Discovering Shadow AI: A Three-Step Program That Doesn't Require New Software | Cybernomics
governanceTuesday, July 7, 2026

Discovering Shadow AI: A Three-Step Program That Doesn't Require New Software

Executives often talk about AI governance as if the first step is buying a platform that discovers "all the AI" in an organization. In practice, the discovery that matters - what people are actually using day-to-day -

Discovering Shadow AI: A Three-Step Program That Doesn't Require New Software

Executives often talk about AI governance as if the first step is buying a platform that discovers "all the AI" in an organization. In practice, the discovery that matters - what people are actually using day-to-day - can be found with the systems you already own and a sensible, human-centered process. At a 900-person professional services firm we worked with, leadership believed they had two approved AI tools. A short discovery program found forty-seven. That gap nearly sank their client confidentiality controls - and then became the basis for an acceptable-use policy people actually followed.

This article lays out the three-step discovery program we used - a confidential employee survey, SSO and expense-report data pulls, and a network-egress review - and shows how to turn that inventory into durable governance without purchasing a new SaaS product first.

Why discovery matters (and why buying a tool isn't the first move)
- Shadow AI isn't just a compliance problem. It's an operational and economic risk: inaccurate models, exposure of client data, and wasted spend on duplicated tools.
- Buying another SaaS discovery tool too early creates false confidence. You need an empirical inventory you and your stakeholders trust before you automate governance.
- Discovery done right builds trust with staff. If people feel they'll be punished for disclosure, they'll hide tools. If you make discovery safe and useful, employees become partners in governance.

A real case: 900 people, two "approved" tools, forty-seven in use
The firm had committed to two enterprise AI vendors. IT enforced SSO for core apps, procurement approved subscriptions for specialists, and the board had asked for an AI inventory. We ran a three-week program that found 47 distinct AI products in active use: browser-based copilots, code assistants, image generators, transcription services, and small vendor niche tools purchased on corporate cards. Many were used with client data or uploaded slide decks. The firm avoided immediate client incidents because discovery happened before a regulatory or reputational event did - and they used the inventory to create an acceptable-use policy people followed.

Three-step discovery program (no new software required)
The program has three complementary pillars. Each on its own gives partial visibility; together they produce a practical inventory.

1) Confidential employee survey - create a safe channel for honest reporting
Why: People often use tools directly in their workflows - and they'll tell you if they're not worried about penalties.

How to run it:
- Lead with the right message. Send the survey from an executive sponsor (COO/CIO) and make clear: no disciplinary action for honest disclosure. Emphasize that the goal is to reduce risk and provide approved alternatives.
- Make it quick and anonymous (or confidential with an option to volunteer contact details for follow-up).
- Use a mix of multiple-choice and open-text questions.

Suggested survey questions that get honest answers:
- Which AI tools do you use in your work? (Please list names or URLs.)
- How often do you use each tool? (Daily / Weekly / Monthly / - For each tool listed, what type of data do you typically use with it? (Public info / Internal non-sensitive / Client-confidential / Personal data / Regulated data such as health/finance)
- Do you use a corporate account (SSO / corporate email) or a personal account for this tool?
- Have you ever uploaded client documents, slides, or spreadsheets to the tool? (Yes/No - please describe.)
- If the tool is not approved, why do you use it? (Speed / Accuracy / No approved alternative / Client request / Other)
- Would you switch to an approved alternative if it met your needs? (Yes/Maybe/No - please explain)
- Do you have concerns about any AI tool you use? (Security/privacy / Accuracy / Bias / Cost / None - please describe)
- Would you be willing to speak with IT/security to help evaluate an approved option? (Yes/No)

Why these questions work:
- They distinguish frequency, data sensitivity, and account type - the three factors that determine immediate risk.
- They capture motivation and willingness to switch, which matter for adoption planning.
- They invite help rather than blame, turning employees into participants.

2) SSO and expense-report data pull - map sanctioned and shadow apps from existing systems
Why: SSO catalogs and corporate card data are objective traces of app usage. They reveal which apps are linked with corporate credentials or paid with corporate funds.

What to pull and how:
- SSO/app catalog: Export the list of all OAuth/SAML integrations and recent authentications. Look for apps that request OAuth access, use API tokens, or have been recently provisioned by new hires.
- Indicators to look for: apps with name variations (e.g., "Chat-X" vs "ChatX"), apps classified as "collaboration" or "developer tools," and single-user provisioning.
- Expense reports/corporate cards: Search vendor names and invoice descriptions for keywords: AI, LLM, generator names, "GPT," "copilot," vendor names, "subscription," and web domains.
- Look for one-off payments, small recurring charges, and purchases outside procurement thresholds.

How to reconcile with the survey:
- Cross-reference the list from SSO and expense reports with survey responses. If employees say they use a tool and you see a corporate card charge for it, it's likely a sanctioned or at least supported use case.
- SSO shows where corporate credentials are used; expense data shows where the organization is paying. Together they distinguish personal experimentation from operational use.

3) Network-egress review - the technical sweep that catches browser-only and free tools
Why: Many AI tools are browser-based, accessed without SSO and paid with personal cards. DNS, proxy, and SIEM logs show connections to vendor domains - a strong indicator of active use.

How to do it with existing tooling:
- Pull top destination domains from your perimeter logs (proxy, firewall, DNS) for a rolling 90-day window. Filter out known benign consumer domains.
- Focus on domains tied to AI vendors (model hosts, inference endpoints, api.* subdomains, or well-known product domains).
- Correlate with user IDs and timeframes where possible; if logs are anonymized, combine with HR/manager knowledge to prioritize departments.

