Deployment Labs
Free tool~5 minutes

Shadow AI audit: find what your team already uses, then give it a name.

Your people are using AI whether or not anyone approved it. Fourteen questions turn that into a registry — every kind of tool in use, where it lives, who should own it, and whether to keep it, move it, retire it or register it. The tool is usually fine. The account it runs on usually isn't.

Shadow AI Audit · Step 1 of 40/13 answered
  1. Your organisation
  2. What people are actually using
  3. Who uses it and what goes in
  4. Ownership and lifecycle
1

Your organisation

So the registry is written in your name, with an owner on it.

Roughly how many people?

A name or a role. Leave it blank and the registry will say so — that is itself a finding.

Why it matters

Shadow AI is the normal state. Unmanaged is the choice.

90%

of companies have employees regularly using personal AI tools for work. Only 40% of companies have bought an official subscription.

MIT NANDA, The GenAI Divide, 2025
$670K

added to the average cost of a breach when shadow AI is involved. Shadow AI was a factor in one breach in five.

IBM Cost of a Data Breach, 2025
42%

of mid-market IT leaders confirmed an AI-related security incident in the last twelve months. Only 42% have an enforced AI policy.

Netrio, 200–5,000 employee companies, June 2026
48%

of desk workers are uncomfortable telling their manager they used AI. Ban it and the usage does not stop — the visibility does.

Slack Workforce Index
What you get

The first artifact of AI governance, done in an afternoon.

Most AI governance starts with a policy. A policy written before the registry describes tools nobody uses and misses the ones everybody does. This puts the inventory first, with a name next to every row.

01

A registry, not a report

One row per kind of tool in use — where it lives, its status, a slot for an owner, the data it is exposed to, the next action, and a review date.

02

Keep, move, retire, register

Every row resolves to one of four actions. The tool people chose is usually fine; the account it runs on usually is not. Nothing here says 'ban'.

03

A coverage score

How much of what is in use is known, owned and reviewable, 0–100, so you can see the gap and measure it closing.

04

Flags that need a decision this week

Credentials in chat windows, client calls recorded on personal note-takers, PHI without a BAA, usage mandates with no visibility.

05

The gaps in your registry discipline

Visibility, ownership, intake, off-boarding, and staff-built prompts — which of the five you are missing, and the specific fix for each.

06

A 30-day plan

Find it, name it, sort it, open a front door. Then, and only then, the policy and the training.

The playbook

Every step behind the audit — the three finders, the four statuses, the front door, and why bans and usage mandates both backfire — written up in full.

Read the Shadow AI Playbook
Questions

About shadow AI