The shadow AI tools your security team can name are not the problem. The problem is the eighteen they cannot name, most of them adopted by people just trying to do their jobs faster.
Every shadow AI audit we run starts with an estimate. We ask the security team how many AI tools are in active use across the organisation. The number we get back is usually nine to fourteen. The number we surface by Friday of week one is closer to forty.
This piece is about what week one of AI tool discovery looks like - what we find, where we find it, and why the gap between estimate and reality is consistent enough to be a structural feature of mid-market organisations rather than a discipline failure at any one firm.
When we present the week-one findings, the reaction is never what people expect. The security team gave us a list of fourteen AI tools, their best estimate of what was running across the organisation. We are showing them forty-three on Friday. Nobody argues with the number. Nobody asks us to recheck. The head of security looks at the list and starts nodding. They already knew Notion AI was there. They had heard about the Cursor accounts in engineering. They also had an idea that the marketing team was using something they had not disclosed. What they did not have was the full list confirmed in one place, with a data source behind each entry. The number was not the revelation; having it on paper was. That is the only thing week one actually reveals: not information the security team could not have guessed, but information they can now act on. - Ankur Arora, Co-Founder, Montro |
Where Shadow AI Lives - Three Pools
The footprint of shadow AI tools splits into three pools. Each requires different discovery methods, and each is invisible to the others.
The first pool is embedded AI features inside SaaS the organisation already approved. The Notion workspace your product team has used since 2022. The Slack you procured years ago. The HubSpot your marketing team has been on for three CRM cycles. Each of these tools added AI features inside the same product release that delivered the bug fixes nobody noticed. Notion AI, Slack AI, HubSpot Breeze, Microsoft Copilot, Salesforce Einstein, Atlassian Intelligence, Zendesk AI, Zoom AI Companion. The procurement record for each tool is years old. The AI inside is months old. The two are not the same product.
Gartner predicts that by 2026, more than 80% of independent software vendors will have embedded GenAI capabilities in their enterprise applications, up from less than 5% today. For a firm with a hundred or more SaaS tools in active use, that puts the embedded-AI population at sixty-plus tools the security team did not separately classify when the AI feature went live.
The second pool is free-tier individual subscriptions. ChatGPT free tier. Claude.ai free tier. Perplexity. The free versions of Midjourney, ElevenLabs, Descript. GitHub Copilot personal accounts. These tools cost the firm nothing, which means they leave no trace in the finance system. They use personal credentials, which means they leave no trace in the SSO. They live in browser sessions and on phones. The only place they show up reliably is in the work that gets produced, the marketing copy that has the unmistakable AI cadence, the code commit with a Cursor signature, the email with the GPT-shaped opener.
The third pool is evaluation creep. A team starts evaluating a new AI tool. The evaluation extends. Three months later the tool is processing customer data in production. A purchase order eventually appears, or it does not. The transition from evaluation to production is rarely a deliberate decision; it is what happens when the alternative - going through procurement to formalise the tool, is more friction than just continuing to use what already works.
What Week One Looks Like
The structured method runs across four data layers in parallel. Each layer surfaces a different slice of the population, and the overlaps between layers are smaller than people assume.
Day one is identity and SSO. The Okta logs, the Microsoft Entra ID directory, the Google Workspace admin records. This finds the sanctioned tools and most paid shadow tools. It typically captures around half of the active tool population.
Days two and three are email and calendar metadata. Every SaaS sends transactional email. Every account creation produces a confirmation message. Every AI tool's onboarding flow creates a verifiable trace. Mining email patterns surfaces tools the SSO does not - the personal-account adoption, the magic-link tools, the products procured by team budget but never federated.
Day three through five is the finance and procurement layer. Expense management exports, accounts payable records, corporate card statements. This catches the paid shadow SaaS that someone in marketing put on a personal card and expensed, the team-budgeted devtools that never crossed central procurement, the auto-renewing subscriptions for tools nobody currently owns.
By Friday, the picture is roughly complete. Endpoint and browser telemetry, where consent and configuration permit, fills in the free-tier pool that the other layers cannot see. The composite finding for a 600-employee firm is typically eighteen to twenty-eight distinct shadow AI tools across six or more departments, a population two-and-a-half to three times the security team's day-one estimate. This is why structured AI tool discovery across all four data layers is the only method that reliably closes the gap.
Where Shadow AI Concentrates By Department
The departmental distribution is consistent enough across audits to be predictive.
Marketing carries the largest single-department footprint. The typical stack: Jasper or Copy.ai for written content, Midjourney or Adobe Firefly for image generation, ElevenLabs or Murf for voice, Descript for podcast and video editing, Canva's AI features for design. Marketing teams are also the most likely to be using free-tier ChatGPT for brainstorming, drafting, and competitor analysis.
HR is concentrated but smaller. Phenom, Eightfold, HireVue, Paradox AI, and Loxo cover most of the recruiting tooling - almost all of which now includes AI-driven candidate matching, screening, or assessment that puts the tool into Annex III high-risk territory under the EU AI Act. The pattern: one or two of these tools are central to the recruiting workflow, and were procured before AI features became the headline.
