Your organization is already using AI. The only real question is: do you know where?
Three ordinary scenes, all seen in well-run organizations:
- An accountant pastes the quarterly income statement into a free AI chatbot to "polish the management commentary".
- A developer plugs a personal coding assistant into the repository that holds your API secrets.
- HR trials a SaaS resume-screening tool found on LinkedIn, with data from 400 candidates.
None of these people mean harm. All of them are trying to move faster. That is exactly what shadow AI is: real, useful, invisible usage, outside any control. Shadow IT all over again, except this time what leaves the building is your data and your decisions.
This article opens our series "AI security: the roadmap": 8 episodes, one every Thursday through late October. We start with the one step that makes every other step possible: the inventory. You cannot govern, contract, or measure what you cannot see.
Why this is a leadership issue, not a tooling issue
Every unrecorded AI use stacks four exposures:
- Data leakage. Whatever gets pasted into a consumer tool may be used for model training or end up outside your jurisdiction. Data exfiltration with no attacker involved: your teams do it themselves, for free.
- Compliance. Personal information processed by an unassessed vendor is a direct Law 25 and GDPR problem: no privacy impact assessment, no contract, no known data residency.
- Intellectual property. Source code, product plans, price lists: once submitted to a third-party service, you control nothing.
- Unauditable decisions. Resume screening or credit analysis assisted by an unknown tool is a business decision nobody can explain or defend.
The "block everything" reflex solves nothing: it pushes usage onto personal phones, where you see nothing at all. The goal is not to forbid. It is to see, then choose.
The playbook: 5 days to a complete inventory
No six-month project required. One owner (security, IT, or compliance), five days, four cross-checked sources.
Day 1: technical traces
- SSO and OAuth logs: list the applications employees have connected to their corporate account. OAuth consents granted to AI tools are your most reliable signal.
- Proxy and DNS logs: filter for major AI service domains and recent SaaS tools. Rank by request volume.
- Browser extensions: if you manage endpoints, export the list. AI assistants breed there.
Day 2: the money
- Expense reports and corporate cards: look for subscriptions in the $20 to $60 per month range. That is the classic signature of an AI tool paid out of a team's own budget.
- SaaS purchases from the last 18 months: half your business tools have added AI features without the contract changing. Your CRM, HR platform, and office suite probably already have.
Day 3: the no-blame declaration
Send a short survey, three questions, with one clear message: full amnesty. Nobody gets sanctioned for a declared use.
- Which AI tools do you use for work, even occasionally?
- For which tasks?
- What kinds of data do you put into them?
The discovery rate of this step surprises every time: the riskiest uses are rarely in the logs, they are in people's habits.
Day 4: the register
Consolidate everything into a single register. Six columns are enough:
| Column | Example | | --------------- | ------------------------------ | | Tool and vendor | Consumer AI chatbot, free tier | | Who uses it | Finance team (4 people) | | Use case | Rewriting management reports | | Data exposed | Unpublished financial results | | Named owner | Finance director | | Status | To be governed |
The "data exposed" column is what turns a list of tools into a risk map. Be specific: "customer data" means nothing, "SINs and addresses of 400 candidates" does.
Day 5: triage
Three statuses, no more:
- Approved: useful, data non-sensitive or vendor under contract. Say it publicly; it buys credibility for everything else.
- To be governed: useful but conditions must change (enterprise tier, no-training clause, anonymized data). With a deadline and an owner.
- Blocked: sensitive data going to a vendor you cannot assess. Rare, justified, and always paired with an approved alternative.
The 3 red flags that warrant immediate action
- Personal information (employees, customers, candidates) in a free consumer tool.
- An AI tool connected by OAuth to your email or file storage, installed by a single employee.
- A decision process (hiring, credit, pricing) where AI is involved without the accountable manager knowing.
What you will have by Friday
A dated register, an owner per use, a three-status triage. That is the foundation for the next seven episodes: governance (who decides what), LLM-specific risks, your vendors, offensive AI, ISO 42001 and NIST AI RMF, AI agents, and finally measuring the risk.
Episode 2, next Thursday: who answers for AI in front of leadership? Roles, committee, a one-page usage policy.
In the meantime, two ways to baseline where you stand: our free cyber risk score includes a "data and AI" domain (18 questions, 10 minutes), and the AI Risk Engine module of the FortaRisks platform turns this kind of register into continuous risk tracking.