The board wants a clear answer to a simple question: what AI tools are our people using, and what risk does that create? A shadow AI audit produces the inventory, the risk scores and the trend data that fit a committee pack in a single page.
"What AI tools are our people using, do we know what happens to the data, and what are we doing about it?" Boards that previously delegated technology risk to IT are now asking directly. The question appears in committee packs, annual risk reviews and pre-meeting briefings.
Most organisations cannot produce a list of AI tools their staff use. IT approved a handful. Staff adopted dozens more. The gap between "sanctioned" and "actual" is the risk the committee needs to quantify.
Every AI tool that accepts text input is a potential data channel. Sales pastes customer data. Legal uploads contracts. Finance runs models. The vendor's training terms determine whether that data becomes part of a public model.
The EU AI Act requires an inventory of AI systems. SEC guidance expects AI risk disclosure. DORA mandates ICT risk registers that include AI. The committee needs evidence the organisation is meeting these obligations.
The average organisation discovers 3 to 5 times more AI tools than management expected. The gap is where reputational, regulatory and data risk accumulates. See current statistics.
A shadow AI audit translates raw network logs into structured, board-level intelligence. Every data point below comes from a single log export.
Total number of distinct AI tools accessed by the organisation. Broken down by category: LLMs, code assistants, image generators, transcription, writing, translation, research and more.
Percentage of AI tools that are on the approved list versus those adopted without approval. This single number tells the committee how effective the current governance is.
How many tools are high, medium and low risk across 13 factors: data sovereignty, training defaults, opt-out availability, enterprise tiers, abusive-purpose flags and more.
Run the audit quarterly and compare results. Is the unsanctioned count rising or falling? Are high-risk tools being replaced by approved alternatives? The trend is the story the committee needs.
Take the audit output and structure it for board consumption. Here is the format risk teams use to present shadow AI findings.
| Total AI tools detected | 47 |
| Sanctioned | 8 (17%) |
| Unsanctioned | 39 (83%) |
| High risk (training on data) | 11 |
| Data sovereignty flags | 4 |
| Users accessing AI tools | 312 / 2,200 |
| Tool | Risk | Users |
|---|---|---|
| ChatGPT (free tier) | High | 187 |
| Otter.ai | High | 43 |
| Midjourney | High | 28 |
| DeepSeek | High | 15 |
Lead with the single most important number: the ratio of unsanctioned to sanctioned AI tools. "83% of AI tools in use were adopted without IT or legal approval." That sentence carries the meeting.
Identify the 3 to 5 tools that pose the highest risk: those with the most users and the worst training terms. The committee needs to know where the exposure is concentrated, not a list of 47 tools.
If this is not the first audit, show the quarter-over-quarter change. Is the unsanctioned percentage dropping? Are high-risk tools being replaced? The trend tells the committee whether controls are working.
Close with two or three specific actions: deploy an AI acceptable-use policy, block the highest-risk tools, schedule the next audit. Give the committee something to approve, not just something to worry about.
Shadow AI creates exposure across multiple risk categories. Each one maps directly to entries the committee already tracks.
| Risk Category | Shadow AI Exposure | Report Evidence | Severity |
|---|---|---|---|
| Data privacy | Staff input confidential data into AI tools that train on inputs by default | Training-verdict flags per tool, user count per tool | High |
| Regulatory compliance | AI inventory obligations unmet (EU AI Act, GDPR Art 30, DORA) | Complete tool list with categories for mandatory registers | High |
| Intellectual property | Proprietary code, designs or strategies entered into generative AI tools | Code-assistant and LLM usage by department | High |
| Vendor risk | Dozens of unvetted AI vendors processing company data | Vendor names, data sovereignty flags, terms summary | Medium |
| Operational risk | Business processes depend on tools that could change terms or disappear | Tool category and usage volume per department | Medium |
| Reputational risk | A data breach via an unapproved AI tool becomes a headline | High-risk tool count and user exposure metrics | Medium |
| Financial risk | Uncontrolled AI spend across departments, duplicate subscriptions | Tool count and category overlap analysis | Medium |
For the full breakdown of shadow AI risks, see Shadow AI Risks: The Complete Guide. For specific examples, see Shadow AI Examples.
