By Inforedge | www.inforedge.com
From browser activity and network telemetry to identities, cloud workloads, and sensitive data, organizations need a connected view of AI adoption—not another blanket ban.
Artificial intelligence has moved beyond isolated experiments.
Employees use AI to summarize documents, write code, analyze information, prepare presentations, and automate administrative work. Development teams integrate models through APIs. Business units explore agents that retrieve information and execute multistep workflows.
Much of this activity creates genuine business value.
But not all of it is visible to the people responsible for security, technology spending, compliance, and business outcomes.
An employee might use a personal AI account to analyze an internal document. A department might purchase an AI subscription outside centralized procurement. A developer could connect an external model to company data. An AI agent might receive broader access to enterprise information than its task requires.
These are different manifestations of shadow AI: AI applications, services, models, or agents being used outside an organization’s established visibility, approval, or governance processes.
The response should not be to treat every unapproved tool as a security incident or every employee experiment as misconduct.
AI is becoming part of how organizations operate. The opportunity is too significant to approach entirely through restriction.
The question facing technology leaders is changing:
How do we understand where AI is being used, protect the information it can access, enable appropriate use cases, and measure the value it delivers?
The answer begins with visibility—and continues through governance.
1. Shadow AI Is a Business Visibility Problem, Not Just a Security Problem
The scale of unmanaged AI adoption is substantial.
In its 2026 Cloud and Threat Report, Netskope found that 47% of generative AI users in its observed customer environment were using personal AI applications, down from 78% the preceding year. The proportion using organization-managed AI accounts increased from 25% to 62%. Some users accessed both personal and managed accounts.
This suggests that more organizations are establishing formal AI access, but it does not mean the visibility problem has disappeared.
Netskope also reported that detected sensitive-data policy violations involving generative AI had doubled year over year, with the average monitored organization experiencing 223 incidents per month. These were detected policy violations, not necessarily confirmed data breaches, and the findings describe Netskope’s monitored environment rather than every organization.
The challenge extends beyond personal AI accounts.
An organization’s AI footprint may include approved enterprise assistants, AI features embedded in SaaS applications, employee-selected browser tools, departmentally purchased subscriptions, developer APIs, locally hosted models, and agents connected to business systems.
Different stakeholders see different portions of that environment.
Finance sees invoices and purchasing records. IT sees licensed applications. Security sees network activity and alerts. Engineering sees model deployments. Business leaders see the workflows employees are trying to improve.
None of those perspectives necessarily provides a complete picture.
An actionable AI inventory should help answer five questions:
- What application, model, or agent is being used?
- Who owns it, and what business purpose does it serve?
- What enterprise information or systems can it access?
- What does it cost, and how is consumption attributed?
- Is its use approved, under review, or outside established policy?
The purpose is not simply to discover more applications.
It is to convert fragmented information into decisions about enablement, risk, ownership, and business value.
2. The Financial Cost of Uncontrolled AI Goes Beyond Subscriptions
Unmanaged AI can create both direct and indirect costs.
Direct expenses include duplicate subscriptions, unallocated model consumption, overlapping AI features, and services purchased outside established contracts.
Potential indirect costs include incident investigation, operational disruption, sensitive-data exposure, remediation, and time spent managing applications with unclear ownership.
IBM’s 2025 Cost of a Data Breach research provides a useful reference point.
Among 600 organizations studied that experienced data breaches between March 2024 and February 2025, one in five reported a breach associated with shadow AI.
Organizations with high levels of shadow AI experienced average breach costs approximately $670,000 higher than those with low or no shadow AI. This is a comparison within IBM’s studied breached organizations—not the expected cost of shadow AI for every business or a prediction of any individual organization’s exposure.
The financial implications also extend to everyday technology management.
An illustrative example: decentralized AI spending
Consider a hypothetical enterprise where employees and departments independently purchase AI tools.
| Cost category | Illustrative assumption | Annual expenditure |
|---|---|---|
| Individual AI subscriptions | 200 subscriptions at $20/month | $48,000 |
| Departmental AI services | 3 teams at $2,000/month | $72,000 |
| Total decentralized AI spending | $120,000 |
These figures are hypothetical, not vendor quotations or Inforedge customer results.
