cover image background
Our Blog
24 Hourtek cybersecurity and businesses, tips and best practices
cover image background
Our Blog
24 Hourtek cybersecurity and businesses, tips and best practices
cover image background
Our Blog
24 Hourtek cybersecurity and businesses, tips and best practices

Future-Proofing

Shadow AI: How to Find the AI Tools Your Team Is Already Using

Todd Moss

Todd Moss

CEO, Co-Founder

Shadow A: How to Find the AI Tools Your Team Is Already Using  cover photo

Shadow AI: How to Find the AI Tools Your Team Is Already Using by Todd Moss

AI tools have become part of everyday work faster than most businesses expected. An employee may use an AI assistant to summarize a meeting, rewrite an email, organize notes, analyze a spreadsheet, create an image, or get unstuck on a difficult task. Often, they are not trying to work around the business. They are simply trying to get through their day more efficiently.

The problem is that AI adoption can move quietly. A tool might be opened in a browser, connected to a work account, or downloaded as an extension without anyone in IT, operations, finance, or leadership knowing it exists. That is what people mean by shadow AI: AI tools used for work without a clear review, approval process, or shared understanding of how company information is handled.

This is not a reason to panic or ban every new tool. It is a reason to get a clearer picture of what is already happening. When leaders understand how their teams are using AI, they can protect sensitive information, reduce duplicate spending, and give people a safer way to use tools that may genuinely help them do their jobs.

What is shadow AI, and why does it matter?

Shadow AI is the use of AI-powered tools, platforms, browser extensions, or features that have not been formally approved for business use. It can include public generative AI chatbots, note-taking assistants, transcription platforms, writing tools, coding assistants, analytics products, AI features built into software subscriptions, and tools employees access through personal accounts.

The concern is not that every unapproved tool is automatically dangerous. The concern is that the organization does not know what data is entering the tool, how that data is stored, whether it is used to train a model, or who else can access the resulting information. A team can unknowingly create a data-handling process outside the controls they already rely on for email, file storage, customer records, and internal communication.

For a nonprofit, that might involve donor information, grant documents, participant details, or sensitive community data. For a startup, it might mean product plans, customer feedback, source code, investor materials, or pricing discussions. For an established small business, it could be contracts, employee records, client files, financial information, or internal operating procedures.

The other issue is visibility. If three employees each choose different AI tools for similar tasks, leadership may end up paying for overlapping subscriptions while no one has a complete view of where work is happening. The company is then trying to manage technology from a partial map.

Why employees use AI outside approved systems

Most shadow AI does not begin with bad intent. It begins with a small friction point.

Someone has a long meeting and needs notes quickly. Someone is staring at an email that needs a clearer first draft. Someone is working with a spreadsheet they do not fully understand. Someone sees a colleague using an AI tool and tries it because it appears to save time. The barrier to entry is low, and the benefits can feel immediate.

In many organizations, the official process for evaluating new software is slower than the problem employees are trying to solve. A person with an urgent deadline may not know whom to ask, what information to provide, or whether the request will receive an answer. If approved tools do not meet a real need, people will often find their own workaround.

That is why an effective response starts with curiosity. If leaders treat every unapproved tool as misconduct, employees may stop mentioning what they use. The tool does not disappear. It simply becomes harder to see.

A better starting point is to ask what work people are trying to improve. The answer may reveal repetitive administrative work, unclear processes, missing documentation, training gaps, or software that no longer fits how the team operates. AI may be the visible part of the issue, but the underlying need is often broader.

The risks are real, but they are not all the same

Shadow AI is often discussed as one large category of risk. In practice, the risks vary based on the tool, the type of data involved, the employee’s access level, and the safeguards already in place.

A public AI tool used to brainstorm generic social media ideas carries a different level of risk than one used to summarize a file containing personal information. An AI meeting assistant connected to a company calendar may create different concerns than an employee pasting a few non-sensitive notes into a writing tool. Good governance recognizes those differences instead of treating every use case the same way.

The most common concerns tend to fall into a few areas:

  1. Sensitive data exposure: Employees may paste confidential business information, personal data, customer records, passwords, financial details, or internal documents into tools that were not designed for that type of information.

