← Back to Insights
Risk explainer11 Min Read

Shadow AI Governance: How to Find Every AI Tool Your Employees Already Use

AZ InnovationsJuly 21, 2026

The short answer: shadow AI is the unsanctioned AI your employees already use, and governing it is an inventory job before it is a policy job. In a Microsoft 365 tenant the discovery tooling is probably already in your licenses: Microsoft Defender for Cloud Apps finds and risk-scores the AI apps in use, Microsoft Purview watches what data flows into them, and the fix is a per-app decision to sanction, monitor, or block, backed by guardrails on the AI you approve. A survey will not answer the question. Tenant telemetry will.

At some point this year, someone asks you the question: a CEO before a Copilot purchase, an auditor working a framework checklist, or an insurance broker at renewal. What AI are we using, and what data is going into it? If the honest answer is a shrug, you have a shadow AI governance gap, and you are in the majority. This guide covers what shadow AI actually includes, the numbers worth taking to leadership, the regulation arriving in 2026, and the specific Microsoft tools that turn "no idea" into an inventory with guardrails.

What counts as shadow AI

Microsoft's own definition is usefully blunt: shadow AI is the unauthorized use of generative AI applications and tools. That is broader than employees chatting with ChatGPT. Microsoft's examples include:

  • Consumer AI chatbots used through personal accounts, where your tenant controls, logging, and data agreements do not apply.
  • Direct calls to AI model APIs such as DeepSeek or Anthropic endpoints, wired into scripts and tools by developers without review.
  • SaaS MCP servers and AI plugins that connect AI tools to business data through OAuth grants nobody approved.
  • AI code generators and unsanctioned agents that act on their own, which Microsoft flags as a distinct risk: uncontrolled AI activity without oversight.

This is why a staff survey or an acceptable-use memo cannot answer the boss's question. Half of this list is invisible to the person doing it, let alone to a questionnaire. The visibility has to come from the tenant itself.

How big the problem actually is

78%

of AI users bring their own AI tools to work, and it is even more common at small businesses. Microsoft and LinkedIn Work Trend Index, 2024.

1 in 5

organizations reported a breach traced to shadow AI, adding an average $670,000 to the breach bill. IBM Cost of a Data Breach Report, 2025.

39.7%

of data movements into AI tools involve sensitive data, per telemetry from billions of real-world data flows. Cyberhaven Labs, 2026.

Two more data points worth knowing. Cyberhaven's 2026 telemetry found 32.3% of ChatGPT usage happens through personal accounts, outside any corporate control. And in IBM's 2025 study, 63% of breached organizations either had no AI governance policy or were still writing one, and among organizations with a policy, only 34% audited for unsanctioned AI. The gap between "we have a policy" and "we checked" is where the breaches live.


🔍 Step one: discover what is actually in use

The discovery engine in a Microsoft 365 tenant is Microsoft Defender for Cloud Apps. Its cloud app catalog now includes a dedicated Generative AI category with more than 1,000 cataloged AI apps, each risk-scored against 90+ security, compliance, and legal factors. In the Microsoft Defender portal, open Cloud apps, then the cloud app catalog, and filter the category to Generative AI: that list, matched against your tenant's traffic, is your shadow AI inventory.

Two details make this more than a report:

  • Sanction and unsanction are enforcement, and blocking has a reach limit worth knowing: tag an app as unsanctioned and it is automatically blocked on devices onboarded to Microsoft Defender for Endpoint, with a softer warn-and-educate mode available. Devices outside Defender for Endpoint do not get the block, which is an argument for finishing device onboarding before writing the AI policy.
  • The OAuth side is covered too: app governance, included with the Defender for Cloud Apps license, gives you visibility into OAuth apps connected to your tenant and can disable the risky ones. This is where unsanctioned AI plugins and agents that hold standing permissions to your data show up.

Microsoft has also added network-level shadow AI discovery through Entra Global Secure Access, a second sensor that feeds the same catalog and risk scores.


📊 Step two: watch what data flows into AI

Knowing the apps is half the picture. Microsoft Purview Data Security Posture Management for AI (DSPM for AI, formerly called AI Hub during its preview) shows the interactions themselves: prompts and responses, AI site visits, and the sensitive information types appearing in what people type, across Microsoft 365 Copilot, agents, and third-party AI sites like ChatGPT and Google Gemini. Purview's Insider Risk Management adds a risky-AI-usage policy template that can spot things like prompt injection attempts and raise a user's risk level automatically.

The license gate is real: DSPM for AI needs Microsoft 365 E5 or the Microsoft Purview Suite, and monitoring Copilot interactions requires the users to hold Microsoft 365 Copilot licenses. If you are not E5, the Defender for Cloud Apps discovery layer is still available and is where to start.


🚦 Step three: sanction, monitor, or block, per app

Governance is a triage decision made per app, using the risk score and the usage data you now have:

  • Sanction the AI you want people using, and put guardrails on it. Sensitivity labels with encryption control what Microsoft 365 Copilot can return, and a one-click Purview policy blocks Copilot and agents from processing your most sensitive labeled content. The Copilot Control System in the Microsoft 365 admin center manages and blocks agents, and Microsoft Entra Agent ID, now rolling out, gives AI agents their own directory identities with Conditional Access support on Entra ID P1.
  • Monitor the gray zone: tolerated apps stay visible in Defender for Cloud Apps and DSPM for AI, with data-level rules underneath. Purview endpoint DLP can warn or block pasting sensitive data into AI websites, and Microsoft Edge for Business adds inline protection that screens typed prompts to consumer AI apps, initially covering ChatGPT, Google Gemini, and DeepSeek, even without endpoint DLP deployed.
  • Block the high-risk tail: unsanction in Defender for Cloud Apps for the device-level block, and tighten Entra user consent settings so employees cannot grant OAuth access to unverified AI apps, with an admin consent workflow so legitimate requests still have a path.