The entire $120,000 should not automatically be considered waste. Some tools might provide substantial business value.
The challenge is determining which subscriptions overlap, which services are approved, who owns the spending, and what outcomes the organization receives.
An unmanaged developer API or agent may also generate consumption that is difficult to allocate to a department or forecast accurately.
This is where shadow AI governance connects with FinOps.
As discussed in our FinOps for AI article, technology leaders increasingly need to connect cloud infrastructure, tokens, licenses, and model consumption to business outcomes.
The goal is not simply to spend less on AI. It is to make AI spending visible, intentional, and financially accountable.
3. How Organizations Discover Shadow AI: Different Layers of Visibility
There is no single discovery method that is universally superior.
Organizations have different architectures, existing security investments, employee workflows, and AI adoption patterns.
A secure web gateway may provide useful network coverage. A managed browser can provide additional context about employee-facing AI use. An identity platform can reveal application permissions. Cloud telemetry can explain developer and agent workloads.
The most useful approach combines relevant evidence according to the questions the organization needs to answer.
| Visibility layer | What it can help identify | Important limitation |
|---|---|---|
| Browser | AI websites, extensions, and activity in supported managed browsers | Unmanaged browsers, desktop tools, and server-side activity may be missed |
| Network and secure web gateway | Connections to known AI services and traffic patterns | Destination traffic does not necessarily reveal business purpose or prompt contents |
| Endpoint | Installed AI applications, extensions, and certain local workloads | Depends on device coverage and detection capabilities |
| Identity and OAuth | Enterprise applications, consent grants, and service identities | Personal accounts and unregistered services may remain invisible |
| SaaS and application APIs | Available usage records, application settings, and permissions | Depends on connector support and authorized API access |
| Cloud and model telemetry | Deployments, API calls, tokens, workloads, and consumption | May lack end-user or business-outcome context |
| Data security and Microsoft 365 | Sensitive information, oversharing, labels, and access permissions | Findings depend on classification and existing permissions |
| Procurement and finance | Contracts, licenses, subscriptions, and billed consumption | Free services and personal purchases may be absent |
Browser visibility: understanding employee-facing AI activity
The browser is an important part of enterprise AI discovery because employees frequently access AI websites and SaaS applications through it.
They may use an assistant to draft an email, summarize research, review code, or analyze a document. Some of these interactions occur through personal accounts and may not appear in the organization’s approved application inventory.
Depending on the technology, configuration, and permissions, managed-browser reporting can help identify AI websites, browser extensions, usage patterns, and certain data-handling activities.
This approach is already reflected in established enterprise technology.
Google documents generative AI and SaaS application reporting for managed Chrome environments, including site visits, managed browser and profile counts, and available information about sensitive-content transfers.
Microsoft Purview also supports specified data-security and compliance capabilities for AI interactions through supported environments. Available monitoring and protection depend on the relevant configuration, licensing, and prerequisites.
These capabilities illustrate how browser-level information can contribute to AI discovery and data protection.
However, browser visibility does not inherently identify every locally hosted model, desktop application, backend API integration, or autonomous agent.
It represents one part of the enterprise AI environment.
Network telemetry: understanding where AI traffic goes
Secure web gateways, firewalls, and Security Service Edge platforms can help identify connections to known AI services.
Microsoft Entra Global Secure Access, for example, documents network-based shadow AI discovery for generative AI applications, model-provider frameworks, and supported SaaS Model Context Protocol services.
Network monitoring can help identify which destinations are being accessed and which users or devices are associated with that activity.
A network connection alone, however, does not demonstrate that confidential information was transmitted.
Organizations should distinguish observed application usage from confirmed sensitive-data exposure.
Identity and application access: understanding permissions
AI services and agents increasingly interact with enterprise systems.
An application might request access to a mailbox or SharePoint content. An agent might operate through a service identity connected to business applications.
Identity reviews should therefore examine application registrations, consent grants, ownership, permissions, privileged access, and lifecycle management.
These signals help answer a different question from browser or network monitoring:
What information or systems could this AI application or agent access?
