HD Field Guide 06

Shadow AI discovery without a witch-hunt

Find unsanctioned AI use, understand why it exists and replace risky workarounds with approved pathways.

Control area
AI governance
Audience
Organisations
Reading time
7 min
Reviewed
16 July 2026

People often adopt AI tools because they solve a real problem faster than an approved process. Discovery should reduce risk while preserving useful innovation—not punish honest experimentation.

Start with transparent questions

Use surveys, workshops and service-owner discussions to identify tools, accounts, connectors, data types and business value. Explain the purpose of discovery and how findings will be handled.

Distinguish personal experimentation from systems that process organisational data or perform business actions.

Prioritise by consequence

Highest priority usually includes confidential data, privileged connectors, public output, automated actions and tools with unclear retention or ownership. A low-risk writing assistant should not be treated the same as an autonomous agent with mailbox access.

Record ownership, approved purpose, data boundaries, supplier status and review date for each accepted tool.

Create a usable safe path

Offer approved tools, practical training and a quick assessment route for new use cases. Policies fail when the only answer is “no” and legitimate needs remain unresolved.

Measure adoption, reported concerns and repeated exceptions so controls can improve over time.

Completion check

Before you close the guide

  • Tool and connector inventory established
  • Business purpose and data types recorded
  • Risk-based approval or replacement decision made
  • Owner and review date assigned

Trusted references

Continue with primary guidance

Defensive guidance boundary

This guide provides general educational information. Adapt it to your organisation’s policies, contracts, legal obligations and incident process. For an active incident, use trusted professional and official support channels.