The audit report is the foundation for a governance framework the committee can oversee. Here is the four-quarter build-out.
Run the first shadow AI audit to establish the baseline. Present findings to the committee. Approve budget for an AI acceptable-use policy and blocking rules.
Deploy the acceptable-use policy. We provide default allow/block rules across 20,399+ AI tools. Run the second audit to measure adoption versus the new baseline.
Implement blocking for high-risk tools. Audit again to verify enforcement. Present the before/after comparison to the committee: which tools disappeared, which persist.
Annual review. Present the full-year trend: starting count, policy effect, enforcement effect, residual risk. Recommend the cycle for next year. The committee has a governance story, not a one-time finding.
Need to build the policy fast? We have prepared optimised default allow, block and monitor rules across 20,399+ AI tools. Set them in minutes, not months. See plans.
Be prepared for these follow-ups when presenting shadow AI findings to the board or risk committee.
Most organisations of similar size and industry discover 30 to 60 AI tools. The sanctioned percentage is typically 15 to 25%. If your numbers are higher, the risk posture is worse than average. If lower, your controls are working.
Frame it as data-breach cost multiplied by the number of high-risk tools with active users. If 11 tools train on input data and 187 users are active on the highest-risk one, the exposure is concentrated. The report quantifies both sides.
Blocking without a sanctioned alternative drives tools underground (personal devices, mobile hotspots). The report identifies what to block (high risk, no enterprise tier) and what to approve with controls (enterprise tier, opt-out confirmed). Detect before you block.
Policy deployment: 2 to 4 weeks. Blocking rules: 1 to 2 weeks after policy approval. First enforcement audit: 30 days after blocking. The four-quarter governance framework above is the realistic timeline for mature AI risk management.
CISO owns the technical controls. Legal owns the policy. Compliance owns the register. The risk committee oversees. The shadow AI audit provides the shared evidence base all four functions need.
SEC guidance increasingly expects AI risk disclosure in 10-K filings. The EU AI Act requires registration of high-risk AI systems. Having the audit evidence demonstrates the organisation identified and is managing the risk. Not having it creates disclosure risk.
Shadow AI from the security leadership perspective: detection, policy, enforcement and reporting to the board.
How to build shadow AI into the ITGC audit programme with workpaper-ready evidence.
Setting up a recurring audit cadence that produces comparable trend data for the committee.
Sector-specific shadow AI risk for banks, asset managers and insurance firms.
Ask IT to export DNS, proxy or firewall logs for the past 14 to 30 days. Most DNS filters (Cisco Umbrella, Cloudflare Gateway, NextDNS) have a one-click export. The file typically contains timestamps, source IPs or usernames, and queried domains.
No. The log export is read once during processing and discarded. Only the resulting report is stored in your account for 90 days. The report contains tool names, risk flags and user mappings, not raw log data.
Quarterly aligns with most committee meeting cycles. Run the audit one to two weeks before the committee meeting to allow time for analysis and pack preparation. The 5-report pack at $299 covers a full annual cycle.
The report provides your organisation's numbers. Based on our data, most organisations discover 30 to 60 AI tools with 15 to 25% sanctioned. Financial services tend to be lower (stricter controls), technology companies higher (more adoption).
Start with quarterly audits to establish the baseline and trend. Monthly plans from $99/mo are available for organisations that want more frequent visibility. The MSP plan at $249/mo supports multi-entity reporting.
No. A single report costs $99 and takes minutes. Run it, prepare the one-page summary and present it to the committee. The evidence makes the case for the governance programme better than any proposal deck.
One log export. One scan. A board-ready AI risk summary with tool counts, risk distribution, training verdicts and trend data.