Finding shadow AI - discovery tools and how to run a sweep
How to find the AI tools your staff already use, using the logs and licences you already own, plus what to do with what you find.
Start with what you already own
You do not need a new product to find shadow AI. Almost every organisation already holds three signals.
| Signal | Where it lives | What it reveals |
|---|---|---|
| OAuth and third party app grants | Microsoft Entra enterprise applications, Google Workspace API controls | Tools with standing access to mail, files and calendars |
| Outbound web traffic | Firewall, secure web gateway, DNS resolver logs, Cloudflare Gateway | Which AI domains staff reach and how often |
| Spend | Card statements, expense claims, SaaS management tool | Paid seats bought outside procurement |
Run all three. The overlap is small: OAuth finds integrations, traffic finds browsers, spend finds the tools an individual team quietly funded.
Tooling by organisation size
Under 50 people. Use what is bundled. Google Workspace admin has an app access control report. Microsoft 365 Business Premium includes Entra enterprise app listings and basic Defender web filtering. A DNS resolver such as Cloudflare Gateway on the free or low tier gives you a domain report in an afternoon. A spreadsheet is an acceptable register at this size.
50 to 500 people. Add a discovery layer. Microsoft Defender for Cloud Apps produces a cloud app catalogue with risk scores and can be pointed at your firewall logs. Netskope, Zscaler and Palo Alto equivalents do the same. SaaS management tools such as Torii or Zluri correlate spend, single sign on and OAuth grants into one list.
Regulated or over 500 people. Route discovery into your existing asset or service management system so an AI tool becomes a configuration item with an owner, a data classification and a review date, rather than a row in a document.
How to run the sweep
- Pick a 90 day window and pull the three signals above.
- Normalise to a single list: tool, vendor, business owner, users, data categories touched, whether it trains on your data.
- Classify each entry as approved, restricted or blocked. Restricted means allowed for a named team or a named use only.
- Communicate the decision with the reason, and name the approved alternative.
- Enforce in the place that matches the finding: revoke the OAuth grant, block the domain, or cancel the licence.
- Diary the next sweep.
What to do with the awkward findings
You will find a tool that is genuinely useful and genuinely non compliant. Do not pretend otherwise in your register. Record it as restricted with a remediation date and a named owner. An assessor reading a register with three honest restrictions and dates trusts it far more than a register where everything is green.
Linking discovery to your policy
Your acceptable use policy should name the approved list and point at the request route for anything new. A discovery sweep with no request route just repeats itself every quarter.