
Here's a number that should make any IT manager uncomfortable: in most mid-sized companies, employees are quietly using between 30 and 100 AI tools that the security team has never heard of. Recent surveys of enterprise SaaS environments consistently find that the number of AI applications in use is three to four times higher than what IT can name. Someone in marketing pasted the quarterly forecast into a free "AI presentation builder." A developer wired an unvetted code-completion plugin into the main repo. A sales rep is running client call transcripts through a note-taker that stores everything on servers nobody has audited.
This is Shadow AI, and it is different from the shadow IT problem we spent the last decade fighting. When someone installed an unauthorized file-sync app in 2015, the worst case was usually a data leak from a folder. When someone connects a Shadow AI tool today, they are often streaming your customer data, source code, or financial records to a third-party model that may train on it, retain it indefinitely, or expose it through a breach you will only hear about months later.
In this guide I will walk through exactly how to detect Shadow AI tools across browsers, endpoints, network traffic, and SaaS integrations. You will get a real detection workflow with numbers, a comparison of the main detection methods, and a practical remediation plan you can start this week. I have run versions of this process across teams of 20 and teams of 800, and the mechanics scale surprisingly well.
Key Takeaways
- Shadow AI hides in four places: browser extensions, desktop apps, OAuth-connected SaaS integrations, and raw network calls to AI APIs. You need visibility into all four.
- OAuth grants are the biggest blind spot. A single "Sign in with Google" click can hand an AI tool ongoing access to your entire email and Drive.
- Network-level DNS logging is your fastest win. Watching for calls to known AI endpoints surfaces most tools in under a week.
- Detection without a sanctioned alternative fails. If you block a tool people love, they will find a workaround within days.
- Automate the recurring scan. New AI tools launch weekly, so a one-time audit is obsolete almost immediately.
- Treat AI browser extensions as high-risk by default because they can read every page a user visits.
What Counts as a Shadow AI Tool
Before you can detect something, you need a working definition. A Shadow AI tool is any AI-powered application, extension, plugin, or API integration that employees use for work without IT review or approval. The "AI-powered" part matters because these tools share a specific risk profile: they ingest data, send it off-premises, and often learn from it.
In practice, Shadow AI falls into a few recognizable buckets:
- Browser extensions: AI writing assistants, summarizers, "chat with any webpage" tools, and autonomous browser agents.
- Desktop applications: local AI note-takers, meeting transcribers, and code assistants installed as native apps.
- SaaS integrations: web apps connected to your Google Workspace or Microsoft 365 through OAuth, often with broad read access.
- Embedded API usage: scripts, bots, and internal tools calling OpenAI, Anthropic, or other model APIs directly, sometimes with a personal API key expensed later.
The last category is the sneakiest. A developer testing a "quick" feature might pipe production support tickets through a model API, and nothing about that shows up in a browser or app inventory. You only catch it at the network layer or in a code review.
Why this is worse than classic shadow IT
With a rogue Dropbox account, the data at least sat in a folder you could later delete. With Shadow AI, the moment data enters a prompt, you have potentially lost control of it. Many free AI tools reserve the right to use inputs for training. Once your unreleased product spec is in a training set, there is no delete button that helps you.
How to Detect Shadow AI Tools: The Four Detection Layers
Effective detection means covering four layers. Skip one and you leave an obvious gap. I recommend working through them in this order because it front-loads the highest-yield, lowest-effort checks.
1. Network and DNS layer
This is where you get the fastest, broadest picture. Every AI tool that talks to a cloud model has to make outbound calls to known domains. Configure your DNS resolver or firewall to log queries and look for endpoints like api.openai.com, api.anthropic.com, generativelanguage.googleapis.com, and the domains of popular consumer AI products.
Even a small team benefits from centralizing DNS through a filtering resolver so those logs exist in one place. If you already run monitoring as part of a broader stack, the Webmaster Tools Suite and similar utilities in our desktop utilities catalog can help you keep an eye on outbound activity from key machines.
2. Endpoint layer
Inventory the actual software installed on company machines. On Windows, that means the installed-programs registry and running-process list. On macOS, the Applications folder and login items. Cross-reference against a list of known AI desktop clients and transcription tools.
