This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.
If an organisation has already accepted that staff may be using AI, the next question is not simply which tools appear on an approved list. It is whether the business can identify the tools, accounts, integrations and data flows that actually exist, including uses that were never reviewed. A shadow AI audit turns that uncertainty into a record that can be assessed.
In short: Shadow AI is any AI system used for business work without the visibility or approval expected by the organisation. An audit combines staff disclosure with existing administrative, purchasing and technical records. The result is not a list of rule-breakers. It is a set of findings that reveal unmet work needs, missing governance, possible data exposure and, in a smaller number of cases, an issue requiring urgent specialist review.
Shadow AI is an unmanaged use, not a particular product
Shadow AI can include a public chatbot used to rewrite a customer email, a meeting assistant connected to a calendar, an AI browser extension, a personal account used for business documents, or an AI feature activated inside approved software without review.
The defining feature is the visibility gap. The UK National Cyber Security Centre describes shadow AI as AI technology used without permission and places it within the wider category of unknown, unmanaged assets. It also says shadow IT usually arises because staff are trying to complete work that approved tools or processes do not support, rather than from malicious intent. Read the NCSC shadow IT guidance.
That distinction affects the audit. A blame-led exercise may reduce disclosure while leaving the underlying use in place. A discovery exercise asks what task the person was completing, what information entered the system and why the approved route did not work.
Two authorities support inventory-based discovery
An inventory is the bridge between finding AI use and governing it. The US National Institute of Standards and Technology places mechanisms for inventorying AI systems in Govern 1.6 of its voluntary AI Risk Management Framework. Its playbook describes an inventory as a database that may include system documentation, incident plans, data information and responsible contacts. See NIST AI RMF Govern 1.6.
The NCSC says an up-to-date asset record helps identify unknown technology and notes that a manually maintained spreadsheet may be sufficient for a very small organisation. It also describes network monitoring and cloud access security brokers as possible discovery sources, while warning that technical tools have limitations. For example, network visibility may show an unapproved service without revealing a personal account inside an approved service. See the NCSC discovery guidance.
Neither framework makes every suggested technique mandatory. NIST expressly describes its framework and playbook as voluntary resources, while the NCSC guidance is security guidance rather than a determination of employment or privacy law.
The shadow AI audit artefact
The audit record can be built in six passes. These are operational research steps, not statements of legal obligation.
| Pass | Evidence examined | What the audit records |
|---|---|---|
| 1. Define the boundary | Business units, managed devices, approved accounts and review period | What was and was not examined |
| 2. Invite disclosure | A short staff survey or team discussion focused on tasks | Tool, account type, task, frequency and reason for use |
| 3. Reconcile commercial records | Expense claims, purchasing records and software subscriptions | Paid tools or upgrades absent from the approved list |
| 4. Review existing administration records | Single sign-on applications, approved-suite consoles, connected apps and API integrations | Accounts, permissions and systems connected to AI functions |
| 5. Review managed technology records | Installed applications, managed browser extensions and proportionate network or endpoint records | Technical indicators that do not appear in staff disclosure |
| 6. Validate each finding | A conversation with the user and system owner | Actual use, data involved, business dependency and current status |
The record should distinguish an observed fact from an inference. An expense labelled with a vendor name proves that a payment occurred, not what data entered the service. A browser extension proves installation, not active use. A staff disclosure may provide the missing context without collecting message content or passwords.
Each row can capture: tool or feature, user or team, business task, account ownership, information categories, connected systems, output destination, business dependency, existing approval, evidence source, review owner and status. Passwords, prompt contents and copied personal data do not belong in the register merely to prove that use occurred.
Where to look without treating surveillance as routine
The least intrusive sources often answer the question first. Staff disclosure, approved application lists, procurement records and existing administrator consoles can expose many gaps without examining the substance of individual communications.
Inspection of browsing histories, message contents, personal accounts or unmanaged devices changes the nature of the exercise. It may become employee monitoring or involve collection of personal information. The applicable position depends on jurisdiction, workforce arrangements, existing notices and the exact data collected. Technical availability is not the same as legal authority or proportionality.
What each shadow AI finding means
A finding becomes useful when it is classified by consequence rather than by whether a tool was approved. The following NTK classification is an editorial decision framework, not a regulatory scale.
| Finding class | Typical evidence | What it means | Appropriate destination |
|---|---|---|---|
| Visibility gap | Low-sensitivity drafting in an otherwise suitable tool | The inventory or approval route has not kept pace with real work | AI register |
| Capability gap | Several people adopted the same tool for the same unsupported task | The sanctioned workflow may not meet a genuine business need | Workflow owner and policy review |
| Control gap | Personal account, unreviewed integration, unknown retention terms or shared credentials | Ownership, access or data handling cannot yet be accounted for | Vendor due-diligence checklist |
| Material-risk indicator | Sensitive records, consequential decisions, broad system access or an important process dependent on the tool | The potential impact is high enough for a documented assessment | AI risk assessment guide |
| Incident indicator | Evidence of unintended disclosure, exposed credentials or unauthorised access | Discovery may have moved beyond governance into incident handling | Incident and professional review pathway |
One tool can generate more than one class. A public chatbot used for generic wording may reveal only a visibility gap. The same service used with identifiable customer records may create a control or material-risk finding. Classification therefore follows the use, data and consequence, not the brand name.
