Category: Shadow AI

Unsanctioned AI tools, the AI features vendors ship into software you already own, and what to do about both.

  • Writing a Shadow AI Policy That People Will Actually Follow

    Most shadow AI policy documents fail the same way. They are written to satisfy an auditor, they prohibit more than they permit, and the people they govern never read past the first paragraph. Six months later usage is unchanged and nobody mentions it, which the policy owner reads as compliance.

    A policy that works looks different, and it is shorter than you expect.

    Why the strict version backfires

    Blanket bans do not reduce AI usage. They relocate it.

    The employee who was using a summariser on their work laptop now uses it on their phone. You have lost the logs, lost the ability to steer them toward something safer, and added a reason for them to stay quiet when something goes wrong. You have made the actual risk worse while making the reported risk zero, which is the worst possible combination because it looks like success.

    Salesforce found 27% of employees have entered confidential data into public AI tools. Those people are not saboteurs. They are trying to finish something, and a rule that makes finishing it harder loses to the deadline every time.

    What to write instead

    Four things, and they fit on one page.

    1. A green list, published and easy to find

    Name the tools people can use without asking, and say what each is cleared for. Most policies lead with prohibitions and bury the permitted list in an appendix, or never write one at all, which leaves “ask IT” as the only sanctioned path. Nobody asks IT. They just use the thing.

    The green list is the single highest-leverage part of the document, because it is the only part that gives people somewhere to go.

    2. A data rule people can apply without a lawyer

    The classification scheme in your security policy is not usable at the moment someone is about to paste. Write the rule so it can be applied in the two seconds actually available.

    Something closer to: never paste customer data, credentials, source code, or anything from an unreleased financial or legal document into any AI tool that is not on the green list. Concrete nouns beat “confidential information”, because everyone believes their own work is fine.

    3. A fast path for anything new

    If approval takes three weeks, your policy is decorative. Someone will have used the tool, finished the project, and forgotten about it before your review meeting happens.

    Commit to a turnaround measured in days, publish it, and hold yourself to it. A five-day answer that is sometimes no beats a three-week answer that is usually yes, because only one of them is fast enough to be worth using.

    4. Amnesty, stated plainly

    You need to know what is already running, and people will only tell you if telling you is safe. Say in the policy that reporting existing use carries no consequence, then honour it the first time somebody tests you, which is when the policy is really written.

    One exception worth being explicit about: if data has already gone somewhere it should not, you need to hear that early, and the incentive has to point toward telling you fast rather than hoping nobody notices.

    The clause almost everyone leaves out

    Every policy above governs tools people go and adopt. Almost none govern the AI your existing vendors switch on inside products you already pay for, and that is now where most new AI processing appears.

    Nobody signed up. No approval was sought, because no human made a decision. Your green list is silent, since the product was already on it, cleared for something that was true last quarter.

    Two lines fix it. State that vendor-shipped AI features count as new tooling and are reviewed on the same footing. And name somebody responsible for watching release notes and changelogs for material changes to what your licensed software does with your data.

    That second line is the one nobody staffs, which is why it keeps happening. Tracking it is what CopperFeed is for.

    Keep it to a page

    Length is inversely correlated with compliance. A one-page document people can hold in their head beats a twelve-page one that is technically comprehensive and functionally invisible.

    Test it before you publish. Give the draft to three people who are not in security or legal, ask them what they are allowed to paste into ChatGPT this afternoon, and see whether they can answer without rereading it. If they cannot, the problem is the document.

    Then revisit it on a schedule, because the tools change faster than the policy will. Something on your green list this quarter may ship a feature next quarter that changes what it does with your data, and the review date is what catches that.

    Finding out what is already running comes first, and costs nothing: How to Find Shadow AI in Your Company Without Buying a Tool. The wider picture is in Shadow AI: The Tools Nobody Approved and Nobody Tracks.

    General guidance, not legal advice. Employment and privacy obligations vary by jurisdiction, and anything touching monitoring or discipline should go past your own counsel before it ships.

  • How to Find Shadow AI in Your Company Without Buying a Tool

    Most shadow AI detection advice ends with buying a platform. You do not need one to get started, and you should not buy one before you know the size of the problem, because the demo you sit through will be calibrated to whatever the vendor thinks scares you most.

    Everything below uses data you already have. A competent admin can work through it in an afternoon.

    Start with OAuth grants

    This is the highest-yield ten minutes available to you, and most teams have never looked.

