Business practice
Shadow AI exposure.
Know exactly what your team is putting into AI tools, what customer data went with it, and what to do about it this week. This shadow AI risk assessment for SaaS and AI companies takes about ninety minutes of your time and a five-question anonymous team survey.
You haven't asked your team what they're using. Not because you don't care, but because you're not sure you want the answer.
The tools arrived without a decision. Someone tried one on a deadline, it worked, and it spread: support transcripts summarized, account notes cleaned up, a contract redline checked, a stubborn bug pasted in along with the code around it. Nobody filed a request, nobody signed anything, and the first time it comes up is when an enterprise customer's security questionnaire asks whether you have a written AI policy. You suspect the honest answer, and you'd rather not put it in writing.
Two weeks from now, you're somewhere else. You know which tools are in use, who's using them, and which kinds of customer data have passed through them. You have a short list you can act on right away and one longer item that needs real work. The uncertainty is gone, and what replaces it is a decision you get to make on purpose.
The approach
Ask, map, then act.
Ask anonymously.
Nobody tells the CEO they pasted a customer's account data into a chatbot. They'll tell an anonymous survey, and they do. The gap between what leadership believes and what the team reports is the finding, and it's almost always wider than expected.
Map the data.
A tool list isn't exposure. Exposure is which kinds of information moved into which tool, under whose account, and whether that vendor trains on what it receives. That mapping turns a vague worry into a specific, finite list.
Act this week.
Every exposure review ends with three things you can do right away at no cost, and one thing that will still be there in six months if nobody owns it. Knowing the difference is most of the value.
The situation, in numbers
Allowed, but not taught.
77%
Of US desk workers say their company allows AI
32%
Say their company provides AI training
23%
Of individual contributors say they get AI training, against 50% at manager level and above
Source: BambooHR's 2025 survey of 1,502 US full-time desk workers. Figures are industry research, not client results.
Recognize this
You already know the answer to one of these.
- You couldn't name every AI tool your team uses today.
- Nobody has ever formally approved a tool, and several are clearly in use.
- A security questionnaire or your cyber renewal asked about AI, and the answer was uncomfortable.
- Someone on the support team is closing tickets noticeably faster than last year, and nobody's asked why.
- You've thought about raising it in a meeting and decided the timing was never right.
The work
Four steps, about ninety minutes of your time.
The leadership conversation
Thirty minutes with the person who signs off, usually the CEO, COO or founder. Six questions covering what you believe is in use, what data touches it, who approved it, what happens when a key person is out, where work gets redone, and what you bought this year that nobody opens.
The anonymous team survey
Five questions, two minutes to answer, sent under your name. Anonymity is the point. This is where the accurate picture comes from, and it's the half of the exercise an assumption can't replace.
The exposure map
One page, back within seventy-two hours. Tools in use against tools approved. The data at risk, from support transcripts and account data to contracts and source code. The specific places where a confidentiality clause in a customer contract and a free AI tool are currently in the same sentence.
The short list
Three things you can do this week without spending anything, and one item that needs real ownership. Useful whether or not the conversation goes any further, which is how a diagnostic should be built.
Related reading.
All insights
Governance
Shadow AI is already in your company. Here's the map
Ask a CEO how many AI tools are in use across the company and you'll usually hear about the ones on the invoice. Ask the team anonymously and the list gets longer: free chatbot accounts, browser extensions, meeting notetakers, and AI features switched on inside software you
Governance
The AI policy your insurer and your customers will ask about
Most companies meeting the AI policy question for the first time do one of three things. They answer no and hope it doesn't matter. They answer yes on the strength of a template somebody downloaded and never circulated. Or they leave it, come back to it, and eventually submit
Questions
Asked before, answered plainly.
No, and the exercise is designed so it can't. The survey is anonymous and results are reported in aggregate, never by individual. The framing to your team is that leadership is deciding which tools to support, which is true. People who fear discipline give you inaccurate answers, and inaccurate answers make the whole exercise worthless.
Then you found it before a customer's security team did, which is the whole reason to look. Serious findings come with immediate containment steps in the same report. Nothing is disclosed to anyone outside your company, and the report belongs to you. What you do with it is your call. If a finding touches a notice obligation in a customer contract or DPA, that's a question for your counsel, and we'll flag it.
The report is useful on its own, and it's yours to keep either way. Three of the four recommendations are things your team can do without us, and we tell you that in writing. If the fourth is worth working on together, we'll say so and describe what that would look like. If it isn't, we'll say that instead.
Blocking handles the managed devices you know about. It doesn't handle personal phones, home machines, browser extensions, or the AI features quietly added inside software you already license. It also does nothing about the reason people reached for the tool in the first place. Technical controls and process controls solve different halves of the problem, and it's common to have only one of them.
About ninety minutes, start to finish. That's the thirty-minute leadership conversation, about five minutes to forward the survey link (your team's part takes two minutes each), and time with the exposure map and the short list once they're back, within seventy-two hours. Everything else is on our side.