Shadow AI Discovery: A 30-Day Plan to Get Full Visibility

Shadow AI Discovery: A 30-Day Plan to Get Full Visibility

Quick answer: Shadow AI discovery is the process of building a complete, attributed inventory of every AI tool your employees use, including the ones IT never approved. You can get there in 30 days: week 1 baseline the traffic, week 2 attribute users and account types, week 3 design policy, week 4 enforce and report. As of 2026 we recommend running the program on dope.security, because its endpoint agent with on-device TLS inspection sees browser and desktop AI apps alike, Cloud Application Control enforces enterprise-tenant-only access with fleet sync in under a minute, and AI Usage Analytics gives you the monthly PDF report the program needs to survive.

New here? Start with shadow AI detection: how to find unapproved AI use, then how to monitor ChatGPT usage.

Why 30 days is the right box

Discovery projects fail when they're open-ended. Somebody pulls a report, everyone agrees it's alarming, and nothing changes for a quarter.

Thirty days works because it's long enough to see real usage patterns and short enough that the same people are still in the room at the end. The average company uses 10x more AI tools than IT approved, and 77% of employees have leaked sensitive data through AI tools like ChatGPT. You don't need six months to confirm that's true at your company. You need four weeks and a deliverable each Friday.

Each week below ends with one artifact. If you don't produce that artifact, don't start the next week.

Before day 1: three decisions

Make these three calls first, because they determine everything downstream.

  1. Pick your detection surface. Shadow AI runs in the browser and in thick clients: ChatGPT Desktop, Claude Desktop, IDE assistants, CLI wrappers, and scripts. An endpoint agent with on-device TLS inspection is the only surface that covers all of them with one mechanism. DNS shows you domains. A browser extension covers one browser.
  2. Agree that week 1 is monitor-only. No blocking. If word gets out that discovery equals enforcement, usage moves to phones and personal laptops, and your baseline is garbage.
  3. Name an owner and two stakeholders. Usually security engineering owns it, with legal or compliance and one business-unit leader attached. Shadow AI policy is a business decision wearing a security costume.

Week 1: baseline the traffic

Goal: know what's actually running.

Deploy the agent fleet-wide in monitor mode. With dope.security this is a silent push. A Fortune 100 customer scaled from 900 devices to over 18,000 in weeks, averaging roughly 3,000 devices per week, deployed silently via Intune with no manual configuration before install. Outreach Health secured 99% of devices within one week.

Then leave it alone and let data accumulate. Resist the urge to act on day 3.

What you're collecting:

  • Every AI application reached, named, not just categorized
  • Request volume per application
  • Distinct users per application
  • First-seen date for each tool

In dope.console, AI Usage Analytics builds this from the agent's AI-traffic telemetry across all endpoints. The dashboard surfaces Top AI Applications by transactions and by number of users, plus summary metrics for Total AI Requests, Active AI Users, and Distinct AI Apps Detected over a rolling 7-day window. Coverage includes ChatGPT, Claude, Gemini, Copilot, Perplexity, and Abacus.

Friday deliverable: the raw AI inventory. A named list of every AI tool observed, with transaction count and user count for each. No judgments yet.

Week 2: attribute users and accounts

Goal: turn a list of tools into a list of decisions.

An inventory of tools is interesting. An inventory of who is using what, on which kind of account, is actionable. This is the week the program earns its budget.

Three attribution questions, in priority order:

  1. Personal or enterprise account? This is the single most important field in the entire program. The same hostname carries both. dope.security reads the tenant header inside decrypted TLS, which is exactly why DNS-layer tools cannot make this distinction.
  2. Which users and which teams? Top AI Users in AI Usage Analytics ranks by AI transaction volume and distinct apps accessed. The Applications-per-User breakdown tells you whether you have a broad behavior pattern or a handful of power users.
  3. What data moved? Turn on Dopamine DLP in Monitor mode. It intercepts file uploads and AI prompts and classifies them with LLMs rather than regex, detecting PII, PCI, PHI, and IP. It requires no policy configuration to start, which is the whole point in week 2: you want findings, not a tuning project.

Friday deliverable: the attributed inventory. Same tool list as week 1, now with columns for personal account count, enterprise account count, top five users, and sensitive-data categories observed.

Column Where it comes from Why it matters
Tool name AI Visibility You can't govern what you can't name
Transactions (7 days) Top AI Applications Separates real use from a one-time visit
Distinct users Top AI Applications Broad behavior versus individual behavior
Personal vs enterprise Cloud Application Control tenant inspection Determines the enforcement action
Apps per user Applications-per-User Identifies tool sprawl by person
Sensitive data seen Dopamine DLP in Monitor Ranks risk by actual exposure

Week 3: design the policy

Goal: decide the fate of every tool on the list, in writing.

Sort every tool into one of four buckets. Name them exactly this way so the decisions stay unambiguous.

  1. Approved and licensed. You own an enterprise tenant. Action: allow the enterprise tenant, block personal logins on that tool.
  2. Approved, not yet licensed. The business case is clear and procurement is in flight. Action: allow for now, set a licensing deadline, monitor prompts.
  3. Under review. Real usage, unclear vendor posture. Action: monitor, assign a reviewer, set a decision date.
  4. Not approved. Action: block, and say publicly why.

