Shadow AI Detection: A Practical Enterprise Guide

AI Security Deep Dive

Shadow AI Detection: A Practical Enterprise Guide

A working framework for finding the AI tools already touching your organization’s data — the four categories to look for, the telemetry that surfaces them, and the classification and remediation patterns that turn discovery into a governed program.

By Dale Boehm, CEO Armorstack — CISA, CDPP|Last reviewed May 1, 2026|9 min read

The 50-Word Answer

Shadow AI is the population of AI tools, features, and integrations touching your organization’s data without security team awareness, governance, or controls — typically the largest single AI risk in mid-market environments. Detection combines network, CASB, and endpoint telemetry; a five-attribute classification model and four remediation patterns turn discovery into a governed program.

Definition

What Shadow AI Is

Shadow AI is the population of AI tools, features, and integrations touching your organization’s data without security team awareness, governance, or controls. It is the AI-era extension of shadow IT, and it is typically the largest single AI risk in mid-market environments today.

A representative mid-market organization (250–1,000 employees) typically has 15–30 distinct AI tools in active use across functions — only a fraction of which are documented in any inventory. The gap between assumed AI usage and actual AI usage is the shadow AI footprint, and closing that gap is the point of everything that follows.

Classification

The Four Categories of Shadow AI

Detection is more tractable when you classify what you’re looking for. Each category requires different telemetry, a different governance model, and a different remediation path.

01

Direct-Use Shadow AI

Employees using public LLMs — ChatGPT, Claude, Gemini, Perplexity, Copilot — directly via web interfaces or consumer accounts. The most common starting point and usually the first thing discovery surfaces.

02

Embedded Shadow AI

Vendor SaaS platforms with active LLM features that touch your data — Microsoft Copilot, Salesforce Einstein, Notion AI, Slack AI, Zoom AI Companion, Atlassian Intelligence, HubSpot’s AI features, and many others. Often active by default with no separate security review.

03

Pilot Shadow AI

Internal AI initiatives launched by individual teams without security review — most often marketing, customer support, or engineering. Usually vendor APIs (OpenAI, Anthropic, Google Vertex) consumed via prototype applications.

04

Vendor-API Shadow AI

Vendors delivering services to your organization that use AI in delivering those services, often without disclosure — translation, content moderation, document processing, transcription tools.

Detection

Discovery Telemetry

Effective shadow AI detection requires three telemetry sources working together. No single source covers all four categories above.

01

Network Egress Monitoring

DNS and TLS visibility into AI provider domains. DNS query logs and TLS SNI records are the highest-leverage telemetry — most organizations already have it; few have dashboarded it for AI provider activity.

02

CASB / SSPM

Cloud Access Security Broker and SaaS Security Posture Management tooling inspects outbound traffic to sanctioned and unsanctioned SaaS platforms — often a richer signal than network egress alone for embedded shadow AI.

03

Endpoint Detection

Process-level visibility into AI client applications running locally — browser extensions, desktop AI applications (Claude Desktop, ChatGPT Desktop, Microsoft 365 Copilot), and developer tools (Cursor, GitHub Copilot, Codeium).

ProviderDomains to Monitor
OpenAIopenai.com, chat.openai.com, platform.openai.com, api.openai.com
Anthropicanthropic.com, claude.ai, api.anthropic.com
Googlegemini.google.com, generativelanguage.googleapis.com, vertex.googleapis.com
Microsoftcopilot.microsoft.com, openai.azure.com
Perplexityperplexity.ai
Meta AImeta.ai
OtherCohere, Mistral, xAI, and the long tail of emerging providers

The combination of these three telemetry sources usually surfaces 80–95% of shadow AI activity within the first month of monitoring.

Classification

The Classification Framework

Once detected, every shadow AI tool needs to be classified. Five attributes drive the classification.

Sanctioned Status

Explicitly approved, conditionally permitted, prohibited, or undecided.

Data-Sensitivity Exposure

What classes of organizational data could touch this tool — PII, PHI, CUI, financial, IP, internal communications.

