Finding shadow AI in your organization (and what to do about it)

You find shadow AI by reading records you already hold — sign-in and OAuth consent logs, DNS or proxy traffic, expense claims and browser-extension inventories — and then asking staff directly what they use and why. What you do about it is rarely a ban: triage by the data reaching each tool, give people a sanctioned alternative, and write an acceptable-use policy that points at it.

Where does shadow AI show up?

No single source sees everything, so use several and record which one found each tool.

SourceWhat it findsWhat it misses
SSO and OAuth consent grantsAI apps connected to mail, files and calendars with a work identityAnything used with a personal account
DNS, proxy or secure web gateway logsWhich AI services are reached from managed networks and devicesHome networks, phones, and what was sent
Expense and card dataSubscriptions bought on a card and claimed backFree tiers
Browser-extension inventoryWriting and meeting assistants that read every pageUnmanaged browsers
Supplier release notes and admin consolesAI features switched on inside products you already pay forNothing announced
A short staff surveyWhat people paste in, and whyWhat people prefer not to mention

Pull the OAuth consent grants from your identity provider. It is quick, it needs no new tooling, and it shows the AI apps that already hold standing access to your mail, files or calendars. OAuth grants deserve particular attention: an app that can read a mailbox keeps reading it long after the person who clicked “allow” has forgotten.

Is it worth asking staff directly?

Yes. Logs tell you which tools are reached; only people can tell you what they paste in and why. Run it as an amnesty rather than an investigation, or the answers will be the ones people think you want. Ask three things: which tools, for which tasks, and what kind of information goes in. The task list is the most useful output of the whole exercise, because it tells you what a sanctioned tool has to do to be adopted.

Which findings should you act on first?

Rank each finding by two questions: what data reaches it, and under which account.

  • Act now: personal, health, financial or client-confidential information reaching a tool on a personal account, or an app holding standing access to mail or files. Where personal information is involved, take it to counsel.
  • Review: confidential business content on a work account, where the vendor’s terms on training and retention are unknown.
  • Record and move on: nothing sensitive goes in.

The NIST AI Risk Management Framework makes the inventory itself an explicit governance outcome:

Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities.

That is GOVERN 1.6 in version 1.0 of the AI RMF, which NIST says it is revising; check the numbering against the current text, as this is written as of September 2026. Note the second half: resourced by risk, not uniformly.

Does banning AI tools solve it?

Blocking the obvious sites is reasonable for tools you have decided against, but a blanket ban mostly moves use onto personal phones and accounts, where you can see nothing. A block works when it sits next to a sanctioned alternative.

The version that holds has three parts. An acceptable-use policy that names what must never be pasted into a general-purpose tool. A sanctioned tool, covering the tasks the survey surfaced, with business terms on training and retention. And a quick route to ask for something new. Building that environment is covered in secure AI environment establishment.

What are the privacy implications?

Shadow AI is often a privacy problem first. Where PIPEDA applies, clause 4.1.3 of its accountability principle keeps an organization responsible for personal information “including information that has been transferred to a third party for processing”, and expects “contractual or other means” to protect it there. A tool someone signed up for without asking rarely comes with either. Where personal information has already gone into an unsanctioned tool, ask your counsel whether that is a breach of security safeguards: PIPEDA section 10.3 requires a record of every such breach, and section 10.1 requires a report to the Privacy Commissioner where the breach creates a real risk of significant harm. That decision is theirs, not ours. Canada’s privacy regulators set out how their principles apply to organizations that use generative AI in their principles for responsible, trustworthy and privacy-protective generative AI.

Does looking for shadow AI raise privacy issues of its own? It can. Discovery reads records about employees, so scope it to tools and data categories, aggregate where you can, and check the method against the privacy law that applies to you with your counsel before it runs. Where the answer is contested, it is a legal question, not a security one.

Discovery is also the first half of vendor risk. Once you know which tools hold which data, the review questions follow; they are set out in shadow AI discovery and AI vendor risk and, for suppliers asking you, in answering the AI security questionnaire.

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

Should we just block AI tools?

Blocking the obvious sites is reasonable for tools you have decided against, but a blanket ban mostly moves use onto personal phones and accounts, where you can see nothing. A block works when it sits next to a sanctioned alternative.

Is a staff survey really worth doing?

Yes. Logs tell you which tools are reached; only people can tell you what they paste in and why. Run it as an amnesty rather than an investigation, or the answers will be the ones people think you want.

Does looking for shadow AI raise privacy issues of its own?

It can. Discovery reads records about employees, so scope it to tools and data categories, aggregate where you can, and check the method against the privacy law that applies to you with your counsel before it runs.

What should we do first?

Pull the OAuth consent grants from your identity provider. It is quick, it needs no new tooling, and it shows the AI apps that already hold standing access to your mail, files or calendars.

Starting the inventory

Tell us which identity provider and network tooling you run, and which data you worry about most. The reply is a discovery plan scoped to tools and data, not people. More of our writing is at writing.

Discuss a scope