Shadow AI: Is Your Team Using AI Without Telling You?

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Shadow AI: Is Your Team Using AI Without Telling You?
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Shadow AI: Is Your Team Using AI Without Telling You?

Ask first, then check. An anonymous two-minute survey with a clear amnesty uncovers most unofficial AI use in a small team. Then confirm it with checks you can run in an afternoon: connected apps in your Google or Microsoft admin console, card and expense statements, browser extensions, and meeting guest lists for AI note-taker bots.

Assume it's already happening. Microsoft and LinkedIn's 2024 Work Trend Index, based on a survey of 31,000 people, found that 78% of people using AI at work were bringing their own tools. The point of finding it isn't to punish anyone. It's to learn which tools touch client data, then move the useful ones onto accounts the business controls.

Follow me on Instagram@sagnikteaches

Why staff keep their AI use quiet

Understanding the reasons tells you how to ask. In a small team, hidden AI use usually comes from one of four places:

Connect on LinkedInSagnik Bhattacharya
  • There's no rule, so people guess. Without a written line, staff assume it's either fine or forbidden, and either way they don't mention it.
  • It feels like cheating. Someone who drafts proposals in half the time may worry it looks lazy, or that it suggests their job could be done by software.
  • It's free and it's quick. Nobody raises a purchase request for a free account they opened in 30 seconds.
  • They don't think of it as AI. The meeting app now writes summaries; the grammar checker now rewrites paragraphs; the design tool now generates images. None of that feels like "using ChatGPT", but it's the same data leaving the building.

So the first move is to make owning up safe and easy.

Subscribe on YouTube@codingliquids

Start with an amnesty, not an investigation

Send a short message before any survey. Something like this works:

We're choosing which AI tools to pay for properly, and I want to start from what people already find useful. Please fill in this two-minute anonymous form by Friday. Nobody will get into trouble for anything they tell us now. After this, we'll agree which tools are approved and what data can go into them.

The wording carries more weight than the form. An illustrative case of getting it wrong: the owner of a small bookkeeping firm opens with "I've noticed some of you using ChatGPT on client work. Please declare which tools you use." Every one of the seven replies says "never" to client information. The card statements then show three separate $20 monthly charges to OpenAI on expense claims. Nobody lied out of malice; "I've noticed" read as the start of a disciplinary process, so people protected themselves. The amnesty version, sent a fortnight later, got four honest answers. You usually only get one clean attempt at this, so send the amnesty wording first.

Then use a form tool that doesn't collect names or email addresses, and keep it to questions that produce decisions:

1. Which AI tools have you used for work in the last three months?
   (Tick all: ChatGPT, Claude, Gemini, Copilot, Perplexity, an image
   generator, a meeting note-taker, a writing or grammar assistant,
   a browser extension, something built into another app, other)
2. Free account, paid by you, or paid by the business?
3. Did you sign in with your work email or a personal one?
4. What do you mainly use it for? (one line)
5. Has any client or customer information gone into it?
   (Never / Names and emails only / Documents or files / Not sure)
6. Does any tool join calls or read your email or calendar?
7. Which one tool would you most want the business to pay for?
8. Anything you'd like to use AI for but aren't sure is allowed?

Question 5 is the one that matters most, so offer "Not sure" as an answer. "Not sure" usually means yes. For a fuller version of this survey aimed at planning a rollout rather than finding hidden use, see how to survey staff before an AI rollout.

When the answers come back, count three things: how many people use AI at all, how many have put client information into a personal account, and which tool gets the most votes in question 7. The first number tells you whether this is a fringe habit or normal working practice. The second tells you how urgent the fix is. The third usually tells you which business plan to buy.

Five checks that show what's really connected

The survey tells you what people remember. These checks show what's actually attached to your systems. Most take 15 to 30 minutes.

1. Google Workspace: the accessed apps list

If you use Google Workspace, sign in to the Admin console and go to Security, then Access and data control, then API controls, then Manage App Access. The accessed apps list shows every third-party app people have signed in to with their work account, how many users each one has, and which Google services it can reach, such as Gmail, Drive or Calendar. Look for note-takers, writing assistants and anything with "AI" or "GPT" in the name. An app that can read Gmail and Drive deserves a closer look than one that only knows a user's name.

