Skip to main content
← Back to Insights
Risk explainer12 Min Read

Shadow AI Governance: How to Audit and Govern Every AI Tool in Your Microsoft 365 Tenant

One in five organizations has traced a breach to shadow AI, and most cannot answer 'what AI are we using?' Here is how a shadow AI audit of a Microsoft 365 tenant actually works — what counts as shadow AI, the discovery telemetry you already license, and how to govern what the audit finds.

AZ InnovationsJuly 21, 2026Updated August 28, 2026

The engagement behind this article

Shadow AI and Agent Discovery Audit

Price fixed after a short scope call.

Review the full scope →

The short answer: shadow AI is the unsanctioned AI your employees already use, and governing it is an inventory job before it is a policy job. In a Microsoft 365 tenant the discovery tooling is probably already in your licenses: Microsoft Defender for Cloud Apps finds and risk-scores the AI apps in use, Microsoft Purview watches what data flows into them, and the fix is a per-app decision to sanction, monitor, or block, backed by guardrails on the AI you approve. A survey will not answer the question. Tenant telemetry will.

At some point this year, someone asks you the question: a CEO before a Copilot purchase, an auditor working a framework checklist, or an insurance broker at renewal. What AI are we using, and what data is going into it? If the honest answer is a shrug, you have a shadow AI governance gap, and you are in the majority. This guide covers what shadow AI actually includes, the numbers worth taking to leadership, the regulation arriving in 2026, and the specific Microsoft tools that turn "no idea" into an inventory with guardrails.

What counts as shadow AI

Microsoft's own definition is usefully blunt: shadow AI is the unauthorized use of generative AI applications and tools. That is broader than employees chatting with ChatGPT. Microsoft's examples include:

  • Consumer AI chatbots used through personal accounts, where your tenant controls, logging, and data agreements do not apply.
  • Direct calls to AI model APIs such as DeepSeek or Anthropic endpoints, wired into scripts and tools by developers without review.
  • SaaS MCP servers and AI plugins that connect AI tools to business data through OAuth grants nobody approved.
  • AI code generators and unsanctioned agents that act on their own, which Microsoft flags as a distinct risk: uncontrolled AI activity without oversight.

This is why a staff survey or an acceptable-use memo cannot answer the boss's question. Half of this list is invisible to the person doing it, let alone to a questionnaire. The visibility has to come from the tenant itself.

How big the problem actually is

78%

of AI users bring their own AI tools to work, and it is even more common at small businesses. Microsoft and LinkedIn Work Trend Index, 2024.

1 in 5

organizations reported a breach traced to shadow AI, adding an average $670,000 to the breach bill. IBM Cost of a Data Breach Report, 2025.

39.7%

of data movements into AI tools involve sensitive data, per telemetry from billions of real-world data flows. Cyberhaven Labs, 2026.

Two more data points worth knowing. Cyberhaven's 2026 telemetry found 32.3% of ChatGPT usage happens through personal accounts, outside any corporate control. And in IBM's 2025 study, 63% of breached organizations either had no AI governance policy or were still writing one, and among organizations with a policy, only 34% audited for unsanctioned AI. The gap between "we have a policy" and "we checked" is where the breaches live.


🔍 Step one: discover what is actually in use

The discovery engine in a Microsoft 365 tenant is Microsoft Defender for Cloud Apps. Its cloud app catalog now includes a dedicated Generative AI category with more than 1,000 cataloged AI apps, each risk-scored against 90+ security, compliance, and legal factors. In the Microsoft Defender portal, open Cloud apps, then the cloud app catalog, and filter the category to Generative AI: that list, matched against your tenant's traffic, is your shadow AI inventory.

