Shadow AI Assessment: Find What You Do Not Know You Are Using

Employees are using AI tools on work tasks that the organisation has not approved, does not know about, and has not assessed for risk. Work data is being pasted into consumer AI tools. Vendor software has quietly added AI capabilities. Browser extensions are processing email and documents. Shadow AI is not a future risk; it is happening now, in most organisations, without visibility or control.

No vendor relationships. No commissions. Senior advisory only.


When this service becomes necessary

  • The organisation suspects employees are using AI tools that have not been approved, but has no picture of what is in use or what risk it carries.
  • A privacy, security, or compliance concern has been raised about employee use of external AI tools with work data.
  • The board or audit committee has asked what AI tools the organisation is using, and the honest answer is that it does not fully know.
  • The organisation is building an AI governance framework and needs an accurate AI inventory as the starting point.
  • An AI tool has been discovered in use that the organisation did not know about, and there is a concern that more exist.
  • A regulatory or privacy audit is approaching and demonstrable AI oversight is required.

What Evoltra reviews

  • AI tools in use without formal approval, identified through structured interviews and tool audit
  • Consumer AI tools used with work data, ChatGPT, Copilot personal, Gemini, Claude, and others
  • AI-enabled browser extensions and productivity tools
  • Vendor software with AI capabilities added without formal notification or assessment
  • Department or team-level AI tool adoption not visible to IT or risk functions
  • Data sent to external AI systems, sensitivity, volume, and contractual exposure
  • Risk classification of identified shadow AI use cases
  • Governance gaps: absence of approved alternatives, acceptable-use guidance, or oversight mechanisms

What the client receives

  • Shadow AI inventory: tools identified, use cases, and organisational spread
  • Risk assessment of identified shadow AI use cases
  • Data exposure summary: what data is being processed by unapproved tools
  • Vendor AI gap analysis: AI capabilities added to existing platforms without assessment
  • Priority risk findings with recommended immediate actions
  • Governance recommendations: approved alternatives, acceptable-use guidance, oversight
  • Executive summary for board or leadership reporting

How the engagement works

  1. 1

    Structured interviews

    Speak with people across the organisation, not just IT, about what AI tools they use on work tasks. Function leaders, team leads, and individual contributors often have different answers. The goal is an honest picture, not a compliance exercise.

  2. 2

    Tool and extension audit

    Review installed software, browser extensions, and application permissions for AI capabilities. Many shadow AI instances are tools that were already in use before AI features were added, employees may not even know the tool is now AI-enabled.

  3. 3

    Vendor AI review

    Assess enterprise software vendors for AI capabilities added to existing contracts, features that process work data through AI without explicit organisational awareness or consent.

  4. 4

    Risk classification

    Classify identified shadow AI use cases by risk, data sensitivity, external processing, vendor terms, reversibility, and accountability. Identify the use cases that require immediate action.

  5. 5

    Findings and recommendations

    Written shadow AI inventory with risk assessment and governance recommendations. Practical: including recommended approved alternatives where relevant, and the governance mechanisms needed to prevent shadow AI from accumulating again.

The review stands on its own.

Evoltra does not need to win implementation work from this engagement. Recommendations can be executed by the client's internal team, their preferred vendor, or any third party they choose.

There are no vendor relationships, referral arrangements or commissions that could influence the outcome. The advice reflects what the evidence supports, not what would be most convenient to recommend.

Who this is for

Organisations that need an honest picture of what AI tools are in use before they can govern them. The shadow AI assessment is typically the starting point for AI governance, you cannot govern what you do not know exists. Also relevant where a specific privacy, security, or compliance concern has been raised about employee AI tool use.


Related Services

Related Reading

Frequently Asked Questions

Ready to discuss?

No sales script. Initial discussion is obligation-free.