In almost every organisation there are AI tools running that the management knows nothing about. That is not a discipline problem. It is a symptom: people are trying to get their work done. Understand that and you will find the tools in two weeks. Treat it as a breach of the rules and you will find nothing.
By Patrick de Kathen, Founder of KlarComply · Reviewed on
The term covers any use of AI tools in a work context that the company does not know about or has not approved. It is broader than the obvious personal account:
A figure from experience with stocktakes: the first proper sweep regularly turns up two to three times as many tools as the management expected. The reason almost never lies with the staff.
Five causes, in order of frequency. All five are management questions, not compliance questions.
| Cause | What sits behind it |
|---|---|
| There is no way to ask | Nobody knows who decides. With no named contact there are no requests — only quiet use. |
| The route takes too long | Someone who waits three weeks for an answer routes around the process next time. A turnaround you keep matters more than a strict assessment. |
| The approved tool cannot do it | Where the internal option is worse than the freely available one, the freely available one wins. Every time. |
| A blanket ban | Bans move the use to personal devices and personal accounts. You lose the last of your visibility. |
| Nobody thought it was reportable | A browser extension does not feel like a software rollout. That is precisely why the rule has to name what it means. |
A ban does not change whether AI is used. It changes whether you find out. After a ban the use moves to the personal phone and the personal account, where you have no contract, no logs and no way to withdraw access when someone leaves.
There is a legal side effect as well. A ban that the management knows is being circumvented is worth very little as an organisational measure under Article 32 GDPR. What is effective is what is actually followed.
The order matters. Start with people, not with technology. Begin with a network analysis and you will get a list of domains and a workforce that volunteers nothing ever again.
By far the most effective single measure, and it costs nothing. Ask what is being used, and state expressly that naming something carries no consequence. Without that assurance you will get polite nil returns.
“We are building an overview of the AI tools in use here. The aim is to put the useful ones on a proper footing, not to remove them. Anything named now counts as helping to solve the problem, not as breaking a rule. From [date] our approval process applies to anything new. If a tool you need is missing, please say so at the same time.”
The last sentence is the trick. It turns a control exercise into an opportunity — and it hands you, as a by-product, the list of what you should be buying so that shadow AI does not grow back.
A company-wide email achieves very little. Fifteen minutes per department achieves a great deal, because you can ask concretely: how does text get written here? How do you translate? How do you summarise minutes? How do you assess incoming bids? Ask about tools and you get tool names. Ask about steps in the work and you get the truth.
Subscriptions give themselves away through payment routes. Go through twelve months of card statements, expense claims and small recurring amounts. Sums between ten and thirty euros a month are typical single licences. This step regularly finds tools that nobody named in the survey — not out of concealment, but because they have long since become routine.
An overview of the extensions on work devices is quick to produce. Pay attention to the permissions: an extension allowed to “read all your data on all websites” also sees your ERP system and your mailbox. Independently of the AI question, that is a security matter.
The most frequently overlooked step. Go through the programs you use anyway and check which AI features arrived in the last twelve months — and whether they are on by default. This is where shadow AI appears without anyone in the workforce doing anything at all.
Technically, a good deal could be established from network or security gateway logs. Legally it is not straightforward, and this is one of the areas where national law diverges most sharply within Europe.
Two things hold everywhere. Analysis that can be traced to individual employees is a processing of personal data and needs a lawful basis, a purpose and transparency towards staff. And where a works council or equivalent employee representation exists, introducing or using a system capable of monitoring conduct or performance normally requires consultation or agreement — in several member states the mere capability is enough, with no monitoring intention required. Directive 2002/14/EC sets the EU-wide floor for informing and consulting employees; national law goes considerably further in some states than in others. The detail is on AI and employee representation.
What is workable is an aggregated analysis with no personal identifiers: which domains are being reached at all, how often, from which area. That is enough to find tools. Analysing by name in order to identify individuals trades a compliance problem for a larger one.
