What Is Shadow AI Discovery?
Shadow AI — employees using unauthorized AI tools that touch corporate, customer, or regulated data without IT or security oversight — is the fastest-growing data governance risk in regulated enterprises. A customer service representative pasting patient records into ChatGPT. A financial analyst uploading a deal model to an AI productivity tool. A developer using an unapproved AI code assistant that trains on proprietary source code.
Shadow AI Discovery is a 30-day fixed-fee engagement that surfaces this risk completely. Armorstack deploys a three-channel telemetry approach: network DNS and proxy log analysis to identify API calls to AI providers, endpoint agent data to catalog installed AI applications and browser extensions, and structured stakeholder interviews to surface sanctioned-but-unmonitored tools. The output is a complete shadow AI inventory ranked by data-exposure severity, with a policy remediation plan, employee communication templates, and an optional managed quarantine service for high-risk tools.
What You Get
- Complete AI use-case inventory: discovered and self-reported, with data-classification for each
- Shadow AI ranked inventory — unauthorized tools scored by data-exposure severity
- Network telemetry analysis: API calls to OpenAI, Anthropic, Google AI, Cohere, Mistral, and 40+ AI providers
- Endpoint and browser extension inventory of installed AI tools
- Data-exposure severity scoring by tool and business unit
- Policy remediation plan with recommended allow/block/monitor tier classification
- Employee communication templates and manager guidance
Who This Is For
CISO
Facing shadow AI exposure from employees using unauthorized tools that process PHI, PCI, IP, or other sensitive data without oversight.
Chief Privacy Officer / DPO
Managing GDPR, CCPA, or HIPAA exposure from employee use of AI tools that may train on or retain sensitive data.
CEO / GC
Wanting a documented, time-bounded engagement to establish a defensible AI governance baseline before formalizing policy.
How It Works
Engagement Scoping
Define organizational scope, telemetry collection sources, data classification tier, and regulatory frameworks. Written engagement proposal executed. Kick-off within 5 business days.
Telemetry Collection (Days 1–14)
Network proxy/DNS log analysis, endpoint agent deployment or log collection, browser extension enumeration, and stakeholder interviews launched concurrently.
Analysis & Scoring (Days 15–25)
Shadow AI inventory compiled, each tool scored by data-exposure severity, business unit exposure map built, regulatory alignment gaps identified.
Delivery (Days 26–30)
Full inventory report delivered with ranked findings, remediation plan, policy templates, and executive briefing for CISO/GC/Board.
Investment
Multi-site or enterprise-scale engagements priced individually.
Timeline: 30-day fixed-fee engagement.
Every engagement begins with a scoping call and a written proposal. Work begins only after the engagement agreement is executed.Request a Consulting Proposal
Why Armorstack
Three-Channel Detection
Network + endpoint + browser telemetry catches what self-reporting and policy surveys miss. Industry average: 3–5x more AI use cases discovered versus self-reported.
Data-Exposure Focused
Inventory scored by what data each tool touches — not just whether it is authorized. PHI, PCI, PII, and IP exposure are surfaced with severity rankings.
Actionable Output
Remediation plan with tool-by-tool allow/block/monitor recommendations, policy language, and employee communication templates. Immediately executable.
No Ongoing Commitment Required
Shadow AI Discovery is a standalone fixed-fee engagement. Clients can implement remediation internally or proceed to the VERITY AI Governance Program.
Frequently Asked Questions
What AI tools do you look for?
The discovery sweep covers 40+ AI providers including OpenAI (ChatGPT, API), Anthropic (Claude), Google (Gemini, Bard), Microsoft Copilot, GitHub Copilot, Notion AI, Grammarly, Jasper, Perplexity, Character.AI, and dozens of productivity, coding, writing, and analytics AI tools. The provider list is updated quarterly as new entrants emerge.
Does this require installing agents on employee devices?
Network-based discovery (DNS/proxy log analysis) does not require endpoint agents and catches API traffic without device access. Endpoint-based discovery catches installed applications and browser extensions and requires either existing endpoint agent access or lightweight agent deployment. Both approaches are available; scope is defined during engagement scoping.
What do we do with the results?
The remediation plan tiers every discovered tool: Allow (sanctioned with policy acknowledgment), Monitor (allowed with telemetry and review), or Block (prohibited due to data-exposure risk). Armorstack provides the policy language, employee communication templates, and technical blocking guidance. Ongoing monitoring is available through LLM Security Observability.
Can we do this without telling employees?
Passive network telemetry collection is typically authorized under existing acceptable use policies and monitoring consent. Endpoint agent deployment may require employee disclosure depending on your jurisdiction and HR policies. Armorstack provides legal/HR guidance language as part of the engagement scoping.
Related Services
Ready to Engage Shadow AI Discovery?
Every VERITY AI engagement begins with a scoping call and a written proposal. No commitments until scope, deliverables, and pricing are agreed upon.Request an Engagement Proposal