AI governance
How to audit shadow AI in your company (checklist)
Shadow AI is any AI tool used at work without approval. Use this one-week checklist: discover tools, assess exposure, fix contracts, and keep the register current.
Published 2026-08-23 · Updated 2026-08-24
Shadow AI is any artificial intelligence tool employees use for work without IT or legal approval — personal ChatGPT accounts, browser copilots, meeting transcribers, AI note-takers. Auditing it is now a standard part of privacy and security reviews. This checklist takes an SMB through a full pass in about a week.
1. Discover (days 1–2)
- Ask finance for card charges to AI vendors — subscriptions leak here first.
- Check SSO / identity-provider apps for AI tools already connected.
- Ask team leads directly: “which AI tools help you this month?” Amnesty beats punishment.
- Review browser extensions and meeting-tool marketplaces.
2. Assess each tool (days 3–4)
- What data goes in? Customer records and employee data raise exposure fastest.
- Does the provider train on submitted data — on this tier?
- Where is it processed, and is there a transfer mechanism (SCCs)?
- Is there a DPA, and do retention settings match the contract?
- Score the tool. Most SMBs end up with a few critical items and a long low-risk tail.
3. Fix (days 4–5)
- Block or replace high-exposure tools; move legitimate use onto enterprise no-train tiers.
- Request DPAs where missing; record every request with a date.
- Publish a one-page acceptable-AI-use note so the next hire knows the rules.
4. Keep it current (ongoing)
- Every approved AI tool gets an owner and a re-review date — 90 days is realistic for AI.
- New tools enter via a lightweight request, not a ban.
- Re-run discovery quarterly; shadow adoption rebounds fast.
Where PrivyLedger fits
Assessment and upkeep are bookkeeping — what PrivyLedger automates. Add each discovered tool to the vendor register, get automatic AI exposure scoring with reasons, chase missing DPAs from the built-in board, and export paste-ready answers when customers ask what AI touches their data.
This guide describes general practice. It is not legal advice.
Questions
What counts as shadow AI?
Any AI system used for work that IT or legal did not approve — personal chatbot accounts, browser copilots, meeting notetakers, unofficial wrappers around foundation models.
Should we ban everything first?
A blanket ban without a sanctioned alternative drives use further underground. Discover with amnesty, then block the high-exposure tools and offer an approved tier.
How often should we re-audit?
Quarterly discovery is realistic for SMBs. AI adoption rebounds quickly after a one-off crackdown.