Shadow IT used to announce itself. Someone expensed a Trello subscription, or a new domain showed up in your network logs, and you had a thread to pull.
Shadow AI mostly doesn't do that. It arrives as a feature inside software you already own and already approved - a summarise button in your CRM, an assistant panel in your project tool, a model quietly processing your support tickets. Nobody signed up for anything. Nobody expensed anything. There's often no new domain to detect.
Which means the discovery methods you built for shadow IT will find some of it and miss a lot. This is about the gap.
Shadow AI is any AI tool, model or AI-powered feature being used with company data without having gone through IT or security review.
It shows up in four fairly different forms, and they need different detection:
The second category is the one that breaks most discovery programmes. It's not shadow procurement. It's shadow capability, inside software your CMDB already lists as approved.
Four reasons your existing methods underperform here.
Discovery tooling generally looks for applications that shouldn't be there. When AI arrives as a feature toggle inside an app that should be there, there's nothing anomalous to flag. The application is approved. The capability is new.
Spend analysis is one of the more reliable shadow IT signals - an unfamiliar charge is a thread you can pull. Most shadow AI starts on a free tier, and AI features bundled into existing subscriptions produce no incremental line item at all.
If the AI capability is served from a domain your sanctioned vendor already uses, network monitoring sees normal traffic to an approved destination. And with more work happening off the corporate network, the coverage gap widens regardless.
This is the important one. A standalone AI tool someone uses to rewrite an email is a modest risk. The same tool granted OAuth access to your CRM is a different proposition entirely - it now has standing, programmatic access to customer data, and that access persists whether or not anyone is still using the tool.
So the useful question isn't "which AI tools are in use?" It's "which AI tools can reach our data, and how much?"
No single method covers the estate. Running one and assuming coverage is the most common failure.
Review third-party applications with granted access in your identity provider and major SaaS platforms. AI tools need data to be useful, and data access requires a grant that gets recorded.
Finds: AI tools connected to your sanctioned systems, including ones nobody is actively using but which retain access.
Misses: tools used purely by copy-paste, with no integration.
Why it's first: highest ratio of risk found to effort spent. These are the tools that can actually reach data.
A managed browser extension sees which AI tools people actually open, including free-tier tools that never touch an integration or an invoice.
Finds: standalone AI usage, including tools with no other footprint.
Misses: anything on unmanaged devices; requires deployment coverage to be meaningful.
Note: genuine privacy considerations here. Be explicit with employees about what's monitored - a discovery method people feel deceived by tends to get uninstalled.
Authentication events reveal AI tools being accessed with corporate credentials, including ones provisioned outside your catalogue.
Finds: tools using corporate SSO or work email.
Misses: tools where someone signed up with a personal account - which is common, and is its own governance problem, since that usage is invisible and unrecoverable at offboarding.
The manual one, and the one nobody does. Go through your top applications and check which AI capabilities are enabled, who can use them, and what data they process.
Finds: the entire "shadow capability" category no automated tool will surface, because from the tool's perspective nothing unapproved is happening.
Misses: nothing in scope - but it's slow, and it needs redoing as vendors ship new features.
Practical tip: tie this to a quarterly cadence rather than a one-off, because your vendors are adding AI features faster than you're reviewing them.
Unfashionable and consistently productive. A short survey - which AI tools do you use for work, what do you put into them - surfaces things no scan will, and it converts the exercise from surveillance into a conversation.
Finds: personal-account usage, tools used by copy-paste, and the reasons people went outside the sanctioned stack.
Misses: whatever people don't want to tell you — so pair it with the technical methods rather than relying on it.
This mirrors the trade-off in general SaaS discovery, where browser, network and API approaches each cover a different slice. Shadow AI just tilts the balance further toward OAuth and feature auditing.
AI sprawl is the uncontrolled accumulation of AI tools and AI-enabled features across an organisation - overlapping capability, redundant spend, and data flowing to more destinations than anyone has mapped.
It looks like SaaS sprawl and behaves slightly differently in three ways:
Which is why "how many AI tools do we have" is the less useful question. "Where is our data going, and under what terms" is the one that matters.
Most shadow AI projects stall at the list. You produce an inventory of sixty AI tools nobody approved, share it, and then nothing happens - because a list isn't a decision.
What turns discovery into control:
The broader governance frame - policy, approval, ownership across the AI estate - sits in AI contextual governance.
One thing to get right in week 3: if the survey reads as enforcement, you'll get incomplete answers and drive usage further underground. Discovery works better as an amnesty than an investigation.
Josys discovers AI tools and AI-enabled applications across your SaaS estate - including tools connected by OAuth and AI capability inside applications you already sanctioned - and maps what each one can actually reach. Because AI tools, SaaS applications and identities sit in one model, you can see which data a given tool touches and which employees granted it access, rather than assembling that from three separate exports.
See identity and app discovery, AI agent discovery, or book a demo.
Shadow AI is any AI tool, model or AI-powered feature used with company data without IT or security review. It includes standalone tools employees sign up for, AI features enabled inside already-approved applications, and AI tools connected to company systems via OAuth.
Start by auditing OAuth grants in your identity provider and major SaaS platforms, since AI tools need data access and access is recorded. Add browser-based detection for standalone usage, review identity provider logs for corporate-credential signups, manually audit which AI features are enabled inside apps you already own, and survey teams directly. No single method covers the estate.
Much of it produces no new application, no new spend and no new domain - it appears as a feature toggle inside software you already approved. Spend analysis fails because most shadow AI starts on free tiers or is bundled into existing subscriptions, and network monitoring fails when the AI capability is served from a domain your sanctioned vendor already uses.
AI sprawl is the uncontrolled accumulation of AI tools and AI-enabled features across an organisation, producing overlapping capability and data flowing to more destinations than anyone has mapped. It differs from SaaS sprawl in that it grows without procurement - existing vendors add AI features - and its main cost is data exposure rather than wasted licences.
The primary risk is data exposure through access rather than through use: an AI tool with OAuth access to a CRM or document store has standing, programmatic access that persists whether or not anyone is still using it. Secondary risks include data processed under terms nobody reviewed, compliance obligations breached without record, and access that survives employee offboarding when signup used a personal account.
Triage by data access rather than tool count, since a tool with OAuth access to core systems matters more than several used by copy-paste. Revoke stale grants first as the least contested wins. Provide a sanctioned option for each genuine use case, because blocking without an alternative moves usage somewhere less visible. Assign an owner to everything you keep, and re-run discovery on a schedule.
Quarterly at minimum, and continuously if tooling allows. Vendors are shipping AI features faster than most organisations review them, so a one-off scan is accurate for roughly a month. The feature-audit step in particular needs repeating, since new capability appears inside applications without any change on your side.