Shadow AI Finder by Agent Trust Cloud

What is shadow AI?

Shadow AI is the use of AI tools at work without the knowledge or approval of the people responsible for the organisation's data and risk: an assistant someone signs up to with a work email, a browser extension that rewrites emails, a meeting recorder that joins calls, or a script that sends data to a model API.

It's rarely malicious. People use these tools because they help. The problem is that nobody has checked where the data goes, how long it's kept or whether the terms fit the company's obligations.

Where shadow AI shows up

The finder tracks 79 AI services in 8 categories. Each category carries a different kind of risk:

Why it matters

How to find it

  1. Export a week or two of DNS, web proxy, firewall or single sign-on logs.
  2. Drop them into the Shadow AI Finder. It lists the AI services it recognises, how often they appear and by how many people or devices. Files never leave your browser.
  3. Look for services used by many people (candidates to approve properly) and services touching sensitive work (candidates to review first).

What to do next

  1. Decide per service: approve, review or block. The finder exports those decisions as a list for IT.
  2. Give people an approved option for the jobs they're already doing, so they don't go around the rules.
  3. Enforce with the tools you have: block and allow lists for DNS filters, proxies and firewalls.
  4. Repeat monthly. New AI tools appear constantly; the finder's list is reviewed monthly.

Questions

Is shadow AI the same as shadow IT?

It's a kind of shadow IT, but with two differences that matter. Many AI tools are free and need only a browser, so they spread faster than other software. And what people type or upload may be kept by the provider, so the exposure can't always be undone by switching the tool off later.

Is using AI tools without approval against the law?

Not in itself. The risk depends on what is shared and where: confidential or personal data, client information under contract, or regulated records. That's why the first step is finding out what is used, not banning everything.

Should we block every AI tool we find?

Usually not. Blocking popular tools pushes people to personal devices, where you can't see anything. Most teams approve a few tools with proper terms, review the rest and block a small number.

Can shadow AI be found without installing anything?

Much of it, yes. DNS, proxy, firewall and sign-in logs you already have show which AI services people reach. Shadow AI Finder reads those exports in your browser and lists the services, how often and by how many people or devices.

What won't logs show?

What was typed or shared, anything used on personal devices or home networks, and AI features built into tools you already approved. Logs show where traffic went, not what it contained.

For a deeper guide to the places shadow AI hides beyond network logs, read Shadow AI: the six places it hides on Agent Trust Cloud.

Find the AI your company already uses

Free, in your browser. Drop in a log export and see which AI services show up.