Privacy Settings
This site uses third-party website tracking technologies to provide and continually improve our services, and to display advertisements according to users' interests. I agree and may revoke or change my consent at any time with effect for the future.
Deny
Accept All
Back to the Article Hub
Shadow IT

Shadow AI Discovery: How to Find the AI Tools Already in Your Stack

Share
Copy to clipboard
Table of Contents

Shadow IT used to announce itself. Someone expensed a Trello subscription, or a new domain showed up in your network logs, and you had a thread to pull.

Shadow AI mostly doesn't do that. It arrives as a feature inside software you already own and already approved - a summarise button in your CRM, an assistant panel in your project tool, a model quietly processing your support tickets. Nobody signed up for anything. Nobody expensed anything. There's often no new domain to detect.

Which means the discovery methods you built for shadow IT will find some of it and miss a lot. This is about the gap.

TL;DR

  • Shadow AI is AI tooling used without IT or security review - including AI features switched on inside applications you already sanctioned.
  • Why it's harder to find: much of it generates no new signup, no new spend and no new domain. The signal is a permission grant, not a purchase.
  • The strongest single detection method: audit OAuth grants. AI tools need data access, and access leaves a record.
  • Discovery isn't the goal: A list of 60 AI tools nobody approved is only useful if someone can decide what happens to each one.

What is shadow AI?

Shadow AI is any AI tool, model or AI-powered feature being used with company data without having gone through IT or security review.

It shows up in four fairly different forms, and they need different detection:

  • Standalone AI tools employees sign up for directly - usually with a work email, often on a free tier. The closest analogue to classic shadow IT.
  • AI features inside sanctioned apps, enabled by a tenant admin or an individual user. You approved the application; nobody approved the AI capability or considered what data it now touches.
  • AI tools connected via OAuth to systems that hold real data - the assistant granted read access to your Drive or your CRM.
  • Agents and automations built on internal platforms, which are governed differently. Covered in AI agent governance.

The second category is the one that breaks most discovery programmes. It's not shadow procurement. It's shadow capability, inside software your CMDB already lists as approved.

Why shadow AI is harder to discover than shadow IT

Four reasons your existing methods underperform here.

There's often no new application to find

Discovery tooling generally looks for applications that shouldn't be there. When AI arrives as a feature toggle inside an app that should be there, there's nothing anomalous to flag. The application is approved. The capability is new.

Finance won't help you

Spend analysis is one of the more reliable shadow IT signals - an unfamiliar charge is a thread you can pull. Most shadow AI starts on a free tier, and AI features bundled into existing subscriptions produce no incremental line item at all.

Network signals are weaker than they used to be

If the AI capability is served from a domain your sanctioned vendor already uses, network monitoring sees normal traffic to an approved destination. And with more work happening off the corporate network, the coverage gap widens regardless.

The risk isn't the tool, it's the grant

This is the important one. A standalone AI tool someone uses to rewrite an email is a modest risk. The same tool granted OAuth access to your CRM is a different proposition entirely - it now has standing, programmatic access to customer data, and that access persists whether or not anyone is still using the tool.

So the useful question isn't "which AI tools are in use?" It's "which AI tools can reach our data, and how much?"

The five discovery methods, and what each one actually finds

No single method covers the estate. Running one and assuming coverage is the most common failure.

1. OAuth grant audit - start here

Review third-party applications with granted access in your identity provider and major SaaS platforms. AI tools need data to be useful, and data access requires a grant that gets recorded.

Finds: AI tools connected to your sanctioned systems, including ones nobody is actively using but which retain access.

Misses: tools used purely by copy-paste, with no integration.

Why it's first: highest ratio of risk found to effort spent. These are the tools that can actually reach data.

2. Browser-based detection

A managed browser extension sees which AI tools people actually open, including free-tier tools that never touch an integration or an invoice.

Finds: standalone AI usage, including tools with no other footprint.

Misses: anything on unmanaged devices; requires deployment coverage to be meaningful.

Note: genuine privacy considerations here. Be explicit with employees about what's monitored - a discovery method people feel deceived by tends to get uninstalled.

3. Identity provider and SSO logs

Authentication events reveal AI tools being accessed with corporate credentials, including ones provisioned outside your catalogue.

Finds: tools using corporate SSO or work email.

Misses: tools where someone signed up with a personal account - which is common, and is its own governance problem, since that usage is invisible and unrecoverable at offboarding.

4. Audit AI features inside apps you already own

The manual one, and the one nobody does. Go through your top applications and check which AI capabilities are enabled, who can use them, and what data they process.

Finds: the entire "shadow capability" category no automated tool will surface, because from the tool's perspective nothing unapproved is happening.

Misses: nothing in scope - but it's slow, and it needs redoing as vendors ship new features.

Practical tip: tie this to a quarterly cadence rather than a one-off, because your vendors are adding AI features faster than you're reviewing them.

5. Ask people

Unfashionable and consistently productive. A short survey - which AI tools do you use for work, what do you put into them - surfaces things no scan will, and it converts the exercise from surveillance into a conversation.

Finds: personal-account usage, tools used by copy-paste, and the reasons people went outside the sanctioned stack.

