Skip to main content

    How to Detect Shadow AI in Your Organization

    Six places to look for the AI tools people use without approval, what each one finds and misses, and a free way to check each. Then a checklist you can print and run.

    The short version

    How do I detect shadow AI?

    Check the signals you already have: identity and OAuth grants, expense and card records, network or DNS logs, browser extensions, and SaaS admin consoles, then the endpoints themselves. Coding assistants and command-line tools that call AI providers from a laptop surface most clearly on the endpoint, where Behest Radar looks.

    Before you start

    The goal is an inventory, not a crackdown. People reach for AI tools because they help, and a punitive audit only drives usage further out of sight. Checking logs, devices, or expense records can count as employee monitoring, so agree the scope with HR, legal, or your privacy team before you start. Depending on where your people work, that can mean giving written notice (some US states, including New York, Connecticut, and Delaware, require it), updating your employee privacy notice, carrying out a data protection impact assessment, or consulting a works council. Tell people what you are checking and why, collect only what the inventory needs, and report by tool and team rather than by person. This is general information, not legal advice.

    Six places to look

    No single source sees everything. Check all six, starting with the ones you already have access to. AI inside SaaS apps runs on the vendor's servers, so it shows up only in each vendor's admin console.

    Six places to look for shadow AI: what each finds, what it misses, the effort, and a free option
    Where to lookWhat it findsWhat it missesEffortFree option
    Identity and OAuth grantsAI apps people sign in to with a company account, and the scopes granted to themPersonal accounts and tools used with plain API keysLowYour identity provider's third-party app or OAuth grant report
    Expense and card recordsPaid AI subscriptions and API bills charged to company cardsFree tiers, and costs on personal cards that are never claimedLowAn export from your expense or card system, filtered by AI vendor names
    Network or DNS logsLookups and connections to known AI domains from the corporate networkLaptops off the network or VPN, and resolvers you do not logMediumThe DNS or proxy logs you already keep, searched for AI domains. Behest Radar sees AI connections from the machine itself, on or off the network
    Browser extensionsAI extensions installed in managed browsersUnmanaged browsers, desktop apps, and command-line toolsLow to mediumYour browser management console's extension inventory. Behest Radar shows which browsers reach AI sites, and how much, not what was typed; it does not list extensions, whose traffic shows up as the browser's
    SaaS admin consolesAI features switched on inside the SaaS apps you already license, and who uses themAnything outside that vendor, with one console per appLow to mediumEach vendor's admin settings and usage reports, where your plan includes them
    EndpointsDesktop AI apps, coding assistants, and CLI tools calling AI services from the machine itselfMachines you have no agent or inventory onMediumosquery for installed apps and processes; Behest Radar for AI agents, apps, and local models on each machine
    1. 1

      Review identity and OAuth grants

      Pull the third-party app or OAuth grant report from your identity provider and flag AI apps. It shows which tools people signed in to with a company account and what data scopes they granted, which tells you where company data may already be flowing.

    2. 2

      Search expense and card records

      Export recent expense claims and card transactions and search for AI vendor names. Paid subscriptions and API bills show up here even when nobody told IT, and the amounts give you a first view of shadow AI spend.

    3. 3

      Search network or DNS logs

      Search the DNS or proxy logs you already keep for known AI domains. This catches tools that never ask for single sign-on, but only while the device is on the corporate network or VPN.

    4. 4

      Inventory browser extensions

      Export the extension inventory from your browser management console and flag AI extensions. Extensions can read the pages people work in, so they matter even when their usage looks small.

    5. 5

      Review SaaS admin consoles

      Check the admin settings of the SaaS apps you already license for AI features that are switched on, and who uses them. That AI runs on the vendor's servers, so no network or endpoint tool sees it.

    6. 6

      Check the endpoints themselves

      Look at the machines, starting with developers. Coding assistants and command-line tools call AI providers directly, often with their own API keys, so the other places can miss them. An installed-software inventory shows what is present; a connection view shows what is in use.

    Coding assistants and CLI tools need an endpoint view

    Developer AI is the hardest shadow AI to see from the center. A coding agent in a terminal can run on a personal API key, never ask for single sign-on, never touch a browser, and keep working on a laptop that is off the corporate network. Identity, browser, and network tools can all miss it.

    An installed-software inventory, such as one built with osquery, tells you which tools are present. To see which AI services a machine actually reaches, Behest Radar is a free, observe-only app that discovers connections from coding assistants, desktop AI apps, and CLI tools to known AI services, recognizing 20+ coding agents and AI apps by name. With permission, it also reads token counts for Claude Code, Codex CLI, and Claude Cowork, and estimates list-price cost for Claude models.

    The guide to finding the AI coding tools your developers use goes deeper, and the shadow AI discovery overview shows how endpoint findings feed an organization-wide inventory in Behest Control.

    Shadow AI audit checklist

    Print this page or copy the list into your own tracker. Work through it once, then repeat it on a schedule.

    1. Before you pull any data, agree the scope with HR, legal, or your privacy team, give people notice, and follow the employee-monitoring rules where they work.
    2. Export OAuth and third-party app grants from your identity provider, and flag AI apps and their scopes.
    3. Pull the last quarter of expense and card transactions, search for AI vendor names, and total them by vendor and team.
    4. Search DNS or proxy logs for known AI domains.
    5. Export browser extension inventories from managed browsers, and flag AI extensions.
    6. Check developer machines for coding assistants and CLI tools that call AI providers directly.
    7. List the AI features switched on inside the SaaS apps you already pay for.
    8. Run a short, non-punitive survey, anonymous if you can, asking which AI tools people use and why.
    9. Sort every finding into approved, under review, or not allowed.
    10. Give each approved tool an owner, a sanctioned path, and a budget.
    11. Repeat the audit on a schedule, because new AI tools ship every month.

    Frequently asked questions

    Is there a free way to find shadow AI?
    Yes. Start with what you already have: OAuth and third-party app reports in your identity provider, expense and card exports, DNS or proxy logs, and browser extension inventories. Open-source tools such as osquery help on endpoints. Behest Radar is a free download that shows which apps on one machine reach AI services and, with permission, list-price cost for Claude models.
    How do I find out which AI tools my employees use?
    Combine an inventory with a conversation. Pull OAuth grants, expense records, DNS or proxy logs, and browser extension lists to see what is in use, then run a short, non-punitive survey to learn why. Check developer machines separately, because coding assistants and CLI tools often call AI providers directly. Agree the scope with HR, legal, or your privacy team first, and tell people what you are checking.
    What should I do after I discover shadow AI?
    Sort what you found into approved, under review, and not allowed. Give approved tools a sanctioned path, then put model calls under policy and cost control: model allowlists, budgets, an audit trail, and PII scrubbing on the Enterprise plan. In Behest, that is the job of the control plane, with AI Token FinOps as its cost-control layer.

    Start with the endpoint you are sitting at

    Behest Radar is a free download. See which AI services your own machine reaches, then read how Behest turns findings into governed, budgeted AI.

    Behest Radar: Find the shadow AI on your machines. Free download.

    Get Radar free