
September 14, 2026 • 10 min read
Shadow AI: How to find and govern unsanctioned AI
AI adoption is outpacing readiness. In our survey of 400+ risk leaders and platform data covering over 50% of the Fortune 500, 53% of organizations are already implementing AI-specific tools. Yet fewer than 30% feel prepared for upcoming AI governance requirements. That gap has a name: shadow AI.
Shadow AI is the artificial intelligence version of shadow IT. Your employees paste sensitive data into public chatbots, install AI browser extensions, and sign up for AI writing tools on their own cards. Each one moves faster than your governance program can track. Every unsanctioned tool becomes a potential compliance gap, a data-leak vector, and an audit finding waiting to happen.
If AI use is invisible, risk is left unmanaged. This guide gives Compliance, Risk, and IT/infosec leaders a practical playbook to detect shadow AI across the organization, then bring it under control without slowing teams down.
Why shadow AI matters more than shadow IT
Shadow IT places unapproved software on your network. Shadow AI does that and more. It sends your data somewhere you can't see, trains on inputs you can't retract, and produces outputs your teams treat as fact.
The stakes are higher for three reasons:
- Data exposure is permanent. Data pasted into a public model may be retained, logged, or used for training. You can't pull it back.
- Regulation is arriving fast. Frameworks like the EU AI Act and ISO 42001 set expectations for AI inventory, risk classification, and human oversight. You can't map controls to tools you don't know exist.
- The typical enterprise already managed a heavy control burden. Our telemetry shows the median enterprise maps its controls to about seven frameworks, covering roughly 2,700 requirements. Add ungoverned AI on top, and the gap grows fast.
Our research found that only 25% of organizations have comprehensive visibility into how employees use AI. Ungoverned AI turns a productivity win into a liability. Governed AI turns it into a competitive edge.
How to detect shadow AI in your organization
Detection isn't one scan. It's a layered sweep. Run these five methods together for a full picture of unsanctioned AI tools across your environment.
1. Run a SaaS audit
Start where the tools live. Pull your identity provider logs, single sign-on records, and OAuth grants to see every app connected to your corporate accounts.
- Review OAuth tokens and third-party app connections in Google Workspace or Microsoft 365.
- Filter for AI vendors and any app with broad read/write permissions to email, files, or calendars.
- Flag tools with data-sharing scopes you never approved.
A SaaS management platform speeds this up by surfacing unsanctioned subscriptions automatically. If you don't have one, an SSO export gets you most of the way.
2. Audit browser extensions
AI browser extensions are the easiest tools to install and the hardest to see. Employees add them in seconds, and many read every page they visit.
- Use your endpoint management or MDM tool to inventory installed extensions across managed devices.
- Identify AI extensions that capture page content, keystrokes, or form data.
- Check what permissions each extension holds, then remove or restrict the risky ones.
Extensions that read page content can scrape customer records, financial data, and internal documents. Treat broad permissions as a red flag.
3. Survey your employees
Only 11% of professionals strongly agree that organizations are giving sufficient attention to ethical standards (ISACA), pointing to a leadership vacuum when it comes to AI guidance. Your teams are already using AI, and they’re waiting for you to define what responsible use looks like.
- Anonymize responses so that employees feel more comfortable giving honest answers.
- Ask what problem each tool solves as an AI needs assessment so that your organization can find better solutions with less risk.
- Tie survey findings to a visible outcome, telling respondents what comes next.
Frame the survey as enablement, not enforcement. Employees turn to shadow AI because it helps them work. Learn why, and you'll design better sanctioned options.
4. Review expense reports
Follow the money. Corporate cards and reimbursement claims expose AI subscriptions that never touched your SSO.
- Search expense data for known AI vendors and generic descriptors like "software subscription."
- Flag recurring small charges that could be indicative of a personal AI tool.
- Cross-reference with your approved-vendor list to spot the gaps.
Expense review catches the tools employees pay for directly, which SaaS audits and network monitoring often miss.
5. Monitor network and API traffic
Close the loop with traffic data. Your network and API logs show connections to AI services in real time.
- Use your secure web gateway, CASB, or firewall logs to identify traffic to known AI domains and API endpoints.
- Watch for large or frequent data transfers to AI providers.
- Set alerts for new AI destinations so detection becomes continuous, not a one-time project.
Network monitoring is the only method that keeps working after the audit ends. Make it your ongoing early-warning system.
How to govern shadow AI once you find it
The goal is to move your teams from unsanctioned tools to approved ones without killing the productivity they're chasing. Your teams found faster ways to work. Governance needs to turn that demand into a safe, approved path.
Build a sanctioned-tool pathway
Give employees a "yes" before you give them a "no." When people have an approved, capable tool, the pull toward shadow AI drops fast.
- Publish a clear list of approved AI tools and the use cases each one covers.
- Vet vendors for data handling, retention, and compliance with your frameworks.
- Make approval fast. A slow pathway pushes people right back to shadow AI.
The best-governed enterprises treat AI enablement as a feature, not a favor. Give teams the tools they need, on your organization’s terms.
Enforce policy with clear rules
Put the guardrails where the work happens. When you start adding approval prompts to your procurement flow and triggering quick reviews when someone requests a new AI tool, compliance starts becoming automatic.
- Define what data can and can't go into AI tools. Be specific about customer data, PII, and regulated records.
- Map each approved tool to the frameworks you report against, so evidence links to controls automatically.
- Enforce technical guardrails: block unapproved AI domains, restrict risky extensions, and set data-loss-prevention rules for AI destinations.
Pair the written policy with automated enforcement. Rules on paper won't stop a paste into a public chatbot. Controls will.
Create an escalation path for new requests
New AI tools launch every week. Your governance has to keep pace. An escalation path turns "no" into "not yet,” or “here's how."
- Give employees a simple way to request review of a new AI tool.
- Set a service-level target for how fast requests get answered.
- Route high-risk requests to compliance and security for a joint call.
A working escalation path does two things. It surfaces new shadow AI before it spreads, and it signals that your program enables progress instead of blocking it.
Turn AI governance into a strategic edge
Shadow AI won't disappear. Your employees will keep reaching for tools that make them faster. Your job isn't to stop them. It's to see what they use, govern the risk, and give them safe alternatives.
You now have the playbook to do it:
- Detect what's already running. Combine network logs, expense data, browser signals, access reviews, and employee input to map every AI tool in use.
- Survey your people. A short, anonymous needs assessment surfaces the tools and unmet demand no scan will catch.
- Build a sanctioned-tool pathway. Give teams a living list of vetted tools and a fast-track approval process, so the approved path becomes the easy path.
- Embed policy in workflows. Put guardrails at the point of decision, map each tool to your frameworks, and enforce technical controls automatically.
- Monitor on a cadence. Reassess your list and controls quarterly, so approvals keep pace with what your teams actually need.
See what separates risk leaders from laggards in 2026. Download The Risk Intelligence Report to unlock the three-phase roadmap to connected risk maturity.
You may also like to read

Seven best cyber risk platforms in 2026

Best third-party risk management software in 2026

Best risk management software in 2026
Discover why industry leaders choose Optro
SCHEDULE A DEMO