    Every time someone clicks “Sign in with Google” or “Continue with Microsoft” on an AI tool, your identity provider records it, along with the scopes that app requested. Not just that the account exists, but what it was allowed to read.

    • Google Workspace: Admin console, Security, API controls, App access control. The third-party apps list is sortable by user count.
    • Microsoft Entra ID: Enterprise applications, filter to those you did not add, and check Permissions on anything unfamiliar.
    • Okta: the OAuth grants report under Reports.

    Sort by scope rather than by popularity. A tool 40 people signed into with basic profile access is a procurement question. A tool two people granted full mailbox read access to is today’s problem, and the count of users tells you nothing about which is which.

    Then read the expense reports

    Free tiers hide the initial adoption, but they are designed to convert, and conversion leaves a trail. Pull twelve months of card and reimbursement data and search descriptions for the obvious vendor names plus the generic ones: “AI”, “GPT”, “assistant”, “copilot”, “transcription”.

    Two patterns matter more than any single line. Look for the same vendor expensed by several people separately, which means a team standardised on something without telling anyone and you are paying retail per seat. And look for small recurring charges under whatever your approval threshold is, because that threshold is exactly where this behaviour lives.

    Look at what the network already knows

    You do not need packet inspection or a new appliance. DNS query logs answer the question well enough, and your resolver is already keeping them.

    Pull the last 30 days, aggregate by domain, and sort by unique internal clients rather than total volume. Volume finds the noisiest tool. Unique clients finds the one that quietly spread across a department, which is the thing you actually want to know about.

    If you run a proxy or an endpoint agent, the same query gets you application-level detail. If you have neither, DNS gets you most of the way for free.

    Check the browser

    The category people forget. Browser extensions with AI features hold permission to read and change data on every page the user visits, which in a browser-based company means every internal system you own.

    Both Chrome and Edge enterprise management report installed extensions across the fleet. Pull that list and look at the permissions column, not the names. An extension does not have to be an AI tool to be reading everything on your admin pages.

    Ask people, honestly

    The step technical teams skip, and frequently the most productive one.

    A short anonymous survey asking what people actually use, framed explicitly as inventory-taking rather than enforcement, will surface tools no log catches: things used on personal devices, things accessed on phones, things people would not have thought to mention.

    It only works if the framing is true. Ask which tools people use, promise nobody is in trouble, then discipline someone for an answer, and you have poisoned the well for every future exercise. If you cannot make that promise honestly, skip this step rather than run it dishonestly.

    The part everyone misses

    Everything so far finds tools your people went out and adopted. It will not find AI that arrived inside software you already own, and that is now the larger category.

    When a vendor ships an AI assistant into an existing product, there is no signup, no OAuth grant, no new domain, no expense line. Your inventory looks unchanged, because by every measure above, it is. What changed is what your existing tools now do with your data.

    Finding those means reading vendor changelogs and release notes for the software you already license, which is tedious and which almost nobody does consistently. It is also precisely what CopperFeed exists to record.

    What to do with the list

    Resist the urge to act on all of it. Sort into three piles.

    1. Fine. Most of it. A summariser with no data access used by one person is not a governance crisis, and treating it as one costs you credibility for the cases that matter.
    2. Consolidate. The four tools doing one job. This is where the money is, and it is an easy win because you are giving people a better-supported version of something they already chose.
    3. Deal with now. Anything holding customer data, source code, or credentials, and anything with broad OAuth scopes. Usually a short list, which is the good news.

    Then decide whether you need a platform. You will be negotiating from a position of knowing your own numbers, which is a different conversation from the one you would have had first.

    What to write once you have the list is in Writing a Shadow AI Policy That People Will Actually Follow. The wider picture is in Shadow AI: The Tools Nobody Approved and Nobody Tracks.

    General guidance, not security or legal advice. Check your own obligations before acting on any of it, particularly around monitoring employee activity, which is regulated differently depending on where your people are.

  • Shadow AI: The Tools Nobody Approved and Nobody Tracks

    Shadow AI is the AI tooling running inside your company that nobody approved. Not smuggled in by bad actors. Signed up for by a product manager on a Tuesday because it saved her an afternoon, paid on a personal card or not paid for at all, and never mentioned to anyone.

    It is the fastest-growing category of software in most organisations right now, and almost none of it appears on the spend report that finance reviews.

