AI security

Shadow AI assessment and discovery

Employees adopt AI tools faster than IT can approve them. Our shadow AI assessment shows who is using which AI tools, how they use them and what company data goes in, so you can set rules and controls based on evidence.

  • Discovery of approved and unapproved AI tools
  • Evidence of what data reaches them
  • Results that feed policy and technical controls
Professional working at a computer from home

Evidence-based discovery

Technical data from your environment plus interviews

Framework-aligned

Results mapped to NIST AI RMF and ISO/IEC 42001

Top virtual CISO services company

Recognized by Cyber Security Review

Analysts working at workstations in an office

What is shadow AI

Shadow AI is AI your organization hasn’t approved or can’t see

Shadow AI covers any AI tool or feature used for work without IT or security knowing about it. That includes public chatbots opened in a browser, AI features switched on inside software you already pay for, browser extensions and personal accounts on AI services used with company data.

Most of it starts with good intentions. People want to write faster, summarize documents or analyze data. The risk comes from what they paste in, where it is stored and whether the service can use it to train its models. Employee ChatGPT risk is the most common example, but it is rarely the only tool in use.

Shadow AI discovery

What the assessment tells you

We combine technical data from your environment with short interviews, so the picture reflects what people actually do.

Shadow AI risk assessment

Risky behaviors we look for

  • Pasting client, patient or employee data into public AI tools
  • Uploading contracts, financials or source code for analysis
  • Using personal AI accounts for company work
  • Installing AI browser extensions that can read web pages and email
  • Connecting AI apps to email, files or calendars with broad permissions
  • Relying on AI output for decisions without review

How it works

How to detect shadow AI and act on it

1

Scope

We agree which users, devices and systems are in scope and which data sources we can review, such as network, identity, endpoint and SaaS logs.

2

Discover

We analyze those sources for AI services and extensions in use, then hold short interviews with teams to understand how and why they use them.

3

Assess

We rate each tool and behavior by the sensitivity of the data involved and the controls around it, and map findings to NIST AI RMF.

4

Recommend

You get a prioritized plan that covers which tools to approve, restrict or block, the policy updates you need and the technical controls to put in place.

From findings to controls

Results that feed policy and controls

Blocking every AI service rarely works. People move to personal devices and the risk becomes harder to see. A better approach is to approve tools that meet the need, set clear rules for data and control the rest.

Your results give you the evidence to do that. We use them to shape your AI governance and acceptable use policy, configure identity and data protection controls and set up ongoing AI monitoring so new tools don’t go unseen.

  • An approved AI tool list based on real business need
  • Acceptable use rules for data in AI tools
  • Sign-in through your identity provider for approved tools
  • Data loss prevention and web filtering for high-risk services
  • Ongoing monitoring for new AI tools
Security engineer working at a workstation in a dark office

FAQ

Shadow AI assessment questions

A shadow AI assessment finds the AI tools employees use without formal approval, shows what data they share with those tools and rates the risk. It ends with recommendations for policy and technical controls.

We review data your environment already holds, such as network and DNS traffic, identity sign-ins, endpoint software and SaaS app connections, and look for AI services and extensions. Interviews with teams fill in how and why each tool is used.

It can be. The risk depends on what data people share, whether they use personal or company accounts and how the service handles and retains that data. The assessment shows which of those conditions apply in your organization.

We focus on patterns across the organization and explain the purpose to staff, which usually improves cooperation. The goal is to give people approved tools and clear rules.

Cost depends on the number of users and locations, the data sources available for discovery and whether you want help putting controls in place afterwards. We scope the work after a short call.

Nothing complicated. It helps to know which logging and security tools you have, and to share any existing AI or acceptable use policy. Our AI acceptable use policy template is a useful starting point if you don’t have one.

Talk to an expert

See the AI tools your people really use

Tell us about your organization and the AI tools you know about. An advisor will reply by email to scope a shadow AI assessment.

  • Scoping call with an AI security advisor
  • Findings that feed policy and controls

Prefer email? Write to [email protected] or call (858) 712-0040.

Send us a message