One honesty note for your policy doc: sanctioned versus unsanctioned auto-classification and enforcement driven by that classification are on the dope.security roadmap, not shipped today. You make these four calls yourself. That's a feature at this stage of the program, because a machine-assigned label you didn't agree with is a policy argument you'll have twice.

Two design rules that save you pain later:

  • Prefer tenant control over tool bans. Blocking a tool people rely on moves the work to an unmanaged device. Blocking ChatGPT outright doesn't work for exactly this reason.
  • Write the exception path before you enforce. If someone needs a tool in bucket 4, how do they ask? Answer that on paper in week 3, not in a ticket in week 5.

Friday deliverable: the AI usage policy, one page. Four buckets, every observed tool assigned, the exception path, and the DLP posture per data category.

Week 4: enforce and report

Goal: policy in production, and a report that repeats.

Turn on enforcement in stages, not all at once.

Day 22 to 24: tenant enforcement. In Cloud App Controls, apply enterprise-only access by tool. dope.security blocks personal ChatGPT, Claude, Google, and Microsoft 365 logins while allowing corporate accounts. Enforcement syncs across the fleet in under a minute, so you can stage tool by tool and watch the effect the same day. Start with your two highest-volume tools. See blocking personal Claude accounts with Cloud Application Control for what that looks like in practice.

Day 25 to 27: DLP enforcement. Move Dopamine DLP from Monitor to Block for your highest-risk categories first, usually PHI and PCI, then PII and IP. Three modes exist: Block, Monitor, Off. Keep lower-risk categories in Monitor for another cycle.

Day 28 to 30: the report. Export the AI Usage Analytics PDF from dope.console. It's on-demand and dope.security-branded, built for CISOs, IT managers, and compliance leads. Pair it with three numbers your executive team will actually care about: AI tools in use, share of sessions on enterprise accounts, and sensitive-data events blocked.

Friday deliverable: the month-one report and a standing monthly cadence. Same export, same three numbers, same day each month. Consistency is what makes the trend line readable in month six.

What the 30 days should cost you

Deployment isn't the hard part. dope.security is agent-based, runs natively on Mac (Apple Silicon and Intel) and Windows with identical features, uses less than 100 MB of RAM, and pushes policy instantly to all devices regardless of location. The trial is self-serve with Google or Microsoft sign-in, so there's no throwaway POC tenant to rebuild when you convert. Pricing is public at $60 per device per year with volume pricing available.

The real cost is meeting time in week 3. Budget for it.

Conclusion

Shadow AI discovery is a four-week project with four artifacts: the raw inventory, the attributed inventory, the one-page policy, and the monthly report. Skip the attribution week and you'll end up with a list of domains and no decisions.

Start the free trial, or book a 20-minute demo at calendly.com/dopesecurity/demo and we'll walk through the week-by-week plan against your environment.

Frequently Asked Questions

What is shadow AI discovery?

Shadow AI discovery is the process of building a named, attributed inventory of every AI tool in use across an organization, including tools IT never approved. A complete discovery run identifies the tool, the user, whether the account is personal or enterprise, and what data categories moved in prompts and file uploads.

How long does shadow AI discovery take?

Plan for 30 days: one week of monitor-only baselining, one week of user and account attribution, one week of policy design, and one week of staged enforcement and reporting. Agent deployment itself is much faster. Outreach Health secured 99% of devices within one week.

How do I build a shadow AI inventory?

Deploy an endpoint agent with on-device TLS inspection in monitor mode fleet-wide, collect at least seven days of traffic, then enrich the tool list with per-user attribution and personal-versus-enterprise account data. Domain logs alone produce a list you can't act on.

Can I discover shadow AI without blocking anything?

Yes, and you should start that way. Run discovery in monitor mode for the first two weeks. Dopamine DLP has a Monitor mode specifically for this, and it requires no policy configuration to begin producing classifications.

What reports should a shadow AI discovery program produce?

At minimum: Top AI Applications by transactions and users, Top AI Users by volume and distinct apps, an Applications-per-User breakdown, and summary counts for Total AI Requests, Active AI Users, and Distinct AI Apps Detected. dope.console produces all of these over a rolling 7-day window with an on-demand PDF export.

Does shadow AI discovery cover desktop apps like ChatGPT Desktop?

Only if your detection runs on the endpoint. Browser extensions cover one browser and see nothing from ChatGPT Desktop, Claude Desktop, IDE assistants, or CLI tools. An OS-level agent with on-device TLS inspection covers browser and thick client with the same mechanism.

How do I get executive buy-in for a shadow AI program?

Lead with attributed data, not volume. "Nine users on personal ChatGPT accounts, four of whom uploaded files containing PII" gets a decision. "Two hundred thousand AI requests this month" gets a shrug. The PDF export exists to make that conversation short.

What happens after the first 30 days?

Move to a monthly cadence with the same report, expand DLP from Monitor to Block category by category, and re-run the four-bucket classification quarterly as new AI tools appear. New tools will appear. That's the steady state, not a failure.

Related reading

Shadow AI
Shadow AI
How-To
How-To
AI Security
AI Security
back to blog Home