Shadow AI is a visibility problem, not a discipline problem
We spent an afternoon researching the risk of twenty AI tools and found five questions with no public answer — because they aren't facts about the tool, they're facts about your own company that nobody wrote down.
We spent an afternoon in June filling in a catalog of the twenty AI tools small teams actually use — ChatGPT, Claude, Gemini, the meeting note-takers, the browser extensions that read whatever page you're on — and we couldn't answer most of the questions we had written ourselves.
The questions weren't exotic. Eight of them, per tool. Does it train on your data? Is there a DPA? Is there a SOC 2 or ISO 27001 certification? Is the retention period documented? Does it support SSO? Does it have admin controls? Does the browser extension read page content? Does it record meetings?
Three of those we could mostly answer from public documentation. Whether a tool ships a page-reading extension or records audio is a product fact, visible to anyone. Whether the consumer tier trains on your chats we could pin down for eleven of the twenty, because those vendors say so plainly.
The other five were close to a shutout. Data retention: zero of twenty. DPA available: zero. Certifications: zero. SSO and admin controls: one each.
The reason those questions have no answer is the actual story
Our first read was the cynical one — vendors are vague on purpose. That's not really it. The honest reason is duller and much worse for the reader: those answers aren't properties of the tool. Whether there's a DPA covering your usage depends on whether someone at your company signed one. Whether training is off depends on which tier that person is on. Whether SSO exists depends on the plan, and whether admin controls apply depends on whether the account is a company account at all — or someone's personal one, opened in a hurry on a Tuesday, now holding a client's contract.
So the fact we needed wasn't "what does OpenAI do." It was "which of the four ChatGPT tiers is my team on, and who's on which." That's not a research problem. That's a question about your own company that you either have written down or you don't.
And almost nobody does. One 2026 small-business AI adoption survey puts it at roughly 77% of AI-using small businesses with no written AI policy at all — no approved-tools list, no data rules, no owner. Not a weak policy. None.
The numbers make this look like a people problem. Look closer.
UpGuard's State of Shadow AI found 81% of employees report using AI tools their company never approved, and fewer than one in five stick to approved tools only. The number we keep coming back to from that survey is a different one: security leaders were the worst offenders, at 88%.
That detail kills the discipline framing on its own. When the people who write the rule are more likely than anyone to break it, you're not looking at a compliance failure among the rank and file. You're looking at a tool everyone finds useful and an organisation with nowhere to put it. The behaviour is rational. The absence of a list is the defect.
Which is why the reflexive fix makes things worse. Ban a tool and about 46% of employees say they'd keep using it anyway. Think about what that trade actually does to your risk position. Before the ban, you had a tool you knew about, could set rules for, and could put on a list. After it, you have the same tool, used on a personal account, invisible to you, and now with a social incentive against anyone mentioning it.
“You didn't remove the risk. You removed your ability to see it — and you taught your team that asking is punished.”
IBM's breach research puts incidents involving shadow AI at roughly $670k more expensive than average. That figure comes from organisations far larger than the ones we're writing for, and we'd be careful quoting it at a twelve-person agency as if it were their bill. The useful part isn't the number. It's the direction: the expensive incidents are the ones nobody could see coming, and invisibility is a choice your policy made.
Detection isn't the answer either, at this size
The obvious counter is: fine, so discover it automatically. Scan the SaaS estate, watch the endpoints, find the shadow tools without asking anyone.
That category exists and it's real, but it's built for companies with a security team, and it's priced for them — the enterprise governance platforms run quote-driven implementations well into five figures on top of licenses. For a small team, the cost isn't the main objection anyway. Monitoring buys you a list of tools at the price of the thing you actually need long-term, which is people telling you what they're using before they use it. If the answer to "hey, can I try this transcription tool?" is a lecture or a silent flag on a dashboard, you get one honest answer and then you get none.
We'd rather have a slightly incomplete list that people voluntarily add to than a complete one that made everyone quieter.
What a small team can actually know by Friday
Here's the part that made us feel better after the catalog afternoon. The five questions we couldn't answer are vendor questions. The ones that carry most of your real risk are internal, and you can answer all of them without a single vendor replying to you:
- Which tools are in use — ask, don't detect. Ask in a way that's safe to answer honestly.
- Who owns each one — a named person, not "the team."
- What data may and may not go into it — the only column non-technical people will actually read.
- Who decided, and when — the difference between a list and evidence.
That's a morning's work and it doesn't need a product. A shared doc gets you most of the way, and we'd genuinely rather someone left this post with a filled-in spreadsheet than a signup.
Start with the list, not the policy
Most teams do this backwards. They feel the anxiety, so they write a policy — a long one, ideally with the word "shall" in it — and then discover it's unenforceable because it refers to tools nobody has enumerated and tiers nobody has confirmed.
The list comes first. Once it exists, the policy is nearly automatic: it's the data-rules column, written out in sentences. And when a client questionnaire or an insurer eventually asks how you govern AI — the moment that turns this from background anxiety into a deadline — the list plus a record of who agreed to it is the answer. The policy on its own isn't.
We're building a small product around exactly this, ToolRoster, mostly because we got tired of the spreadsheet version going stale. It isn't public yet, and we'd be overselling it to tell you it's the reason to start. The reason to start is that the list takes a morning and the alternative is finding out what your team uses during an incident.
If you do only one thing this week: open a doc, list every AI tool you can think of that someone at your company has used, and mark the ones where you don't know what tier they're on. That column of unknowns is your actual risk register. Everything else is downstream of it.