Cloud and model telemetry: understanding consumption
For internally developed AI applications, cloud and model telemetry may provide information such as request volume, token consumption, latency, errors, and workload attribution.
This information can support engineering, security, and FinOps teams.
It also helps distinguish an approved production workload from an experiment whose ownership or spending has become unclear.
The important principle is to correlate the available signals rather than assume that any one data source tells the entire story.
4. How Technology Companies Are Responding to Shadow AI
The technology market is developing across overlapping areas: network security, managed browsers, cloud discovery, data security, AI application protection, and AI governance.
These technologies address different parts of the problem.
Microsoft: discovery, data protection, and Microsoft 365 governance
Microsoft provides complementary capabilities through Defender for Cloud Apps, Entra, Microsoft Purview, and SharePoint administration.
Depending on deployment and licensing, these technologies can support application discovery, access governance, data-loss prevention, and reviews of potentially overshared Microsoft 365 information.
Microsoft recommends reviewing SharePoint and OneDrive permissions and content governance when preparing for Copilot and agents.
For organizations already invested in Microsoft 365, these capabilities provide an opportunity to build on existing controls.
Google: managed-browser reporting and data controls
Chrome Enterprise supports managed-browser reporting for generative AI and SaaS usage.
Google also documents additional capabilities through Chrome Enterprise Premium that can support data-protection and access-control policies.
This illustrates the role that browser-level information can play within a larger enterprise security architecture.
Netskope and Palo Alto Networks: network and access security
Netskope addresses AI usage through its broader cloud and data-security approach, including application visibility and applicable policy controls.
Palo Alto Networks describes AI Access Security capabilities for discovering generative AI applications, understanding usage, and applying relevant access and data-protection policies through supported products.
These approaches can help organizations distinguish sanctioned, tolerated, and unsanctioned AI use.
Cloudflare: protecting AI applications organizations build
Shadow AI is not limited to external websites employees visit.
Organizations also develop internet-facing applications that incorporate AI models.
Cloudflare’s AI Security for Apps supports discovery of certain AI-powered endpoints across protected web applications, alongside applicable protections for AI-specific threats.
This addresses another part of the AI environment: securing applications that organizations deploy themselves.
Cyera: understanding AI-related data exposure
Data-security providers such as Cyera approach AI risk through the relationship between AI assets, identities, and sensitive information.
Cyera’s published AI Security Posture Management materials describe discovery and inventory of AI assets, together with identity and sensitive-data context. These are the company’s stated capabilities, not an independent evaluation of deployment performance.
This data-centric perspective complements other discovery and governance capabilities.
Umbrion AI: connecting discovery with governance
Emerging AI governance platforms such as Umbrion AI are addressing the need to connect AI discovery with inventory, usage visibility, risk indicators, cost intelligence, and policies.
Umbrion’s approach includes browser-level visibility for identifying AI application usage in supported browser environments.
This information can contribute to a wider enterprise AI inventory and help organizations develop a clearer understanding of employee-facing AI adoption.
A broader governance process can then associate discovered applications with business owners, intended use cases, available consumption information, and applicable policies.
For example, a discovered application may warrant approval, further assessment, employee guidance, or restriction for a particular category of information.
As organizations evaluate Umbrion or other AI governance technologies, relevant considerations include the deployment method, supported browsers, available integrations, information collected, and how findings can be correlated with existing security and operational data.
A governance platform should be considered alongside existing investments rather than automatically positioned as a replacement for a firewall, secure web gateway, endpoint system, or data-loss prevention solution.
Discovery identifies activity. Governance connects that activity to business context and helps determine what happens next.
5. Healthcare, Public Sector, and Other Industries Need Context-Aware AI Governance
The consequences of unmanaged AI differ by industry and use case.
A marketing employee experimenting with publicly available information presents a different risk profile from a healthcare administrator processing patient information or a government employee working with sensitive citizen records.
Governance should account for those differences.
Healthcare: protecting information while improving workflows
Healthcare organizations may explore AI for document processing, clinical administration, revenue-cycle activities, patient communications, and knowledge retrieval.
An employee may see an immediate productivity benefit from uploading a document to an AI service.
But the organization needs to determine whether the tool is approved for that workflow, what information is involved, and which safeguards and contractual arrangements apply.
