How to Find Shadow AI in Your Company Without Buying a Tool

Most shadow AI detection advice ends with buying a platform. You do not need one to get started, and you should not buy one before you know the size of the problem, because the demo you sit through will be calibrated to whatever the vendor thinks scares you most.

Everything below uses data you already have. A competent admin can work through it in an afternoon.

Start with OAuth grants

This is the highest-yield ten minutes available to you, and most teams have never looked.

Every time someone clicks “Sign in with Google” or “Continue with Microsoft” on an AI tool, your identity provider records it, along with the scopes that app requested. Not just that the account exists, but what it was allowed to read.

  • Google Workspace: Admin console, Security, API controls, App access control. The third-party apps list is sortable by user count.
  • Microsoft Entra ID: Enterprise applications, filter to those you did not add, and check Permissions on anything unfamiliar.
  • Okta: the OAuth grants report under Reports.

Sort by scope rather than by popularity. A tool 40 people signed into with basic profile access is a procurement question. A tool two people granted full mailbox read access to is today’s problem, and the count of users tells you nothing about which is which.

Then read the expense reports

Free tiers hide the initial adoption, but they are designed to convert, and conversion leaves a trail. Pull twelve months of card and reimbursement data and search descriptions for the obvious vendor names plus the generic ones: “AI”, “GPT”, “assistant”, “copilot”, “transcription”.

Two patterns matter more than any single line. Look for the same vendor expensed by several people separately, which means a team standardised on something without telling anyone and you are paying retail per seat. And look for small recurring charges under whatever your approval threshold is, because that threshold is exactly where this behaviour lives.

Look at what the network already knows

You do not need packet inspection or a new appliance. DNS query logs answer the question well enough, and your resolver is already keeping them.

Pull the last 30 days, aggregate by domain, and sort by unique internal clients rather than total volume. Volume finds the noisiest tool. Unique clients finds the one that quietly spread across a department, which is the thing you actually want to know about.

If you run a proxy or an endpoint agent, the same query gets you application-level detail. If you have neither, DNS gets you most of the way for free.

Check the browser

The category people forget. Browser extensions with AI features hold permission to read and change data on every page the user visits, which in a browser-based company means every internal system you own.

Both Chrome and Edge enterprise management report installed extensions across the fleet. Pull that list and look at the permissions column, not the names. An extension does not have to be an AI tool to be reading everything on your admin pages.

Ask people, honestly

The step technical teams skip, and frequently the most productive one.

A short anonymous survey asking what people actually use, framed explicitly as inventory-taking rather than enforcement, will surface tools no log catches: things used on personal devices, things accessed on phones, things people would not have thought to mention.

It only works if the framing is true. Ask which tools people use, promise nobody is in trouble, then discipline someone for an answer, and you have poisoned the well for every future exercise. If you cannot make that promise honestly, skip this step rather than run it dishonestly.

The part everyone misses

Everything so far finds tools your people went out and adopted. It will not find AI that arrived inside software you already own, and that is now the larger category.

When a vendor ships an AI assistant into an existing product, there is no signup, no OAuth grant, no new domain, no expense line. Your inventory looks unchanged, because by every measure above, it is. What changed is what your existing tools now do with your data.

Finding those means reading vendor changelogs and release notes for the software you already license, which is tedious and which almost nobody does consistently. It is also precisely what CopperFeed exists to record.

What to do with the list

Resist the urge to act on all of it. Sort into three piles.

  1. Fine. Most of it. A summariser with no data access used by one person is not a governance crisis, and treating it as one costs you credibility for the cases that matter.
  2. Consolidate. The four tools doing one job. This is where the money is, and it is an easy win because you are giving people a better-supported version of something they already chose.
  3. Deal with now. Anything holding customer data, source code, or credentials, and anything with broad OAuth scopes. Usually a short list, which is the good news.

Then decide whether you need a platform. You will be negotiating from a position of knowing your own numbers, which is a different conversation from the one you would have had first.

What to write once you have the list is in Writing a Shadow AI Policy That People Will Actually Follow. The wider picture is in Shadow AI: The Tools Nobody Approved and Nobody Tracks.

General guidance, not security or legal advice. Check your own obligations before acting on any of it, particularly around monitoring employee activity, which is regulated differently depending on where your people are.