It can include employees using public generative-AI accounts, teams calling unreviewed model APIs, locally run models, unofficial agents and AI capabilities introduced through an update to an otherwise approved software service. The activity is not necessarily malicious; the defining problem is that normal risk ownership and control processes are bypassed or absent.
Without an accurate inventory, an organization may not know what information is sent to a provider, which retention terms apply, what identities or tools an agent can use, or whether outputs influence important decisions. A practical response combines discovery with sanctioned alternatives, clear data-handling rules, education, accessible review and exception paths, and proportionate controls.
Key points
Discovery scopeLook beyond well-known chat websites to browser extensions, developer tools, SaaS features, API traffic, cloud resources, notebooks, model repositories, local runtimes, agents and automation platforms.
Triage questionsIdentify the owner, purpose, users, provider, data classes, model and region, connected systems, permissions, retention, contractual terms and whether output drives consequential action.
Risk reductionOffer approved services, apply identity and least-privilege controls, enforce data-loss protections where appropriate, monitor use, train staff and make legitimate adoption easier to register.
Important limitationDomain blocking, network monitoring, expense records and staff surveys each reveal only part of the picture; embedded, local and indirect AI use can remain invisible. An indiscriminate ban can also push useful activity further outside governance.