A healthcare AI readiness review can examine the intended use case, data access, approved services, human oversight, financial considerations, and applicable privacy and security requirements.
The goal is to enable useful workflows without creating unmanaged exposure.
Public sector: connecting governance with accountability
State and local government organizations often manage technology across multiple agencies, budgets, contracts, and operating models.
A centralized cloud contract does not necessarily mean that every department’s AI experimentation is visible.
One agency may use an approved enterprise assistant while another explores specialized applications or model APIs.
A practical governance model should clarify ownership, procurement, information handling, financial accountability, and approval processes.
An executive assessment can help connect technical findings with agency priorities and service-delivery outcomes.
Commercial enterprises: managing a growing ecosystem
Manufacturers, universities, financial-services organizations, and professional-services firms face similar questions involving intellectual property, customer information, operational systems, and employee productivity.
The aim should not be identical restrictions for every use case.
It should be applying controls proportionate to the information involved, the intended purpose, and the potential consequences.
6. The Right Response Is to Enable AI With Appropriate Guardrails
A strategy based entirely on blocking AI applications can overlook why employees adopt them in the first place.
Employees often turn to AI because they want to work more efficiently, automate repetitive tasks, or obtain information more quickly.
Unapproved usage can therefore reveal both governance gaps and unmet business needs.
If employees use an external assistant to search internal documentation, the organization should investigate whether an approved solution can address that requirement.
If developers are experimenting with model APIs, the organization should consider whether an approved development environment, appropriate cost controls, and data-handling guidance would support their work.
The NIST AI Risk Management Framework provides a useful structure through its Govern, Map, Measure, and Manage functions. The framework is voluntary and intended to be adapted to organizational context.
A practical AI governance program can distinguish among three categories:
| Classification | Illustrative approach |
|---|---|
| Approved | Enable defined business uses with appropriate controls and monitoring |
| Under review | Assess business need, data access, risk, contracts, and ownership |
| Prohibited for a specified use | Restrict that activity and provide an appropriate alternative where feasible |
The same AI service might be appropriate for preparing a presentation using public information but unsuitable for processing particular confidential records.
That distinction should be clear to employees.
Successful AI governance is not measured only by how many tools an organization blocks. It is measured by whether the organization can enable appropriate adoption while maintaining accountability for risk, cost, and business outcomes.
7. How Inforedge Helps Organizations Understand AI Readiness and Exposure
Technology discovery produces information.
Executive leadership needs that information translated into decisions.
At Inforedge, our approach brings cloud, AI, data, security, and operational perspectives together through focused assessments and readiness reviews.
Our advisory model can involve experienced technology leaders, including former CIOs and CISOs, to help connect technical findings with executive priorities, governance requirements, and implementation planning.
We help organizations work toward answering five questions:
- Where is AI being used today?
- Which uses are approved, and which require further review?
- What information and systems can those applications or agents access?
- Who owns the business purpose, financial responsibility, and governance decisions?
- What should the organization prioritize over the next 30, 60, and 90 days?
AI discovery and current-state assessments
An assessment can begin with existing application inventories, managed-browser information, network reporting, identity records, cloud telemetry, procurement data, and relevant security tools.
The precise scope depends on customer authorization, available technology, and accessible information.
Rather than assuming one discovery method is sufficient, the assessment can identify confirmed findings, relevant limitations, and areas requiring further investigation.
AI readiness and Microsoft 365 exposure reviews
For Microsoft-centric organizations, AI readiness requires more than purchasing Copilot licenses.
Microsoft recommends reviewing access permissions, potentially overshared SharePoint content, OneDrive governance, and applicable information-protection controls when preparing for Copilot and agents.
An Inforedge readiness review can examine the customer’s relevant Microsoft 365 configuration, available security reporting, access governance, and existing policies.
The resulting findings can distinguish opportunities to use current capabilities from those requiring configuration changes, additional licensing, or implementation work.
AI inventory, risk, usage, and cost visibility
Where appropriate, Inforedge can help customers evaluate technologies that support AI inventory, risk indicators, usage information, and cost intelligence.
