Guides

How to Discover Shadow AI: Detection Methods, Blind Spots, and a Gateway-First Approach

A practical guide to shadow AI discovery — the detection methods that actually work, where each one goes blind, and how Prompt Shields surfaces every AI tool, integration, and vendor touching your data.

11 min read
{ }????
Guides
Contents·17 sections

Shadow AI discovery is the process of identifying every AI tool your workforce touches — sanctioned or not. That is no longer a short list of chatbots. It includes purpose-built apps like ChatGPT and Claude, OAuth grants that hand AI tools access to your business data, MCP server connections, AI features quietly switched on inside the SaaS you already pay for, and the third-party AI buried in your vendors' supply chains. The surface area is far larger than most teams assume, and it grows every week.

This guide breaks down what a complete discovery effort has to cover, where each common detection method goes blind, and how a gateway-first approach — the model Prompt Shields is built on — closes the gaps that email- and browser-only tools leave open.

What is shadow AI discovery?

Shadow AI discovery is the practice of finding and cataloguing every AI app, account, integration, and data dependency that could expose corporate data to a third-party model. Your inventory should capture the AI that IT procured and sanctioned and the long tail of tools employees adopted on their own — the free-tier signups, the browser extensions, the AI toggles inside tools nobody thought of as “AI tools” at all.

Done well, it answers questions like:

  • Who is using AI across the organisation, and which tools?
  • Have unapproved AI tools entered the environment outside our governance process?
  • Which AI tools are integrated with the apps that hold our sensitive data, and at what level of access?
  • Are AI-enabled features in our existing SaaS quietly sending data to a model?
  • Do our vendors run our data through third-party AI — and under what terms?

The most common mistake is to scope discovery down to prompt activity in a handful of known chatbots. That is the tip of the iceberg. The line between “AI tool” and “SaaS tool” is dissolving fast, and any discovery strategy built on a static list of AI domains will be out of date within a quarter.

Note: this guide covers workforce AI use — the tools and embedded AI that gain access to your data through how employees use them. Model security and agentic AI security are related topics that deserve their own deep dives.

What shadow AI discovery should include

Six categories of AI asset belong in any serious inventory.

1. Purpose-built AI apps

Apps like ChatGPT, Claude, Perplexity, and the hundreds behind them that give employees a direct interface to a model. You want every account, across every app in this category — which is hard when new tools launch faster than any vendor can catalogue them. Look for discovery that pattern-matches AI behaviour rather than checking names against a fixed list.

2. OAuth grants and API keys

Most AI tools offer one-click connections to other platforms. A well-meaning employee can hand an AI notetaker access to their entire calendar, inbox, or Drive without understanding the scope they just granted. Discovery has to inventory these app-to-app integrations, surface the scopes, flag the risky ones — and ideally let you revoke access directly.

3. MCP servers and agent connections

The Model Context Protocol changed how AI reaches corporate data. Instead of one-off uploads, MCP servers let models query your SaaS directly through backend APIs, typically inheriting the permissions of whoever created the connection — often far broader access than intended. Discovering and governing these connections is now a core part of the job, not an edge case.

4. Embedded AI in your SaaS stack

SaaS vendors are racing to bolt AI features onto products you already sanctioned. Enabling one can route your data to an underlying model without anyone approving an “AI tool.” Your strategy has to account for AI arriving inside software already in your environment — including whether that vendor trains on your data and what opt-outs exist.

5. AI in your vendors' supply chain

Your SaaS providers may themselves pipe customer data through third-party AI for support, analytics, or internal tooling. Support tickets, shared tokens, and API keys can all end up in a model you never evaluated. Ask vendors directly whether they process your data through a third-party AI provider, and what controls limit that exposure.

6. Prompt and file-upload activity

Beyond discovering apps, you often need visibility into what employees are actually sending: API keys, customer records, confidential documents. Catching that requires a control positioned in the data path — one that can recognise sensitive content before it reaches the model, not just after the fact.

What you can discover with tools you already own

You can start surfacing AI use without buying anything — just know the ceiling on each method before you rely on it.

  • Expense reports reveal paid tools, but miss every free trial and free-tier account — which is where most shadow AI lives.
  • Network logs can flag traffic to known AI domains, but you have to know what to look for, separate real tools from false positives, and accept that a remote workforce barely touches your network.
  • IdP OAuth grants show where employees used “sign in with Google/Microsoft” — but only when they used work identity, and you still have to decide which grants are AI tools.
  • SSO activity covers only apps already onboarded into SSO, which by definition excludes the unsanctioned tools you most want to find.

These are useful starting points, not a program. The data is partial, ages quickly, and takes real manual effort to maintain. Unless you run an unusually locked-down environment, you will need a dedicated approach.

Discovery methods compared

No single method sees everything. Each has a distinct blind spot, which is why durable programs layer more than one.

