
How to Detect Shadow AI in Your Organisation | CIQ Cloud
How Can an Organisation Detect Shadow AI?
AI adoption is happening faster than most organisations can govern it.
An employee can start using a generative AI service from a browser in seconds. A developer can connect an application to an external AI API. Someone can install a local Large Language Model (LLM) on a powerful laptop, while another department might adopt an AI-enabled SaaS application without involving IT at all.
This creates a fundamental problem:
How do you govern AI if you don't know where it is being used?
Detecting Shadow AI isn't as simple as deploying a single discovery tool. Different types of AI leave different technical footprints, which means organisations need to combine information from endpoints, networks, browsers, identity systems and cloud platforms.
The objective is to gradually close the gap between the AI an organisation thinks it uses and the AI that is actually being used.
What Is Shadow AI?
Shadow AI is the use of artificial intelligence technologies outside an organisation's established approval, management or governance processes.
It might be an employee using a public AI chatbot with their corporate data. It could be a developer experimenting with an external model API, a user running an LLM locally, or a department connecting an AI-powered SaaS service to Microsoft 365.
Shadow AI isn't necessarily malicious.
In many cases employees are simply looking for better ways to work.
The problem is that when IT doesn't know the technology exists, it cannot determine what information is being processed, whether the service is appropriate, what security controls apply or whether the organisation is accumulating unnecessary risk and cost.
Before Shadow AI can be governed, it first has to be discovered.
What Are the Signs of Shadow AI?
Shadow AI rarely identifies itself neatly as "Shadow AI".
Instead, organisations need to look for indicators of AI activity.
An unfamiliar AI application appearing across several laptops is one indicator. Regular connections to a generative AI website are another. An unexpected OAuth application requesting access to corporate files might provide another clue.
Other signals could include new AI SDKs on developer machines, connections to model-provider APIs, local LLM runtimes, unexplained AI expenditure or previously unknown AI agents communicating with external services.
Individually these signals don't necessarily prove that inappropriate AI use is taking place.
Together they begin to reveal the organisation's real AI estate.
1. Start with Your Endpoint Inventory
One of the easiest places to start looking for Shadow AI is information the organisation may already collect.
Endpoint management, IT Asset Management, RMM and device-management platforms commonly maintain inventories of software installed across managed devices.
The important change is to stop looking at that information purely as a software inventory and begin interpreting it from an AI perspective.
For example, an inventory might reveal:
Local LLM runtimes capable of downloading and running models directly on a workstation.
AI desktop applications providing access to generative AI services.
AI coding assistants and development tools being used by developers.
Model-management tools, frameworks and SDKs indicating AI development or experimentation.
An application that previously appeared to be just another software record can therefore become an important AI discovery signal.
This approach is particularly valuable for local AI.
Once an LLM has been downloaded, it may operate almost entirely on the device. Network monitoring alone could therefore miss much of its subsequent activity.
2. Look at Network, DNS and Web Traffic
Many other forms of AI leave a network footprint.
Employees accessing browser-based AI services, applications communicating with AI APIs and agents communicating with external models all potentially generate traffic that can be detected.
Firewalls, secure web gateways, DNS monitoring, proxies and endpoint network telemetry can therefore provide another important discovery layer.
The practical question isn't simply:
"Has anyone connected to an AI website?"
It is:
"Who connected to it, from which device, how frequently and is this expected?"
Suppose an organisation suddenly sees connections to a previously unknown AI service from 60 endpoints.
That doesn't automatically mean there is a security incident. But it does provide an important signal that something has changed within the AI estate and deserves investigation.
Traffic volumes can provide additional context. Occasional access may represent experimentation, whereas regular connections or significant data transfers could indicate that an AI service has become embedded within a business process.
Microsoft, for example, now provides Shadow AI discovery capabilities through Global Secure Access designed to identify access to generative AI applications and AI model providers from network traffic.
Network visibility, however, isn't enough on its own.
A locally running LLM may generate very little external traffic. An employee using a personal device and mobile connection could bypass the corporate network completely.
3. Don't Forget Browser-Based AI
Browser AI represents one of the most challenging areas of Shadow AI.
There may be nothing to install.
An employee can simply visit ChatGPT, Claude, Gemini or one of the rapidly growing number of specialist AI services.
Web security and network telemetry can help identify this activity, particularly where access can be associated with individual users and devices.
The real value comes from monitoring patterns and changes rather than simply maintaining a blacklist of AI websites.
If five people occasionally access a new AI service, that might represent experimentation.
If 150 people across several departments suddenly begin accessing it regularly, that tells you something very different.
Shadow AI detection requires Operational Visibility and therefore needs to become continuous rather than a one-off audit.
4. Examine Identity and OAuth Connections
Another useful source of Shadow AI evidence is the organisation's identity platform.
AI applications increasingly integrate with Microsoft 365, Google Workspace, GitHub, Salesforce and other business platforms using OAuth.
Reviewing enterprise applications, OAuth consent and third-party integrations can reveal services that have been given access to organisational information.
An unknown AI application that has permission to access email, documents or corporate data is considerably more interesting from a governance perspective than an employee simply visiting an AI website.
This changes the question from:
"Which AI applications have employees installed?"
to:
"Which AI services have been granted access to our organisation?"
That is an important distinction.
5. Look at Developer and API Activity
Developers create a different Shadow AI detection challenge.
They may never install a recognisable AI application or visit a public chatbot.
Instead, AI might be consumed directly through an API.
Useful indicators can therefore include connections to AI provider endpoints, AI SDKs and development libraries, CI/CD activity, cloud workloads, containers and environment configurations.
