Dev.to AI 🤖 Ai 👁 0 📖 11 min read

Shadow AI Discovery: See Which AI Tools Employees Actually Use

AI tools are arriving in companies faster than traditional inventory processes can keep up with. Most of them don't come in through a website visit. They come in through work accounts, sign-in buttons, and OAuth consent

Shadow AI Discovery: See Which AI Tools Employees Actually Use

AI tools are arriving in companies faster than traditional inventory processes can keep up with. Most of them don't come in through a website visit. They come in through work accounts, sign-in buttons, and OAuth consent screens.

If you work in IT, you probably have a sense that AI is being used across your company in more places than you can currently point to. People mention tools in meetings. Unfamiliar app names show up in admin consoles.

The growing use of AI isn't surprising. What's frustrating is not having a clear list: who is using what, whether each tool is safe, or whether it's an unvetted app someone in Marketing found through an ad and signed up for to make a few AI videos. But let's not blame anyone just yet. It's simply a sign that AI adoption is moving faster than we can notice and keep track of it. Let's walk through a few points that can help.

TL;DR

  • AI adoption is moving faster than traditional IT inventory processes can track. Employees are already connecting AI tools to work accounts, often before IT teams know they exist.
  • Shadow AI is not just about someone visiting an AI website. AI usage can appear through identity providers, OAuth connections, and SaaS application access.
  • The first step is not blocking AI. It is understanding what AI tools exist, who uses them, and what access they have.
  • AssetLoom Shadow AI Scanner helps IT teams discover AI and SaaS applications through existing identity records from Google Workspace, Microsoft Entra ID, and Okta.

AI tools are arriving in companies faster than traditional inventory processes can keep up with. Most of them don't come in through a website visit. They come in through work accounts, sign-in buttons, and OAuth consent screens.

If you work in IT, you probably have a sense that AI is being used across your company in more places than you can currently point to. People mention tools in meetings. Unfamiliar app names show up in admin consoles.

The growing use of AI isn't surprising. What's frustrating is not having a clear list: who is using what, whether each tool is safe, or whether it's an unvetted app someone in Marketing found through an ad and signed up for to make a few AI videos. But let's not blame anyone just yet. It's simply a sign that AI adoption is moving faster than we can notice and keep track of it. Let's walk through a few points that can help.

Shadow AI discoveryn

AI adoption is moving faster than inventory can track

Not long ago, "AI at work" mostly meant someone opening ChatGPT in a browser tab to rewrite an email. It was easy to picture, and it felt manageable. A website can be spotted in web traffic logs or blocked with a filter, so it seemed like something IT could keep an eye on.

That picture doesn't hold anymore. Today, people sign in to AI tools with their work Google or Microsoft accounts. They connect meeting note-takers to their calendars so the bot can join every call. They let writing assistants read their inbox to draft replies. They turn on AI features inside tools the company already pays for, like the assistants now built into Notion, Slack, and Zoom. Each of these is a different way in, and each one gives AI a different kind of access to company data.

Now compare that with how traditional procurement and IT inventory work. Someone requests a tool, procurement reviews it, a purchase order gets approved, licenses are assigned, and the asset lands in a system of record. There's a moment in that process where IT sees the tool before anyone uses it.

That process was built for a less-hustle rhythm. Today, many AI tools start with a free plan. You just sign up and start using it. There's no purchase order yet, no vendor review, nor contracts.

And it rarely stops at one person. Let's walk through how it usually goes. On Monday, someone on the sales team hears about an AI note-taker from a contact at another company. That afternoon, they sign up with their work Google account and connect their calendar. On Tuesday, the bot joins their client calls and sends a neat summary to everyone on the invite. By Thursday, three colleagues who received those summaries have signed up too, because it looked useful. A week later, the tool is attached to a dozen calendars, joining calls with customers, and storing transcripts on a server nobody in IT has reviewed.

This is the gap. AI tools spread from person to person in days, while traditional inventory tracking only notices them when they pass through procurement, which many of them never do.

