Governance - shadow AI

The shadow AI audit: how to find and govern unapproved AI in 2026

A shadow AI audit is a structured sweep for the AI tools your staff adopted without approval. You build an inventory from SSO logs and expense data, score each tool for data and legal exposure, run DPIA screening where GDPR demands it, and replace the risky tools with sanctioned ones. Budget two weeks for the first pass.

A shadow AI audit is a structured review that finds every AI tool employees use without IT approval, scores each for data and legal risk, checks whether GDPR requires an impact assessment, and replaces high-risk tools with sanctioned alternatives. The inventory comes from SSO logs, expense records and a staff survey, repeated quarterly.

Start with the definition, then move past it

Our answer page on what shadow AI is defines it in one line: employee use of AI tools that IT has not approved, reviewed or contracted. That page answers what. This one answers how. How you find the tools, how you rank them, and what you do with the list once it exists.

Why 2026 forces the issue

Two legal deadlines changed the math. The EU AI Act's prohibitions and AI literacy duties have applied since 2 February 2025, and the bulk of its high-risk obligations arrive on 2 August 2026. The Act binds deployers, meaning any organisation using an AI system in the EU, including ones that built nothing themselves. When an account manager pastes client records into a personal ChatGPT account, your company becomes the deployer of a system nobody assessed.

GDPR never left. Article 35 requires a data protection impact assessment wherever processing is likely to put people at high risk, and an unvetted consumer tool holding customer data fits that description. The fine ceiling sits at 20 million euros or 4 percent of global turnover, whichever is higher.

There is a softer duty hiding in the same law. Since 2 February 2025 the Act has required AI literacy for staff who operate AI systems on a company's behalf. Training people on tools you officially pretend they do not use is an awkward brief. An audit resolves the contradiction, because once the inventory is honest the training can be too.

Meanwhile the tools spread on their own. ChatGPT and Copilot run in a browser on a free tier, so no procurement step exists for anyone to catch. A junior marketer can adopt one before lunch. Your identity logs almost certainly show it already happened.

The five-step shadow AI audit

Step 1: build the inventory from SSO and expense data

You cannot govern a list you do not have. Three sources produce it in about a week.

Merge the three into one sheet with four columns: tool, who uses it, what data goes in, personal or company account. That sheet is the audit's spine. Everything else builds on it.

Step 2: classify each tool by risk

Tier the list before you touch policy. High tier means the tool sees personal data, client deliverables, source code or financials. Medium means internal but non-personal content, such as meeting notes and drafts. Low means public content only, and those tools can wait.

Then score every high-tier tool against the four exposure types from our definition page: what goes in (confidentiality), who processes it (regulatory), what comes out (accuracy), and what your client contracts say about AI use. A tool can pass three and still fail on the fourth. AI clauses in client contracts are increasingly common, and breaching one is a commercial problem before it becomes a legal one.

A concrete case makes the tiers real. A recruiter summarising candidate CVs through a free ChatGPT account sits at the top of the high tier. The CVs are personal data, the free tier's terms were never reviewed, and the summaries feed hiring decisions. One habit, formed in an afternoon, touching three exposure types at once.

Step 3: check the DPIA triggers

GDPR Article 35 requires a DPIA where processing is likely to put the people behind the data at high risk. Two triggers catch most shadow AI cases: systematic evaluation of individuals, and large-scale processing of sensitive categories of data. An HR assistant screening CVs through an unapproved tool trips both at once. Our page on whether you need a DPIA for AI walks through the full test.

Do the screening in writing even when the answer is no. A one-page record showing you asked the question is the difference between a defensible position and a shrug when a regulator writes to you.

Step 4: publish a sanctioned-tool policy

Prohibition fails. Blocking ChatGPT at the firewall moves usage to personal phones, where you see nothing, and teaches staff to hide rather than ask. Sanctioning works better. Pick one approved tool per job and put it behind SSO. Sign a data processing agreement with the vendor before anyone logs in.

Write data rules people can hold in their head. Three short categories beat a 40-page policy. Green content is fine to paste. Amber needs a question first. Red never leaves the building. Staff remember traffic lights long after they have forgotten a PDF.