Two details make this more than a report:

  • Sanction and unsanction are enforcement, and blocking has a reach limit worth knowing: tag an app as unsanctioned and it is automatically blocked on devices onboarded to Microsoft Defender for Endpoint, with a softer warn-and-educate mode available. Devices outside Defender for Endpoint do not get the block, which is an argument for finishing device onboarding before writing the AI policy.
  • The OAuth side is covered too: app governance, included with the Defender for Cloud Apps license, gives you visibility into OAuth apps connected to your tenant and can disable the risky ones. This is where unsanctioned AI plugins and agents that hold standing permissions to your data show up.

Microsoft has also added network-level shadow AI discovery through Entra Global Secure Access, a second sensor that feeds the same catalog and risk scores.


📊 Step two: watch what data flows into AI

Knowing the apps is half the picture. Microsoft Purview Data Security Posture Management for AI (DSPM for AI, formerly called AI Hub during its preview) shows the interactions themselves: prompts and responses, AI site visits, and the sensitive information types appearing in what people type, across Microsoft 365 Copilot, agents, and third-party AI sites like ChatGPT and Google Gemini. Purview's Insider Risk Management adds a risky-AI-usage policy template that can spot things like prompt injection attempts and raise a user's risk level automatically.

The license gate is real: DSPM for AI needs Microsoft 365 E5 or the Microsoft Purview Suite, and monitoring Copilot interactions requires the users to hold Microsoft 365 Copilot licenses. If you are not E5, the Defender for Cloud Apps discovery layer is still available and is where to start.


🚦 Step three: sanction, monitor, or block, per app

Governance is a triage decision made per app, using the risk score and the usage data you now have:

  • Sanction the AI you want people using, and put guardrails on it. Sensitivity labels with encryption control what Microsoft 365 Copilot can return, and a one-click Purview policy blocks Copilot and agents from processing your most sensitive labeled content. The Copilot Control System in the Microsoft 365 admin center manages and blocks agents, and Microsoft Entra Agent ID, now rolling out, gives AI agents their own directory identities with Conditional Access support on Entra ID P1.
  • Monitor the gray zone: tolerated apps stay visible in Defender for Cloud Apps and DSPM for AI, with data-level rules underneath. Purview endpoint DLP can warn or block pasting sensitive data into AI websites, and Microsoft Edge for Business adds inline protection that screens typed prompts to consumer AI apps, initially covering ChatGPT, Google Gemini, and DeepSeek, even without endpoint DLP deployed.
  • Block the high-risk tail: unsanction in Defender for Cloud Apps for the device-level block, and tighten Entra user consent settings so employees cannot grant OAuth access to unverified AI apps, with an admin consent workflow so legitimate requests still have a path.

Why "block everything" backfires

Blanket bans feel decisive and measure well in a board slide. In practice they push the same usage onto personal phones and home laptops, where your telemetry ends and the 32.3% personal-account problem grows. Microsoft ships a warn-and-educate mode for exactly this reason. The governance that holds is a sanctioned AI path that is genuinely useful, data-level guardrails on everything else, and blocks reserved for the apps whose risk scores earn them.


The 2026 pressure: why this stopped being optional

On August 2, 2026 the EU AI Act becomes generally applicable, including its transparency obligations: telling people when they are interacting with AI, and labeling AI-generated content. It reaches beyond Europe, applying to companies whose AI output is used in the EU regardless of where they sit.

One precision most coverage misses: the EU's Digital Omnibus package, finalized in early July 2026, deferred the stand-alone high-risk system obligations to December 2, 2027. August is about general applicability and transparency, so anyone telling you the high-risk rules bite this summer is out of date.

In the US there is still no comprehensive federal AI law. Texas's Responsible AI Governance Act has been in effect since January 1, 2026, while Colorado repealed and replaced its AI act, now a narrower disclosure law effective January 1, 2027. The voluntary yardstick auditors reach for is the NIST AI Risk Management Framework, with its Govern, Map, Measure, and Manage functions. Brokers report that underwriters increasingly expect documented evidence of AI governance (Aon, 2026).

Every one of these conversations starts with the same first question: what AI are you running? The inventory is the entry ticket.


