MKT · 9 tools
ENG · 11 tools
HR · 4 tools
FIN · 5 tools
SUP · 6 tools
Learn / Examples

Shadow AI examples, department by department

Shadow AI is not evenly distributed. Each department gravitates to its own tool types, feeds them its own data, and leaves its own signature in the logs. All examples generic-safe, drawn from patterns audits surface repeatedly.

See your own department map free
The anatomy

Five departments, five signatures

For each: the tool types that appear, the data at stake, and the shape of the log evidence that gives it away.

Marketing

usually the largest cluster
Typical tool types
  • Image generators and upscalers for campaign assets.
  • Copywriting and paraphrasing tools for ads and posts.
  • Video generators and avatar tools for social clips.
  • SEO and content-optimization assistants.
Data at stake
  • Unreleased product imagery and launch plans inside prompts.
  • Brand assets uploaded to tools with training-by-default tiers.
  • Customer-facing copy that may be contractually client-owned.
Log signature
Image & Visual + Video categories spike; bursts around launches; many distinct tools with few users each, the comparison-shopping pattern.

Engineering

deepest per-user usage
Typical tool types
  • Code assistants and AI-first editors.
  • Model hubs, hosted inference APIs and agent frameworks.
  • AI features inside repos, CI and observability SaaS.
Data at stake
  • Proprietary source code in consumer-tier assistants.
  • Credentials and internal hostnames pasted in debugging sessions.
  • Pipeline integrations moving data without review.
Log signature
Code & Development + Models & Infrastructure; steady daily use; api. subdomains; the tell: service accounts reaching AI hosts.

Human resources

smallest cluster, highest sensitivity
Typical tool types
  • Writing assistants for reviews, offers and difficult emails.
  • Resume screeners and interview-summary tools.
  • Transcription bots in interviews and grievance meetings.
Data at stake
  • Names, salaries, health accommodations and performance text: personal data by definition.
  • Interview recordings under two-party-consent questions.
  • Bias exposure if screening tools go unvetted.
Log signature
Low volume, few users, Text & Language + transcription; calendar-correlated spikes at review season. Small numbers, never small findings.

Finance

the spreadsheet-shaped cluster
Typical tool types
  • Data-analysis copilots fed exported spreadsheets.
  • Document summarizers for contracts and reports.
  • AI features inside BI and accounting SaaS.
Data at stake
  • Pre-announcement numbers, forecasts, board material.
  • Vendor pricing and contract terms under NDA.
  • Anything a regulator would call material non-public information.
Log signature
Data & Analytics + Search/Docs categories; month-end and quarter-end spikes; few tools, heavy repeat use by the same handful of users.

Support and sales

the customer-data cluster
Typical tool types
  • Chat assistants drafting replies from pasted tickets.
  • Call transcription and meeting bots on customer calls.
  • Translation tools for international queues.
Data at stake
  • Customer PII and account details inside pasted threads.
  • Recorded customer voices in transcription tools, consent unclear.
  • Deal terms and pricing in sales-call summaries.
Log signature
High-volume Text & Language use across many users; meeting-bot domains attending call schedules; volume tracks queue load, not calendars.

The audit's category table is this page applied to your network: each category total maps to the department that owns the conversation. The annotated report tour shows where to read it.

Cross-cutting examples

Three patterns that ignore the org chart

Some of the most consequential examples belong to no single department.

The meeting bot that attends everything

Invited once by one person, then auto-joining recurring invites across teams. Every department's confidential calls, one tool, one unclear consent state.

The founder's personal stack

Leadership's own unsanctioned tools set culture harder than any policy memo. Executive per-user rows deserve the same review, delivered with more tact.

The embedded feature wave

The CRM, the design suite and the video platform all shipped AI features after procurement approved them. Every department "uses AI" through door three without choosing to. The taxonomy lives on what is shadow AI.

Reading your own map

From example to evidence in one export

These anatomies become your network's facts in three steps.

1. Audit with identities

Export a month of DNS, proxy or firewall logs with the user or device column. The walkthrough shows where that column lives per source.

2. Map categories to owners

Each category with a real total gets the matching department head invited to the review. This page is the seating chart.

3. Compare signatures

Where your patterns differ from the anatomy, that is your finding: engineering-shaped usage in finance means something worth asking about.

The audit reads hostnames and identities, never prompt content. Uploads are discarded after each run and reports are deletable before the 90-day expiry.

See what a department map looks like finished

The sample report's category table and per-user rows are this page rendered as evidence, on sample data.

Open the sample report
Department conversations

Openers that work, per audience

The same finding lands differently per department. Openers that keep the meeting collaborative:

To marketing

"Which of these tools would you keep if we paid for proper licenses?" Consolidation framed as an upgrade, not a confiscation.

To engineering

"Which of these are load-bearing in the pipeline?" Respecting the CI integration's existence buys honesty about everything else.

To HR and finance

"Here is the training verdict on the tool the team uses for sensitive text." Terms, not blame, and the migration proposal in the same breath.

To support and sales

"The transcription bot heard 40 customer calls last month. Whose consent covers that?" A concrete number turns an abstract worry into an agenda item.

FAQ

Examples questions

Which department has the most shadow AI?

By tool count, usually marketing; by depth of use, engineering; by sensitivity per finding, HR. Your audit's category table gives your actual ranking.

Are these examples real companies?

They are generic-safe composites of patterns that recur across audits. No real organization is described, and the report you run contains only your own data.

What is the most commonly missed example?

Meeting transcription bots, because they attend rather than get used, and embedded AI features inside sanctioned SaaS, because nobody thinks of them as tools.

How do I find which departments use which tools?

Run the audit with an identity column in the export. Department prefixes in usernames or per-team subnets turn the per-user table into a department map.

Should different departments have different AI rules?

Yes, that is the point of category-level policy: image tools in marketing and code assistants in engineering deserve separate verdicts. See sanctioned vs unsanctioned.

What if a department's cluster is empty?

Verify coverage before celebrating: that department may work off-network or through an unlogged path. An empty cluster with confirmed coverage is genuinely good news.

Your org chart is already annotated in the logs

One export with identities shows which of these anatomies is yours. The free preview draws the category map today.

Run the free audit