How to control shadow AI
A process for finding the AI tools that IT and security have not sanctioned, assessing what they can reach, and bringing the ones that earn their place under the same inventory, ownership, and review as approved tools.
Shadow AI is the use of AI tools that IT and security have not sanctioned or do not know about, from an unapproved chatbot to a team's own agent wired into company data. Controlling it starts with discovery, because unknown tools cannot be assessed, then brings the tools that earn their place under the same inventory, ownership, and review as sanctioned ones, and retires the rest. The aim is oversight, not a blanket ban that pushes usage further underground.
Shadow AI is the AI equivalent of shadow IT, and it is spreading faster. A team signs up for an assistant, wires it to a data source, and starts relying on it, all before security hears the name of the tool. The risk is not that AI is used, it is that this usage is invisible and therefore unassessed.
Control starts with discovery, not with a policy nobody can enforce. Once you can see what is in use, you can assess data reach, sanction what earns its place, and bring it under the same governance as everything else. The steps below turn shadow AI from a blind spot into a governed part of the stack.
Steps
-
Discover unsanctioned usage
Find the AI tools and agents in use that were never approved, across Microsoft and non-Microsoft vendors. Discovery is the precondition: a tool nobody knows about cannot be risk-assessed or governed.
-
Assess data reach
For each discovered tool, determine what data it can reach and what it can do. This is what separates a harmless convenience app from an agent quietly wired into sensitive systems.
-
Sanction or retire
Decide, per tool, whether it earns a place. A blanket ban tends to push usage further into the shadows, so approve the tools that add value under conditions, and retire the rest deliberately.
-
Bring sanctioned tools under governance
Move approved tools into the same inventory, ownership, and access-review model as the rest of the AI stack, so yesterday's shadow AI is today's governed tool rather than a permanent blind spot.
-
Monitor continuously
Keep discovery running, because shadow AI is not a one-time cleanup. New tools appear constantly, and continuous monitoring is what keeps the blind spot from reopening.
Related connectors
Related reading
- How to govern AI tools beyond Microsoft CopilotHow to extend a single governance model, inventory, ownership, risk classification, and access review, across every AI tool your teams use, not just the Microsoft ones.
- How to govern AI coding assistantsHow to bring AI coding assistants like GitHub Copilot, Cursor, and Windsurf under the same inventory-and-oversight model as the rest of your AI stack, covering repo access, ownership, and review.
- How to inventory the AI tools in use across your organizationA step-by-step approach to building a continuous inventory of every AI assistant, agent, and LLM tool in use across the organization, spanning Microsoft Copilot and the non-Microsoft tools teams adopt alongside it.