Practical notes:
- Start with top domains by volume and number of unique users.
- Use simple scripts or existing SIEM searches to produce a priority list.
- For environments with endpoint DLP or EDR, search for uploads to these domains - that indicates data exfiltration risk.

Triage: turn 47 items into a practical, risk-tiered inventory
Discovery often produces more items than the team can remediate at once. Triage by concrete risk criteria:

Risk factors to consider (use a simple scoring model):
- Data sensitivity: Does the tool see client-confidential, regulated, or PII? (High)
- Account type: Corporate SSO vs personal account. (SSO is easier to govern; personal is riskier.)
- Integration level: API/connected app vs browser only. (APIs usually have higher blast radius)
- Vendor maturity: Enterprise contractual protections and SOC/ISO attestations vs consumer tools.
- Frequency and scale of use: Single user vs many users.

Suggested risk tiers and actions:
- Tier 1 - High risk (client data + personal account or API access, high usage): Immediate review with Legal & Security. Apply DLP rules, require migration to enterprise alternative or temporary block, and open a procurement/legal contract review.
- Tier 2 - Medium risk (internal sensitive data, corporate account, moderate usage): Require justification, add monitoring (DLP, logging), and schedule to move to approved platform or obtain contract terms.
- Tier 3 - Low risk (public data, personal use, occasional): Informational - educate users, recommend approved alternatives, and monitor.

Turning discovery into governance that people follow
Inventory without governance is shelfware. Use discovery results to craft policies and processes that enable safe AI use - not just restrict it.

1) Draft an acceptable-use policy grounded in reality
- Base the policy on the inventory and the triage outcomes. If people rely on certain tools for productivity, your policy should acknowledge that and offer approved alternatives or an exception process.
- Keep rules operational: define what's allowed with public data vs client data, required approvals for regulated data, and mandatory training.
- Include a "safe harbor" for honest disclosure during the discovery window to encourage future reporting.

2) Create a practical approval and exceptions workflow
- Define clear owners: Procurement for vendor contracts, Security for technical controls, Legal for client and regulatory risk, and Business units for use justification.
- Set fast SLAs for exceptions (e.g., 5-10 business days) so teams don't feel forced into shadow choices.
- Maintain a lightweight exceptions register as part of the AI inventory.

3) Operational controls mapped to risk tiers
- High risk: Mandatory enterprise accounts, contractual clauses (data use, deletion rights), DLP policies, audit logging, periodic attestations, and documented business justification.
- Medium risk: Monitoring, user training, and migration plan to approved tools.
- Low risk: Approved list of consumer tools for public data and communication guidance.

4) Ongoing discovery and KPIs
- Schedule quarterly refreshes using the same three data sources. Automate the SSO and expense pulls if possible.
- Track these KPIs: number of AI tools in inventory, number of Tier 1 tools, exception SLA compliance, number of users migrated to enterprise tools, and incidents related to AI use.
- Report to a governance forum (e.g., AI steering committee or risk committee) monthly until steady state.

Change management: from enforcement to adoption
- Communicate outcomes and rationale clearly to staff. Publish an FAQ and migration pathways.
- Provide approved alternatives and migration support (SSO enablement, account provisioning).
- Train managers on the policy and the role they play in approving justified exceptions.
- Reward compliance by highlighting time saved or improved accuracy with approved tools - governance should accelerate, not block, value.

Compliance and frameworks: align but don't paper-over risk
- Use frameworks like NIST AI RMF and the EU AI Act as guardrails when assessing high-risk cases (e.g., systems that impact safety, fairness, or regulated decisions).
- For vendors handling client data, require contract clauses aligned with ISO/IEC 27001/42001 practices and data processing addenda.
- Don't let frameworks become an excuse for paralysis - use them to prioritize the highest risk items uncovered in discovery.

Roles and timeline: a practical plan for a mid-market firm
- Week 0: Executive sponsor message and launch - CIO/COO and head of security.
- Week 1: Deploy confidential survey (1-2 weeks open). IT exports SSO app list.
- Week 2: Pull expense report and corporate card data (30-60 days).
- Week 3: Run network-egress review for top domains (90-day window).
- Week 4: Cross-walk results, tier by risk, and produce an inventory and recommended controls.
- Week 5+: Remediation begins: approvals, migrations, exceptions.

Owners:
- Program lead (PMO or CIO office): coordinate activity and reporting.
- Security: technical review and DLP configuration.
- Legal/Procurement: vendor contract review.
- HR/People: communications and training.
- Business unit leads: justify essential tools and manage migration.

Conclusion - a concrete next step
Discovery doesn't need a vendor or a heavy audit to start - it needs a trustworthy process and the data you already have. The 900-person firm's forty-seven tools became a turning point: they moved from surprise to control, built policy that reflected how people actually worked, and created a governance loop that reduced risk while preserving productivity.

Three actions you can take this week:
1. Send a short, anonymous survey to your staff (use the sample questions above) with an executive note promising no penalties for honest disclosure.
2. Ask IT to export the SSO app list and your finance team to run a 90-day corporate card/vendor name search for AI-related keywords.
3. Pull the top 100 destination domains from your DNS/proxy logs for the last 90 days and flag obvious AI vendors.

Those three steps will give you an evidence-based inventory you can triage and turn into a practical acceptable-use policy - the foundation of being AI-economy-ready.

AI GovernanceShadow AIDiscoveryAI Inventory

Original Article by Cybernomics

Expert operational AI insights for business leaders

Learn About Operational AI