What is Shadow AI and how do you find it?
Short answer
Shadow AI is work use of an AI tool the business has not approved. That includes a personal ChatGPT account on a work laptop, a meeting bot that joined the calendar without a review, an AI feature that shipped inside software you already pay for, and — in Microsoft’s current product language — unsanctioned local agents running on managed endpoints.
People use it because the approved path is slow, missing, or worse at the job. The risk is not that they used AI. It is that nobody can say what data went in, under whose account, or whether an agent took an action.
You find it with overlapping methods, not one scan: DNS and proxy, CASB, OAuth grants, browser extensions, expenses, API/MCP connections, and department interviews. Then you run an intake: allow, restrict, or block, with a sanctioned alternative when you block. A blanket ban without an approved path recreates Shadow AI on personal phones.
This is risk-management content, not a compliance certificate. Finding Shadow AI does not make you CMMC Level 2 certified or FedRAMP authorized. There is already a live tool for a first pass — the Shadow AI Risk Assessment. This article does not duplicate it. Use the tool when you want a scored picture of what you do and do not know; use the methods below when you are ready to look.
What Shadow AI is (and is not)
In this knowledge base, Shadow AI means:
- A tool that is not on the approved list, used for company work.
- A personal account of an otherwise approved product (consumer Copilot vs tenant Copilot is the usual split).
- An AI feature inside a SaaS product that was never scoped, even if the product itself is licensed.
- A browser extension that reads the page and sends it to a model.
- An agent or bot that can act — send mail, write to a record, call an API — that security did not inventory.
It is not “any AI.” Microsoft 365 Copilot on the tenant, with SSO and a data-class decision, is not Shadow AI. It can still be ungoverned. That is a different problem, covered in AI data governance in 2026.
Gartner’s November 2025 survey of 302 cybersecurity leaders is the figure we already cite there: 69% of organizations suspect or have confirmed employees using prohibited public GenAI tools, and Gartner predicts more than 40% of enterprises will see shadow-AI incidents by 2030. Treat that as a vendor survey, not a census of your company. The point stands: if you have not looked, you should not be confident.
Microsoft’s “shadow agents” language
As of this August 2026 review, Microsoft documents a Shadow AI experience in the Microsoft 365 admin center (Frontier) for unsanctioned local AI agents on Intune-enrolled Windows devices. Microsoft’s Cloud Adoption Framework also names shadow AI proliferation and dormant agents as operational risks when you manage agents across the organization.
That language is current. It is also narrower than the definition above. The admin-center page does not see a personal ChatGPT tab on a phone, a contractor’s home PC, or a meeting bot that only exists as an OAuth grant. Use it if you have the license. Do not treat it as the inventory.
Why employees use it
Almost never malice. Typical reasons, in the order we hear them:
- The approved tool is not approved yet — procurement takes months; the deadline is Friday.
- The approved tool is worse at the task — summarising a long contract, cleaning a spreadsheet, drafting a first email.
- The approved tool is on a different account — they already pay for ChatGPT Plus at home; SSO was never turned on at work.
- They did not know it was AI — a notetaker in the meeting, a suggest-reply in the help desk, a copilot toggle in the CRM.
- IT blocked the website and not the work — so the same paste happens on a phone using cellular, which your DNS never sees.
Governance that ignores those incentives will lose. The acceptable-use policy has to name a sanctioned path, not only a prohibition.
What actually goes wrong
NIST AI 600-1 lists data privacy and information security among risks unique to or exacerbated by generative AI. OWASP’s agent cheat sheet adds tool abuse, data exfiltration, and excessive autonomy once the tool can act. In operator language:
| What happens | Why it matters | What closes it |
|---|---|---|
| Confidential files in a consumer model | A prompt is egress. You may not be able to delete it later. | Classification mapped to approved tools; DLP where it reaches the desktop |
| No attribution | Shared or personal logins. You cannot answer who pasted the contract. | SSO on approved tools; ban shared AI accounts |
| An agent acts | Mail sent, record changed, API called. A chatbot risk becomes an action risk. | Inventory agents separately; identity, allowlists, human approval, kill switch |
| CUI leaves the assessed boundary | Existing contract and NIST SP 800-171 issues. Not a new AI certificate. | Scoping. If you do not hold CUI, say so; do not collect a badge you do not have |
| You cannot investigate Tuesday | No logs of the tool, the prompt, or the OAuth grant. | Identity logs, DNS, and — for agents — tool-call logs, not chat transcripts |
We do not use health-record examples here. If you are a covered entity, your existing privacy program owns that mapping.