Give the policy one owner with a name, usually whoever runs IT or operations. Policies owned by committees go stale by the second quarter. The owner approves new tools, fields the amber questions, and runs the re-scan described below.

Vet the vendors before you sanction them. Our AI vendor due diligence checklist covers what to ask about training-data use and retention, and what a vendor must sign before your data touches their servers.

Step 5: re-scan every quarter

New AI tools launch weekly, and staff adopt them faster than procurement can meet. Book a 90-minute re-scan each quarter. Pull the same SSO and expense reports and diff them against the last inventory. Triage anything new within the same week. The audit is a cycle, and the first pass is the only expensive one.

One more use for the list. Our definition page calls shadow AI a map of where your processes are slow, and the map is the point. The tool an employee risked a policy breach to keep using is exactly the automation your company should build properly, with a contract and SSO behind it.

The printable checklist

Print this or paste it into your task tracker. One named owner per row beats a committee.

#TaskEvidence to keep
1Pull third-party app grants from Google Workspace or Microsoft EntraExported grant list, dated
2Search 12 months of expenses for AI vendor namesFiltered expense report
3Run a no-consequences staff survey, under five questionsSurvey results
4Merge findings into one inventory: tool, user, data types, account typeThe inventory sheet
5Tier every tool high, medium or lowTier column filled in
6Score high-tier tools against the four exposure typesNotes per tool
7Screen high-tier tools against GDPR Article 35One-page DPIA screening record each
8Select sanctioned tools, sign DPAs, enforce SSOSigned agreements
9Publish the green, amber, red data ruleThe one-page policy
10Book the quarterly re-scanRecurring calendar entry

What Digiton's audit covers

We run this five-step process for companies in 8 countries, and the entry point costs nothing. The free AI audit takes under two minutes to request and comes back within 48 hours. It maps where AI already shows up in your operations and ranks automation opportunities by hours saved.

The full engagement goes further. We build the inventory with you, tier it, run the DPIA screening, and then convert your top shadow uses into sanctioned systems with contracts and SSO in place. The productivity your staff already found stays. The liability goes.

Frequently asked questions

What is a shadow AI audit?

A structured review that inventories every AI tool employees use without IT approval, then scores each one for confidentiality, regulatory, accuracy and contract exposure. Inventory sources are SSO logs, expense records and a staff survey. The output is a risk-tiered tool list, written DPIA screening records where GDPR requires them, and a sanctioned-tool policy staff can remember.

How long does a shadow AI audit take?

Plan two weeks for the first pass. The inventory takes about a week across SSO logs, expense data and a survey, and the tiering, DPIA screening and policy work fill the second. The quarterly re-scan afterwards takes about 90 minutes, since you only diff new findings against the existing sheet.

Does the EU AI Act apply if we only use AI tools and never build them?

Yes. The Act assigns duties to deployers, meaning organisations that use AI systems in the EU. AI literacy obligations have applied since 2 February 2025, and most high-risk system obligations arrive on 2 August 2026. An unapproved tool your staff use in client work still counts as your deployment.

Do we need a DPIA for every AI tool?

No. GDPR Article 35 requires one where processing is likely to put people at high risk, with systematic evaluation of individuals and large-scale sensitive data as the common triggers. Screen every high-tier tool and record the answer in writing, even when the answer is no. The record itself is the protection.

Should we just block ChatGPT?

Blocking moves usage to personal phones, where you have no logs and no recourse, and teaches staff to hide rather than ask. A sanctioned alternative behind SSO with a signed data processing agreement gives people the productivity they already found, on infrastructure you control and can audit.

How often should we repeat the audit?

Quarterly. New tools appear faster than annual reviews can catch, and a 90-minute diff against the previous inventory keeps the list honest. Put the re-scan in the calendar before the first audit closes, with a named owner, or it will quietly stop happening.

Related

What is shadow AIAI vendor due diligence checklistDo we need a DPIA for AIFree AI audit

Ready to put AI to work?

Book a discovery audit and we will map the highest-ROI AI agents and automations for your business.

Book a discovery audit →