Learn more: AI Asset Inventory: Building Visibility for the New Era of AI Adoption

Shadow AI isn't only about someone using a chatbot they shouldn't. A more useful definition is this: shadow AI is any AI tool, feature, or connection that can reach company accounts or data without IT knowing about it or having reviewed it. That includes brand-new tools nobody approved. But it also includes AI features switched on inside tools the company already pays for, and AI apps connected through accounts IT manages every day.

That last part is what makes shadow AI risk different from the older idea of shadow IT. It rarely looks suspicious. In most cases, it comes in through the systems we trust the most.

Shadow AI is appearing through trusted systems

Shadow AI isn't only about someone using a chatbot they shouldn't. A more useful definition is this: shadow AI is any AI tool, feature, or connection that can reach company accounts or data without IT knowing about it or having reviewed it. That includes brand-new tools nobody approved. But it also includes AI features switched on inside tools the company already pays for, and AI apps connected through accounts IT manages every day.

That last part is what makes shadow AI different from the older idea of shadow IT. It rarely looks suspicious. In most cases, it comes in through the systems we trust the most.

Four ways Shadow AI enters through trusted systems
Four ways Shadow AI enters through trusted systems

It comes in through your company login. When someone clicks "Sign in with Google" or "Sign in with Microsoft" on an AI tool, they're using the same identity your company protects with strong passwords, multi-factor authentication, and security policies. The login is legitimate. It's the tool on the other side that nobody has looked at.

It comes in through official consent screens. When an AI tool asks for access to email, calendars, or files, the request appears on a Google or Microsoft consent screen. It looks official because it is official. People have learned to trust those screens. But clicking accept gives the tool ongoing access to company data, and that access doesn't end when the browser tab closes. It stays until someone revokes it.

It comes in through tools you already approved. Many apps that passed IT review years ago now include AI assistants. Notion, Slack, and Zoom have all added them. The app is the same one on your approved list, but what it does with your data may have changed since the day you approved it.

It comes in through your SSO catalog. In Okta, an AI app can be assigned to users right next to the approved tools they use every day. Sometimes that went through a proper review. Sometimes a team admin added it because a few people asked.

Consider this scenario: an AI writing tool becomes popular, and 200 employees sign in using their work accounts. Most only share basic identity information. Later, one user enables an email assistant feature and grants the tool full mailbox access. Every step happened through trusted systems, but one permission change significantly increased the application's access to company data.

This is the quiet irony of shadow AI. The same trust signals that make these systems safe to use are what make AI tools inside them easy to overlook.

The good news is that trusted systems keep records. Every one of those sign-ins, consents, and assignments is logged somewhere you already control. Which brings us to the question of what to do about it.

The first step is understanding, not blocking

When teams realize how much AI is already in use, the natural reaction is to lock things down. Block the well-known names, send a firm reminder, tighten the policy.

We understand that instinct, but the evidence suggests it doesn't work the way people hope. In a Software AG study of 6,000 knowledge workers, 46% said they would keep using their personal AI tools even if their company banned them completely. Blocking doesn't make the usage disappear. It just moves it somewhere IT can't see, often to personal accounts and personal devices.

It also helps to remember that this isn't really about people breaking rules on purpose. UpGuard's research found that 88% of security leaders use unapproved AI tools themselves, compared with 81% of employees overall. People at every level are simply trying to get their work done faster. Keeping it under control is a new trend now, as part of the AI governance.

How AssetLoom Shadow AI Scanner helps

AssetLoom Shadow SaaS Scanner helps organizations discover AI and SaaS applications connected through existing identity systems.

AssetLoom shadow AI scanner
Instead of requiring endpoint agents or asking every employee to manually report their tools, the scanner uses available identity data from supported providers: Google Workspace, Microsoft Entra ID, and Okta.

