI tools found than the team expected
2 to 3 weeksfrom kickoff to a full risk-ranked inventory
Client-data leakscaught and closed in the first pass
Typical ranges for this pattern, not client claims. Your numbers get modeled in the audit.
Systems it connects
Google WorkspaceMicrosoft 365Oktaexpense and subscription tools like Ramp and BrexQuickBooksbrowser and extension inventorymeeting tools like Zoom, Google Meet, and Firefliesnetwork and DNS logs where availableAttio
Plus most tools with an API. The audit maps your exact stack.
Who this fits
You handle client or confidential data, so an unapproved AI tool is a real exposure, not a minor one
10 or more employees, past the point where you can just ask everyone what they use
You suspect AI use is happening across the team but have no clear list of what or where
You want visibility and safer approved options, not a way to catch and punish staff
Frequently asked questions
Shadow AI detection is a way to find the AI tools your team uses that were never approved, without guessing. It reads signals a company already has: expense and subscription records, login logs, browser extensions, and which AI notetakers joined which calls. From those, it builds one inventory of every AI tool actually in use and flags the ones that touch client or confidential data. You end up with a clear approved-or-blocked list instead of a vague sense that "people are probably using ChatGPT." The goal is visibility and safer options, not a hunt.
Asking works until it does not: people forget tools, or leave off the ones they suspect are not allowed, which are exactly the ones that matter. This reads real signals, so the list is closer to reality. At the other end, the heavy enterprise security suites (sometimes sold as DLP, for data loss prevention) sit on all your network traffic and are priced and staffed for large security teams. This is lighter and built for a 10 to 70 person company. It works from records you already have, and it produces a decision list you can act on, not a stream of alerts.
No. It inventories tools and data flows at the business level, not individuals. It looks at what AI tools are in use and what data they can reach, using company records like expenses, logins, and meeting attendance. It is not keylogging, reading private messages, or tracking what any one person types. It works best run in the open: you tell the team you are building an approved AI tool list so people can use AI safely. When staff understand the point is safer options and not punishment, they help you find the tools instead of hiding them, which is the only way this stays accurate over time.
It can, and it is built to be honest about that. No single signal catches everything: a tool paid for personally with no browser extension and no meeting bot can slip past. That is why it combines several sources instead of trusting one, and why a person reviews the flags rather than auto-blocking. Every tool on the list points back to the signal that surfaced it, so you can check any item. The first pass finds the bulk of what is there and the highest-risk uses; the ongoing check keeps the list current as new tools appear.
On the signal side, it reads Google Workspace or Microsoft 365 admin and login data, single sign-on tools like Okta, expense and subscription tools like Ramp, Brex, or QuickBooks, browser and extension inventories, meeting tools like Zoom, Google Meet, and Fireflies, and network or DNS logs where they exist. On the output side, the inventory can land in your CRM such as Attio, a shared doc, or Slack, wherever your team will actually see it. Most tools with an API can be added. The audit maps your exact stack and picks the signals that matter for your setup.
Usually two to three weeks. The first days go to connecting the signal sources you already have and pulling the initial data. Then the tools get matched against the directory of known AI tools, the risky ones get flagged, and a person reviews the edge cases with you so the list reflects your real risk, not a generic score. You have a first full inventory quickly. The rest of the window is deciding your approved-or-blocked calls and setting up the light ongoing check so the list stays current after the first pass.
Two parts. Tooling runs as a modest monthly cost for reading the signals and matching them, which scales with how many sources and people you cover. Implementation is a fixed scope, quoted once the audit maps your signal sources, your risk rules, and where the inventory should live, so you are pricing a defined build rather than an open-ended retainer. The audit itself is where the scope and price get set against every other opportunity in your business, priced as part of the audit, so you are not guessing at effort up front.