How to find it
Seven methods. Run more than one. Each misses a different slice.
1. DNS, proxy and firewall
Consumer chatbot domains, vendor API endpoints, and new SaaS. Your existing WAN and firewall logs are often enough to see volume you did not know you had. This is the NOC vantage: the data path is a network path. It misses personal phones on cellular and it misses AI that never leaves a SaaS you already allow (a Copilot toggle inside a licensed CRM).
2. CASB or equivalent SaaS discovery
If you have a cloud-access security broker, or Microsoft Defender / Google equivalent discovery, use it for unsanctioned SaaS. Same limit as DNS for devices you do not manage.
3. OAuth grant review
Meeting bots, calendar assistants, “summarize my inbox” apps. In Microsoft 365 and Google Workspace, list third-party apps with access to mail, files and calendar. Revoke anything with no named owner. This is how you find the bot that never hit a blocked domain because it signed in as the user.
4. Browser extensions
Anything that can read the page. Inventory via Intune, Chrome/Edge enterprise, or a device-management equivalent. Extensions are a prompt channel that looks like a productivity feature.
5. Expenses and cards
ChatGPT Plus, Claude Pro, Copilot Pro, Midjourney, meeting-notetaker seats on a personal or department card. Finance will find tools DNS never saw. Ask for AI-looking merchants, not a perfect taxonomy.
6. APIs, MCP and local agents
Developers wire models and tools directly. Look for API keys in vaults and repos, MCP server configs, and local agents on managed endpoints. Microsoft’s Shadow AI admin-center page is one feed for the last of those on Intune-enrolled Windows. OWASP’s warning about unrestricted MCP tools is the engineering version of the same hunt.
7. Department interviews
Sales, finance, operations, legal, support, and whoever answers the phone. Ask: what do you paste into a chatbot, which meeting bot do you use, who has a personal Copilot, which browser extension “writes for you”? Technical discovery misses the tool that never touches your DNS. Interviews miss the person who will not admit it until there is an intake that is not a gotcha.
The Shadow AI Risk Assessment is a scored questionnaire. It runs in your browser, creates no account, and does not send your answers anywhere. It will not scan your network. It will tell you which of the questions above you cannot yet answer, and which three gaps to close first. About four minutes. This article is the how-to; the tool is the conversion path, not a second copy of the same page.
Intake: what you do when you find it
Discovery without a decision framework produces a spreadsheet and no change. The policy article names the path; here is the operating sequence.
- A named intake — ticket queue or mailbox, not a vague “tell IT.”
- A short form — tool, job it does, data classes involved, who already uses it, whether it can act (send/write/pay).
- A decision in days, not months — allow with conditions, restrict (data class or department only), or block.
- A sanctioned alternative when you block — otherwise the work moves to a phone.
- Write it on the living approved/restricted/blocked list — the list the acceptable-use policy points at.
- First honest report is intake, not a gotcha. Punishment on first disclosure ends disclosure.
Block versus govern
Block when you cannot accept the data path: consumer models for Confidential or CUI, unsanctioned agents that can send or pay, extensions that read every tab, tools with no SSO and no retention story. Govern when the job is real and you can put it on a company account with a data-class rule.
Microsoft’s own Shadow AI blocking, where it exists, is an Intune policy on managed Windows — useful, and limited to those devices. A DNS sinkhole of chatbot domains is the same idea at the network edge, with the same hole: unmanaged endpoints.
The 40-control checklist is the rest of the program once you can see the estate: identity, agent controls, monitoring, oversight, incident response. Shadow AI is controls 6–10 plus the intake. It is not the whole list.
Frequently asked questions
What is Shadow AI?
Work use of an AI tool the organization has not approved — including a personal account of an otherwise approved product, a meeting bot nobody reviewed, an AI feature that shipped inside software you already pay for, and unsanctioned local agents on endpoints. It is usually not malice. It is a deadline and a tool that was faster.
