Shadow AI is the part of your AI risk nobody budgeted for. Here's how to find it without turning discovery into a witch hunt.
By the NTD Consulting principal. Former CTO/CIO at public companies and CISO at a Nasdaq-listed crypto FinTech platform.
Every AI governance conversation starts the same way. Someone asks "so what AI are we actually using?" and the room discovers, usually within an hour, that nobody knows. Procurement knows what was purchased. Security knows what was flagged. Nobody knows what the marketing team adopted in a Slack channel eight months ago.
That gap is the whole game. Every control you want to build, approval workflows, vendor reviews, oversight, reporting, references the inventory. Skip the inventory and your AI policy is a press release.
Not exfiltration. Not a breach. Shadow AI is mundane. A senior engineer running a personal license of a code assistant because the company one is worse. An analyst pasting a customer spreadsheet into a chatbot to save an hour. A support platform whose vendor quietly shipped a "smart reply" feature that trains on your tickets by default.
The last one is the dangerous category, and it's growing. The AI came pre-installed inside a tool you already approved. Nobody made a decision; a feature flag flipped. When I run discovery with a new client, embedded features inside approved SaaS routinely account for the biggest jump in findings, ahead of the shadow tools everyone half-knows about.
One discovery technique catches one category of blind spot. Run all four. Where the results don't overlap is exactly where your unknowns live.
First, ask people. A short blameless survey plus a handful of interviews. Two questions work: "What AI do you use for work?" and "What AI features have appeared inside tools you already use?" The phrasing matters. If people think the answers trigger a crackdown, you'll get nothing and learn less. I've watched a first survey come back with three tools listed and a DNS log show forty. The survey was still useful, it told us which tools people depend on, which is a different question than which tools exist.
Second, follow the money. Expense reports and procurement records. AI subscriptions and API credits are small dollar amounts with long shadows. The tools people pay for personally are the ones they actually rely on, which tells you where governance will hurt if it's clumsy.
Third, watch the estate. This pass runs along two tracks. The first is network traffic: look at CASB or DNS logs for AI service categories and you'll see what's actually being reached, including the free tools that never touch an expense report. The second is your SSO catalog: sweep it for AI features enabled inside products you already own, because vendors ship those quietly. I have used Cato Networks for this piece myself; it gives me the traffic view and the policy controls to block or allow AI categories per user group, which makes the discovery output actionable instead of just informational.
Fourth, reconcile and repeat. Merge everything, assign each finding an owner, a purpose, a data-sensitivity tier, and a review date. Then put the whole exercise on a quarterly clock. AI adoption moves faster than annual audits and the inventory rots quietly if nobody owns it.
An inventory by itself earns nothing. Within six weeks of discovery, a lean program can be standing:
Every item gets a risk tier by data sensitivity and business criticality, which decides how much review it deserves. One named person approves new AI use, and the front-door process needs to be faster than the side door or people will route around it. Acceptable-use rules stay short and scenario-based, wired into onboarding and procurement so they're enforced rather than filed. Human oversight gets defined per tier, from full review of customer-facing output down to sampled QA. And AI vendors get the same treatment as any other critical vendor, with the questions that matter: training-data practices, retention, sub-processors, and notice when a model changes underneath you.
That whole structure maps onto NIST's AI Risk Management Framework if your customers or auditors speak it. The heavier machinery, formal model validation, certifiable management systems, incident playbooks for model failure, can wait until your risk actually calls for it. Most companies' doesn't yet.
The diligence question has changed. It used to be "do you use AI?" Now it's "how do you govern it," and the follow-up is "show me." With the inventory and the program above, that follow-up is an artifact: what's in it, what changed this quarter, what's approved, what's pending, what near-missed. Without it, the same question starts a two-week scramble that ends with a weaker negotiating position.
Our AI governance advisory runs this sequence end to end, and the downloadable policy template gives you the starting structure for the policy layer. Both are useful even if you never hire us; the inventory exercise is something a competent two-person team can run internally with a month of part-time effort.
The 30-minute assessment is free. We'll tell you where the likely gaps are and whether the inventory you have would survive a diligence question.
Schedule a 30-Minute Consultation