Organisations that have approved specific AI providers can also compare actual network and development activity against those approved platforms.
If the organisation has standardised on two AI providers but developers are communicating with six, there is clearly something worth investigating.
This is also where traditional software inventory becomes less effective.
An application running in a container, virtual machine or cloud function may not appear in the inventory of the physical endpoint used by the developer.
Again, another detection layer is required.
6. Look for Local LLMs and AI Agents
Local AI deserves particular attention because modern computers increasingly have enough processing power to run sophisticated models directly on the endpoint.
Local LLM runtimes and model-management applications can therefore be valuable indicators of Shadow AI.
Their presence doesn't prove that inappropriate activity is taking place.
It does, however, tell the organisation that a device potentially has the ability to execute AI models locally.
AI agents add another dimension.
Instead of an employee interacting directly with a chatbot, an agent may autonomously communicate with applications, APIs, models and external services.
As agentic AI becomes more widely adopted, organisations will increasingly need to answer not only:
"Which AI applications are our employees using?"
but also:
"Which AI agents are operating inside our environment, and what are they doing?"
Where Are the Shadow AI Detection Gaps?
The challenge becomes clearer when the different detection methods are compared.
No single technology sees everything.
This is why a layered approach matters.
Endpoint visibility can find things the network cannot. Network monitoring can find things endpoint inventory cannot. Identity reveals relationships that neither may understand, while provider monitoring explains what is happening inside known AI environments.
There will still be blind spots.
The objective isn't necessarily to achieve a theoretically perfect inventory of every AI interaction.
It is to continuously reduce the unknown portion of the AI estate.

How CIQ Cloud Helps Detect Shadow AI
This is where CIQ Cloud's approach to AI Estate Discovery fits into the wider picture.
CIQ Cloud can use available endpoint and asset information to identify technologies associated with AI across managed devices.
Instead of simply presenting another software inventory, the objective is to interpret that information through an AI-specific discovery layer.
For example, discovering a local LLM runtime on a workstation is more significant than simply knowing that another application has been installed.
It tells you that the device potentially has local AI capabilities.
Similarly, discovering AI development tools across machines that aren't expected to be involved in AI development may justify further investigation.
CIQ Cloud can therefore help organisations answer questions such as:
Where are AI technologies appearing across our endpoints?
Which devices have local AI capabilities?
Which AI tools are beginning to appear across the estate?
Is the technology expected and approved?
What has changed since we last looked?
The result is an increasingly useful AI Estate Inventory.
Importantly, CIQ Cloud should be considered one detection layer rather than a claim to see every possible instance of Shadow AI.
Browser-only usage, applications hidden inside containers or virtual machines, unmanaged devices and services accessed through personal accounts may require additional sources of visibility.
Combining these sources provides a much stronger picture, providing a view of Shadow AI and reducing AI Sprawl.
Discovery Is Only the Beginning
Finding Shadow AI isn't the ultimate objective.
Once something has been discovered, the organisation needs to understand it.
Suppose CIQ Cloud identifies a local LLM runtime appearing on 25 engineering laptops.
The immediate reaction shouldn't necessarily be to remove it.
Instead, investigate.
Why are the developers using it? What models are they running? What business problem are they solving? Is corporate information being processed? Is there already an approved alternative? Could this technology itself become an approved solution?
Shadow AI discovery can reveal risk.
But it can also reveal innovation that the organisation didn't previously know was happening.
Effective AI governance should therefore provide control without automatically preventing experimentation.
Monitor the AI You Already Know About
There is another important part of the AI visibility problem.
Not all unmanaged AI activity happens outside approved platforms.
An organisation may have an approved OpenAI environment while individual projects, API keys, models and expenditure grow without sufficient central oversight.
CIQ Cloud's AI monitoring capabilities complement AI Estate Discovery by providing visibility into supported AI environments.
That creates two complementary questions.
AI Discovery:
"What AI exists that we may not already know about?"
AI Monitoring:
"What is happening inside the AI environments we do know about?"
Together they provide a much stronger foundation for AI governance.
From Shadow AI Detection to Continuous AI Governance
A one-off Shadow AI audit has limited value because the AI landscape changes so quickly.
New applications appear. Employees experiment with new services. Developers adopt different models. AI capabilities are added to existing SaaS applications.
Organisations therefore need to move from periodic discovery towards continuous AI visibility.
This fits naturally into the CIQ Cloud Operational Visibility lifecycle:
Discover → Monitor → Understand → Govern → Optimise

Discover where AI technologies are appearing.
Monitor how usage and the AI estate change.
Understand what the technology is, who is using it and why.
Govern whether it should be approved, restricted, investigated or removed.
Optimise the resulting AI estate to reduce risk, unnecessary duplication and cost.
And then repeat the process.
Because tomorrow's Shadow AI may be a product that didn't exist when today's audit was performed.
Shadow AI Is Ultimately a Visibility Problem
Organisations are unlikely to stop employees experimenting with artificial intelligence.
Nor should stopping AI adoption necessarily be the objective.
The challenge is allowing AI adoption and innovation without losing organisational visibility and control.
That starts by using the information already available across endpoints, networks, browsers, identities, cloud platforms and AI providers to look for signs of AI activity.
CIQ Cloud contributes to that process by providing AI-specific discovery across available endpoint and asset information, alongside monitoring of supported AI platforms.
No single source will reveal everything.
But every additional source helps close the gap between the AI an organisation thinks it has and the AI that is actually being used.
Because before an organisation can govern AI, it needs to answer a much more fundamental question:
Can we see it?