  2. Unclear data retention and training practices: Some services may store inputs, use them to improve their products, or retain them longer than the organization expects. Terms can differ across free plans, paid plans, enterprise plans, and connected integrations.

  3. Identity and access gaps: A tool connected through a personal account may remain accessible after an employee leaves. Shared work can become difficult to retrieve, transfer, or protect.

  4. Inaccurate outputs: AI can produce information that sounds confident but is incomplete, outdated, or wrong. If people use those outputs without review, errors can affect client communication, financial decisions, policy documents, or public-facing material.

  5. Compliance and contractual obligations: Certain industries, contracts, grant requirements, and privacy commitments may limit how information can be processed. A new tool may create obligations that were never considered during procurement.

  6. Fragmented spending and workflow: Teams may build processes around tools that no one else supports, creating duplicated costs and operational confusion when a person changes roles or leaves.

These issues do not mean AI has no place in the organization. They mean AI needs the same practical attention given to any software that touches people, systems, and data.

Start by defining what you are trying to find

Before looking for shadow AI, decide what counts as relevant. If the scope is too broad, the project can become overwhelming. If it is too narrow, it may miss the tools that matter most.

A useful definition includes AI tools employees use for company work, whether they are accessed through company devices, personal devices, browser extensions, work email accounts, personal accounts, or embedded features inside existing software. It should also include tools that can receive, process, store, summarize, transcribe, generate, analyze, or connect to business information.

This is an important distinction because AI is not always labeled clearly. Many platforms now include AI features inside products the company already uses. An employee may not think of a meeting recorder, CRM assistant, spreadsheet helper, design platform, or email-writing feature as a separate AI tool. From a governance perspective, it still matters how data moves through that feature and what controls are available.

Set a reasonable goal for the first review. The aim is not to build a perfect inventory overnight. The aim is to identify meaningful use, understand the data involved, and create a repeatable way to evaluate new tools going forward.

Business team reviewing data charts on a large display

A structured review helps leaders identify the tools their teams rely on, understand what data those tools handle, and make informed decisions about AI use.

Begin with a conversation, not a crackdown

The fastest way to lose visibility is to make employees feel they will be punished for being honest. If people assume that disclosing a tool will result in an immediate ban or blame, they have little reason to share what they use.

A short, straightforward message can work better than a long policy announcement. Explain that the business is reviewing AI use so it can protect sensitive information and support useful tools responsibly. Make it clear that the goal is to understand current workflows, not to single out individuals for trying to work more efficiently.

A simple internal survey can help surface early information. Ask employees which AI tools or features they use, what problems those tools help solve, whether they use a work or personal account, what kind of data they enter, and whether the tool connects to other systems. Encourage them to include tools they have tried and stopped using, since those can still reveal unmet needs.

The language matters. “Tell us every AI tool you have used” can sound like an audit. “Help us understand where AI is already helping or creating friction in your work” invites a more useful response.

This conversation also gives leaders a chance to set a basic expectation: employees should not enter sensitive information into an AI tool unless they know it is approved for that purpose. That rule is not complicated, but it needs to be repeated clearly and paired with a practical route for asking questions.

Look at the systems you already manage

Employee input is important, but it is only one source of information. A clearer picture usually comes from combining conversations with a review of existing technology records.

Start with the places where software use leaves a footprint. That may include expense reports, credit card transactions, software procurement records, single sign-on dashboards, browser extension management, email security logs, endpoint management platforms, and DNS or web-filtering reports. The exact sources depend on how your organization manages devices and accounts.

Expense records can reveal AI subscriptions employees bought with company cards or submitted for reimbursement. Single sign-on systems can show new applications connected through a work identity. Browser management can reveal extensions that access websites, email, documents, or clipboard content. Web activity data may show recurring access to AI platforms that are not listed in the approved application inventory.

Each source has limits. A personal account may not appear in single sign-on records. An employee could use a free service without an expense transaction. Web logs can show a domain was visited but may not explain what information was submitted. That is why this work is better viewed as assembling a picture rather than searching for one perfect answer.

