AI systems and governance

Discovery before policy

Shadow AI audit

Find unapproved AI use and build a practical remediation plan.

Start the toolEstimated: 10 minutes
Save or restore a private device draft

Work stays in this tab unless you choose to save a device copy.

Start with discovery, not surveillance.

Four stages of five checks, then a private tool inventory. The optional team survey shows aggregate findings only after five responses; private downloads do not require a survey.

Your owner assessment and tool inventory stay in this tab. Nothing you enter there is uploaded, emailed, or sent to AI. You may choose to save a seven-day copy on this device. If you explicitly create the team survey after signup, anonymous structured responses are stored for 30 days. Owner reporting begins at five responses, suppresses tool names reported by only one person, and never exposes individual answers. Use product names and broad workflow labels only. Do not enter employee names, prompts, customer records, credentials, contract details, or regulated data.

Stage 1 of 4 · 0 of 20 answered

1. Find the use

Include browser extensions, embedded AI features, automations, and paid accounts. Required before a supervised pilot.

Name the task and accountable role, not the employee who disclosed it.

Use aggregate expense review; do not ask people to expose unrelated personal purchases.

Extensions and newly added product features can gain access outside the main AI app.

Record the connection and permission scope without copying secrets into this tool. Required before a supervised pilot.

Private inventory

Map the tool, account, data, and dependency.

Risk scores are transparent triage rules, not breach predictions. Empty rows are ignored.

Tool 1
Add a product name to build the inventory
Tool and workRiskWhyNext decision

Working remediation plan

Support the work, then reduce the exposure.

First 48 hours: contain without blaming

  1. No high-risk inventory rows were entered. Verify the inventory with the team before treating this as complete.

Next 30 days: close the operating gaps

  1. No self-reported assessment gaps. Verify evidence, ownership, data terms, and offboarding in practice.

Three policy rules to write first

  1. Approved tools and data: name approved tools and uses; prohibit credentials and restricted data by default; provide a fast exception path.
  2. Company ownership and access: important work uses company-owned accounts, named roles, minimum permissions, MFA, and tested offboarding.
  3. Human review and incidents: people verify consequential output, report mistakes without blame, contain exposure, preserve evidence, and approve changes.

Complete all 20 checks and add at least one tool to download the private export and survey gate.

What this audit can · and cannot · tell you.

Shadow AI is work use of AI systems outside the organization's approved visibility or controls. This audit surfaces self-reported operating gaps. It does not scan devices, inspect employee activity, test vendors, or determine legal compliance.

The score, risk points, 75-point guide, five-response report threshold, and two-mention tool suppression are Nerd Out editorial safeguards, not official standards. Review method and policy sources semiannually. Last reviewed August 31, 2026.

How this tool works

Find useful AI work that is outside your controls, protect the data and continuity around it, and give the team a supported path forward.

  1. Complete 20 operating checks
  2. Inventory tools, accounts, data classes, and dependencies
  3. Review the remediation plan, then export or invite the team

What is shadow AI?

Shadow AI is work use of AI that sits outside the organization’s approved visibility or controls.

The useful first move is an inventory, not a ban. Ask which tool supports which task, who owns the account, what broad data class enters it, what the tool connects to, and whether the workflow stops when one person leaves. That turns a vague concern into reviewable operating decisions.

Treat disclosure as evidence that people need a better supported option. Contain credentials and restricted data quickly, but do not turn a discovery survey into employee monitoring. Approve, replace, retire, or temporarily contain each tool with an accountable owner, evidence, conditions, and a review date.

Questions owners ask

Shadow AI audit questions

What is shadow AI?

Shadow AI is business use of AI systems, features, extensions, or connected agents outside an organization’s approved visibility or controls. It can include useful work as well as unmanaged account, data, access, continuity, and review risks.

Does this audit scan employee devices or accounts?

No. It is a self-reported owner assessment and optional anonymous team survey. It does not install software, inspect browsing, connect to accounts, read prompts, or verify vendor behavior.

How is the Shadow AI risk score calculated?

The control score gives each of 20 checks zero, one, or two points. Critical gaps cannot be averaged away. Each inventory row separately receives visible points for account ownership, data class, workflow dependency, and review status. These are uncalibrated planning heuristics, not breach predictions or certification.

Is the team survey really anonymous?

The survey requests no name or email and stores no network address or analytics identity. The owner receives no result below five responses, never receives response rows, and sees a tool name only when at least two people report the same normalized name. A small-team organizer should still avoid trying to infer respondents from the aggregates.

What should we do when an unapproved tool is found?

Preserve evidence and contain restricted data, credentials, or excessive access first. Then understand the business need and choose approve, replace, retire, or a time-limited exception. Provide a supported alternative and do not make honest disclosure a performance issue.

Will Nerd Out save or email my inventory?

No. The owner assessment, tool inventory, plan, and exports are generated in the browser and are not uploaded or emailed. You can optionally save a seven-day device draft of the owner assessment and inventory. Only a team survey you explicitly create stores structured anonymous responses, and it expires after 30 days behind separate participant and owner capability links.