Somewhere in your organization, a well-meaning employee pasted something into a consumer AI tool this week. It probably helped them. It definitely wasn't logged. The risk conversation most leadership teams are having is about whether to adopt AI, when the accurate conversation is about the adoption that already happened without them.
It rarely looks like defiance. It looks like a nurse manager drafting patient-facing letters on a personal account because the templates were slow. A junior associate pasting deposition excerpts into a browser tab to get a summary before a partner meeting. A claims analyst who installed a browser extension that reads every page she opens, including the ones with member data on them. A department head who put a monthly AI subscription on a corporate card, categorized as software, and never mentioned it because nobody asked.
Each of those people was trying to do their job faster. None of them read the consumer terms of service, which in many cases permit the vendor to retain inputs and use them to improve models. In a regulated setting, that single clause is the whole problem. Records that should never leave your control were sent to an endpoint you have no contract with, no retention terms for, and no log of.
The standard first response is a policy email banning AI tools. It fails for a specific reason: the ban removes the sanctioned option while leaving the unsanctioned ones exactly as available as they were before. The employee who found a two-hour time savings does not give it back. They get quieter about it.
Prohibition also destroys the one thing you most need, which is honest information. Once using AI is a fireable offense, nobody will tell you where it is being used, what data has already gone out, or which workflows now silently depend on it. You have converted a visibility problem into a visibility problem plus a trust problem.
There is a narrower version of prohibition that does work, and it comes later: a short, specific list of things that may never be pasted into any AI tool, sanctioned or not. That rule survives because it is enforceable and because employees can see the logic. A blanket ban survives only on paper.
The goal of discovery is a map, not a list of names. If the exercise feels like an investigation, people will hide, and your map will be wrong. Three sources get you most of the way. Expense records surface the departmental subscriptions. Network and DNS logs surface the consumer endpoints and browser extensions, at the domain level, without reading anyone's prompts. Structured conversations with team leads surface the workflows, which is the part the logs cannot tell you: what task the tool was solving, and what data it touched.
An amnesty window makes the conversations honest. State plainly that anything disclosed in the next thirty days carries no consequence, that the purpose is to build a sanctioned path, and mean it. Then triage what you find by data sensitivity, not by tool. A marketing team drafting social copy on a consumer account is a low-priority finding. Anyone who has pasted PHI, privileged material, or customer financial records anywhere needs to be at the top of the list, because you may have disclosure or notification questions to work through with counsel.
People stop using unsanctioned tools when the sanctioned one is genuinely better for their task, not when the memo gets sterner. Better means fast, available, and covered by terms you actually negotiated. This is where enterprise deployment differs from a consumer account in ways that matter to a regulator: your data is not used to train models, retention is defined in a contract, and every interaction is logged in a form you can review. Those three properties are contractual and architectural facts you can point to, and they are the core of our Governed-by-Design framework.
The pieces are concrete.
Logging every AI interaction is visibility, and visibility can shade into surveillance if you let it. Be explicit with staff about what the logs are for: reconstructing what the system did when a question arises, not scoring individuals on their prompts. Put the review policy in writing, restrict who can read the logs, and audit that access too. Employees will accept oversight of a work tool when the rules are stated up front. They resent oversight that arrives quietly after the fact, and resentment is what built the shadow inventory in the first place.
If you are not sure where to start, start with the map. Our free Claude Readiness Assessment walks through exactly these questions: where AI is already in use, what data it can reach, and what a governed deployment would need to look like in your environment.
Shadow AI is evidence of demand. Your people found the value before you built the guardrails, which means the appetite problem is already solved. What remains is the visibility problem, and that one has a known fix.