The register records what exists. The acceptable-use policy states which uses are permitted, restricted or escalated. A risk assessment examines a higher-impact use in context. These artefacts have different jobs and should not be collapsed into one checklist.
Monitoring boundaries differ by jurisdiction
European Union
Where discovery processes personal data, GDPR Article 5 states that processing is governed by lawfulness, fairness, transparency, purpose limitation and data minimisation. Article 13 addresses information supplied when personal data are collected, while Article 35 covers impact assessments for processing likely to create high risk. Their application to a particular workplace audit depends on the facts and relevant member-state law. Read the GDPR on EUR-Lex.
United Kingdom
The ICO says worker monitoring normally requires transparency, a defined purpose and proportionate accountability measures. Its guidance says a data protection impact assessment is required before monitoring likely to create high risk, and identifies keystroke monitoring as one possible high-risk example. Read the ICO worker-monitoring guidance.
Canada
Canada's Office of the Privacy Commissioner says workplace privacy coverage differs between federal and provincial settings. Its guidance describes employee monitoring as something to assess for a specific purpose, necessity, proportionality and transparency, while also noting that the governing statute depends on the organisation. Read the OPC workplace privacy guidance.
United States
NIST's AI inventory guidance is voluntary and does not decide whether a particular employee-monitoring technique is lawful. Federal, state, sector and contractual rules may affect that question, so an organisation considering intrusive discovery requires advice matched to its location and workforce. Read the NIST AI RMF overview.
Australia
The OAIC says its commercially available AI guidance addresses AI systems involving personal information, including publicly accessible tools. It recommends due diligence, policies, staff training and ongoing review, but also states that its document is not a comprehensive account of every relevant privacy issue or regulatory regime. Read the OAIC commercial AI guidance.
Where this audit stops
A shadow AI audit establishes evidence, not a legal conclusion. It cannot determine from a tool name alone whether a disclosure was authorised, whether employee monitoring is proportionate, whether a contract covers a particular use or whether an incident notification threshold has been met.
Those questions depend on facts the artefact may not contain. Material ambiguity belongs with the organisation's privacy, employment, security or legal adviser, supported by the audit record rather than replaced by it.
Questions raised by the findings
- Which business task led to the unapproved use?
- What information entered the system, and what evidence supports that answer?
- Was the account controlled by the organisation or an individual?
- Which systems, extensions or integrations could the tool access?
- Would stopping the tool interrupt a customer-facing or critical process?
- Does the discovery method itself collect employee personal information?
- Which finding belongs in the register, policy, risk assessment or incident pathway?
How this was researched
This guide is researched against primary regulatory sources and official regulator guidance, checked against those documents as of the date shown, and written for a business with no dedicated compliance function. We report what a named authority has published and link the document so you can read it yourself. We do not tell you what your legal obligations are.
Read our full methodology and independence and disclosure policy.
Related reading: AI data residency comparison, AI vendor breach response plan template, guide to liability for AI-generated content, and AI governance by region.
Related reading: Claude AI Review: Pricing, Features, and Business Verdict and Is Claude Pro Worth It? An Honest Assessment for Business Users.
Free tools: AI Tool Pricing Tracker to check current pricing across the major AI platforms | AI Privacy Risk Scorer to score your current AI tool setup against data-privacy best practice.
Try our free AI Compliance Checker to check whether your AI tools meet your compliance obligations.
Is shadow AI the same as an unapproved chatbot?
No. It includes unapproved chatbots, but it can also include AI features within ordinary software, meeting assistants, browser extensions, connected applications and personal accounts used for business work.
Does every shadow AI finding mean data was leaked?
No. A finding proves an unmanaged or poorly documented use. Data exposure requires separate evidence about what entered the system, where it went, who could access it and what the provider did with it.
Can a staff survey replace technical discovery?
Not completely. A survey provides purpose and context that logs cannot, while administrative or purchasing records may reveal forgotten accounts and integrations. Comparing several evidence sources produces a more defensible inventory than treating any single source as complete.
Should every unapproved tool be blocked immediately?
Not automatically. The finding matrix separates routine visibility and capability gaps from material-risk or incident indicators. The appropriate response depends on the use, information, access and business dependency, with urgent specialist review reserved for evidence that justifies it.
Methodology
This desk-research assessment reviewed primary guidance from NIST, the UK NCSC, the ICO, EUR-Lex, Canada's OPC and the OAIC in September 2026. The six-pass audit and finding matrix are NTK editorial syntheses designed to connect discovery evidence with the correct governance artefact. They are not regulator-issued procedures or legal advice.
The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.
Use the AI acceptable-use policy template to record permitted, restricted and escalated uses
Use the AI acceptable-use policy...