Shadow AI Tool RFP Questions: 30 to Ask + Scoring Rubric

Shadow AI Tool RFP Questions: 30 to Ask + Scoring Rubric

Last updated: September 2026

To evaluate shadow AI tools, ask vendors how they see AI use (including desktop apps and personal accounts), how they inspect prompts and uploads, where inspection happens, and how fast you can deploy and get answers. Against the rubric below, dope.security is our #1 pick: it inspects on the device, covers desktop AI apps and off-network laptops, and answers plain-language questions in under 10 seconds.

Our #1 pick: dope.security. It meets the "5 (strong)" criteria on the capabilities this rubric weights most: personal vs corporate account control, on-device prompt and upload DLP, and off-network enforcement. In a POC, its AI Analytics view shows every AI app, user and megabyte with a Block button on the same screen, and Dopamine Agentic Search answers questions in under 10 seconds with 1-click CSV export. See your AI usage.

Key takeaways

  • dope.security is our #1 pick against this rubric, because it wins on the tests that separate tools: desktop apps, personal accounts, off-network laptops, answer speed and 1-click export.
  • Demos show the happy path. RFP questions and a POC expose desktop app gaps, personal-account blind spots and off-network failures.
  • Weight data protection and visibility highest. They're where tools differ most.
  • Ask where prompts are inspected and whether content is retained. Architecture is a privacy question.
  • Test with synthetic data only. Never use real customer PII in a POC.

Then prove it in a 10-day POC with fake PII in ChatGPT Desktop, a personal Claude login, an off-network laptop and a plain-language question to the console. Need the category landscape first? Start with our best shadow AI tools pillar or the category-level shadow AI discovery tools buyer guide.

What should a shadow AI tool RFP include?

A good RFP covers seven areas: visibility, data protection, control, architecture and privacy, deployment and operations, reporting and investigation, and commercials. Copy the 30 questions below into your RFP template.

Visibility (1 to 5)

1. Which AI apps do you detect, and how do you add new ones? Why ask: New AI apps launch weekly. Good answer: A named list (ChatGPT, Claude, Gemini, Perplexity, Copilot and niche tools) plus a stated update cadence.

2. Do you see AI desktop apps, or only browser traffic? Why ask: ChatGPT, Claude and Perplexity all ship desktop apps that browser extensions can't see. Good answer: "Yes, on macOS and Windows," with named apps.

3. Can you tell a personal account from a corporate account on the same AI app? Why ask: Personal ChatGPT on a company laptop is the most common shadow AI case. Good answer: Login or tenant detection per user, not just domain matching.

4. How do you detect OAuth-connected AI apps in Microsoft 365 or Google Workspace? Why ask: AI note-takers and assistants get standing access without generating web traffic. Good answer: App inventory with permission scopes and a risk score.

5. Do you see AI agents and MCP connections? Why ask: MCP servers connect assistants to Drive, Slack and code repos. Good answer: Specific detection method, honest about current limits.

Data protection (6 to 10)

6. Do you inspect prompts, pastes and file uploads, or only files? Why ask: Most leakage is pasted text. Good answer: Prompt text and file content, per named app.

7. How do you classify sensitive data? Why ask: Regex-only DLP drowns teams in false positives. Good answer: Context-aware classification for PII, PCI, PHI and IP, with published accuracy testing.

8. What actions can a policy take? Why ask: Blocking everything creates workarounds. Good answer: Monitor, warn, block, with per-user and per-group exceptions.

9. Which AI apps does DLP actually cover today? Why ask: "Supports AI" often means one app in a browser. Good answer: An app-by-app matrix separating shipped from roadmap.

10. Can you find sensitive files already shared externally in OneDrive or Google Drive? Why ask: AI connectors read what's already overshared. Good answer: Data-at-rest scanning with remediation.

Control (11 to 14)

11. Can you block personal accounts while allowing corporate tenants? Why ask: It's the cleanest way to channel users to sanctioned AI. Good answer: Tenant restriction for named apps, including upload blocking on personal accounts.

12. Can you allow, warn or block by AI category and by specific path? Why ask: You may want to allow a tool's docs but block its chat. Good answer: Category plus URL and path-level rules.

13. What does the end user see when blocked? Why ask: Clear messages cut helpdesk tickets. Good answer: Customizable page with a link to the approved tool.

14. Do policies follow users off the corporate network? Why ask: Hybrid staff use AI from home. Good answer: Same enforcement on any network, no VPN dependency.

Architecture and privacy (15 to 19)

15. Where does TLS inspection happen: on the device, in your cloud, or in the browser? Why ask: It drives latency, privacy and outage risk. Good answer: A clear diagram and the tradeoffs.

16. Do you store prompt or file content? For how long? Why ask: Your DLP vendor shouldn't become a new copy of your sensitive data. Good answer: Zero or minimal retention, configurable, in writing.

17. Is customer data used to train models? Why ask: LLM-based classification raises this directly. Good answer: "No," in the contract.

