What is shadow AI?
Shadow AI is the use of AI tools at work without the knowledge or approval of the people responsible for the organisation's data and risk: an assistant someone signs up to with a work email, a browser extension that rewrites emails, a meeting recorder that joins calls, or a script that sends data to a model API.
It's rarely malicious. People use these tools because they help. The problem is that nobody has checked where the data goes, how long it's kept or whether the terms fit the company's obligations.
Where shadow AI shows up
The finder tracks 79 AI services in 8 categories. Each category carries a different kind of risk:
- Agent and automation (4 services, for example Manus, Lindy, Relevance AI). These services act on the user's behalf, which can include browsing, filling in forms and sending messages.
- Chat assistant (17 services, for example ChatGPT / OpenAI, Claude, Gemini). People type questions into these assistants and often paste in text, documents or data, which then leaves the company.
- Coding assistant (9 services, for example GitHub Copilot, Cursor, Windsurf / Codeium). These tools read source code from a developer's editor to suggest or write code, so code and any secrets in it can be sent to the service.
- Image, video and voice (12 services, for example Midjourney, Leonardo.Ai, Ideogram). Used to generate images, video, voice or music. Uploads can include brand material or recordings of real people.
- Meeting recorder (9 services, for example Otter.ai, Fireflies.ai, Fathom). These services join, record or transcribe meetings and keep the transcripts, so it matters who agreed to the recording and where it's stored.
- Model API or platform (13 services, for example OpenAI API, Anthropic API, Google AI Studio / Gemini API). Traffic to a model API usually comes from software, a script or an agent calling the model, not from a person in a browser. The next step is finding which application makes the calls.
- Slides, research and documents (8 services, for example NotebookLM, Gamma, Tome). Documents and research material are uploaded to produce slides, summaries or answers.
- Writing and translation (7 services, for example Grammarly, DeepL, QuillBot). Text pasted in for rewriting, checking or translation leaves the company, including anything confidential in it.
Why it matters
- Data leaves the company. Text, documents, code and recordings go to a provider under that provider's consumer terms, not a contract you negotiated.
- Obligations still apply. Client confidentiality, data protection and sector rules don't stop applying because a tool was adopted informally.
- No one owns it. Without an inventory there's no owner to answer questions, renew terms or switch a tool off.
- Decisions go unrecorded. When AI output feeds real decisions, there's no record of which tool produced it.
How to find it
- Export a week or two of DNS, web proxy, firewall or single sign-on logs.
- Drop them into the Shadow AI Finder. It lists the AI services it recognises, how often they appear and by how many people or devices. Files never leave your browser.
- Look for services used by many people (candidates to approve properly) and services touching sensitive work (candidates to review first).
What to do next
- Decide per service: approve, review or block. The finder exports those decisions as a list for IT.
- Give people an approved option for the jobs they're already doing, so they don't go around the rules.
- Enforce with the tools you have: block and allow lists for DNS filters, proxies and firewalls.
- Repeat monthly. New AI tools appear constantly; the finder's list is reviewed monthly.
Questions
Is shadow AI the same as shadow IT?
It's a kind of shadow IT, but with two differences that matter. Many AI tools are free and need only a browser, so they spread faster than other software. And what people type or upload may be kept by the provider, so the exposure can't always be undone by switching the tool off later.
Is using AI tools without approval against the law?
Not in itself. The risk depends on what is shared and where: confidential or personal data, client information under contract, or regulated records. That's why the first step is finding out what is used, not banning everything.
Should we block every AI tool we find?
Usually not. Blocking popular tools pushes people to personal devices, where you can't see anything. Most teams approve a few tools with proper terms, review the rest and block a small number.
Can shadow AI be found without installing anything?
Much of it, yes. DNS, proxy, firewall and sign-in logs you already have show which AI services people reach. Shadow AI Finder reads those exports in your browser and lists the services, how often and by how many people or devices.
What won't logs show?
What was typed or shared, anything used on personal devices or home networks, and AI features built into tools you already approved. Logs show where traffic went, not what it contained.
For a deeper guide to the places shadow AI hides beyond network logs, read Shadow AI: the six places it hides on Agent Trust Cloud.
Find the AI your company already uses
Free, in your browser. Drop in a log export and see which AI services show up.
Open the Shadow AI Finder Monitor AI agents with Agent Trust Cloud (free Discover tier)