SaaS Tech Watch
saas

Shadow AI inventory: discovery, acceptable use, and the governance category that formed to fix it

Every figure states its provenance: measured (we ran it) · reported (vendor says) · derived (we calculated).

Every security and IT leadership review this year includes a slide on AI tools employees are using without approval, always presented as a problem. The framing needs revision. Employees adopting AI faster than procurement can register it is not primarily a compliance failure; it is a demand signal plus an inventory failure. The inventory failure is the part we can fix. This piece covers discovery, acceptable use, and the governance tooling category that has formed in response.

Why “shadow IT” analysis does not port to AI

Classic shadow IT discovery assumed tools were installed, subscribed, or integrated. AI tools break all three: browser-only tools have no binary to detect; personal-tier accounts bypass corporate billing; feature-level AI hides inside already-sanctioned tools, where the risk is not “did we buy it” but “did we mean to enable this AI feature.”

The implication: discovery must pull from network and identity telemetry, not procurement.

Discovery: what actually surfaces AI usage

Four telemetry sources, in rough order of coverage:

SourceWhat it catchesWhat it misses
DNS / SWG egressDomains for known AI services, by frequencyREST API use inside sanctioned tools; mobile off-network
SSO logsAI tools signed up with corporate identityTools used under personal accounts
Browser extension inventoryAI plugins and copilots in the browserWeb-only tools
SaaS management platform APIOAuth grants employees have given AI tools to corporate dataTools accessed without OAuth

A working inventory joins these four. Any single one misleads. The hardest gap is the personal-account case: a user copying customer text into a personal AI tool leaves almost no corporate telemetry. No tooling solves this completely; policy and education carry the load.

For AI features embedded inside sanctioned SaaS — the “Copilot in the tool we already bought” class — discovery shifts to vendor audit: which vendors enabled AI features on our tenant, with what defaults, processing what data? Vendor security pages rarely answer this clearly. Direct questions in security review get better answers than documentation.

Acceptable use: the patterns that survive

An acceptable-use policy that says “do not use unauthorised AI tools” is not a policy; it is a wish. Policies that survive contact with engineering teams share three properties.

They classify use, not tool. Tools ship monthly; a single approved list does not match reality. Classification by data class and task works better: “public information, any task” is permissive; “customer personal data in an external prompt” is not; “confidential internal documents” sits between with named exceptions. Users can self-answer without a ticket per new tool.

They name the default. A short sanctioned list with SSO login beats a long prohibition list. Adoption follows the path of least resistance; an easy sanctioned path is the most effective control against the unsanctioned one.

They define the prohibited narrowly. A short bright-line list — no customer personal data, no credentials, no unannounced financials — is auditable. A long list of banned tool names is not.

The governance tooling category that formed

A recognisable category has formed over the last 18 months: AI governance platforms, sometimes marketed as AI-SPM (AI security posture management). The category is heterogeneous enough that a buyer needs to split it before evaluating:

Sub-categoryWhat it doesTypical buyer
AI usage discoveryInventory of AI tools in use, often via SWG / SaaS management integrationsSecurity
AI data-loss preventionIntercept prompts and outputs at browser or proxy levelSecurity + DLP teams
Model and vendor governanceTrack which models are used by first-party AI features, their versions, their data flowsPlatform engineering + risk
Policy and attestationDistribute acceptable-use policy, collect per-user attestation, log violationsCompliance

These categories are sold as one product and are not. A platform strong at discovery may be weak at DLP on browser prompts. Evaluate each sub-capability against the specific gap.

Two implementation notes. Prompt interception at the browser has privacy implications in many jurisdictions; works-council and employee-relations review belongs in the rollout plan, not after. And none of these tools see what happens off corporate devices and networks — policy and culture remain the primary control for the long tail.

What a sane 90-day rollout looks like

A pragmatic sequence for a team starting with no formal position:

  1. Weeks 1–3: discovery. Join the four telemetry sources into a per-team AI usage map. Resist the urge to act on what it shows.
  2. Weeks 4–6: sanctioned default. Stand up at least one sanctioned AI tool for the dominant use case. Adoption of the sanctioned path is the primary control.
  3. Weeks 7–9: acceptable-use. Classification by data and task, short prohibition list, named defaults. Socialise in engineering and security first; company-wide second.
  4. Weeks 10–13: governance tooling. Choose tooling now, with discovery data and policy shape in hand — against real gaps, not marketing slides.

Teams that buy tooling first discover they bought the wrong sub-category. The tooling fits the policy, not the other way around.

What we would not do

  • Block categories at the proxy as the primary control. Users route around it; the sanctioned-default strategy has better long-term results.
  • Treat every unsanctioned use as a discipline event. The goal is visibility, then alignment, not punishment.
  • Assume the inventory is complete. Plan and communicate in the explicit knowledge that it is not.

The bottom line

Shadow AI is a permanent condition, not an incident. The mature posture is continuous discovery, a sanctioned default for dominant use cases, acceptable use defined by data class and task rather than tool, and governance tooling chosen after policy shape exists. Teams that adopt this framing stop chasing tools and start managing risk.

Related reading

from the desk ▸