Governance
Your staff are already using AI. Here is how to find out where.
Unsanctioned AI use is not a discipline problem. It is unpaid product research telling you exactly where the friction in your business is — provided you find out about it before it costs you something.
The short answer
Assume AI is already in use in your organization. MIT's 2025 research found employees at over 90% of surveyed companies using personal AI tools at work, while only about 40% of companies had purchased official licenses.
Discover it through a combination of amnesty conversations, expense and subscription review, identity and browser telemetry, and looking at AI features already switched on inside software you own.
Read the findings as a roadmap rather than an incident log. Where people reached for a tool on their own is where the work is genuinely painful.
Move fast on two things only: data that should never have left, and vendor settings that permit training on your inputs. Everything else can be sequenced.
Most leaders we speak with suspect AI is being used inside their organization without oversight, and are unsure how much. The research suggests the answer is more than they think. MIT's State of AI in Business 2025 found that employees at over 90% of surveyed companies were already using personal AI tools for work, while only about 40% of those companies had bought official licenses.
That gap is worth sitting with. It means the dominant mode of AI adoption in most organizations is not a managed rollout. It is individuals solving their own problems with whatever they can access, and it is happening whether or not anyone has approved it.
Why this is happening, and why it is rational
It is tempting to read unsanctioned AI use as carelessness. It is more accurately read as initiative pointed in an unmanaged direction. Someone had a task that was tedious, repetitive, or slow. They found a tool that made it faster. Nobody had told them not to, and waiting for permission would have cost them the afternoon.
This framing matters because it determines what you learn. Treated as misconduct, discovery becomes an investigation and people conceal things. Treated as signal, the same exercise produces a map of where your processes are actually painful — assembled by the people who do the work, at no cost to you.
Every unsanctioned AI tool in your organization is a note from an employee about a process that is harder than it should be.
What the actual risks are, in order
Not all of this exposure is equally urgent, and treating it as undifferentiated danger makes it harder to act. In our engagements the same handful of problems recur, and they are not equally severe.
Proprietary material entered into models that train on it
This is the one we see most often and the one that is least recoverable. Teams upload intellectual property, client material, and internal documents without ever opening the settings to check whether the vendor uses inputs for training. In many products that control exists and is straightforward to change. Almost nobody looks.
The reason this ranks first is that it cannot be undone. A misconfigured permission can be corrected; information that has already been absorbed into a training corpus cannot be retrieved. If you check one thing this week, check this.
Regulated data in consumer tools
If you handle patient information, cardholder data, privileged client material, or controlled information under a contract, a single prompt can constitute a reportable event regardless of intent. The employee summarizing notes to save fifteen minutes is not thinking about breach notification thresholds. Severity here depends entirely on your obligations, which is why this is worth mapping before you go looking.
Unverified output entering real work
This is the quietest of the failures and, cumulatively, often the most expensive. Staff who have not been trained on how these tools fail do not know that fluent, confident output can be entirely fabricated. So they do not check. Figures go into a document, a summary gets forwarded, a clause gets paraphrased, and nobody verifies the content that came back. The time saved is real; so is the eventual cost of catching it late, and correcting one such error frequently exceeds every minute the tool saved that month.
Redundant and mis-tiered subscriptions
Less alarming, more immediately measurable. Organizations end up paying for several overlapping platforms because three departments each solved the same problem independently. Beyond the duplication, the plan choice is frequently wrong in one of two directions: an expensive tier where consumption runs unchecked and the bill climbs, or an inadequate tier producing weak results that get blamed on the technology rather than the plan. Both are avoidable with a few minutes of attention and neither gets it.
How to actually find out
Use several of these together. Any single method will understate what is happening.
- 01Ask, with a real amnesty. The highest-yield method by a wide margin, and the one most organizations skip because it feels insufficiently rigorous. Say plainly that you are mapping what is in use, that nobody is in trouble, and that the objective is to make good tools officially available. Then honor it without exception. One penalty for an honest answer ends the usefulness of this channel permanently.
- 02Review expenses and card statements. Individual AI subscriptions are inexpensive enough to clear approval thresholds without comment. Search reimbursements and corporate cards for recurring charges in the ten-to-fifty-dollar range and you will usually find several.
- 03Check identity and single sign-on logs. If you use a managed identity provider, third-party application grants are recorded. Look at which applications employees have authorized against their work account — this also reveals what data those applications were permitted to read.
- 04Inventory browser extensions. A significant share of unsanctioned AI arrives as an extension with broad page-reading permissions, which is a materially different risk profile from a website someone visits.
- 05Audit the AI features in software you already own. Frequently overlooked and frequently the largest surface. Your existing productivity suite, CRM, help desk, and meeting platform have all shipped AI capabilities, some enabled by default. That is AI processing your data under settings nobody reviewed.
- 06Talk to the enthusiasts. Every organization has two or three people who are ahead of everyone else on this. They know what colleagues are using, they have opinions about what works, and they will tell you in detail if asked. They are also your best candidates for internal champions later.
From our engagements
We routinely recommend that clients invest in upskilling their workforce before expanding tooling, usually through self-directed training. Almost none take it up. They want to start using the tools immediately, and instead spend thousands of dollars on subscriptions across multiple platforms — money that would have covered the training several times over. The failures that follow are then attributed to AI rather than to sequence.
Reading the results
Once you have the picture, resist the urge to reduce it to a risk register. Read it twice.
The first pass is exposure: what data went where, which vendors train on inputs, which tools hold permissions nobody granted deliberately. Act immediately on the two items that do not wait — proprietary or regulated material in the wrong place, and training settings that should be switched off.
The second pass is opportunity, and it is the more valuable of the two. Cluster the usage by the problem it was solving. Several people independently reaching for the same category of tool is a strong signal about where your organization loses time. That is a better-evidenced starting list than any strategy workshop will produce, because it reflects what people chose to fix when they were choosing for themselves.
The tools your staff adopted without asking are the closest thing you have to a validated list of your own inefficiencies.
Bringing usage into the open
Discovery is only useful if it changes the arrangement. Three moves, in order.
Sanction the good tools quickly. If people are getting real value from something and it survives review, approve it and move them onto an appropriate tier with sensible settings. Speed here is what proves the process is worth using next time.
Consolidate the overlap. Where three tools serve one purpose, choose one, negotiate properly, and retire the rest. This usually pays for the training you have been deferring.
Then close the loop with a policy and basic literacy — what these systems are unreliable at, how to verify output, what never goes into a prompt. Discovery without that is a snapshot that goes stale in a quarter.
What not to do
Do not respond to what you find with a blanket ban. It is the intuitive move and it makes the situation worse: usage continues, disclosure stops, and you have traded a visible problem for an invisible one. Do not make an example of anyone who was honest with you. And do not let the exercise conclude in a document — an inventory that produces no approved tools, no policy, and no training has cost you the goodwill of asking and returned nothing.
Stay in the loop
New writing, when there is something worth sending
Occasional notes on AI governance, adoption, and what we are seeing in client work. No newsletter cadence, no sequence — we write when we have something useful.
Next step
Find out what is actually in use before you plan anything else.
A shadow AI discovery exercise is usually a short engagement and it reliably changes what an organization decides to do next. We can run it with you, or hand you the method and let you run it yourself.
Start an AI Conversation