Vendor Security Posture

Does the vendor have appropriate controls — SOC 2, contractual data-handling commitments, opt-out from training.

Usage Prevalence

Single-user, team-level, or organization-wide adoption.

Replaceability

Is there an enterprise-grade alternative serving the same function.

The classification informs the remediation path: prohibit, gate, redirect to sanctioned alternative, or sanction with controls.

Remediation

The Remediation Patterns

Four patterns cover most shadow AI remediation paths. Most environments need all four simultaneously.

01

Prohibit and Block

Used where the data exposure cannot be controlled and no acceptable alternative exists. Implementation: network egress block, DNS sinkhole, CASB policy enforcement.

02

Redirect to Sanctioned Alternative

Used when employees have a legitimate need served by an enterprise-controlled tool. Most common: redirect ChatGPT consumer accounts to ChatGPT Enterprise or Microsoft Copilot for Microsoft 365.

03

Sanction with Controls

Used when the tool serves a real business need and can be governed appropriately. Implementation: enterprise SSO + MFA, audit logging, contractual data handling, acceptable-use training.

04

Conditional Permit

Used for tools allowed for specific use cases but not others. Implementation: documented use-case classification, role-based access, supervisor approval for sensitive cases.

Lessons Learned

Common Pitfalls

Four patterns that recur across shadow AI programs that stall or backfire.

Binary Block-or-Allow

Treating shadow AI as a single yes/no decision. Most environments need all four remediation patterns simultaneously — a single policy across every tool produces enforcement that’s either too lax to matter or too strict to comply with.

Ignoring Embedded Shadow AI

Over-rotating on direct-use tools. ChatGPT in the browser is the most visible category but often not the largest data-exposure risk — embedded shadow AI in vendor SaaS frequently touches more sensitive data.

Treating Discovery as One-Time

New AI tools launch monthly; vendor features get added quarterly. Discovery cadence should be continuous, not periodic.

Skipping the Employee Conversation

Top-down enforcement without engaging the employees actually using the tools produces resistance and underground usage. Discovery + classification + governance works substantially better when affected employees are part of the design.

FAQ

Common Questions

What’s the smallest first step?
A single-day Shadow AI Discovery — pull 30–60 days of DNS and TLS logs, run them against an AI-provider domain list, dashboard the results. The output of one day’s work is usually sufficient to scope a fuller program.
How often should we rerun discovery?
Continuous. Once the initial discovery is complete, the same telemetry sources should feed an ongoing monitoring dashboard with weekly anomaly review.
We’re using Microsoft 365 Copilot. Is that shadow AI?
If it was reviewed, sanctioned, and governed, it is not shadow AI. If it was activated by IT or marketing without security team review and policy, it falls into the embedded shadow AI category.
What about employee-owned AI accounts used for personal productivity?
The boundary is whether the tool touches organizational data. An employee using ChatGPT for personal tasks on a personal account from a personal device is not shadow AI. The same employee pasting work content into the same account from a corporate device is.
How does this interact with AI governance under NIST AI RMF?
Shadow AI Discovery is the natural first step in the NIST AI RMF “Map” function. Without discovery, the inventory required by Map is incomplete. With discovery, the inventory becomes meaningful.
Armorstack Approach

Get Help

Armorstack runs Shadow AI Discovery as a fixed-scope engagement. Most engagements complete the initial discovery within 5–10 business days and produce a remediation roadmap with prioritized actions. Book a 30-minute call: armorstack.ai/contact · 877-890-5508.

Want the Shadow AI Discovery service itself, with pricing and deliverables? →  |  Need the full governance framework, not just detection? →

Ready to Run Shadow AI Discovery on Your Environment?

Armorstack scopes the four shadow AI categories, stands up the telemetry, and delivers a classified inventory with a prioritized remediation roadmap — most engagements complete initial discovery in 5–10 business days. Schedule AI Security Consult →

Last reviewed 2026-05-01 · Authored by Dale Boehm, CEO Armorstack — CISA, CDPP