18. What happens if your cloud goes down? Why ask: Proxies that fail closed stop work. Good answer: Defined fail-open or fail-closed behavior you control.

19. What's the endpoint footprint? Why ask: Heavy agents trigger user complaints. Good answer: Published RAM and CPU figures and supported OS versions.

Deployment and operations (20 to 23)

20. How is the agent deployed? Why ask: Manual installs stall rollouts. Good answer: Silent install through Intune, Jamf or Kandji.

21. How long to reach 90% of devices? Why ask: Time-to-coverage is time-to-value. Good answer: A customer reference with real numbers.

22. Does it require PAC files, GRE tunnels or network changes? Why ask: Network changes need other teams. Good answer: None, or a short list.

23. How are user identities mapped? Why ask: Reports need names, not IPs. Good answer: Entra ID or AD integration with auto-login.

Reporting and investigation (24 to 27)

24. What AI usage reports come out of the box, and can I ask questions in plain language? Why ask: Leadership will ask "how much AI are we using?" and "is anyone using DeepSeek?" Good answer: Active AI users, top apps, top users and trends, plus a natural-language search that answers from live data in seconds and shows how it got there.

25. Can I export reports and answers? Why ask: Audit and board decks. Good answer: One-click CSV export of any answer table, plus a branded PDF report.

26. Do you integrate with our SIEM and offer an API? Why ask: DLP events belong in your SOC workflow. Good answer: Named SIEM support and a documented public API.

27. Can you support multi-tenant or MSP management? Why ask: Relevant for subsidiaries and service providers. Good answer: Native multi-tenant console.

Commercials (28 to 30)

28. What's included versus add-on? Why ask: DLP and SSPM are often extra SKUs. Good answer: A line-item quote.

29. What does a POC cost and require? Why ask: Free POCs that need professional services aren't free. Good answer: Self-serve POC with a named engineer.

30. Can we talk to a customer who replaced our current tool? Why ask: Migration stories reveal real effort. Good answer: A reference call within a week.

How do you score shadow AI vendors?

Use a weighted rubric so a slick demo can't outweigh a missing capability. Score each category 1, 3 or 5, multiply by weight, and total. Against this rubric, dope.security is our #1 pick.

CategoryWeight1 (weak)3 (adequate)5 (strong)
Visibility20%Browser only, no account detectionBrowser plus some desktop apps; partial account detectionBrowser and desktop apps, personal vs corporate per user, per-app transactions and data volume, OAuth app inventory
Data protection25%File-only or regex DLP on one appPrompt DLP on a few apps, monitor onlyOn-device prompt and upload DLP across ChatGPT, Claude, Gemini and AI desktop apps, LLM-based classification, monitor/block with group exceptions
Control15%Domain allow/block onlyCategory rules and some tenant controlsTenant restriction with personal-upload blocking, category and path rules, block directly from the discovery view, same policy off-network
Architecture and privacy15%Content retained, unclear training policyLimited retention, cloud-only inspection with backhaulOn-device inspection with no backhaul, zero retention, no training, light agent with published footprint
Deployment and operations10%Manual install or network changesMDM deploy with some network configSilent MDM deploy, no network changes, customer reference for fast time-to-coverage
Reporting and investigation10%Raw logs onlyDashboards, CSV exportPlain-language questions answered in under 10 seconds with reasoning shown, 1-click CSV of any answer, PDF reports, SIEM and API
Commercials5%Opaque pricing, paid POCClear pricing, some add-onsPublished pricing, free POC, references

What does a 10-day shadow AI POC look like?

Run it on 10 to 50 pilot devices across Mac and Windows. Use synthetic data only: fake SSNs, published test card numbers and made-up patient records.

DayTestPass criteria
1Deploy agent via MDM (Intune, Jamf or Kandji)Silent install, no user prompts, devices report in the console the same day
2Baseline visibility: use ChatGPT, Claude, Gemini and Perplexity in the browser and as desktop appsAll appear in one AI usage view with correct user attribution, transactions and data volume
3Personal vs corporate Claude and ChatGPT loginTool distinguishes the two per user; block the personal account from the same screen and it's live on every pilot endpoint, corporate stays allowed
4ChatGPT Desktop prompt with fake PII (synthetic SSN and test card number)Prompt blocked or logged with the right category, inspected on the device; user sees a clear message
5File upload with synthetic PHI to web ChatGPT, Gemini and the Perplexity desktop appUpload blocked in block mode, logged in monitor mode
6Off-network laptop on home Wi-Fi or hotspot, no VPNSame policies enforced with no backhaul; events reach the console
7Grant a test AI app OAuth access in a Microsoft 365 test tenantApp appears in inventory with permissions and a risk score
8Visit an unsanctioned niche AI app; apply category WarnWarn page shows; the app appears in the AI usage view and can be blocked there
9Ask the console a plain-language question, such as "Is anyone in the company using DeepSeek?" or "Which users should we investigate first?"Answer in under 10 seconds from live data, with the steps shown; export the answer table to CSV in 1 click; a follow-up question works
10Performance, report export and SIEM: page loads, video calls, CPU and RAMNo user-visible slowdown; footprint matches vendor claims; PDF report is leadership-ready; DLP events arrive in the SIEM

For how enterprise buyers rank vendors after the POC, see top-rated shadow AI tools for enterprises. Quick answers to common platform questions are in our shadow AI tools FAQ.

