Shadow AI Statistics Are Scary. Your Own Logs Are Scarier

A woman security analyst shining a glowing flashlight that reveals hidden glowing footprints across the floor while a friendly robot assistant holds

Every few weeks another shadow AI survey announces what share of employees use AI tools their employer hasn’t approved, and how much risk that creates. The numbers are usually alarming, and they make good slides. But you can’t act on someone else’s survey. It doesn’t tell you which of your departments are involved, which tools they’re using, or whether customer data is going with them.

Your own logs can. They show which AI services your people reach, how often, from which parts of the organization, and in some cases how much data is being sent. In my experience they’re more unsettling than any survey, precisely because they’re specific: this team, this tool, this volume, last Tuesday. Measuring your own shadow AI risk takes about two hours with data you already collect, and the result is far more useful than a statistic.

Why your logs beat any survey

  • They’re about you. Not an industry average, but your people and your tools.
  • They show where to act. Which departments, which services, which kinds of use.
  • They show exposure, not just use. Uploads and connected apps matter more than page visits.
  • They give you a baseline. Once you publish a policy and an approved tool, the same logs show whether unapproved use is falling.

Where the evidence lives

  1. DNS logs. Your DNS resolver or filtering service records which domains devices look up. Good for a broad picture of which AI services are in use and how often.
  2. Web proxy or secure web gateway logs. More detail: which users, which services, and often how much data was sent. Large outbound transfers to an AI service are a sign of documents being uploaded.
  3. SaaS discovery tools. Many cloud access security and secure web gateway products classify generative AI applications as their own category and assign risk ratings. If you have one, this is the fastest starting point.
  4. Identity logs and app consent grants. Sign-ins to AI services with corporate accounts, and third-party AI apps that users have authorized to access mail, files, or calendars. These are often the highest-risk findings, because they’re persistent access rather than one-off visits.
  5. Endpoint inventory. AI desktop applications and browser extensions installed on company devices.
  6. Expense and procurement records. AI subscriptions paid for by individuals and claimed as expenses.

Building your list of AI services

You need a list of AI services to search for. Start with the obvious general assistants, such as chatgpt.com, claude.ai, gemini.google.com, perplexity.ai, and copilot.microsoft.com, then add categories: meeting note-takers, writing assistants, image generators, coding assistants, and document tools. If your security tools maintain a generative AI category, use it rather than building your own. Whichever way you build it, the list will be incomplete, and new tools appear constantly, so review it every quarter.

The asset: a two-hour shadow AI log audit

  1. Pull 30 days of logs from DNS and your web proxy, filtered to your AI service list. (20 minutes)
  2. Count unique users per service, and group them by department. Separate approved tools from unapproved ones. (20 minutes)
  3. Flag likely uploads: sessions with large outbound data volumes to AI services, grouped by service and department. (20 minutes)
  4. Review app consent grants for AI applications, noting what each is allowed to access: mail, files, calendars. (20 minutes)
  5. Check endpoints for AI desktop apps and browser extensions. (15 minutes)
  6. Search expense records for AI subscriptions. (10 minutes)
  7. Write a one-page summary. (15 minutes)

The one-page summary

  • Number of people using unapproved AI services in the last 30 days.
  • The top five services by users.
  • The departments with the heaviest use.
  • Evidence of uploads, by department.
  • AI apps with access to corporate mail, files, or calendars.
  • Three recommended actions, each with an owner.

The findings I see most often

Every organization is different, but first audits tend to turn up the same handful of things. Several general-purpose AI assistants in use, not just one. Meeting note-takers connected to people’s calendars, often with access to far more than meetings. Heavy use in sales and marketing, where the work is writing. Uploads from finance or HR, which is where the real exposure usually sits. And a scattering of browser extensions that read every page their users visit. None of these findings is a scandal. Together, they’re the most persuasive case you’ll have for an approved tool and a clear policy.

What your logs can’t see

Be honest about the limits, especially when you present results. Personal phones on mobile data are invisible to your network logs. Without TLS inspection, proxy logs show which service was used but not what was sent. AI features inside approved SaaS applications won’t show up as separate services at all. So your logs undercount. That’s worth saying explicitly: the real number is higher than what you found, which strengthens rather than weakens the case for acting.

Do it for insight, not punishment

The goal is to understand demand and reduce risk, not to discipline individuals. Report results in aggregate, by department and service. If the first audit leads to punishment, people will simply move their AI use to personal devices, where you can’t see it at all. Tell employees that use of AI services is monitored; that notice belongs in your AI acceptable use policy, and it tends to change behavior on its own. Some jurisdictions have specific requirements for notifying employees about electronic monitoring, so check with HR or legal before you start.

What to do with the results

Heavy use of unapproved AI is a demand signal as much as a risk. People are telling you what they need. The response that works is to offer an approved alternative first, then warn about or block unapproved services, not the other way round. The sequence is in the shadow AI policy your IT team actually needs, and consumer AI vs. enterprise AI covers choosing the approved tool. Revoke risky app consent grants immediately and restrict who can grant them, as described in identity is your AI control plane. Add everything you found to your AI inventory.

Presenting the results to leadership

Lead with the demand, then the exposure, then the plan. “Most of our sales team uses a public AI assistant every week” tells leadership people want this. “Some of that use involves uploading documents” tells them why it matters. “Here’s the approved tool and policy we’ll roll out this month, and here’s how we’ll measure the change” tells them it’s under control. Show aggregate numbers only, and state the limits of what logs can see. Leaders respond better to a specific, honest picture with a plan attached than to an alarming statistic with none.

Run it again every month

The first audit is a baseline. The second one, a month after your approved tool and policy go live, shows whether they’re working. Unapproved use should fall steadily once people have a good alternative. If it doesn’t, that’s feedback about the approved tool, not a compliance failure. Report the trend to leadership each month for the first quarter; a falling line on a chart is the best evidence your AI governance is working.

Where does your team actually stand?

Shadow AI is one of the questions in the free AI Readiness Score, which uses 10 of the 24 assessment questions and gives you a score in a few minutes.

Get your free AI Readiness Score →

Want to see how shadow AI shows up in a full report? Flip through a complete 38-page sample report.

Related guides

Frequently asked questions

How do you find shadow AI use in your organization?

Check logs you already collect: DNS and web proxy logs for AI services, SaaS discovery tools that categorize generative AI apps, identity logs and app consent grants, endpoint inventories for AI apps and browser extensions, and expense records for AI subscriptions.

How long does a shadow AI log audit take?

About two hours for a first pass: pull 30 days of logs filtered to AI services, count users per service and department, flag likely uploads, review app consent grants, check endpoints and expenses, and write a one-page summary.

What can't logs show about shadow AI?

Personal phones on mobile data, the content of encrypted traffic without inspection, and AI features inside approved SaaS apps. Logs undercount real use, which strengthens rather than weakens the case for acting.

Should employees be disciplined for using unapproved AI tools?

Not on the first audit. Report results in aggregate by department and service, offer an approved alternative, and tell employees monitoring exists. If the first audit leads to punishment, use moves to personal devices where you can't see it.

Scroll to Top