Index / Research / The one-week shadow AI playbook

The one-week shadow AI playbook

Playbook8 min readCited sources

You do not need a new platform or a year-long program to get an honest first picture of shadow AI. One focused week takes you from a vague suspicion to a named inventory, a clear read on how much of it runs on personal accounts, and a safer default that people will actually use. This is a plan for that week, built on signals most teams already hold.

What one week can and cannot do

The goal of this week is a defensible baseline, not a finished control. By Friday you should be able to name the AI tools in real use, say roughly how much of that use runs on accounts you do not govern, and point to a better default you have started to offer. What you will not have is complete coverage or a permanent detection capability. Treat the week as the first honest measurement, the one that turns suspicion into a number you can bring to a decision.

69% of organizations have evidence or suspect their employees are using public generative AI at work.
Gartner, 2025

That figure is the reason this week is worth running. Most security teams already believe shadow AI is happening inside their walls. The gap is not belief, it is visibility. A week of deliberate work closes enough of that gap to act on, and it does so without waiting on procurement or a new tool.

Day 1: Frame the question and pull the signals you already hold

Start by writing down the question you actually want answered, in one sentence, because a fuzzy question produces a fuzzy inventory. A good version is: which AI tools are our people using for real work, and whose account is the data landing in. Notice that the question is about accounts as much as tools. That framing carries the whole week.

Then pull what you already have. You do not need new instrumentation on day one. Most environments hold enough signal in places the team already runs:

Keep a single running list from the first hour. For each tool you find, record the name, where you saw it, and one detail you do not yet know. The unknowns are as useful as the finds, because they tell you where day two has to look.

Day 2: Separate the tool from the account

Day one tells you which tools appear. Day two answers the question that actually governs risk: whose account is signed in. This is the distinction that separates governable use from invisible use, and it is where most inventories stop too early.

67% of employees who use AI on corporate devices sign in with a personal account.
Verizon, 2026 Data Breach Investigations Report

Go back through the tools from day one and sort each one by identity. Corporate-account use shows up in your identity provider as a sanctioned OAuth grant or a managed login. Personal-account use usually does not appear there at all, which is the point. Where your logs cannot tell you, the domain pattern often can: consumer sign-in pages and free-tier endpoints look different from enterprise tenants. For anything you still cannot place, mark it personal until proven otherwise, because two out of three AI sessions on corporate devices run on personal logins, so the base rate is against you.

By the end of day two you want the inventory split into three buckets: sanctioned and on a corporate identity, sanctioned but running on personal logins, and entirely unsanctioned. The middle bucket is usually the surprise. It is the same approved tool people were told to use, reached through the account you cannot see.

Day 3: Talk to the work, not the policy

Logs tell you what moved. People tell you why. Spend day three in short conversations with a handful of teams that do information-heavy work: sales, engineering, legal, finance, support. Ask what they use AI for, which tools they reach for first, and what they would lose if those tools disappeared tomorrow. Do not open with the policy. Open with their work.

This matters because the behavior is almost never malicious. People bring their own AI because it is faster and already familiar. Across the workforce, 78% of the people using AI at work bring their own tools rather than wait for a company-provided one (Microsoft and LinkedIn, 2024 Work Trend Index). You are not looking for a bad actor. You are mapping a rational shortcut, and the map only comes from asking.

78% of the people using AI at work bring their own AI tools.
Microsoft and LinkedIn, 2024 Work Trend Index

Write down two things from each conversation: the job the tool is doing, and the sensitive data that job touches. A contract summarizer touches legal text. A support assistant touches customer records. This is what turns a tool list into a risk picture, because the risk is never the tool alone. It is the tool holding that team's most sensitive input on an account you do not control.

Day 4: Give people a better default

By now you know the tools, the accounts, and the work behind them. Day four is where you start to change the picture rather than just describe it. The move that reduces exposure fastest is not a ban. It is a genuinely good sanctioned option on a managed identity, offered to the teams whose shadow use touches the most sensitive data.

Pick the one or two tools that showed up most on personal accounts in day two, and make the corporate-identity version of them the easy path. That means a real login people can use in a minute, clear word that it is approved, and a plain explanation of why the personal account is the risk. When the safe path is as fast as the shortcut, most people take it without being told twice. Bans tend to push the same behavior onto phones and home devices, where you have even less visibility than you started with.

