Free security assessment — no obligation Get a Proposal
← All insights
Governance

Finding your shadow AI: a two-week plan

Published Updated

Most organizations already have AI in use before they have a policy for it — staff using assistants in the browser, features quietly switched on in existing tools, scripts calling an API. That's shadow AI, and the first step is simply to see it.

Week one: inventory

Survey teams, review expenses and SSO logs, and check which of your existing vendors have shipped AI features. The goal is a single list of where AI touches your data and workflows.

Week two: policy and tiering

Turn the inventory into a short, enforceable acceptable-use policy and tier each use by risk. High-risk uses (customer data, code, regulated records) get guardrails first.

Two weeks, fixed scope — it's the fastest way to regain control. More on our AI use inventory or book an assessment.

More insights