The scanner identifies connected applications and provides context such as:

  • Application category
  • Users associated with applications
  • OAuth permissions where available
  • Application risk level

How it decides what matters

Each app gets a risk level based on the access it holds. Full access to mail or files, contacts, and any admin permission counts as high. Read-only access and calendars count as medium. Basic sign-in details count as low.

An app's risk is set by the most access anyone has given it. So in the writing tool example from earlier, that one person who granted full mailbox access marks the whole app as high risk, even though everyone else shared only their name and email.

The scanner is also careful about trust. An app's display name is chosen by the app itself, so anyone can call their tool "Zoom Helper." Its OAuth client ID, on the other hand, is issued by the identity provider and can't be copied. The scanner only treats an app as verified when its client ID matches one the real vendor has published. That's what --risky shows: apps holding high-risk access that can't prove who they are.

What stays private, and what it won't see

Scan results stay in memory while the command runs. The only files written are the reports you ask for, such as a CSV or a single HTML file that works offline. Nothing is sent anywhere except the calls to your own identity provider.

We also want to be clear about the limits. The scanner sees AI tools connected to work accounts. It won't see someone using a chatbot with a personal login, desktop apps on laptops, or AI services in your cloud accounts. And because Okta records app assignments rather than detailed permissions, Okta scans show which apps are connected and who uses them, but without risk scoring. We still think the identity layer is the right place to start, because it's where AI tools ask for access to company data.

Making it a habit

A single scan gives you a snapshot. Running it regularly gives you awareness. For Google and Entra, --fail-on-risky makes the scanner exit with a specific code whenever it finds unverified high-risk apps, so a scheduled scan can alert you only when something new appears. Over time, shadow AI stops being a background worry and becomes part of normal asset management.

From Shadow AI discovery to SaaS inventory intelligence

Discovery creates visibility, but visibility becomes more valuable when it connects with ongoing IT asset management (ITAM) processes. Once organizations understand which applications exist, they can begin answering longer-term questions:

  • Who owns this application?
  • Is it approved?
  • Is it still needed?
  • What happens when the user leaves?
  • Should access be reviewed regularly?

Shadow AI discovery can become the starting point for a broader SaaS inventory workflow, where applications are not only discovered but also tracked throughout their lifecycle.

The scan provides the starting point by revealing applications that may not appear in traditional IT inventories. From there, organizations can build a clearer picture of their SaaS environment, track ownership, review access, and manage applications throughout their lifecycle.

Start by discovering your hidden AI and SaaS applications with AssetLoom Shadow AI Scanner. Then bring those insights into a complete IT asset management workflow with AssetLoom.

Download AssetLoom Shadow AI Scanner for free ->

Explore AssetLoom IT Asset Management ->

Frequently Asked Questions

What is Shadow AI discovery?

Shadow AI discovery is the process of identifying AI applications and services being used across an organization without complete visibility from IT teams. It helps organizations understand which AI tools exist, who is using them, and what level of access those tools have.

Why is Shadow AI difficult to discover?

Shadow AI is difficult to discover because AI tools often connect through existing identity systems instead of traditional software installation processes. Employees can authorize applications through OAuth, connect SaaS tools through SSO, or create accounts using company identities without those applications appearing in traditional software inventories.

How does AssetLoom Shadow AI Scanner discover applications?

AssetLoom Shadow AI Scanner uses identity and access information from supported providers:

  • Google Workspace
  • Microsoft Entra ID
  • Okta

Depending on the provider, the scanner can identify connected applications, user assignments, OAuth permissions, and application risk information.

Does AssetLoom Shadow AI Scanner require installing agents?

No. AssetLoom Shadow AI Scanner does not require endpoint agents. It uses read-only access to supported identity providers to discover connected applications and access information.

What happens after discovering Shadow AI applications?

Discovery is the first step. Organizations can use the findings as the foundation for SaaS management and IT asset intelligence workflows, helping them track ownership, review access, and manage applications throughout their lifecycle.

📰 Read the original article on Dev.to AI

Originally published by Dev.to AI. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.