You will not migrate everyone in a day. The aim is to prove the pattern with one team and one tool, so that the ninety-day plan you write tomorrow has a working example inside it rather than a theory.

Day 5: Write the one-page picture and set the next ninety days

Close the week by writing a single page a leader can read. It has three parts. First, what you found: the count of AI tools in real use and the share running on personal accounts. Second, where the sharpest exposure sits: the teams whose sensitive work is landing on ungoverned identities. Third, what you did and what comes next: the better default you stood up, and the two or three moves for the next ninety days.

Keep the page honest about coverage. Say what the week could see and what it could not, so the number is trusted rather than oversold. A baseline that admits its blind spots is more useful than a dashboard that implies it caught everything, because the whole problem with shadow AI is the confidence that you already have visibility you do not. If you want a structured version of this picture across five signals, the assessment on this site scores AI visibility, data movement, identity, evidence, and remediation reach in about ten minutes, and it makes a clean companion to the one-pager.

What to keep measuring after week one

The week gives you a baseline. The value comes from watching a few of those numbers move. Carry a small set forward rather than a wall of metrics: the count of AI tools in use and how it changes, the share of AI use on personal versus corporate accounts, and the time between a new tool appearing and someone acting on it. These are the same measures that hold up in front of a board, and we cover how to frame them in AI insider risk KPIs for the board.

One week does not make shadow AI a solved problem. It makes it a measured one, which is the step most organizations have not taken. The teams that get ahead of this are not the ones with the biggest tool budget. They are the ones who ran the first honest measurement early and kept the number in view.

In short
  • One focused week gets you a named inventory, a read on personal-account use, and a safer default, using signals you already hold.
  • Day one pulls existing web, identity, and spend signals. The question is about accounts, not just tools.
  • Day two splits use by identity. 67% of employees who use AI on corporate devices sign in with a personal account (Verizon, 2026 DBIR), so the base rate favors personal.
  • Day three maps the work behind each tool, because the behavior is rational, not malicious. 78% of AI users at work bring their own tools (Microsoft and LinkedIn, 2024 Work Trend Index).
  • Day four offers a genuinely good sanctioned option on a managed identity rather than a ban, which moves behavior into the light.
  • Day five writes a one-page picture that is honest about coverage, then sets the next ninety days.

Common questions

How do you detect shadow AI in a week?

Pull the signals you already hold on day one: web and DNS logs, identity provider sign-in and OAuth records, endpoint telemetry, and AI-related expense. Sort each tool you find by account on day two, talk to information-heavy teams on day three, stand up a better sanctioned default on day four, and write a one-page baseline on day five. The output is a defensible first picture, not a permanent detection capability.

Can you find shadow AI without buying a new product?

For a first baseline, yes. Most environments already hold enough signal in web gateway logs, identity provider records, endpoint telemetry, and expense data to name the AI tools in real use and estimate how much runs on personal accounts. A dedicated tool helps you move from a one-time baseline to continuous visibility at the point of data movement, but it is not required to run the first week.

Why does the account matter more than the tool?

The same AI tool is governable on a corporate identity and invisible on a personal one. A corporate login leaves a trail you can audit and cut off at offboarding. A personal login does not, and 67% of employees who use AI on corporate devices sign in with a personal account (Verizon, 2026 DBIR). That is why the inventory has to be sorted by account, not just by which tools appear.

Should you block shadow AI once you find it?

Blanket bans tend to push the same behavior onto phones and home devices where you have even less visibility. The faster reduction comes from offering a genuinely good sanctioned tool on a managed identity, making it the easy path, and explaining plainly why the personal account is the risk. Coach toward the safe default rather than banning the behavior outright.

What do you measure after the first week?

Carry a small set of measures forward: the count of AI tools in use and how it changes, the share of AI use on personal versus corporate accounts, and the time between a new tool appearing and someone acting on it. These hold up in front of a board and turn a one-time baseline into a trend you can manage.

Go deeper on the platform side. Anzenna's work on how shadow AI detection works at the point of data movement covers how teams move from a one-week baseline to continuous visibility.

Score your exposure

Fifteen questions, about ten minutes, no registration to see your result.

Take the assessment