- Learn
- How to approach AI automation in your business
- How to detect shadow AI in your business
How to detect shadow AI in your business
Four places to look for unapproved AI use, what to record about each finding, and why blocking tools before measuring them makes the problem harder to see.
Shadow AI is the AI your staff already use that the business never approved. It is rarely malicious. Someone has a deadline, a chatbot is faster than the process, and a client document ends up pasted into a personal account. This guide covers how to find out where that is happening in your business, and what to do once you know.
Why asking does not work
The obvious approach is to ask the team. It under-reports, for ordinary reasons: people do not think a free chatbot counts as a tool, they are not sure whether it was allowed, or they assume the answer will get them in trouble. If you intend to write policy from the answers, you need something better than a show of hands.
The second instinct is to block the well-known tools at the firewall. That moves the activity onto phones and personal accounts, where you can no longer see it at all. Blocking without measuring usually buys the appearance of control rather than control.
Where the evidence actually is
Four places tend to hold usable evidence, in rough order of effort:
Identity and sign-in records. If your business uses Microsoft 365 or Google Workspace, staff signing into third-party AI services with their work account leave a record. This finds sanctioned-looking usage quickly, and misses anything done with a personal account.
Expenses and card statements. Individual AI subscriptions charged to a corporate card, or reimbursed, are one of the more reliable indicators that a tool has become part of someone's daily work rather than an experiment.
Network and DNS logs. Requests to AI service domains from company networks show volume and rough frequency. They show that a service was reached, not what was sent to it, and they stop working the moment someone uses a phone on cellular data.
Direct measurement on the computers themselves. Observing the actual work on participating machines, with the team's knowledge and consent, is the only method that shows the task a person was doing when they reached for an AI tool. That context is what tells you whether the usage is a risk to shut down or a process to fix.
What to record about each finding
A list of tool names is not enough to act on. For each one, record who is using it, how often, what kind of work it is being used for, whether sensitive information is plausibly involved, and whether an approved tool could do the same job. Most usefully, record what the person was trying to accomplish. Shadow AI is usually a symptom of a slow internal process, and the process is the thing worth fixing.
Acting on what you find
Findings generally sort into three piles. Some usage is fine and should simply be brought onto an approved account. Some is genuinely risky, involves client or personal information in an unreviewed service, and needs to stop with a supported alternative offered in its place. The rest points at work that is repetitive enough that staff went looking for help — which is a candidate for automation.
Write the AI use policy after this exercise rather than before it. A policy written against real findings names the tools people actually use and the situations they actually face. One written in advance tends to be ignored by the people it was meant to govern.
Where the assessment fits
The Edgerton assessment measures work across participating computers over ten business days, with agreed scope and staff consent. Unsanctioned AI use is one of the things it surfaces, alongside the repetitive work that tends to cause it. You receive a report and a proposal covering both — what needs attention, and what is worth automating.
It is a measurement exercise, not a compliance certification and not covert monitoring. Staff know what is being measured before it starts. See what an assessment should tell you for how the findings are presented.
Frequently asked questions
Brian Kelly
Founder, Automated Edge
Brian Kelly brings more than 20 years in IT, security, and managed services to Automated Edge. His team measures the work with Edgerton, proposes the improvements, and builds and supports the agreed system with Edgekeeper.
More in this series
How managed AI engagements are priced
Understand the assessment fee, scoped build price, and ongoing service. Compare costs with measured opportunities, not a generic rate card.
How to write an AI use policy for your business
A guide to the decisions behind your AI policy: approved tools, information handling, review, access, and responsible owners.
What an AI readiness assessment should tell you
The evidence, consent, report, and proposal behind a decision to automate. What Edgerton measures and what happens next.
Start with the work.
A free 30-minute conversation about your team, tools and repetitive work. We explain whether a paid Edgerton assessment is a useful next step.
Book a Strategy Call