Shadow AI audit: find what your team already uses, then give it a name.
Your people are using AI whether or not anyone approved it. Fourteen questions turn that into a registry — every kind of tool in use, where it lives, who should own it, and whether to keep it, move it, retire it or register it. The tool is usually fine. The account it runs on usually isn't.
- Your organisation
- What people are actually using
- Who uses it and what goes in
- Ownership and lifecycle
Your organisation
So the registry is written in your name, with an owner on it.
A name or a role. Leave it blank and the registry will say so — that is itself a finding.
Shadow AI is the normal state. Unmanaged is the choice.
of companies have employees regularly using personal AI tools for work. Only 40% of companies have bought an official subscription.
added to the average cost of a breach when shadow AI is involved. Shadow AI was a factor in one breach in five.
of mid-market IT leaders confirmed an AI-related security incident in the last twelve months. Only 42% have an enforced AI policy.
of desk workers are uncomfortable telling their manager they used AI. Ban it and the usage does not stop — the visibility does.
The first artifact of AI governance, done in an afternoon.
Most AI governance starts with a policy. A policy written before the registry describes tools nobody uses and misses the ones everybody does. This puts the inventory first, with a name next to every row.
A registry, not a report
One row per kind of tool in use — where it lives, its status, a slot for an owner, the data it is exposed to, the next action, and a review date.
Keep, move, retire, register
Every row resolves to one of four actions. The tool people chose is usually fine; the account it runs on usually is not. Nothing here says 'ban'.
A coverage score
How much of what is in use is known, owned and reviewable, 0–100, so you can see the gap and measure it closing.
Flags that need a decision this week
Credentials in chat windows, client calls recorded on personal note-takers, PHI without a BAA, usage mandates with no visibility.
The gaps in your registry discipline
Visibility, ownership, intake, off-boarding, and staff-built prompts — which of the five you are missing, and the specific fix for each.
A 30-day plan
Find it, name it, sort it, open a front door. Then, and only then, the policy and the training.
Every step behind the audit — the three finders, the four statuses, the front door, and why bans and usage mandates both backfire — written up in full.