Sort every tool you find into exactly one of four boxes. Anything else produces a list that nobody works through.
| Decision | When | What to do |
|---|---|---|
| Adopt | clear benefit, manageable risk | take out a business tier, settle the contract and the processor arrangement, add it to the inventory, define the user group |
| Replace | clear benefit, but this tool is unsuitable | provide an equivalent approved alternative — before switching the old one off, not afterwards |
| Restrict | tolerable only for certain content | approve subject to conditions, for example no personal data at all, with a date for the next review |
| Switch off | no defensible benefit, or unacceptable risk | explain the reasons, withdraw access, name an alternative, record it in the inventory as refused |
The order matters: alternative first, switch-off second. Block first and search afterwards and you will have the same shadow AI back within two weeks, better hidden.
So that the survey does not look like an end in itself, here are the four real points of exposure, ordered by how often they bite in practice.
A stocktake with no follow-up process is a snapshot. Four measures hold the position:
Two sentences with the same content and opposite effects:
Does not work: “It has come to our attention that unapproved AI tools are in use. Please report them immediately.”
Works: “We want to know what makes your work easier so we can set it up properly. Please tell us what you use and what you are missing.”
The second costs nothing and produces a fuller picture. The first produces a list missing precisely the tools you most needed to know about.
Two weeks is enough in a company of up to two hundred and fifty people, provided the steps run in parallel.
| When | Step | Effort |
|---|---|---|
| Day 1 | Announcement by the management, with the amnesty and the cut-off date | 30 minutes |
| Days 1 to 5 | Keep the survey open, answer questions | ongoing |
| Days 2 to 7 | Department conversations, 15 minutes each | 2 to 4 hours in total |
| Day 3 | Review twelve months of payment routes | 1 to 2 hours |
| Day 5 | Check browser extensions and release notes | 2 hours |
| Days 8 to 10 | Create inventory entries, record risk-class reasoning | 3 to 5 hours |
| Day 10 | Four-box decision per tool, communicate the outcome | 2 hours |
At the end, record how you carried out the survey and when. That description of the method is the actual evidence. No review expects completeness; every review expects a procedure it can follow.
Where you stand after the sweep takes two minutes to check with the free quick check, including the points that typically stay open.
The sweep has one extra column for you. Under Article 2 of the AI Act, a deployer established in a third country is in scope where the output produced by the AI system is used in the Union. Shadow AI is exactly the kind of use where nobody has considered that question, because nobody knew the tool existed. Record, per tool found, whether its output reaches the EU. It takes a second per row and it is the answer to a question a customer will eventually ask.
AI tools used in a work context without the company knowing about them or approving them. That includes personal accounts, browser extensions, AI features that arrived by update in existing software, and AI used by service providers working on your behalf.
That is not advisable. A ban does not change whether AI is used, only whether you find out. The use moves to personal devices and accounts, where you have no contract, no logs and no way to withdraw access. A fast approval route plus one genuinely usable approved tool works better.
In this order: an amnesty survey with an express assurance of no consequences, individual conversations per department, a review of twelve months of payment routes, an overview of browser extensions, and finally the release notes of the software you already run. The last of those finds the tools nobody installed.
Only within limits, and the limits differ by country. Analysis traceable to individuals is processing of personal data and needs a lawful basis and transparency. Where employee representation exists, introducing or using a system capable of monitoring conduct or performance normally requires consultation or agreement, and in several member states the mere capability is enough. An aggregated analysis with no personal identifiers is workable and sufficient to identify tools.
Four options: adopt with a business contract, replace with a suitable alternative, restrict subject to conditions, or switch off. The order matters — the alternative has to be in place before anything is switched off, or the same use returns within weeks, less visibly.
For the period before a clear rule existed that would be counterproductive and usually unfounded: where there was no known rule, there was no breach. Give an assurance of no consequences, set a cut-off date and publicise the approval route. From then the rule applies, and from then it carries weight.
A short half-yearly enquiry with two questions per department — what is new and what is missing — plus an ad hoc check after major software updates. Withdrawal of access and a closing question also belong in your offboarding.
The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.
Start the quick check — free