What to take away
Shadow AI is the use of AI tools for work outside your organization’s approval process. Managing it starts with knowing which tools people use, what data they need, and which controls actually cover that work. This guide provides an inventory structure and a practical validation checklist.
1. Review the use case as well as the tool
An employee might draft a public announcement in a personal chatbot account, upload a customer spreadsheet to an unapproved assistant, or connect an AI agent to a shared drive. These situations need different decisions. A recognizable provider name alone does not establish whether the account, information, or connected permissions are appropriate.
Start by asking what the person is trying to accomplish. Record the application, business owner, account context, data involved, and any connected tools. ANSSI’s guidance treats generative AI security across deployment and use; apply that perspective by reviewing the workflow when its data or permissions change, not only when the tool first appears.
References: ANSSI — Security recommendations for generative AI systems
2. Build an inventory with evidence behind each entry
Combine application connectors, relevant OAuth grants, browser observations, and information from employees or application owners. Keep the source and observation date with each record. A browser visit establishes observed use; it does not prove that an account exists, a subscription was bought, or sensitive information was submitted.
Use the following fields in a spreadsheet or application inventory. Leave unknown values visible and assign someone to verify them. An apparently complete inventory built from assumptions is less useful than a smaller one whose evidence can be checked.
| Field | What to record | Decision it supports |
|---|---|---|
| Tool and purpose | Application, work task, business owner | Is there a legitimate need? |
| Evidence | Connector, grant, observation, or owner confirmation; date | What is confirmed and what needs checking? |
| Account context | Work, personal, signed out, or unknown | Does use match the approved account arrangement? |
| Data and permissions | Allowed data categories and connected access | What could be exposed or changed? |
| Policy and coverage | Approval, exception owner, covered browsers and actions | What response is available? |
3. Match the response to the exposure
Consider a fictional sales team using an unapproved assistant to summarize customer calls. The next useful step is to verify the account, intended inputs, and business requirement. You might approve a reviewed work account for suitable material, provide another tool, or prohibit that use while an assessment is pending. Record the decision and explain the acceptable path to the team.
A policy should specify permitted tools, account types, data categories, and an exception process. Separate the provider’s reputation from your organization’s approval decision. A well-regarded application may still be unsuitable for a particular dataset. The NCSC’s secure AI guidance also identifies prompts and logs as assets to protect: keep your investigation records from becoming a new store of unnecessary sensitive content.
- Name an owner who can approve the use and revisit an exception.
- Give employees examples of acceptable and prohibited inputs, using synthetic data.
- Explain what a warning or block means and how to request a legitimate alternative.
- Record the devices, accounts, and interactions that your controls do not cover.
References: NCSC and international partners — Guidelines for secure AI system development
4. Test the control at the point of use
Turn the policy into a small set of repeatable checks. On an enrolled test device, submit a harmless prompt, a synthetic example that should trigger your sensitive-data rule, and representative supported uploads. Compare the expected warning or block with the observed result. Repeat for each browser and account arrangement you intend to support.
Test a format that the control cannot inspect as well. Record whether it is ignored, described through metadata, warned about, or blocked under a separate rule. An upload completing without an alert does not establish that its contents were examined. Keep the test date and configuration so a later change can be checked against the same cases.
5. Review connected agents separately
If the tool can act through connected applications, review those permissions alongside prompts and uploads. The NCSC’s guidance on agentic AI recommends constrained access, clear human accountability, and the ability to monitor and contain actions. A chatbot approval should not silently authorize an agent to change files, send messages, or operate other systems.
Add the connected resources, allowed actions, access approver, and person who can stop the workflow to the inventory. Revisit the assessment when a new connector or action is enabled. Keep this review connected to your normal application-access process so the permission decision has a clear owner.
References: NCSC — Thinking carefully before adopting agentic AI
How Elba supports this workflow
Elba brings observed browser use into its application inventory and can show supported work, personal, or signed-out account context. Configured Playbooks can block supported sensitive prompts or uploads. Coverage depends on the browser, enrollment, application interaction, and configuration; validate those conditions before relying on a control.
Supported text files provide a bounded excerpt for inspection. Binary formats such as PDFs, Office files, most images, and archives provide metadata only; incomplete inspection does not itself block an upload. A configured check can send the relevant prompt or excerpt through Elba’s classification service. Stored findings retain classifications, hashes, and necessary metadata rather than raw prompts or file contents.
Shadow AI review checklist
Your checks stay on this page and reset when you reload it.
Common questions
Is every AI tool used without approval dangerous?
No. Unapproved use means the organization has not established its conditions for use. Investigate the business purpose, account, data, and permissions before choosing an appropriate response.
Does a browser observation prove that data was leaked?
No. It is evidence of observed use. Whether an account exists or information was submitted requires additional evidence. Keep these findings distinct when reporting risk.
Can one policy cover both chatbots and AI agents?
A shared policy can set general expectations, but an agent that accesses tools or takes actions needs a review of those permissions, accountability, and stopping mechanisms.
What should we measure?
Track verified inventory coverage, unresolved approvals, exceptions awaiting review, and tested control outcomes. Treat alert counts in the context of deployment coverage and actual follow-up.
Sources & further reading
Primary documentation used to review this guide. Product settings and edition requirements can change; check the linked documentation before making changes.