One last connection worth making: for most Microsoft shops the sanctioned path is Microsoft 365 Copilot, and its economics are their own decision. Every Copilot license, the free tier, and the metered agent pricing are broken down in the Copilot pricing guide. Sanctioning Copilot also puts your file permissions in scope, because it answers using whatever the person asking could already open, and OneDrive vs SharePoint vs Azure Files covers where those files should sit before you switch it on. Governing shadow AI and funding the sanctioned alternative are two halves of the same decision.


What a shadow AI audit actually covers

"Audit our AI use" gets asked a lot and defined almost never, so here is the concrete version — the steps a shadow AI audit of a Microsoft 365 tenant walks through, and what you hold at the end:

  1. Inventory from telemetry, not surveys. Microsoft Defender for Cloud Apps discovery is read against its Generative AI catalog, Microsoft Purview DSPM for AI against the interaction and sensitive-data signals, and the Entra sign-in and audit logs against app consents and connectors. Every AI application, agent, and connector the tenant can see goes on the list — with the evidence source recorded beside each entry, because an inventory an auditor cannot trace is an opinion.
  2. Consent and connector review. The OAuth grants and plugins users have approved on their own — the quiet path AI tools use to reach mail, files, and calendars long after the browser tab closes.
  3. Risk and usage ranking. Each finding is ranked by what it can reach and how much it is actually used, so the tool with three curious users is not treated like the one half of sales pastes deals into.
  4. An allow, watch, or block call on every tool found. Not a philosophy — a written recommendation per entry, with the reason.
  5. A governance plan and an executive readout. Which rules would enforce the calls once rolled out, and a summary an owner or a board can read without a glossary.

Two properties matter as much as the steps. The audit is read-only — nothing is blocked or switched off while it runs, because discovery done mid-crackdown chases the usage underground, exactly the failure mode described above. And it is honest about its edges: a tool used entirely off company accounts and devices leaves no trace in tenant telemetry, and no review reads what individual employees typed into an AI tool — the inventory tracks tools and data reach, not people.

Common shadow AI governance questions

What is shadow AI?

Shadow AI is the unauthorized use of generative AI applications and tools inside an organization. Microsoft's definition includes consumer AI chatbots used through personal accounts, direct calls to AI model APIs, SaaS MCP servers and AI plugins connected by OAuth, and AI code generators or agents nobody approved. It is a specific subset of shadow IT, and riskier, because the data typed into these tools leaves your control and may be retained or used by the provider.

How do I find out which AI tools my employees are using?

Use tenant telemetry rather than a survey. Microsoft Defender for Cloud Apps discovers the AI apps in use and matches them against a Generative AI catalog of more than 1,000 apps, each with a risk score. Microsoft Purview DSPM for AI shows the interactions and whether sensitive data appears in prompts, and Entra Global Secure Access adds network-level shadow AI discovery. Together they produce an inventory of every AI app, agent, and connector touching your data.

Should we just block ChatGPT?

Usually no. A blanket block pushes usage onto personal accounts and personal devices, where you lose all visibility; roughly a third of ChatGPT use already happens through personal accounts. The stronger pattern is to offer a sanctioned AI with guardrails, apply data-level controls like endpoint DLP that block sensitive data from reaching AI sites, and reserve hard blocks for high-risk apps. Microsoft supports a warn-and-educate mode for exactly this middle ground.

Does Microsoft 365 include tools to govern AI use?

Yes, and you may already license them. Microsoft Defender for Cloud Apps handles discovery, risk scoring, and app blocking, and includes app governance for OAuth-connected AI. Microsoft Purview provides DSPM for AI monitoring and endpoint DLP, gated on Microsoft 365 E5 or the Purview Suite. Microsoft Edge for Business adds inline prompt protection, Entra consent settings control which AI apps users can authorize, and the Copilot Control System manages sanctioned Copilot and agents.

What is shadow AI governance?

