AI security
Shadow AI assessment and discovery
Employees adopt AI tools faster than IT can approve them. Our shadow AI assessment shows who is using which AI tools, how they use them and what company data goes in, so you can set rules and controls based on evidence.

Evidence-based discovery
Technical data from your environment plus interviews
Framework-aligned
Results mapped to NIST AI RMF and ISO/IEC 42001
Top virtual CISO services company
Recognized by Cyber Security Review

What is shadow AI
Shadow AI is AI your organization hasn’t approved or can’t see
Shadow AI covers any AI tool or feature used for work without IT or security knowing about it. That includes public chatbots opened in a browser, AI features switched on inside software you already pay for, browser extensions and personal accounts on AI services used with company data.
Most of it starts with good intentions. People want to write faster, summarize documents or analyze data. The risk comes from what they paste in, where it is stored and whether the service can use it to train its models. Employee ChatGPT risk is the most common example, but it is rarely the only tool in use.
Shadow AI discovery
What the assessment tells you
We combine technical data from your environment with short interviews, so the picture reflects what people actually do.
Who is using AI
Which departments, roles and individuals use AI tools, and how often.
Which AI tools
Public chatbots, AI features in SaaS apps, browser extensions, coding assistants and AI agents with access to your systems.
What data goes in
The kinds of information shared with AI tools, from general text to client records, source code and financial data.
How accounts are set up
Whether people use company or personal accounts, and whether sign-in runs through your identity provider.
Vendor terms and settings
Retention, training and data handling settings for the tools in use, and where they fall short of your requirements.
Business need
Why teams chose each tool, so approved alternatives meet the need and people stop working around policy.
Shadow AI risk assessment
Risky behaviors we look for
How it works
How to detect shadow AI and act on it
Scope
We agree which users, devices and systems are in scope and which data sources we can review, such as network, identity, endpoint and SaaS logs.
Discover
We analyze those sources for AI services and extensions in use, then hold short interviews with teams to understand how and why they use them.
Assess
We rate each tool and behavior by the sensitivity of the data involved and the controls around it, and map findings to NIST AI RMF.
Recommend
You get a prioritized plan that covers which tools to approve, restrict or block, the policy updates you need and the technical controls to put in place.
From findings to controls
Results that feed policy and controls
Blocking every AI service rarely works. People move to personal devices and the risk becomes harder to see. A better approach is to approve tools that meet the need, set clear rules for data and control the rest.
Your results give you the evidence to do that. We use them to shape your AI governance and acceptable use policy, configure identity and data protection controls and set up ongoing AI monitoring so new tools don’t go unseen.

FAQ
Shadow AI assessment questions
Related services
Related AI services
Talk to an expert
See the AI tools your people really use
Tell us about your organization and the AI tools you know about. An advisor will reply by email to scope a shadow AI assessment.
Prefer email? Write to [email protected] or call (858) 712-0040.
