Posted on

Shadow AI Oversight: 6 Unapproved Tools in Your Business

Team reviewing a list of AI tools employees use without approval

Shadow AI is not a hypothetical. Survey after survey finds that a large majority of knowledge workers have used an AI tool at work without approval, and that a substantial share deliberately hide it from their managers. Verizon’s most recent Data Breach Investigations Report placed shadow AI among the most common non-malicious insider actions turning up in data-loss incidents, and it climbed sharply year over year.

The useful question is not whether it is happening in your business. It is which categories are present, because they carry different risks and only some of them can be found by looking for unfamiliar vendors. This shadow AI oversight guide walks the six we find most often, in rough order of how easily they are missed.

Why This Is Not Just Shadow IT Again

Shadow AI inherits the shape of the shadow IT problem, which we covered in our piece on shadow IT risk for growing companies, but two things are different enough to change how you handle it.

The first is what gets sent. Unapproved file-sharing exposed documents people chose to upload. Unapproved AI receives whatever context somebody pasted to get a useful answer, which routinely includes a client contract, a patient summary, a salary list, or a block of proprietary code. The exposure is in the prompt rather than in a file, so it leaves no upload to review.

The second is where it lands. Most of these accounts are personal rather than company-controlled, so your data sits in a consumer service under someone’s private login, outside your retention rules, invisible to your audit trail, and beyond your reach if that person leaves. You cannot produce it for a client request and you cannot delete it.

1. Personal AI Chat Accounts

The most common category and the easiest to picture. Somebody signs into a general-purpose assistant with a personal email and uses it for real work: rewriting a client email, summarising a contract, cleaning up a spreadsheet, drafting a policy.

This rarely feels like a policy breach to the person doing it. They are not installing anything, not sharing a password, and not touching a company system. They opened a website and typed. That framing is why bans do not work well on their own, because the behaviour does not register as the kind of thing a ban would cover.

What makes it consequential is volume and habit. It is not one prompt with one contract. It is months of pasting whatever was on screen into a service with no agreement covering your data.

2. Meeting Assistants and Transcription Bots

The second category attends your meetings. Somebody connects a note-taking assistant to their calendar, and from then on it joins calls, records them, transcribes them, and stores summaries in a service you have no relationship with.

This one deserves particular attention for two reasons. Its capture is indiscriminate, so it collects the candid part of the conversation along with the agenda, including client details, commercial terms, and personnel discussion. And it involves other people. When it joins a call with a client or candidate, you have arguably recorded a third party through an unvetted processor, which is a consent question as much as a security one.

Check the calendar side of this specifically, because a connected assistant keeps attending long after the person has stopped thinking about it.

3. Browser Extensions With Page-Read Access

Third are AI extensions installed in the browser. A summariser, a writing helper, a research tool. To function, most of them request permission to read the content of the pages you visit.

That permission is much broader than the feature suggests. A logged-in browser session reaches your email, your CRM, your finance system, and any client portal you use, and an extension with page-read access sees what is rendered there. The user consented to a writing helper. What they actually granted was a reader sitting inside every authenticated session on that machine.

Extensions are also the category most likely to change hands. A useful tool acquired by a new owner can ship an update with different data practices, and nothing prompts the user to reconsider.

4. AI Features Inside Tools You Already Approved

This is the category almost every shadow AI review misses, and it is the one we would look at first.

Vendors have spent the last two years switching AI features on inside existing products. Your CRM summarises accounts, your help desk drafts replies, your document platform answers questions about your files, your HR system screens applications. No new vendor appears, no new subscription shows up in expense reports, no unfamiliar domain appears in your traffic, and often no consent screen is shown to anyone.

That makes it structurally invisible to the usual discovery approach, which works by spotting unknown services. Nothing is unknown here. The tool was approved, the invoice is expected, and the capability arrived in a release note. Meanwhile it is the category processing your most sensitive records, because these are the systems holding your client and employee data.

Handle it as a review of your existing vendors rather than as a hunt. For each significant system, ask three questions: what AI features are enabled, what data do they process, and is our content used for model training. The third question matters most and its answer often depends on which plan you are on. Our note on securing data privacy in an AI-driven world covers the contractual side of that.