Gateway-based discovery

A gateway sits in the path between your users, agents, and the models they call. Because every request flows through it, it sees the ground truth: which tools are used, by whom, how often, and — critically — what data is moving in the prompts and responses themselves. Unlike domain-sniffing, it distinguishes an actual model call from someone merely visiting a marketing page.

Strengths: real-time visibility, content-level insight, and an enforcement point in the same place you discover — so you can move from “we found it” to “we control it” without a second tool. Limits: it sees the traffic routed through it, so onboarding coverage matters. The gateway's job is to become the default path to every model, then close the alternates.

Browser-based discovery

A lightweight browser extension observes AI activity at the point of use — signups, logins, and what employees paste into a chatbot. It is excellent for catching consumer tools accessed over the open web and for nudging users in the moment. Its blind spots: mobile and personal devices, limited historical view, and dependence on being installed everywhere.

API connections and posture management

Direct API connections into your critical SaaS (an SSPM-style approach) reveal the app-to-app integrations, OAuth grants, and MCP connections wired into systems like your CRM or code host. This is the right lens for auditing and revoking data-sharing entitlements between core systems and AI tools. Its limit is that it only covers apps you have explicitly connected — it audits known ground rather than discovering the truly unknown.

Vendor and supply-chain intake

The categories above find AI your employees introduce. They miss AI your vendors introduce. Surfacing that requires structured intake of what each provider discloses about the models and fourth parties behind their product, and what your data is used for once it arrives.

Shadow AI discovery with Prompt Shields

Prompt Shields treats discovery as a foundation for control, not a standalone report. The platform combines the methods above around a gateway core, so what you discover is immediately governable.

  • One gateway in front of every model. Prompt Shields' AI gateway routes model traffic through a single control point, giving real-time visibility into which tools are called, by whom, and what data is in the request — the highest- fidelity discovery signal available, because it reads the traffic itself rather than guessing from a domain.
  • Atlas AI posture management. The Atlas AI (AISPM) platform turns that signal into an inventory: accounts, usage patterns, authentication methods, and risk — with monitoring and alerting built for security operations teams, not just ML engineers.
  • Point-of-use nudges with Promptly. Promptly catches AI use in the browser and routes employees to approved tools — applying policy nudges at the point of paste, where risky sharing actually happens.
  • Vendor and supply-chain AI. SaaS Vendor AI surfaces which of your vendors quietly shipped AI, where your data goes, and which models and fourth parties sit behind them.
  • A single system of record. Everything discovered feeds the AI Use-Case Registry, mapping each use case to its cost, risk, and adoption so governance decisions are made against one authoritative view.

Together these give you both breadth — the full landscape of AI in use — and depth — the specific data flows and entitlements behind each tool. That combination is what lets security teams apply appropriate controls without blocking the legitimate AI adoption the business wants.

From discovery to control

Discovery is not a one-time exercise. New tools appear weekly, and AI keeps getting embedded into the products you already run — so an inventory taken today is stale within the month. The advantage of a gateway-first model is that discovery and enforcement live in the same place: when a new tool shows up, you can screen its inputs with the Prompt Scorer, strip sensitive data with the PII Anonymiser, and codify the rules with the AI Usage Policy Generator — all against the same inventory, without stitching together a second set of tools.

If you are starting from zero, begin where your exposure is highest: put a gateway in front of the models your teams already use, turn on discovery, and let the inventory build itself. From there, governance becomes a matter of deciding what to allow — not scrambling to find out what is already happening.

Frequently asked questions

What is shadow AI discovery? The process of identifying every AI tool a workforce uses, including apps adopted without IT approval. It goes beyond chatbots to cover OAuth integrations, MCP server connections, AI features embedded in existing SaaS, and AI in vendor supply chains. Because no single method sees everything, effective discovery layers several.

What is the difference between shadow AI and shadow IT? Shadow IT is any technology used without IT approval. Shadow AI is the subset involving AI tools, AI-enabled SaaS features, and AI integrations that can expose corporate data to third-party models — introducing risks, particularly through OAuth grants and MCP connections, that traditional shadow-IT discovery was never designed to catch.

Why is shadow AI discovery difficult? Employees adopt tools quickly, often with personal email or free tiers that never hit financial systems, and AI capabilities keep getting embedded into SaaS you already use. Forward-looking methods miss historical adoption, and static lists of known tools go stale as the market grows. Discovery that identifies AI behaviour dynamically — rather than by name — closes that gap best.

Why gateway-first? A gateway sits in the data path, so it sees not just that a tool is used but what is being sent through it — and it doubles as the enforcement point. That collapses discovery and control into one place, which is why Prompt Shields builds around it.

Ready to see what is already running in your environment? Explore the Atlas AI platform or the gateway to get started.

Filed under

Shadow AIAI SecurityAI GovernanceAISPMDiscoverySaaS Security
Get started

Read next

The cheapest part of AI just got expensive

The 'AI vs headcount' maths that justified every AI budget is breaking — token prices are climbing and the best models may not even be available to you in the EU. AI ROI is no longer about picking the cheapest or biggest model. It's about governing the spend.