    How big is it really

    Bigger than most inventories suggest, though the honest answer is that nobody knows precisely, and the published numbers disagree with each other more than the coverage admits.

    Microsoft’s 2025 Work Trend Index found that 78% of people using AI at work are bringing their own tools, outside IT approval. Salesforce’s State of IT research put it lower, at 65% of employees using at least one AI tool their IT or security team has not sanctioned. Other vendor surveys in 2026 report figures as high as 98% of organisations. The spread is not a rounding error.

    The gap comes from definitions rather than from anyone being wrong. Does a browser extension count? A free ChatGPT account on a work laptop? An AI feature that a vendor switched on inside a tool you already licensed? That last one is doing a lot of work in these numbers, and it is the category nobody has a policy for, because nothing was installed and nobody signed up for anything.

    Treat any single shadow AI percentage you see as an argument rather than a measurement. What holds across all of them is the direction and the rough shape: most companies, most employees, growing fast.

    Why it is different from ordinary shadow IT

    Shadow IT is decades old and the playbook is well worn. Someone buys Dropbox, IT finds out, it gets consolidated. Annoying, bounded, solved.

    Three things make the AI version behave differently.

    The data leaves. A rogue project management tool holds your task list. A rogue AI tool holds whatever your employee pasted into it, and people paste a lot. Salesforce found 27% of employees have put confidential company data into public AI tools. That is not a permissions problem you can fix after the fact. The text is already gone, possibly into a training set, and there is no revoking it.

    It is free, so procurement never sees it. Shadow IT used to surface through expense reports, because software cost money. The free tier is the entire problem here. No invoice, no card charge, no renewal, no vendor record. Your spend management platform is structurally blind to it, and every dashboard you own will keep reporting that everything is fine.

    It arrives inside tools you already bought. The vendor ships an AI assistant into the product next quarter and it is on by default. Nobody adopted anything. Your approved software is now doing inference against your data under terms most buyers have not read since the original signature.

    What it actually costs

    Gartner’s 2025 research puts some numbers on this. Organisations without governance structures spend 2.5 times more on AI incident remediation than those with controls in place, and it projects shadow AI will cost enterprises more than $40 billion by 2027. Only 34% of organisations have a formal shadow AI detection program at all.

    Worth reading those with the usual caution, since analyst projections about emerging categories have a poor track record and the firms publishing them sell governance advice. The 34% figure is the interesting one anyway, because it is a measurement rather than a forecast, and it says two thirds of companies are not looking.

    The costs that land first are duller than a breach and more likely:

    • Duplicate spend you cannot see. Four teams on four AI writing tools, three of them free until the trial ends and someone expenses an upgrade.
    • Data in places your DPA does not cover. Which becomes a real problem the first time a customer asks where their data goes, or an auditor does.
    • Work that depends on an account nobody owns. The workflow runs on a tool registered to someone’s personal email. That person leaves. Nobody can log in.
    • Vendors that vanish. The AI tooling market is churning hard, and a free tool with no contract gives you no notice period and no data export commitment when it goes. See what happened to Lattice HRIS customers, and that was a paid product with eight months of notice.

    Why banning it does not work

    The instinct is a blanket prohibition. It fails, reliably, for a reason worth understanding before you try it.

    People adopt these tools because they work. Someone found a way to do a two-hour task in ten minutes, and a policy telling them to stop is a policy telling them to be slower at their job. What a ban produces is not less usage. It is the same usage on personal devices, where you have no visibility at all, and where the employee now has a reason not to tell you when something goes wrong.

    The organisations getting this right treat it as a supply problem. If people are reaching for unsanctioned tools, the sanctioned ones are missing, too slow to get approved, or nobody knows they exist. We cover what to write instead in Writing a Shadow AI Policy That People Will Actually Follow.

    Start by looking

    You cannot make decisions about an inventory you do not have, and the first pass costs nothing. Your SSO logs, OAuth grants, expense reports and DNS traffic already contain most of the answer, which is the subject of How to Find Shadow AI in Your Company Without Buying a Tool.

    What that exercise tends to surface is not a security horror story. It is a list of eleven tools doing four jobs, two of which you are paying for twice, and one of which is holding something it should not. That list is worth having before somebody else compiles it for you.

    CopperFeed tracks what changed in SaaS and AI tooling as it happens, including the AI features vendors switch on inside products you already own.

    Figures here come from published vendor and analyst research, attributed inline. Shadow AI statistics vary widely by definition and methodology, so treat any single number as indicative.