Misses: whatever people don't want to tell you — so pair it with the technical methods rather than relying on it.

This mirrors the trade-off in general SaaS discovery, where browser, network and API approaches each cover a different slice. Shadow AI just tilts the balance further toward OAuth and feature auditing.

AI sprawl: what happens after discovery

AI sprawl is the uncontrolled accumulation of AI tools and AI-enabled features across an organisation - overlapping capability, redundant spend, and data flowing to more destinations than anyone has mapped.

It looks like SaaS sprawl and behaves slightly differently in three ways:

  • It grows without procurement. Existing vendors add AI features; your surface expands without anyone buying anything.
  • Overlap is severe. Six tools that all summarise documents is a normal state, not an unusual one.
  • The cost isn't primarily financial. With classic SaaS sprawl, the headline problem is wasted licences. With AI sprawl, it's data exposure - the same document reaching four different models under four different data-handling agreements.

Which is why "how many AI tools do we have" is the less useful question. "Where is our data going, and under what terms" is the one that matters.

From discovery to management

Most shadow AI projects stall at the list. You produce an inventory of sixty AI tools nobody approved, share it, and then nothing happens - because a list isn't a decision.

What turns discovery into control:

  1. Triage by data access, not by tool count. A tool with OAuth access to your CRM outranks twenty tools someone pastes text into. Sort by what can be reached.
  2. Have a sanctioned option for each real use case. Discovery reveals demand. If people are using six summarisation tools, they need summarisation - blocking without offering an alternative just moves the usage somewhere less visible.
  3. Revoke stale grants first. The easiest, least contested wins are OAuth grants to tools nobody uses any more. Nobody defends those.
  4. Assign an owner to what you keep. Every sanctioned AI tool needs an accountable person, or you'll rediscover it as shadow AI next year.
  5. Re-run discovery on a schedule. This is not a project. Vendors ship AI features continuously, so a one-off scan is accurate for about a month.

The broader governance frame - policy, approval, ownership across the AI estate - sits in AI contextual governance.

A 30-day starting plan

  • Week 1: audit OAuth grants across your identity provider and top ten SaaS platforms. Flag anything AI-related, and note the scopes granted.
  • Week 2: review AI features enabled inside your top ten applications. This is manual and it will surprise you.
  • Week 3: survey teams on AI tool usage. Frame it as "help us sanction what you need," not as an audit.
  • Week 4: triage by data access. Revoke stale grants, shortlist tools to sanction, and assign owners.

One thing to get right in week 3: if the survey reads as enforcement, you'll get incomplete answers and drive usage further underground. Discovery works better as an amnesty than an investigation.

How Josys helps

Josys discovers AI tools and AI-enabled applications across your SaaS estate - including tools connected by OAuth and AI capability inside applications you already sanctioned - and maps what each one can actually reach. Because AI tools, SaaS applications and identities sit in one model, you can see which data a given tool touches and which employees granted it access, rather than assembling that from three separate exports.

See identity and app discovery, AI agent discovery, or book a demo.

Frequently asked questions

What is shadow AI?

Shadow AI is any AI tool, model or AI-powered feature used with company data without IT or security review. It includes standalone tools employees sign up for, AI features enabled inside already-approved applications, and AI tools connected to company systems via OAuth.

How do you discover shadow AI?

Start by auditing OAuth grants in your identity provider and major SaaS platforms, since AI tools need data access and access is recorded. Add browser-based detection for standalone usage, review identity provider logs for corporate-credential signups, manually audit which AI features are enabled inside apps you already own, and survey teams directly. No single method covers the estate.

Why is shadow AI harder to detect than shadow IT?

Much of it produces no new application, no new spend and no new domain - it appears as a feature toggle inside software you already approved. Spend analysis fails because most shadow AI starts on free tiers or is bundled into existing subscriptions, and network monitoring fails when the AI capability is served from a domain your sanctioned vendor already uses.

What is AI sprawl?

AI sprawl is the uncontrolled accumulation of AI tools and AI-enabled features across an organisation, producing overlapping capability and data flowing to more destinations than anyone has mapped. It differs from SaaS sprawl in that it grows without procurement - existing vendors add AI features - and its main cost is data exposure rather than wasted licences.

What are the risks of shadow AI?

The primary risk is data exposure through access rather than through use: an AI tool with OAuth access to a CRM or document store has standing, programmatic access that persists whether or not anyone is still using it. Secondary risks include data processed under terms nobody reviewed, compliance obligations breached without record, and access that survives employee offboarding when signup used a personal account.

How do you manage shadow AI once you've found it?

Triage by data access rather than tool count, since a tool with OAuth access to core systems matters more than several used by copy-paste. Revoke stale grants first as the least contested wins. Provide a sanctioned option for each genuine use case, because blocking without an alternative moves usage somewhere less visible. Assign an owner to everything you keep, and re-run discovery on a schedule.

How often should you run AI discovery?

Quarterly at minimum, and continuously if tooling allows. Vendors are shipping AI features faster than most organisations review them, so a one-off scan is accurate for roughly a month. The feature-audit step in particular needs repeating, since new capability appears inside applications without any change on your side.

Questions? Answers.

No items found.