An employee on your team pastes a paragraph of client correspondence into ChatGPT to help draft a reply. Someone in accounting installs a browser extension that summarizes long PDFs. Your marketing coordinator turns on the AI writing assistant built into your CRM without ever mentioning it to IT. None of these people are trying to cause a problem. They're trying to get their work done faster. But each one just created a data exposure risk that didn't exist a year ago, and that nobody in your organization currently has visibility into.
This is shadow AI: artificial intelligence tools, features, and agents being used inside a business without formal IT approval or oversight. It's the starting point of any AI governance program, because you cannot assess, classify, or control a risk you don't know exists.
What Is Shadow AI, Exactly?
Shadow AI covers a wider range of tools than most business owners expect. It includes standalone chatbots employees sign up for on their own, AI features already built into software you already pay for, browser extensions that add AI capabilities to everyday sites, and increasingly, autonomous AI agents that can take actions (sending emails, updating records, scheduling meetings) without a human approving every step.
Some of this AI use is genuinely useful and low-risk. Some of it is quietly connected to systems holding sensitive client, financial, or patient data. The problem is that without a discovery process, every one of these tools looks the same from IT's perspective: invisible.
Why Shadow AI Is Growing So Fast
A few years ago, adopting new business software required a purchase, a login, and usually an IT ticket. AI changed that. Most AI tools are free or cheap to start, require no procurement process, and now ship as a checkbox feature inside software your team already uses, from productivity suites to project management platforms to customer support tools. Turning AI on has never been easier, and turning it off has never been harder to notice.
That combination is why shadow AI has become one of the fastest-growing blind spots for small and mid-sized businesses, and why AI discovery has to be the starting point of any serious governance effort rather than an afterthought.
Common AI Tools Hiding in Plain Sight
When businesses run their first AI discovery process, the list is almost always longer than they expected. It typically includes some combination of:
- General-purpose AI assistants: ChatGPT, Microsoft Copilot, Google Gemini, and Claude, used for writing, research, coding, and analysis.
- Writing and communication tools: Grammarly AI and similar tools embedded in email and document workflows.
- Meeting and transcription tools: Zoom AI Companion, Otter.ai, and other AI note-takers that record and summarize conversations, sometimes including confidential discussions.
- Design and content tools: Canva AI and other creative platforms with AI-generated content or image features.
- AI features inside existing SaaS platforms: CRMs, helpdesk software, accounting platforms, and HR systems increasingly ship with AI features turned on by default.
- Browser extensions: small, easily installed add-ons that can read, summarize, or interact with whatever is on an employee's screen.
- Emerging autonomous AI agents: tools that can complete multi-step tasks on their own, often with access to email, calendars, or business systems.
How to Build Your AI Inventory
A reliable AI inventory usually takes a combination of approaches; no single method catches everything on its own
- Ask directly. A short, judgment-free survey asking employees what AI tools they use for work will surface far more than most businesses expect. Framing it as a fact-finding exercise, not a disciplinary one, gets honest answers.
- Review software and SaaS spend. Expense reports, credit card statements, and SaaS management tools often reveal AI subscriptions that never went through a formal approval process.
- Check identity and access logs. Microsoft 365 and Entra ID (Azure AD) app registrations and sign-in logs will show which AI services employees have connected using their work accounts.
- Audit browser extensions. Endpoint management tools can pull a list of installed browser extensions across company devices, many of which are AI-powered.
- Review DNS and web traffic. Web filtering and DNS logs show which AI domains employees are actually visiting, including tools nobody mentioned in the survey.
- Talk to department leads. Marketing, sales, HR, and finance teams frequently adopt AI tools independently to speed up their own workflows. A quick conversation with each department head often reveals tools IT never knew about.
Approved, Unapproved & Unknown: Sorting What You Find
Once your inventory is built, every tool on it will fall into one of three buckets: officially approved AI that IT rolled out and sanctioned, unapproved AI that employees adopted on their own, and unknown or shadow AI that nobody in the organization has evaluated at all. That sorting is useful, but it's not the finish line. It just tells you where to point your risk assessment first.
The tools in the unapproved and unknown buckets deserve the closest look, since nobody has yet documented what data they touch or how secure they actually are. That's the next step in the process: turning your inventory into an actual risk picture for each tool. Our guide, How to Conduct an AI Risk Assessment: Data, Vendors & Compliance, walks through exactly what to document and how to arrive at a risk rating you can act on.
Call us at 937-428-9234, email info@harbourtech.net, or contact Harbour Technology Consulting to talk through where your business stands today.

.jpg)




