Shadow AI Detection: A Practical Enterprise Guide
A working framework for finding the AI tools already touching your organization’s data — the four categories to look for, the telemetry that surfaces them, and the classification and remediation patterns that turn discovery into a governed program.
Shadow AI is the population of AI tools, features, and integrations touching your organization’s data without security team awareness, governance, or controls — typically the largest single AI risk in mid-market environments. Detection combines network, CASB, and endpoint telemetry; a five-attribute classification model and four remediation patterns turn discovery into a governed program.
What Shadow AI Is
A representative mid-market organization (250–1,000 employees) typically has 15–30 distinct AI tools in active use across functions — only a fraction of which are documented in any inventory. The gap between assumed AI usage and actual AI usage is the shadow AI footprint, and closing that gap is the point of everything that follows.
The Four Categories of Shadow AI
Detection is more tractable when you classify what you’re looking for. Each category requires different telemetry, a different governance model, and a different remediation path.
Direct-Use Shadow AI
Employees using public LLMs — ChatGPT, Claude, Gemini, Perplexity, Copilot — directly via web interfaces or consumer accounts. The most common starting point and usually the first thing discovery surfaces.
Embedded Shadow AI
Vendor SaaS platforms with active LLM features that touch your data — Microsoft Copilot, Salesforce Einstein, Notion AI, Slack AI, Zoom AI Companion, Atlassian Intelligence, HubSpot’s AI features, and many others. Often active by default with no separate security review.
Pilot Shadow AI
Internal AI initiatives launched by individual teams without security review — most often marketing, customer support, or engineering. Usually vendor APIs (OpenAI, Anthropic, Google Vertex) consumed via prototype applications.
Vendor-API Shadow AI
Vendors delivering services to your organization that use AI in delivering those services, often without disclosure — translation, content moderation, document processing, transcription tools.
Discovery Telemetry
Effective shadow AI detection requires three telemetry sources working together. No single source covers all four categories above.
Network Egress Monitoring
DNS and TLS visibility into AI provider domains. DNS query logs and TLS SNI records are the highest-leverage telemetry — most organizations already have it; few have dashboarded it for AI provider activity.
CASB / SSPM
Cloud Access Security Broker and SaaS Security Posture Management tooling inspects outbound traffic to sanctioned and unsanctioned SaaS platforms — often a richer signal than network egress alone for embedded shadow AI.
Endpoint Detection
Process-level visibility into AI client applications running locally — browser extensions, desktop AI applications (Claude Desktop, ChatGPT Desktop, Microsoft 365 Copilot), and developer tools (Cursor, GitHub Copilot, Codeium).
The combination of these three telemetry sources usually surfaces 80–95% of shadow AI activity within the first month of monitoring.
The Classification Framework
Once detected, every shadow AI tool needs to be classified. Five attributes drive the classification.
Explicitly approved, conditionally permitted, prohibited, or undecided.
What classes of organizational data could touch this tool — PII, PHI, CUI, financial, IP, internal communications.
Does the vendor have appropriate controls — SOC 2, contractual data-handling commitments, opt-out from training.
Single-user, team-level, or organization-wide adoption.
Is there an enterprise-grade alternative serving the same function.
The classification informs the remediation path: prohibit, gate, redirect to sanctioned alternative, or sanction with controls.
The Remediation Patterns
Four patterns cover most shadow AI remediation paths. Most environments need all four simultaneously.
Prohibit and Block
Used where the data exposure cannot be controlled and no acceptable alternative exists. Implementation: network egress block, DNS sinkhole, CASB policy enforcement.
Redirect to Sanctioned Alternative
Used when employees have a legitimate need served by an enterprise-controlled tool. Most common: redirect ChatGPT consumer accounts to ChatGPT Enterprise or Microsoft Copilot for Microsoft 365.
Sanction with Controls
Used when the tool serves a real business need and can be governed appropriately. Implementation: enterprise SSO + MFA, audit logging, contractual data handling, acceptable-use training.
Conditional Permit
Used for tools allowed for specific use cases but not others. Implementation: documented use-case classification, role-based access, supervisor approval for sensitive cases.
Common Pitfalls
Four patterns that recur across shadow AI programs that stall or backfire.
Treating shadow AI as a single yes/no decision. Most environments need all four remediation patterns simultaneously — a single policy across every tool produces enforcement that’s either too lax to matter or too strict to comply with.
Over-rotating on direct-use tools. ChatGPT in the browser is the most visible category but often not the largest data-exposure risk — embedded shadow AI in vendor SaaS frequently touches more sensitive data.
New AI tools launch monthly; vendor features get added quarterly. Discovery cadence should be continuous, not periodic.
Top-down enforcement without engaging the employees actually using the tools produces resistance and underground usage. Discovery + classification + governance works substantially better when affected employees are part of the design.
Common Questions
What’s the smallest first step?
How often should we rerun discovery?
We’re using Microsoft 365 Copilot. Is that shadow AI?
What about employee-owned AI accounts used for personal productivity?
How does this interact with AI governance under NIST AI RMF?
Get Help
Armorstack runs Shadow AI Discovery as a fixed-scope engagement. Most engagements complete the initial discovery within 5–10 business days and produce a remediation roadmap with prioritized actions. Book a 30-minute call: armorstack.ai/contact · 877-890-5508.
Want the Shadow AI Discovery service itself, with pricing and deliverables? → | Need the full governance framework, not just detection? →
Continue Reading
Ready to Run Shadow AI Discovery on Your Environment?
Armorstack scopes the four shadow AI categories, stands up the telemetry, and delivers a classified inventory with a prioritized remediation roadmap — most engagements complete initial discovery in 5–10 business days. Schedule AI Security Consult →
Last reviewed 2026-05-01 · Authored by Dale Boehm, CEO Armorstack — CISA, CDPP