Why "block everything" backfires

Blanket bans feel decisive and measure well in a board slide. In practice they push the same usage onto personal phones and home laptops, where your telemetry ends and the 32.3% personal-account problem grows. Microsoft ships a warn-and-educate mode for exactly this reason. The governance that holds is a sanctioned AI path that is genuinely useful, data-level guardrails on everything else, and blocks reserved for the apps whose risk scores earn them.


The 2026 pressure: why this stopped being optional

On August 2, 2026 the EU AI Act becomes generally applicable, including its transparency obligations: telling people when they are interacting with AI and labeling AI-generated content. It reaches beyond Europe, applying to companies whose AI output is used in the EU regardless of where they sit. One precision most coverage misses: the EU's Digital Omnibus package, finalized in early July 2026, deferred the stand-alone high-risk system obligations to December 2, 2027, so August 2026 is about general applicability and transparency, and anyone telling you the high-risk rules bite this summer is out of date. In the US there is still no comprehensive federal AI law: Texas's Responsible AI Governance Act has been in effect since January 1, 2026, while Colorado repealed and replaced its AI act, now a narrower disclosure law effective January 1, 2027. The voluntary yardstick auditors reach for is the NIST AI Risk Management Framework, with its Govern, Map, Measure, and Manage functions. And brokers report underwriters increasingly expect documented evidence of AI governance (Aon, 2026). Every one of these conversations starts with the same first question: what AI are you running? The inventory is the entry ticket.


One last connection worth making: for most Microsoft shops the sanctioned path is Microsoft 365 Copilot, and its economics are their own decision. We broke down every Copilot license, the free tier, and the metered agent pricing in our Copilot pricing guide. Governing shadow AI and funding the sanctioned alternative are two halves of the same decision.


Common shadow AI governance questions

What is shadow AI?

Shadow AI is the unauthorized use of generative AI applications and tools inside an organization. Microsoft's definition includes consumer AI chatbots used through personal accounts, direct calls to AI model APIs, SaaS MCP servers and AI plugins connected by OAuth, and AI code generators or agents nobody approved. It is a specific subset of shadow IT, and riskier, because the data typed into these tools leaves your control and may be retained or used by the provider.

How do I find out which AI tools my employees are using?

Use tenant telemetry rather than a survey. Microsoft Defender for Cloud Apps discovers the AI apps in use and matches them against a Generative AI catalog of more than 1,000 apps, each with a risk score. Microsoft Purview DSPM for AI shows the interactions and whether sensitive data appears in prompts, and Entra Global Secure Access adds network-level shadow AI discovery. Together they produce an inventory of every AI app, agent, and connector touching your data.

Should we just block ChatGPT?

Usually no. A blanket block pushes usage onto personal accounts and personal devices, where you lose all visibility; roughly a third of ChatGPT use already happens through personal accounts. The stronger pattern is to offer a sanctioned AI with guardrails, apply data-level controls like endpoint DLP that block sensitive data from reaching AI sites, and reserve hard blocks for high-risk apps. Microsoft supports a warn-and-educate mode for exactly this middle ground.

Does Microsoft 365 include tools to govern AI use?

Yes, and you may already license them. Microsoft Defender for Cloud Apps handles discovery, risk scoring, and app blocking, and includes app governance for OAuth-connected AI. Microsoft Purview provides DSPM for AI monitoring and endpoint DLP, gated on Microsoft 365 E5 or the Purview Suite. Microsoft Edge for Business adds inline prompt protection, Entra consent settings control which AI apps users can authorize, and the Copilot Control System manages sanctioned Copilot and agents.

Is shadow AI actually causing breaches?

Yes. In the IBM Cost of a Data Breach Report 2025, one in five organizations reported a breach traced to shadow AI, and those breaches cost an average of $670,000 more than at organizations with little or none. The same study found 63% of breached organizations had no AI governance policy or were still developing one, and only 34% of organizations with a policy actually audited for unsanctioned AI.

If the board asked "what AI are we using?" could you answer?

Our Copilot and Shadow AI Exposure Report is that answer in document form: a discovery inventory of every AI app, agent, and connector in your tenant built on Defender for Cloud Apps, a shadow AI risk register ranked by usage and risk, and a sanction, monitor, or block governance plan, in the format a board, auditor, or underwriter can read. Fixed fee: $3,450 to $4,500 standard scope, Compact from $2,500 for smaller tenants.

See the Shadow AI Exposure Report

Want this proven in your tenant?

The Copilot & Shadow AI Exposure Report turns this into scored findings and a fixed remediation plan for your environment.

Fixed fee: $3,450 to $4,500 standard scope, Compact from $2,500.

Under 75 users on a single tenant? Compact-scope diagnostics start at $1,500. Check eligibility in 60 seconds

Diagnostics Contact