Here's roughly what you might find and how to rank it, in an illustrative ten-person firm:

AppUsersCan reachPriority
An AI meeting note-taker3Calendar, Gmail, DriveHigh: joins calls and reads mail
A "GPT for Sheets" style add-on1Drive, SheetsHigh: can open every spreadsheet that user can
An AI email-reply extension2Gmail (read and send)High: can send as the user
A grammar assistant6Basic profile onlyLow at this level; check its own settings
An AI slide generator1Basic profile, Drive files it createsLow

Start with the top three rows and ignore the user counts when ranking. One person's add-on with access to every spreadsheet in Drive matters more than six people's grammar checker that only knows their name.

2. Microsoft 365: enterprise applications

In the Microsoft Entra admin console, go to Entra ID, then Enterprise apps, then All applications. This lists apps people have granted access to with their work account, and you can review the permissions each one was given. Sort by date added to see what's new since your last look. While you're there, check the user consent settings, which decide whether staff can connect apps on their own at all.

A typical find, as an illustration: sorted by date added, the list shows a meeting-notes app connected three weeks ago by one sales manager, with permission to read their mail and calendar. Nobody else uses it, and it never came up in the survey because the sales manager thought of it as "the calendar plugin", not an AI tool. Open the app's permissions page to see exactly what was granted, have a two-minute conversation with the person, then either approve the app properly or remove it and revoke its access.

3. Card statements and expense claims

Search the last six months of company card statements and expense claims for: OpenAI, ChatGPT, Anthropic, Claude, Perplexity, Midjourney, Otter, Fireflies, Grammarly, Jasper, and the word "AI". Check app-store subscriptions on company phones too. Small recurring charges of about $20 a month are the usual sign of personal plans bought for work.

Charges don't always carry the tool's name, so read the descriptions as well as searching them. An illustrative six-month search at a small architecture practice turned up four lines worth querying:

Statement or claim lineWhat it turned out to beWhy the search nearly missed it
OpenAI ChatGPT subscription, $20 monthlyA personal Plus account on the company cardIt didn't: the name was on the line
App-store charge on a company phone, about $15 monthlyAn AI transcription app bought in-appApp-store billing shows the store, not the app
Expense claim: "software subscription, writing tool", $12An AI writing assistant used on client reportsThe claim was described generically
Google subscription, $19.99 monthlyGoogle AI Pro on a designer's personal Google accountIt looked like a storage plan

The last two only surfaced because someone asked "what is this?" about every recurring software line under $30, not just the ones containing a known brand.

4. Browser extensions

If your browsers are managed through Chrome Enterprise, the Admin console has an apps and extensions usage report (Devices, then Chrome, then Reports) that lists every extension installed across managed browsers, and you can export it. If your browsers aren't managed, ask everyone to open their extensions page during a team meeting and read out what's there. The ones to worry about are AI extensions with permission to read and change data on all websites, because that includes your webmail, CRM and online banking. In Chrome, open an extension's details and check its site access: an AI "page summariser" set to run on all sites can see every page that person opens, including the CRM record they're looking at. How to spot fake AI apps and risky browser extensions explains what to look for in the permissions.

5. Meeting guest lists

AI note-takers usually join calls as a visible participant with a name like "Notetaker" or the tool's brand. Look back through a fortnight of client calls and internal meetings, and check calendar invites for bot addresses. If a note-taker has been recording client calls without the client being told, that needs sorting before anything else on this list.

What no check will show you

Some shadow AI is invisible from the business side. Personal phones, personal accounts opened in a browser without "sign in with Google" or Microsoft, and text copied from a work screen into a free website leave no trace in your admin consoles. Neither do AI features switched on by default inside tools you've already approved.

A four-person physiotherapy clinic shows how that last one happens, as an illustration: an update to the clinic's booking and notes software adds an "AI summary" button to each treatment note. Two physios start using it to tidy their notes, which is exactly the kind of use nobody would think to mention in a survey about "AI tools". But treatment notes are health information, and nobody at the clinic has read what the software vendor now does with text sent to its AI feature, or whether it can be switched off. The fix is an admin-settings check of every approved tool after each major update, plus one question on the survey: "Has any software you use added an AI button recently?"

That's why the amnesty comes first. It's also why you shouldn't try to catch people out with AI-writing detectors. They produce false positives, and OpenAI withdrew its own AI-text classifier in 2023 because of its low accuracy. Accusing a good employee on the strength of a detector score costs you far more trust than the shadow AI did.

Worked example: an afternoon audit at a nine-person events company

Here's how this might play out at an illustrative nine-person events company that runs conferences and corporate parties for clients.

The survey took 15 minutes to set up and two minutes each to fill in. Six of the nine said they use AI at work. Four use personal ChatGPT accounts (two free, two Plus at $20 a month, both expensed). One uses an image generator on a personal card for client mood boards. Two answered "Not sure" to question 5.

