HD Field Guide 06
Shadow AI discovery without a witch-hunt
Find unsanctioned AI use, understand why it exists and replace risky workarounds with approved pathways.
People often adopt AI tools because they solve a real problem faster than an approved process. Discovery should reduce risk while preserving useful innovation—not punish honest experimentation.
Start with transparent questions
Use surveys, workshops and service-owner discussions to identify tools, accounts, connectors, data types and business value. Explain the purpose of discovery and how findings will be handled.
Distinguish personal experimentation from systems that process organisational data or perform business actions.
Prioritise by consequence
Highest priority usually includes confidential data, privileged connectors, public output, automated actions and tools with unclear retention or ownership. A low-risk writing assistant should not be treated the same as an autonomous agent with mailbox access.
Record ownership, approved purpose, data boundaries, supplier status and review date for each accepted tool.
Create a usable safe path
Offer approved tools, practical training and a quick assessment route for new use cases. Policies fail when the only answer is “no” and legitimate needs remain unresolved.
Measure adoption, reported concerns and repeated exceptions so controls can improve over time.
Before you close the guide
- Tool and connector inventory established
- Business purpose and data types recorded
- Risk-based approval or replacement decision made
- Owner and review date assigned
Continue with primary guidance
This guide provides general educational information. Adapt it to your organisation’s policies, contracts, legal obligations and incident process. For an active incident, use trusted professional and official support channels.