Is Microsoft’s “Shadow AI” the same as employee chatbots?
Not exactly. As of this review, Microsoft documents a Shadow AI page in the Microsoft 365 admin center for unsanctioned local AI agents on Intune-managed Windows devices. That is one feed, and a narrower idea than every unsanctioned chatbot. Use Microsoft’s language for local agents; do not treat the admin-center page as a complete inventory.
Does finding Shadow AI certify us for CMMC or FedRAMP?
No. Discovery is risk management, not a certificate. An inventory does not make you CMMC Level 2 certified or FedRAMP authorized. If CUI went into an unapproved tool, that is a scoping and contract problem under existing rules — still not an AI badge.
Should we just block every AI website?
Usually no. A blanket block without a sanctioned alternative moves the same work onto personal phones and home ISPs you cannot see. Block what you cannot accept; govern the rest; give people an approved path for the job they were doing.
How do you actually find Shadow AI?
Seven overlapping methods: DNS and proxy logs, CASB or equivalent SaaS discovery, OAuth grant review, browser-extension inventory, expense and card review, API and MCP connection review, and department interviews. No single method is complete. Interviews catch what the network never sees.
Is the Shadow AI Assessment a network scan?
No. It is a scored questionnaire that runs in your browser and sends nothing. It tells you which questions you cannot yet answer. It does not replace DNS, OAuth or interviews, and this article does not duplicate the tool.
Why do employees use unapproved AI?
The approved path is slow, missing, or worse at the task. People paste a contract to summarize it, record a call because notes take an hour, or use a personal Copilot because IT has not licensed the tenant feature. Governance that ignores that incentive will lose.
What is a reasonable intake process?
A named mailbox or ticket, a short form (what tool, what job, what data, who already uses it), a decision in days not months (allow, restrict, or block), and a sanctioned alternative when you block. First honest report is intake, not a gotcha.
Related articles
- Shadow AI Risk Assessment — the live tool. Free, private, in-browser. This page does not copy it.
- AI agent security for business: 12 safeguards — the agent-access pillar; inventory is safeguard 2.
- How to build an enterprise AI inventory — the living approved / restricted / blocked list these methods fill.
- AI security checklist for businesses: 40 controls — discovery is controls 6–10; the rest of the program sits around it.
- How to create a corporate AI acceptable use policy — the document that defines Shadow AI and the intake path.
- What does AI data governance actually require in 2026? — Shadow AI as one of four problems, not the only one.
- What separates AI agents that ship to production from the ones that stay demos? — when Shadow AI can act, not only answer.
- ChatGPT can now read and send your Apple Messages — personal accounts and unmanaged Macs as a Shadow AI question.
- Five inexpensive cybersecurity improvements — MFA and identity hygiene discovery sits on.
References
Microsoft’s Shadow AI admin-center language was checked in August 2026 and is treated as current. The assessment tool is separate and live; this article links it rather than rebuilding it.
- Microsoft Learn — Shadow AI in the Microsoft 365 admin center— current Microsoft language for unsanctioned local AI agents on Intune-managed Windows devices. Not a complete Shadow AI inventory.
- Microsoft Learn — Manage AI agents across your organization— names shadow AI proliferation and dormant agents as operational risks.
- Microsoft Learn — Secure autonomous agentic AI systems— why an unsanctioned agent is a different problem from an unsanctioned chatbot.
- NIST AI 600-1 — Generative AI Profile (July 2024)— data privacy and information security among generative-AI risks. Voluntary.
- NIST CSF 2.0 (February 2024)— Identify and Govern as the functions discovery sits in.
- OWASP — AI Agent Security Cheat Sheet— tool abuse and data exfiltration once the unsanctioned tool can act.
- Gartner — Critical GenAI Blind Spots (19 November 2025)— 69% suspect or confirm prohibited public GenAI; prediction of shadow-AI incidents by 2030. Survey of 302 cybersecurity leaders, not a census.
Managed network and communications services, SDVOSB. Shadow AI is often a network-visibility problem wearing an AI name: if you can see the path, you can decide. This article is not a CMMC or FedRAMP certificate. Run the Shadow AI Assessment, then we can help with inventory, policy and the 40 controls. Support: (888) 989-4872 · support@adampulse.us