Skip to main content

Boardroom Answers · AI & Data · AI, Data & Analytics

Shadow AI is eating every enterprise — staff pasting data into unapproved tools. You claim to help govern it. What do you actually detect, and what is YOUR internal shadow-AI posture?

The question a Chief Automation Officer (CAO) asks.

The short answer

A real shadow-AI register: discovery from expense, SSO, network and survey sources, risk triage to block/review/sanction/monitor, and policy-gap analysis — and internally, our own AI usage is fully metered by the same cost ledger.

The full executive answer

The product ships a dedicated Shadow-AI Discovery and Policy module — it is a first-class register, not a slide. It inventories AI tools found in the organisation across realistic discovery sources — expense reports, network logs, single-sign-on logs, staff surveys, CASB or proxy data, and manual entry — and classifies each by category, from chat assistants and code copilots to meeting notetakers and agent platforms, by user count, department, and the sensitivity of data it touches. A risk-triage engine then grades each tool and recommends an action — block, review, sanction, or monitor — and a policy-coverage analysis shows where your governance documents have holes, with starter templates for authoring the missing policies. Honest scoping: it governs what the discovery sources reveal — it is a governance register and triage engine over your telemetry, not a network sensor we deploy; it does not sniff your traffic itself.

Our own posture, since you are right to ask: we are a small pre-launch team, which makes shadow-AI tractable in a way it is not for you — the approved-tool surface is the model registry itself, and the platform’s own AI usage is fully accounted: every model call, including retries and second opinions, lands in a per-generation cost ledger, so unaccounted AI usage inside the product is structurally visible. The candid part: our internal acceptable-use policy for staff tooling is the same starter-template discipline we ship to customers, applied at startup scale — enforced by size and telemetry today, and it will need the full formal treatment as we hire. We eat the cooking; the kitchen is just still small.

Grounded in: ISO/IEC 42001 Annex A (inventory and acceptable use of AI systems); NIST AI RMF GOVERN 1.6 (AI inventory including third-party tools); OWASP LLM Top 10 supply-chain and data-leakage classes as the risk vocabulary.

Want this answered live, on your data?