What shadow AI looks like
Shadow AI is AI use that sits outside the organisation's current visibility or approval process. It can include an employee's separate account for a public assistant, a browser extension that summarizes pages, or an agent connected to an internal system. The label describes a visibility gap; it does not prove misconduct or establish that a particular use is unsafe. Start by recording the business purpose, people affected, data involved, permitted actions and the owner who can verify those facts.
Discovery methods (SSO, network, expense, browser)
Use several authorised sources because each shows a different slice of activity. SSO assignments can reveal provisioned services but miss personal accounts and applications that do not use your identity provider. Expense and procurement records can reveal paid services but may use an unfamiliar merchant name or omit free use. Approved browser-extension inventories show what is installed on managed browsers, not necessarily what was used or what data it handled. Network or endpoint evidence can show connections or software indicators, but encryption, mobile devices, off-network use and shared infrastructure can limit attribution. None of these sources alone proves a complete inventory.
Set a bounded discovery scope: business units, managed devices, approved data sources, review period and authorised analysts. Prefer aggregate service and configuration evidence over collecting message contents or individual browsing histories. Record the source, date, coverage and known blind spots for every finding. NIST's voluntary AI RMF 1.0 MAP function calls for establishing and documenting system context, intended purpose and deployment setting; it is a useful risk-management reference, not a discovery tool or certification. NIST says the framework is being revised. Read NIST AI RMF 1.0, especially MAP and its current status page.
Survey template
Use a short, non-punitive questionnaire to learn about workflows that technical sources may not reveal. Send it through an established internal process, explain who will use responses, and do not ask staff to paste prompts, customer records or credentials.
- Which AI-enabled service, feature, extension or agent do you use for this work? If you do not know its name, describe how you access it.
- What work task does it support, and which team owns the workflow?
- What kinds of information are submitted or made accessible? Choose the organisation's approved data categories; use “unknown” when unsure.
- Does it only provide suggestions, prepare drafts, or take an action in another system? Describe the action without including sensitive content.
- What human review or approval occurs before an output is used or an action is completed?
- Which business owner can confirm the service, purpose and access? What evidence source could help verify the record?
Illustrative hypothetical response: “Meeting-summary assistant; operations team; internal meeting notes; drafts summaries only; meeting owner reviews before sharing; service name and retention are unconfirmed.” Treat the unknowns as follow-up questions, not as evidence of a violation.
Triage
First verify that the service or agent exists and that the report describes the actual deployment. Then assign an owner and record purpose, data category, integrations, permissions, human checkpoints, evidence source and confidence. Prioritise follow-up when sensitive data, write access, consequential decisions or unclear ownership is involved, using your organisation's approved process. Keep the reason and reviewer visible. A missing expense entry or a builder's review label is not a legal risk classification, proof of policy breach or evidence that all use has been found.
For example, suppose a team reports a meeting assistant absent from SSO and expense records. Record the service as reported, mark account type and retention unknown, identify the meeting workflow owner, and ask an authorised service owner to verify the deployment and data handling. Do not infer that the report is false merely because two sources did not match.
Bringing tools into governance
Have the accountable owner decide whether to approve, constrain, replace or retire the workflow under existing policy. Capture the decision and evidence reference, define allowed data and actions, and set a review trigger for changes to service, permissions, model or purpose. Reconcile later discovery signals with the owner-validated record. This page offers a manual workflow only: this site does not scan identity, network, expense or browser systems, survey employees, or monitor service use.
For context and implementation guidance, the public ISO overview describes ISO/IEC 42001:2023 as an AI management-system standard, but the licensed normative text was not available in the reviewed source set; this page makes no Annex A clause mapping or conformity claim. The SEO brief also mentions EU AI Act Article 49, but this workflow does not classify systems or determine registration duties; check the official regulation and obtain qualified review before making a legal determination.
Continue with the AI agent inventory builder, the AI inventory template, or the AI agent inventory template.
Sources: NIST AI RMF 1.0; NIST AI RMF status; ISO/IEC 42001 public overview; EU AI Act official text.