Engineering uses Cursor, GitHub Copilot (often through personal accounts even where the firm has an enterprise plan), Tabnine, and Codeium. Engineering shadow AI is the easiest to find because it leaves traces in code commits, but the hardest to remediate because the tools are deeply integrated into developer workflows and bans drive usage further underground rather than reducing it.
Finance is more concentrated than people expect. ChatGPT free tier for analysis and summarisation. Hebbia or Numerade for document review. Anchor for financial modelling. The exposure is high because the data being processed includes unaudited financials, M&A pipelines, and personnel decisions.
Customer support runs Forethought, Ada, Cresta, or Intercom Fin for AI-driven response generation and sentiment analysis. Most of these tools sit in Article 50 transparency territory under the EU AI Act and trigger GDPR considerations around the processing of customer communications.
Legal has been slower to adopt but is moving fast. Harvey, CoCounsel, and Spellbook for document review and drafting. Legal-team shadow AI is small in tool count but high in sensitivity because of the data type.
Why Employees Adopt These Tools
Naming the pattern matters because it shapes the response.
Shadow AI adoption is not a discipline failure. It is the rational behaviour of people working under time pressure, with peers using the same tools, where the firm has not provided a sanctioned alternative, and where the friction of getting one approved through formal procurement exceeds the friction of just adopting the tool quietly. Every firm that has tried to ban shadow AI has discovered, six weeks in, that usage moved to phones and personal devices. The ban removed visibility, not usage. Gartner's November 2025 research of 302 cybersecurity leaders puts a number on the scale of the problem this creates - 69% of organisations already suspect or have evidence of employees using prohibited public GenAI tools - and the practitioner consensus building around that data points the same direction: governance and approved alternatives are the interventions that hold, not blanket bans.
The framing that works internally: the procurement system was designed for a buying pattern that no longer matches how software is adopted. Fixing the procurement layer is harder than running discovery, but it is the only intervention that holds. Until then, structured AI tool discovery and proportionate shadow AI governance is the working compromise.
The First Three Things To Do Once You Know
Discovery is the start, not the end. The structured next steps:
- Classify each tool by risk. The EU AI Act tiers - prohibited, high-risk, limited-risk, minimal-risk, applied honestly across the inventory as part of a structured AI risk assessment. Most tools resolve as limited-risk Article 50 transparency or minimal-risk; a small but material subset resolve as high-risk under Annex III, particularly the HR and customer-decisioning tools.
- Map regulatory obligations across the four EU regimes. The same shadow AI tool typically generates GDPR processor obligations, EU AI Act deployer obligations, where applicable DORA register obligations, and NIS2 supply chain considerations. The cross-mapping is the leverage point - done once, the operational layer serves all four regimes.
- Build the renewal-cycle and exception register before the next quarter. Tools that cannot yet be brought into governance are tracked as exceptions with a remediation date. Tools approaching renewal are reviewed against the new classification before the auto-renewal hits.
The output at thirty days is an audit-ready inventory and classification register, the foundation of a credible shadow AI governance programme. Not a complete governance programme, that is a longer build, but the point at which the board question becomes answerable: how many AI tools do we have, what are they doing, and what regulatory regimes do they cross.
Frequently Asked Questions
How many shadow AI tools does the average mid-market organisation actually have?
More than the security team estimates, usually by a factor of two to three. When we ask before running a discovery audit, the number we hear is nine to fourteen. The number we surface by Friday of week one is closer to forty. For a 600-employee organisation, the composite finding from Montro discovery audits across European mid-market firms (2024–2025) is typically between eighteen to twenty-eight distinct shadow AI tools across six or more departments. The gap is not a discipline failure at any one firm. It is a structural feature of how AI tools are adopted, across three separate pools that each require different discovery methods to surface.
Why can't standard SSO and financial data find all the shadow AI tools?
Because each of the three pools of shadow AI leaves traces in different systems, and no single system sees all three. Identity and SSO data surfaces sanctioned tools and most paid shadow tools, but typically captures around half the active population. Free-tier tools - ChatGPT, Claude.ai, Perplexity, personal GitHub Copilot accounts, use personal credentials and cost nothing, leaving no trace in either the SSO or the finance system. Embedded AI features inside already-approved SaaS tools are missed entirely because the procurement record predates the AI feature by months or years. A structured AI tool discovery audit runs all four data layers in parallel - identity, email metadata, finance, and endpoint telemetry - because no single layer sees the full picture.
What makes shadow AI harder to discover than shadow IT?
One pool of shadow AI leaves no financial trace and no identity trace, making it invisible to the methods standard SaaS management tools were built around. Shadow IT discovery assumes unauthorised software, something expensed on a card or signed up to with a corporate email. SSO discovery and financial data mining catch most of it. Shadow AI's free-tier pool - ChatGPT, Claude.ai, Perplexity - is accessed through personal accounts at no cost to the firm, with no corporate credential involved. A second pool is embedded AI inside already-approved tools, which does not look like shadow IT at all because the procurement record is years old and the AI feature arrived in a product update. Standard discovery tools were not built to track AI feature adoption inside products that are already sanctioned.





