Resource
Shadow AI: finding the AI you have not governed
Almost every organisation underestimates its AI estate, and the gap is rarely deliberate. Most of it arrives through vendor features and everyday tooling that never triggered a governance event.
Three sources, one problem
- Staff use of public AI tools for real work, outside any approval
- AI features enabled inside software the organisation already approved
- Internally built models, scripts and pipelines never registered
- Consultant or agency deliverables produced with AI assistance
- Pilots that quietly became business-critical
- Acquired systems inherited without an AI inventory
Why the register is always shorter than reality
Registers are populated by events: a procurement, a project, a change request. Embedded AI does not create an event. A vendor ships a feature, a toggle is switched on, and AI begins influencing decisions inside a system that was assessed before the capability existed.
The consequence is a governance record that is accurate about what it contains and silent about everything it never saw.
Discover from artefacts, not from surveillance
The practical starting point is the material the organisation already holds: vendor contracts and schedules, security questionnaires, data protection assessments, architecture and integration records, project documentation and process descriptions.
AIRAS Cloud extracts text and lineage from uploaded documents server-side and applies contextual analysis to identify candidate AI systems, with the supporting excerpt shown next to each candidate so a reviewer can confirm or dismiss it. Nothing is asserted without the passage it came from.
Treat every finding as a candidate, not a conclusion
Discovery that over-reports is as damaging as discovery that under-reports, because reviewers stop trusting the queue. Candidates arrive with confidence indicators, the evidence excerpt, the source document and a clear dismissal path with a recorded reason.
False-positive suppression matters: a document that merely mentions artificial intelligence in a marketing sentence is not evidence of an AI system in use.
Convert findings into governed entries
The value of discovery is realised at the hand-off. A confirmed candidate becomes a register entry with owners, then flows through qualification, assessment, controls, review and decision on the same path as any other AI system.
Every reviewer action — confirm, dismiss, reopen, promote — is written to an append-only audit record, so the organisation can show how its inventory reached its current state.
Frequently asked questions
- What is shadow AI?
- Shadow AI is any use of artificial intelligence inside an organisation that is not recorded in the AI register or subject to governance. It includes staff use of public AI tools, AI features switched on inside approved vendor software, and internally built models or scripts that were never registered.
- Why is embedded vendor AI the largest source of shadow AI?
- Because it arrives through software the organisation already approved. A feature update can add summarisation, scoring or automated drafting to a tool that was assessed before those capabilities existed, so the AI enters production without any new procurement or governance event.
- How do you discover shadow AI without surveillance?
- Start with artefacts the organisation already holds — contracts, vendor documentation, DPIAs, architecture records, project material and process documents — and analyse them for AI indicators. This finds documented AI use and its lineage without monitoring individual employees.
- What should happen when shadow AI is found?
- Register it, assign owners, qualify whether it is in scope, assess it against the standard criteria, and decide: permit with controls, permit with conditions, or discontinue. Discovery without a decision path simply produces a longer list.
Find out how large your AI estate really is
A structured discovery exercise on documentation you already hold, producing a reviewed candidate list and a governed register.
No pricing commitment. No confidential information required.