For organizations with limited internal IT capacity, this may be a useful place to get help. 24hourtek works with businesses that need to review their technology environment without turning a practical security issue into a large internal project. The goal is to identify what is in use, clarify the risk, and make the next steps manageable.

Review your existing software for built-in AI features

Some of the most important AI use may already exist inside approved tools. Email platforms, meeting software, productivity suites, design applications, CRMs, project management tools, and customer support platforms increasingly include AI features by default or as optional add-ons.

These features can be useful, but they should not be assumed safe simply because the main platform is already approved. The AI feature may have separate settings, data controls, licensing terms, or administrative options. In some cases, the feature is disabled by default. In others, employees can turn it on individually.

Make a list of the core platforms your team uses and review their AI capabilities one by one. Ask whether the feature is enabled, who can access it, what data it processes, whether data is retained, whether the organization can control usage, and whether employees have been given guidance on appropriate use.

This review often leads to a helpful outcome: the organization may already have secure, managed AI features available through tools it pays for. If those tools meet employee needs, there may be less reason for people to rely on unknown alternatives.

Map tools to the data they touch

Finding a tool is only the first step. The next question is what information enters it.

A useful review does not require technical language. It can begin with a simple description of the workflow. For example: “The marketing coordinator uses this tool to draft campaign ideas from public information.” Or: “The operations manager uses this tool to summarize internal meeting transcripts.” Or: “The finance team uses this feature to analyze monthly reporting data.”

Once the workflow is clear, identify the data category. Does it include public information, internal business information, customer data, employee data, financial records, health information, legal documents, credentials, or proprietary work? The more sensitive the data, the more important it is to understand the tool’s settings and contractual protections.

It also helps to identify where the output goes. Is it reviewed by a person before it is used? Is it copied into a client email, published online, saved in a shared drive, or entered into another system? An AI-generated summary that stays as an internal draft has different implications than one that automatically updates a customer-facing record.

This process does not need to be heavy. A small tool inventory with the tool name, owner, use case, account type, data category, integrations, cost, and approval status is often enough to reveal where attention is needed.

Separate low-risk experimentation from higher-risk use

Not every AI use deserves the same response. A simple risk framework helps teams move away from all-or-nothing decisions.

Low-risk uses may include brainstorming from public information, improving the clarity of a generic draft, generating a meeting agenda, or creating an outline that is reviewed by a person. These uses still benefit from guidelines, but they may not require a lengthy approval process.

Moderate-risk uses may involve internal documents, work emails, non-public strategies, or structured data that needs review before it is entered into a tool. These should generally use approved accounts, documented settings, and clear data-handling rules.

Higher-risk uses may involve personal information, regulated information, client confidentiality, financial records, credentials, legal materials, proprietary source code, or decisions that can materially affect people. These need a more careful review before use, and some may not be appropriate for public or consumer-grade AI tools at all.

The purpose of classification is not to make employees memorize a complicated framework. It is to make the right decision easier in the moment. People should know that public information and sensitive information are not handled the same way, and they should know where to ask when they are unsure.

Create an AI policy people can actually use

An AI policy should guide real decisions, not become another document employees never open. The best policies are short enough to understand, specific enough to apply, and flexible enough to evolve as tools change.

Start with the basics. Explain what AI use is allowed, what information must never be entered into unapproved tools, who can approve a new platform, and what employees should do if they are uncertain. Include a short list of examples so people can recognize sensitive data in their own work.

The policy should also address output quality. Employees should understand that AI can help create a draft, summarize information, or speed up routine work, but it does not replace judgment. People remain responsible for checking facts, protecting confidentiality, following company standards, and ensuring final work is appropriate for its audience.

A policy without a workable process often creates more shadow AI. If asking for a tool review means waiting weeks with no update, employees may go back to finding their own solutions. Give people a clear request path, a realistic response time, and a simple form that asks only for the information needed to assess the tool.

Give employees approved ways to solve common problems

A company can tell employees not to use unapproved AI, but that instruction works best when there is an alternative.

Look at the use cases that appear most often in the discovery process. If people want help with meeting summaries, identify an approved approach. If they need writing support, clarify which tool and account type they can use. If they need help with research, data analysis, or coding, provide guidelines that fit those tasks instead of issuing one broad rule for every situation.