Solutions such as Umbrion AI may be considered as part of a broader evaluation alongside Microsoft and other existing technology investments.
The appropriate solution and data sources depend on the customer’s actual environment and requirements.
Executive assessment and advisory reporting
A useful assessment should deliver more than a technical dashboard.
Depending on the agreed scope, an executive-ready report can include:
- Current-state observations and an AI inventory.
- Confirmed visibility gaps and potential data exposure.
- Microsoft 365 access and oversharing findings.
- Ownership, policy, and financial-management considerations.
- Prioritized recommendations and a practical implementation roadmap.
With input from experienced technical and executive advisors, the objective is to translate discovery into a clear set of actions.
This aligns with our broader approach to outcome-based IT services: technology initiatives should be tied to defined business problems and measurable results.
8. Where Should Organizations Start? A Practical 30/60/90-Day Approach
Organizations do not need to solve every AI governance challenge before improving visibility.
The first step is to determine which data sources already exist and which questions are most important.
There is no universally correct first technology. The starting point should reflect the environment.
| If your immediate priority is… | Relevant data sources to evaluate |
|---|---|
| Employee use of public AI websites | Managed-browser reporting and relevant network logs |
| Connections to unsanctioned AI services | Secure web gateway, firewall, or network telemetry |
| AI access to corporate identities and applications | Identity records, OAuth consent, and application inventories |
| Sensitive information accessible through Microsoft 365 | SharePoint, OneDrive, Purview, and access-governance reports |
| Developer AI applications and agent consumption | Cloud deployments, model API telemetry, and service identities |
| Duplicate subscriptions and unallocated expenses | Procurement, SaaS inventory, invoices, and FinOps reporting |
First 30 days: establish visibility
Begin with the data already available.
Identify major AI services, known business owners, current policies, and the systems that can provide relevant usage information.
Select discovery sources according to the environment. An organization may review browser and network activity, identity and application permissions, cloud telemetry, or several of these together.
Correlate findings with purchasing and business-ownership information where possible.
Develop an initial inventory and identify areas where coverage is incomplete.
Days 31–60: assess and prioritize
Evaluate discovered applications according to business purpose, ownership, data access, and applicable policies.
Review Microsoft 365 exposure where relevant. Determine whether unapproved usage points to an unmet business requirement.
Identify financial-management opportunities, including overlapping subscriptions or consumption without clear ownership.
Produce executive findings and agree on remediation priorities.
Days 61–90: implement and measure
Implement selected controls and address high-priority findings.
Establish an approved-use process, clear ownership, appropriate employee guidance, and ongoing reporting.
Where necessary, evaluate additional browser, network, data-security, or governance capabilities to address meaningful visibility gaps.
Measure progress through relevant outcomes, such as approved-use adoption, ownership coverage, remediation status, and cost attribution.
The result should be an ongoing operating practice—not an inventory produced once and forgotten.
The Bottom Line: AI Adoption Needs Visibility, Not Fear
AI is becoming a lasting part of enterprise technology and business operations.
The opportunity is too important to approach only through restriction, and the associated risks are too significant to leave unmanaged.
Shadow AI often reveals something important: employees and business units are discovering useful applications faster than formal processes can respond.
Organizations need to understand that demand, evaluate it, and provide a practical path to responsible adoption.
Browser, network, identity, endpoint, cloud, and data-security information all contribute different perspectives.
Together, these sources can help organizations understand not only which AI tools are being used, but also why they are being used, what information they can access, what they cost, and what should happen next.
You cannot govern an entire AI environment through a single data source. But you can develop a connected view of AI adoption and a clear process for turning that visibility into informed action.
That is where meaningful AI governance begins.
About Inforedge
Inforedge is an IT services and consulting company helping organizations address technology challenges across Microsoft cloud, AI readiness, data, application modernization, and IT service management.
Through focused assessments, Microsoft 365 exposure reviews, and technology advisory services, we help organizations understand their current environments, identify implementation priorities, and develop practical plans aligned with business objectives.
Our approach combines technical delivery with executive advisory perspectives, including former CIO and CISO experience where appropriate to the engagement.
Explore how Inforedge can support your AI readiness initiatives at www.inforedge.com.