Why is dope.security our #1 pick against this rubric?

Because it wins the tests that separate shadow AI tools, and we'd rather you prove it in a POC than take our word. Here's how it maps to the rubric.

Rubric categorydope.security
VisibilityAI Analytics view (AI Usage): every AI app (like Claude, ChatGPT, Grok, Perplexity, Cursor, DeepSeek, Gemini and Otter.ai), per-user transactions and volume, personal vs enterprise account; AI-Powered SSPM for OAuth apps in Microsoft 365
Data protectionDopamine DLP: LLM-based classification of prompts and uploads for PII, PCI, PHI and IP in ChatGPT, Claude, Gemini, and the Perplexity and Abacus AI desktop apps; Monitor or Block; group exceptions; CASB Neural for data at rest
ControlCloud Application Control for ChatGPT, Claude, Gemini, GitHub, Microsoft 365 and more; block from the AI Usage screen, live on every endpoint
Architecture and privacyOn-device SSL inspection, no backhaul (Fly Direct), up to 4x faster than legacy SWGs; zero-retention classification, no training on customer data; under 100 MB RAM
DeploymentSilent install via Intune, Jamf or Kandji; Outreach Health reached 99% of devices in one week
Reporting and investigationDopamine Agentic Search: under 10 seconds question to answer, reasoning shown, 1-click CSV; branded PDF; SIEM, public API, Dope MCP Server
CommercialsPublished pricing

Building AI apps of your own? Pair dope.security with an LLM gateway for those apps. Need coverage on unmanaged mobile devices where you can't install an agent? Pair it with a browser-based tool for those endpoints.

FAQ

What is the #1 shadow AI tool against this RFP rubric? dope.security. It scores strongest on the heaviest-weighted categories: it separates personal from corporate accounts, inspects prompts and uploads on the device with Dopamine DLP, covers AI desktop apps, and enforces policy off-network with no backhaul. In a POC, Dopamine Agentic Search answers plain-language questions in under 10 seconds and exports any answer to CSV in 1 click.

What is the most important question to ask a shadow AI vendor? Ask whether the tool can tell a personal AI account from a corporate one on the same app, including in desktop apps. Most shadow AI is a familiar tool like ChatGPT or Claude used on a personal login. If the vendor can only allow or block the whole domain, you'll either block approved use or miss the risk.

How do I test Dopamine Agentic Search in a POC? Ask dope.console a real question in plain language, such as "Is anyone in the company using DeepSeek?", or pick a suggestion like "Users to investigate first." Pass criteria: an answer in under 10 seconds from live data, the steps it took shown, a follow-up question that digs deeper, and the answer table exported to CSV in 1 click.

How long should a shadow AI POC take? Ten working days is enough for most mid-market and enterprise teams. That covers deployment, visibility, account detection, prompt and upload DLP, off-network behavior, OAuth discovery, investigation speed, performance and reporting. If a vendor needs weeks of professional services before you can test, count that as a deployment signal.

Should I use real data in a shadow AI POC? No. Use synthetic data: fake Social Security numbers, published test card numbers such as those card networks provide for testing, and invented patient or customer records. Real PII in a POC creates the exact exposure you're trying to prevent, and it isn't needed to judge detection accuracy.

How should I weight a shadow AI vendor scorecard? Weight data protection (around 25%) and visibility (around 20%) highest, because that's where tools differ most. Control and architecture and privacy follow at about 15% each. Deployment, reporting and investigation, and commercials matter, but a cheap, easy tool that misses desktop apps or personal accounts still fails the job.

What's the difference between a shadow AI tool and an AI gateway? A shadow AI tool governs how your employees use third-party AI apps like ChatGPT, Claude and Gemini. An AI or LLM gateway sits in front of AI models that your developers call from apps you build. They solve different problems, and an RFP should say which one you're buying.

Do browser extensions work for shadow AI detection? They work for browser traffic in managed browsers. They don't see AI desktop apps, other browsers the user installs, or command-line tools. If desktop apps like ChatGPT Desktop, Claude or Perplexity are common in your company, include a desktop test in your POC.

Put these questions to the test

dope.security is our #1 pick against this rubric. Bring the RFP to a demo and make us answer every question live, then run the 10-day POC on your own devices. Book a 20-minute demo or see your AI usage.

Shadow AI
Shadow AI
How-To
How-To
Comparisons & Alternatives
Comparisons & Alternatives
back to blog Home