This does not mean leadership needs to select a separate AI product for every department. It means people need a small set of supported options for their most common needs. Clear options reduce the temptation to use tools that have not been assessed.

Training should be practical and brief. Instead of explaining every detail of how AI models work, show employees what they can use, what they should avoid entering, how to review an output, and where to get help. A short example is often more memorable than a long presentation.

Build review into onboarding and offboarding

Shadow AI becomes harder to manage when it is treated as a one-time cleanup. Tools and features change too quickly for that approach to hold up.

Include AI questions in onboarding. New employees should know which tools are approved, how to request a new one, what data-handling rules apply, and why personal accounts may not be appropriate for business work. This can sit alongside existing guidance on passwords, file sharing, phishing, and acceptable use.

Offboarding matters too. If an employee used a personal account to create work-related documents, transcripts, prompts, or workflows, the company may not have access to that work after they leave. A standard offboarding checklist should ask whether any business processes, files, or subscriptions are tied to personal accounts and move them where possible.

This is also where a broader security model helps. Zero Trust onboarding is not about assuming employees are untrustworthy. It is about ensuring that access is intentional, limited to what a role needs, and reviewed as people join, change responsibilities, or leave. The same thinking applies to AI tools connected to company data.

Person reviewing analytics dashboards and charts on a laptop at a desk.

Regular monitoring helps businesses spot new AI tools, understand how they are being used, and address potential data risks before they become harder to manage.

Use monitoring to maintain visibility over time

Once the initial review is complete, the work shifts from discovery to ongoing visibility. New AI tools will continue to appear, existing software will add AI features, and employees will keep looking for ways to save time.

That does not require tracking every click or creating an atmosphere of surveillance. It means putting reasonable monitoring and review practices around company systems. Depending on the organization, that may include reviewing new software connected through work accounts, monitoring browser extensions on managed devices, checking unusual SaaS spending, and reviewing DNS or web-filtering data for new tools with significant usage.

The purpose is to notice patterns early. If a new tool appears across multiple teams, that could indicate a useful unmet need. If a tool is receiving sensitive information, that may require a quicker review. If employees are using different personal accounts for the same workflow, leadership may need to provide a shared, managed option.

Shadow AI monitoring works best when it is part of a wider approach to understanding how technology is used across the organization. It should help leaders make better decisions, not simply create more reports.

Make AI governance part of future-proofing IT

Future-proofing IT is often described as a technology project, but it is really a decision-making habit. It means creating enough structure that the organization can adopt useful changes without losing track of risk, cost, or ownership.

AI is a clear example. Businesses do not need a perfect five-year AI roadmap before they begin. They do need a way to recognize new tools, understand the data involved, make reasonable decisions, and update those decisions as the technology changes.

This approach is especially useful for organizations that already feel stretched. Cybersecurity for nonprofits, startups, and small businesses cannot rely on policies that assume a large internal security team. Controls need to be proportional, understandable, and connected to the way people actually work.

Good governance also makes conversations with clients, funders, partners, and auditors easier. When someone asks how the organization manages AI use, leadership can explain the process plainly: which tools are approved, how new tools are reviewed, what information is protected, and how employees receive guidance.

Common mistakes to avoid

The first common mistake is treating AI as a problem to eliminate. AI tools are already part of many employees’ personal and professional lives. A blanket ban may feel simple, but it often drives use further out of view while doing little to address the reasons people adopted the tools in the first place.

The second mistake is creating rules without providing alternatives. If the policy says no but the team still has the same time-consuming work, people may feel they have been given a restriction without support. Approved options, clear workflows, and a responsive review process make compliance more realistic.

The third mistake is focusing only on a public chatbot while overlooking AI features inside existing software. The most significant data movement may happen through a tool the company already pays for but has not configured or reviewed carefully.

The fourth mistake is assuming an AI output is reliable because it sounds polished. AI can be useful for drafts and summaries, but important information should still be reviewed by someone who understands the context. That is especially true for content involving contracts, policies, finances, compliance, customers, or public communication.

The fifth mistake is making the process too complex. A small organization does not need a large committee meeting every time someone wants to test a productivity tool. It needs clear thresholds for what can be tried, what needs review, and who can make the call.