5. AI Coding Assistants on Proprietary Code

If you build or maintain software, this category is worth separating out. Developers adopt AI assistants faster than any other group, usually before procurement is aware, and the material involved is your source code, your configuration, and sometimes credentials embedded in what gets shared for context.

Two specific risks sit here. Code and configuration pasted for debugging can include connection strings and keys, which is a credential exposure rather than a confidentiality one. And a personal-tier assistant may retain submitted content in ways an enterprise agreement would exclude.

The fix is usually straightforward, because this is one group where an approved alternative is genuinely wanted. Provide a company-controlled option with a proper agreement and most of the personal usage stops on its own.

6. Free Document and Screening Tools

The last category is the one-off utility. A free service to translate a document, compress a PDF, summarise a report, or rank a stack of CVs. Nobody thinks of these as AI adoption, so they never come up in a survey, and there is no account to discover because many require no sign-in at all.

The documents involved tend to be the sensitive ones. People reach for a quick converter precisely when handling something unusual: a signed agreement, a medical letter, a batch of applications. Recruitment screening carries its own exposure, since running candidate data through an unvetted service raises fairness and data-protection questions well beyond confidentiality.

What to Do About It

The instinct is to ban, and bans mostly relocate the behaviour. People who were using an assistant openly start using it on their phones, which removes your visibility without removing your exposure. A more effective sequence:

  • Ask before you scan. An amnesty survey, genuinely framed as no-blame, surfaces more in a week than tooling finds in a month, and it tells you what people were trying to accomplish.
  • Review the vendors you already have. Work through your significant systems for enabled AI features and training-data terms. This is the invisible category and it is entirely reviewable.
  • Provide sanctioned options that are actually good. Shadow AI thrives where the approved tool is worse or slower. A company-controlled assistant with a real agreement removes most of the demand.
  • Write a short, specific policy. Name what may never be pasted into an unapproved tool, in concrete terms: client records, patient information, credentials, source code, personnel data. A one-page rule people can remember beats a document nobody opens.
  • Handle discoveries as conversations. When you find something, ask what business need drove it, then either adopt a safe version or point to an existing approved tool. Responding punitively guarantees the next one stays hidden.

None of this requires new platforms. It needs one honest inventory, a vendor review, and a policy short enough to be read, which is a few weeks of steady work for most companies. For deeper oversight of AI systems you deliberately deploy, our pieces on AI agents and data privacy and enterprise-grade agent governance go further.

If you would rather not run the inventory alone, our cloud security and AI agents teams do this review with clients, and our data breach response team is who you want if something has already been exposed. Book a free strategy call and we will start with the vendors you already pay for.

Frequently Asked Questions

What is shadow AI?

Shadow AI is the use of artificial intelligence tools at work without approval or oversight. It covers personal assistant accounts, meeting transcription bots, browser extensions, free document utilities, and AI features enabled inside software your business already uses.

Why is shadow AI riskier than shadow IT?

Because the exposure sits in what people type rather than in files they upload, so it leaves no artefact to review, and because most of the accounts are personal rather than company-controlled. That puts your data outside your retention rules and audit trail, and beyond your reach once the employee leaves.

What is the hardest kind of shadow AI to find?

AI features switched on inside tools you already approved. No new vendor appears, no new subscription shows up in expense reports, and often nobody is shown a consent screen, so discovery aimed at unknown services cannot see it. It is also the category handling your most sensitive client and employee records.

Should we just ban AI tools at work?

A ban alone usually moves the activity to personal phones, which removes your visibility without reducing your exposure. Pairing a short and specific policy with a sanctioned tool that is genuinely good removes most of the reason people went looking elsewhere.

How do we find out what our team is actually using?

Start with a no-blame amnesty survey, which typically surfaces more than technical discovery does and explains the business need behind each tool. Then review the AI features and training-data terms of the systems you already pay for, since that is the part no survey will reveal.

Related Posts

Matt Rosenthal