Blog

Shadow AI: How to Find the AI Already in Your Business

Written by sallydeiteratecom | Sep 16, 2026, 10:24:53 PM

Somewhere in your organisation, right now, someone is having a wonderful time with a tool you have never heard of.

They’re not being sneaky. They found something that turns a two-hour job into a ten-minute one and did what any sensible person would do. They used it. Then they mentioned it to a colleague, who mentioned it to two more, and now a small but committed group depends on software that has never appeared in a procurement conversation, a risk assessment, or anyone's budget.

That is shadow AI. It rarely arrives through a decision. It arrives through convenience, and convenience is undefeated.

Stop looking for someone to blame

The instinct is to treat this as a discipline problem. Send a stern email. Remind everyone of the policy. Perhaps deploy the phrase "as previously communicated," which has never once improved a situation.

It won't work, because nobody involved thinks they've done anything wrong. Your team isn't smuggling AI into the building under a coat. They're using a feature that appeared in software you already pay for, or a free tool that solved a Tuesday afternoon problem.

If you want an accurate picture of what's in use, you need people to tell you things. That only happens if telling you is safe.

Where to actually look

Start with the money. Expense claims and company card statements are the least glamorous and most reliable source you have. Individual subscriptions tend to be small enough to slip through approval and large enough to show up in a finance export. Search the last six months for anything ending in ".ai" and prepare yourself.

Check your SSO and identity logs. Every tool someone signed into with their work account left a trace. This is the closest thing to a free answer you'll get, and most organisations have never once looked.

Audit browser extensions. A remarkable amount of AI has entered businesses through a Chrome extension someone installed to summarise web pages. Extensions can read what's on the screen, which is a sentence worth sitting with for a moment.

Read your suppliers' release notes. This is where the genuinely uncomfortable discoveries live. Your CRM, your help desk, your document tool and your meeting platform have all shipped AI features in the past eighteen months. Some arrived switched on. You didn't adopt them. They adopted you.

Look at calendar invites. Note-takers announce themselves by joining meetings with a name and a little icon. If something called Otter, Fathom or Fireflies has been attending your leadership meetings since March, the calendar knows.

Ask, properly. Run a short, blameless survey. Make it explicit that nothing here results in trouble, then ask what people use, what for, and what they put into it. Say the word "amnesty" out loud. You'll get more honest answers in one week than in a year of policy reminders.

What to do with the haul

You'll end up with a list that's longer than expected and messier than you'd like. Good. That list is more valuable than any policy you could write this quarter.

Sort each tool into something rough. Approved and fine. Approved with conditions. Needs a proper look. Absolutely not, please stop immediately.

For the middle two categories, the questions worth answering are what data goes in, where that data ends up, whether the vendor trains on it, who reviews the output before it's used, and who inside your business owns the decision to keep using it. Record the answers somewhere that isn't a person's memory.

Then put the whole lot into an AI register, which is the thing your auditor, your biggest customer and eventually your board will ask to see. ISO 42001 assumes you have one. ISO 27001 auditors are increasingly asking for the same information in a different accent.

The part people skip

Discovery is not a one-time exercise, sadly. Tools keep arriving, suppliers keep shipping features, and your team keeps finding shortcuts, because they are good at their jobs and short of time.

Build a rhythm instead of a raid. A quarterly check of the same sources takes an afternoon and prevents the version of this conversation that starts with a customer asking a question you can't answer.

The organisations that handle AI well aren't the ones with the strictest policy. They're the ones who know what's actually happening.

Not sure where you stand?

Our free AI Risk Assessment takes under five minutes and covers seven layers of AI risk across six business domains, including the ones that tend to surprise people.

Take the assessment or book a demo to see how de.iterate keeps your AI register connected to the risks, suppliers and evidence around it.