A practical first-month plan

If your organization is starting from zero, a focused first month can create useful momentum without becoming a major internal disruption.

  1. Week one: Set the scope and communicate the purpose. Define shadow AI in plain language, announce the review, and ask employees to share what tools or AI features they use for work.

  2. Week two: Gather the available evidence. Review software expenses, work-account connections, managed browser extensions, current SaaS records, and other available system data. Combine this with employee feedback.

  3. Week three: Classify the tools. Identify the use case, data involved, account type, integrations, ownership, and level of risk. Decide which tools can remain in use, which need changes, and which need to stop.

  4. Week four: Publish simple guidance. Share approved tools, prohibited data types, a request process for new tools, and expectations for reviewing AI-generated work. Schedule the next review before the project loses momentum.

This process will not answer every question, and it does not need to. The point is to move from uncertainty to a more informed baseline. From there, the organization can improve its practices as its use of AI develops.

The goal is safe progress, not perfect control

AI adoption will keep changing. New products will launch, existing platforms will add features, and employees will find new ways to use technology in their work. Trying to control every possibility is not realistic.

What is realistic is creating a culture where people understand the boundaries, feel comfortable asking questions, and have safe options for common tasks. It is also realistic to maintain enough visibility that leaders are not surprised by a tool only after a problem occurs.

At 24hourtek, we see this as part of the day-to-day work of helping businesses make technology less stressful and more dependable. The useful outcome is not a long inventory for its own sake. It is a clearer understanding of where data is going, which tools are helping, and what needs attention before it becomes a bigger issue.

About 24hourtek

24hourtek, Inc is a forward thinking managed service provider that offers ongoing IT support and strategic guidance to businesses. We meet with our clients at least once a month to review strategy, security posture, and provide guidance on future-proofing your IT.

📅 Let us help you, book a call with us today

Frequently Asked Questions

Can't find the answer you're looking for?

What is an example of shadow AI?

How can a business detect shadow AI?

Should businesses ban AI tools at work?

Frequently Asked Questions

Can't find the answer you're looking for?

What is an example of shadow AI?

How can a business detect shadow AI?

Should businesses ban AI tools at work?

Frequently Asked Questions

Can't find the answer you're looking for?

What is an example of shadow AI?

How can a business detect shadow AI?

Should businesses ban AI tools at work?

Looking for a managed IT services provider?

Contact us today to explore the possibilities.

Learn how our team will future-proof your IT.

The Forward Thinking IT Company.

24HourTek serves businesses across the San Francisco Bay Area with managed IT support, cybersecurity, Microsoft 365 management, and IT consulting. Our clients are located throughout San Francisco, Oakland, San Jose, Fremont, Berkeley, Walnut Creek, Palo Alto, Redwood City, Santa Clara, and the broader Bay Area region, including Alameda County, Santa Clara County, and San Mateo County. We support companies of all sizes with both on-site and remote IT services across Northern California.

© 2024 All Rights Preserved by 24hourtek, LLC.

We focus on user experience as IT service partners.

24HourTek serves businesses across the San Francisco Bay Area with managed IT support, cybersecurity, Microsoft 365 management, and IT consulting. Our clients are located throughout San Francisco, Oakland, San Jose, Fremont, Berkeley, Walnut Creek, Palo Alto, Redwood City, Santa Clara, and the broader Bay Area region, including Alameda County, Santa Clara County, and San Mateo County. We support companies of all sizes with both on-site and remote IT services across Northern California.

© 2024 All Rights Preserved by 24hourtek, LLC.

The Forward Thinking IT Company.

24HourTek serves businesses across the San Francisco Bay Area with managed IT support, cybersecurity, Microsoft 365 management, and IT consulting. Our clients are located throughout San Francisco, Oakland, San Jose, Fremont, Berkeley, Walnut Creek, Palo Alto, Redwood City, Santa Clara, and the broader Bay Area region, including Alameda County, Santa Clara County, and San Mateo County. We support companies of all sizes with both on-site and remote IT services across Northern California.

24hourtek, LLC © 2024 All Rights Reserved.