Shadow AI governance is the set of decisions and controls that turn an unknown population of AI tools into a known one: an inventory built from evidence, an owner for each tool, a recorded allow, watch or block decision, and an approval path for the next tool so the inventory does not rot. It is not a single product. The discovery part comes from tenant telemetry, the decisions come from the business, and the controls come from tools most Microsoft 365 tenants already license.

How do you govern shadow AI without blocking everything?

In three steps, in this order. First, discover what is actually in use from tenant evidence: app consents and the scopes they hold, enterprise applications, the Teams app inventory, Intune-detected software, and the audit log. Second, give every discovered tool an owner and a decision: allow, watch or block, with the reason written down. Third, configure the approval path so a new tool gets a decision before it gets data, and revoke the consents that should never have been granted. A blanket block skips the first two steps and pushes usage onto personal accounts where you can see nothing.

What should a shadow AI policy say?

A workable policy is short and names things. It lists the approved tools and what data may go into each, the tools that are blocked and why, how someone requests a new tool and how long a decision takes, and what happens to a tool that is discovered outside the list. A policy that says "use AI responsibly" with no list behind it is not a policy, because nobody can tell whether they are complying with it.

Do we need a shadow AI governance platform, or can we use what we have?

Usually what you have. Microsoft Defender for Cloud Apps discovers AI apps and risk-scores them, its App Governance feature shows which connected apps hold permissions into Microsoft 365, and Purview's data security posture management for AI reports what sensitive information is being typed into AI tools. Each has a blind spot: browser-based visibility needs an extension deployed to every device, discovery needs traffic logs or Defender for Endpoint, and an unmanaged laptop on home Wi-Fi is invisible to all of them. The useful question is which of those you already license, which are switched on, and what none of them can see, and that is an audit question before it is a purchasing one.

We are worried about shadow AI. Who can audit our Microsoft 365 environment and set up governance?

Anyone with read-only access to the tenant and the method above can build the inventory; a badge is not what makes the audit credible, the evidence source against each entry is. AZ Innovations is an independent Microsoft 365 provider, not a Microsoft partner, and runs this as a fixed-scope, read-only audit over five working days that closes with the inventory, a recommended decision on every tool, and a costed correction plan. The corrections and the approval path are then scoped from that plan rather than guessed at up front.

What does a shadow AI audit include?

A telemetry-based inventory of every AI application, agent, and connector the tenant can see — built from Defender for Cloud Apps discovery, Purview DSPM for AI, and the Entra sign-in and audit logs, with the evidence source recorded beside each entry. Each finding is ranked by risk and usage and carries a written allow, watch, or block recommendation, and the audit closes with a governance plan and an executive readout. It runs read-only: nothing is blocked while it runs, and it does not read what individual employees typed into any tool.

Does shadow AI governance differ for local government or healthcare?

The method is the same; the stakes and the record-keeping differ. A local government has public-records obligations, so a prompt typed into a consumer chatbot may be a record nobody retained. A healthcare organization has protected health information, so the question is not only which tools are in use but which of them ever saw patient data. In both cases the inventory has to carry the evidence source and the data reach per tool, because that is what an auditor or a records officer will ask for, and a survey cannot supply it.

Is shadow AI actually causing breaches?

Yes. In the IBM Cost of a Data Breach Report 2025, one in five organizations reported a breach traced to shadow AI, and those breaches cost an average of $670,000 more than at organizations with little or none. The same study found 63% of breached organizations had no AI governance policy or were still developing one, and only 34% of organizations with a policy actually audited for unsanctioned AI.

About this article

Published by AZ Innovations, which completes fixed-scope Microsoft 365, security, migration, and automation work. See who does the work or the delivered work.

Find the shadow AI tools and agents your staff already use, from your own tenant.

You get a list of every shadow AI tool, agent and connected app in use in your Microsoft 365 tenant, built from tenant evidence rather than a survey. Each entry shows who uses it, what it can reach, and a recommended allow, watch or block decision. The audit is read-only, runs over five working days, and ends with a readout and a costed plan for the fixes.