3. Browser extension layer
Browser extensions are the single most common home for Shadow AI, and also the most dangerous, because an extension can read and modify every page a user loads. Audit installed extensions on managed browsers and flag anything with AI capabilities or broad host permissions. Our walkthrough on how to detect and remove malicious browser extensions installed without consent covers the mechanics in detail, and the same technique applies to unauthorized AI add-ons.
4. SaaS and OAuth layer
Check which third-party apps have been granted access to your Google Workspace or Microsoft 365 tenant. This is where an "innocent" free tool quietly obtains ongoing permission to read every email or file. Both platforms expose an admin view of connected apps and the specific scopes they were granted.
A Worked Example: Auditing a 60-Person Company in One Week
Let me make this concrete. Say you run IT for a 60-person company: 25 in sales and marketing, 20 in engineering, 15 in operations and finance. You suspect Shadow AI but have no data yet. Here is the week I would run.
- Day 1 — Turn on DNS logging. You route all office and VPN traffic through a filtering resolver and start logging queries. By end of day you have a baseline capture running.
- Day 2 — Pull the OAuth grant report. In Google Workspace Admin you export the third-party app access list. You find 34 distinct apps with access; 11 are AI tools nobody documented. Three have full Drive read scope.
- Day 3 — Scan endpoints. A script collects installed apps from all 60 machines. Result: 9 devices run an AI meeting transcriber, 4 developers have an unvetted local code assistant.
- Day 4 — Audit browser extensions. Across the managed Chrome fleet you find 17 AI-related extensions, including two "read any page" summarizers with alarming permissions.
- Day 5 — Review DNS logs. Now that you have four days of traffic, you see calls to 23 unique AI domains, including seven you had not caught through the other three layers, mostly developer API usage.
Total unique Shadow AI tools discovered: roughly 28 to 30 in a company where the official answer to "what AI do we use?" was "just the ChatGPT team plan." That gap between the sanctioned two and the actual thirty is the entire problem in one number.
The before/after is stark. Before the audit: unknown exposure, zero policy, customer call transcripts flowing to an unaudited vendor. After: a ranked list of tools, a documented decision on each, and three high-risk OAuth grants revoked within the hour.
Comparing the Main Detection Methods
No single method catches everything. Here is how the four layers stack up on the criteria that actually matter when you are deciding where to invest effort first.
| Method | Coverage breadth | Setup effort | Catches API usage? | Ongoing cost |
|---|---|---|---|---|
| DNS / network logging | High | Medium | Yes | Low |
| Endpoint software inventory | Medium | Medium | No | Low |
| Browser extension audit | Medium | Low | No | Low |
| OAuth / SaaS grant review | Medium | Low | Partial | Low |
| Dedicated CASB / SSPM platform | Very high | High | Yes | High |
My honest take: for teams under about 200 people, the combination of DNS logging plus OAuth review plus a browser audit covers the overwhelming majority of Shadow AI at almost no license cost. A dedicated cloud access security broker earns its price once you are past that scale, or once compliance auditors start asking for continuous evidence.
Step-by-Step: Building a Repeatable Detection Workflow
A one-time sweep goes stale fast because new AI tools ship every week. Turn detection into a recurring process. Here is the workflow I hand to teams.
- Maintain a living AI-domain blocklist and watchlist. Keep a text file of known AI endpoints. Split it into "watch" (log only) and "block" (deny) tiers. Update it monthly.
- Schedule an automated endpoint scan. Run your installed-software inventory script weekly and diff the results against last week's. New AI apps stand out immediately in the diff.
- Set an OAuth review cadence. Review new third-party grants every two weeks. Auto-flag any grant requesting mail, drive, or calendar read scope.
- Alert on new AI DNS hits. Configure your resolver to notify you the first time any device queries a new domain on your AI watchlist.
- Log and version every decision. For each discovered tool, record: approved, restricted, or blocked, plus the reason. A lightweight text-snippet tool like
Cover image: Innovate Maryland Emerging Technology Center by MDGovpics, licensed under BY 2.0 via Openverse.