The admin checks took about 90 minutes and found two things the survey missed. An AI note-taker was connected to three people's calendars and had joined every client planning call for two months. And an AI email extension had read access to one account manager's entire Gmail, including supplier contracts and attendee lists.

The decisions:

  • The five regular users move to ChatGPT Business on annual billing at $20 a seat, $100 a month in total, replacing $40 a month of expensed Plus accounts. Client names and briefs can go into the business workspace; attendee lists with dietary and access needs can't.
  • The note-taker is paused on client calls until there's agreed wording for telling clients. Whether AI note-takers are safe for client calls covers the consent side.
  • The email extension is removed and the account manager changes their password.
  • The image generator is approved for mood boards, with one rule: no photos of real clients or guests go into it.

Total cost: one afternoon of the owner's time and $60 a month more than before, in exchange for knowing where client data goes.

Keep, move or stop: sorting what you find

Every find fits one of three actions. Decide by what the tool can reach, not by how useful it is.

What you foundWarning signAction
Personal chat assistant used with client names or documentsNo business contract, account owned by the individualMove to a business plan the company owns
Free tool used only for generic drafting, no client dataLowKeep, and add it to the approved list
Note-taker bot on client callsRecording people who haven't agreedStop on client calls until consent wording exists
Browser extension that can read all websitesSees webmail, CRM and bankingStop, then change passwords
AI feature switched on inside an approved appNobody checked the data termsKeep or stop after checking the admin setting
Tool paid for on a personal cardThe business can't cancel or control itMove to company billing, or stop

Stopping it going back underground

Once it's in the open, keep it there. Four things do most of the work:

  1. An approved list of one or two tools, with a line on what data can go into each. For the events company above, it fits in a few lines:
    ChatGPT Business (company workspace): client names, briefs, venue
      and supplier emails. Never: attendee dietary, health or access needs.
    Image generator (company account): mood boards from text and our own
      stock images. Never: photos of real clients or guests.
    Meeting note-taker: internal meetings only, until client wording agreed.
    Anything else: ask the office manager first; answer within 48 hours.
  2. A quick way to ask for more. If requesting a new tool takes a week, people will quietly sign up for it instead. A simple AI tool approval process can be a one-question form and a 48-hour answer.
  3. A short written rule. For a small team, a one-page AI policy is enough to make the approved list stick.
  4. A repeat check every six months: the same survey and the same five checks. The second round usually takes half the time.

The second round is also how you find out whether the first one worked. For the events company, a healthy comparison might read:

MeasureFirst roundSix months later
Personal AI accounts used on client work40
Expensed AI subscriptions per month$40$0
Connected AI apps nobody approved21 new one, sorted within a week
"Not sure" answers to question 520
Requests through the approval formNone (no form existed)3, two approved

The last row matters most. People asking for tools means the route in the open is easier than the quiet one. If "Not sure" answers go up instead, staff haven't understood the approved list, and that's a wording problem to fix, not a discipline problem.

If you'd like to tighten things technically, both Google Workspace and Microsoft 365 let you restrict which third-party apps staff can connect to their work accounts. Turn that on after the amnesty, not before, or you'll push use onto personal devices. How to stop staff pasting client data into free tools covers the prevention side in more depth.

Questions owners ask about finding shadow AI

Is it legal to check which apps my staff have connected?

Reviewing your own admin consoles, company card statements and company-managed browsers is normal administration of business systems. Monitoring what individuals do in detail is regulated in many places and usually needs to be disclosed in your policies. Tell staff what you check and why, and ask an employment adviser before you install any monitoring software.

Should I just ban AI tools instead?

A ban mostly moves AI use onto personal phones and home laptops, where you can't see it and client data is even less protected. Most owners get better results by approving one or two tools on business accounts, saying clearly what data can go into them, and giving staff a quick way to ask for anything else.

Do AI features built into our existing software count as shadow AI?

They count if nobody decided to allow them. Meeting software, design apps, grammar checkers and CRMs increasingly switch AI features on by default. Check each tool's admin settings, confirm whether business data is used for training, and record the decision so it becomes approved use rather than accidental use.

Further reads

Sources: Microsoft and LinkedIn 2024 Work Trend Index announcement; Google Workspace Admin Help on app access control; Chrome Enterprise Help on the apps and extensions usage report; Microsoft Learn on reviewing permissions granted to enterprise applications (checked September 2026).

Found more AI in use than you expected?

On a 1:1 call we'll go through what your team is using, decide which tools to keep and move onto business accounts, and set a simple way for staff to request new ones.

Book a 1:1 call with me