How Do I Find Out Which AI Tools My Employees Are Using Without Permission?
You can answer this in an afternoon with admin consoles you already pay for. In Google Workspace, open Security, then Access and data control, then API controls, and read the list of accessed apps. In Microsoft 365, review consented app permissions in Entra ID. In monday.com, check installed apps and automation connections. Then read your card statements for small recurring software charges. Discover first, decide second, and expect the picture to be incomplete.


Helps business teams design, deploy, and govern monday.com systems and the AI that runs on top of them — from native AI agents and Sidekick to Claude agents connected through MCP.
If you have started wondering which AI tools your team is already using, you are asking a good question at a good time. Your people found useful tools faster than any approval process could keep up, and that is what capable teams do.
The numbers you will meet along the way do not all survive checking, so we start there.
Why is the most repeated shadow AI statistic worth checking first?
The number you meet everywhere is that 98% of organisations are affected by shadow AI. Two named publishers do print 98% here, and neither prints that.
Varonis, a data security vendor, prints this finding from its 2025 State of Data Security Report: “We found that 98% of organizations have unverified apps, including unsanctioned AI, also known as shadow AI, which increases the risk of exposure and data breaches.” That counts organisations with unverified apps of any kind, with unsanctioned AI named as one thing inside the category, and Varonis prints no shadow-AI-only percentage anywhere. The work behind it is an analysis of 1,000 real-world IT environments rather than a survey, so the population is organisations that ran a Varonis assessment, not a random sample of every business.
Ten days later, on its own shadow AI page, Varonis restates the figure from that same report: “In fact, our 2025 State of Data Security Report revealed that 98% of employees use unsanctioned apps across shadow AI and shadow IT use cases.” Organisations became employees, and unverified became unsanctioned. Same publisher, same report, two different statistics.
A separate 98% exists in Mimecast’s The State of Human Risk 2026, a survey of 2,500 IT security and IT decision makers across nine countries. There it means organisations that use AI in their own defensive security operations, which is not a count of staff using unapproved AI. When that same Mimecast article reaches for prevalence, it says only that research suggests the vast majority of organisations now have employees using unsanctioned AI apps. No number of its own, and “the vast majority” links to a statistics roundup whose headline figure counts workers, whereas Mimecast’s clause counts organisations.

It happens again with a second publisher. UpGuard, a security firm, published a State of Shadow AI report in November 2025, with fieldwork by Dynata and Prolific. Its press release says 90% of security leaders report using unapproved AI tools and 41% of employees find a way around blocks, from 542 security leaders and 1,020 employees. Its own report landing page says 88% and 45%, from 500 and 1,000.
None of this is a gotcha. Where two pages disagree, we use the one that publishes its method.
What do the numbers that survive actually say?
The strongest evidence is a global study of more than 48,000 people across 47 countries, led by the University of Melbourne with KPMG. Almost half of employees admit to using AI in ways that contravene company policies, including uploading sensitive company information into free public AI tools.
Then the finding that should shape your approach. Only 47% of employees say they have received AI training, and only 40% say their workplace has a policy or guidance on generative AI use. If a majority work somewhere with no published guidance, there is no approval process to route around.

Where do you look first in Google Workspace ?
In the Google Admin console, go to Menu, then Security, then Access and data control, then API controls. Accessed apps are third-party apps used by users that have accessed Google data, which is where an AI tool signed into with a work Google account appears. Google’s documentation says details about third-party apps typically appear 24 to 48 hours after authorisation.

If your Chrome browsers are enrolled in Chrome management, a second report at Devices, then Chrome, then Reports, then Apps and extensions usage can be searched by permission, which is how you spot an extension that can read every page. Unmanaged browsers return nothing.
Where do you look first in Microsoft 365 ?
Start on the identity side. In Microsoft Entra ID, go to Enterprise apps, then All applications, then an application, then Permissions, and read both the Admin consent and User consent tabs. Reviewing needs at least the Cloud Application Administrator role. Microsoft prints two caveats: User consent permissions cannot be revoked in the portal, and revoking a permission does not stop the user consenting again tomorrow.
Then the network side. Microsoft ships a feature called Shadow AI discovery in Microsoft Entra Global Secure Access. It is network-based, identifying traffic to AI services including ChatGPT, Claude, SaaS MCP servers and AI model provider APIs such as the Anthropic Claude API. You view it under Global Secure Access, then Applications, then Insights and Analytics, using a Generative AI apps and tools filter.
Two limits before you plan around it. Global Secure Access only sees traffic forwarded to it, and Microsoft states that traffic which does not match a configured profile is not forwarded. The internet access profile also needs Microsoft Entra ID P1 or P2 plus Microsoft Entra Internet Access or the Microsoft Entra Suite, so it is not something you own by having Microsoft 365.

Microsoft has a deeper feature in preview too, Generative AI Insights, which uses TLS inspection and deep packet inspection to log actual prompt content.
What does monday.com already show you?
If you run monday.com, this part is reassuring. Account admins are the only users who can install apps, and when someone else tries, every admin receives an approval request by email and in the marketplace, with the app staying uninstalled until it is approved.
One exception to know about: on Enterprise accounts, admins can create a custom role that lets a named non-admin install and manage apps. Check Administration, then Apps, then Installed apps, and Administration, then Connections, then Automation connections, which shows what is actually connected. One honest limit: uninstalling an app does not automatically delete automations built with it.

On the Enterprise plan, admins also get an Audit Log under Administration, then Security, then the Audit tab. It displays events including failed logins, attachment downloads and the export of board data. That last one matters most, because the real concern is whether company data left.
What does the expense report tell you that no console can?
Individual AI subscriptions are bought on a card, so give finance the specific amounts. ChatGPT lists Go at 6 US dollars a month, Plus at 20 and Pro from 100. Claude lists Pro at 17 US dollars a month on an annual subscription billed at 200 up front, or 20 billed monthly.

What will none of these methods find?
Every method above finds AI tools that touched your accounts, your devices or your network. None of them sees an employee using a personal AI account on a personal phone, and no vendor here claims otherwise. The gaps are printed by the vendors themselves: Google’s app details lag 24 to 48 hours, Chrome reports lag up to 24 hours, and Global Secure Access sees only traffic that matches a forwarding profile. Even Anthropic’s Compliance API, whose session endpoints are in beta and open to Claude Enterprise organisations only, states that local session transcripts show what Claude was asked to do and what it returned, not what happened on the device.
So treat discovery as a strong sample, not a complete inventory. That is not a reason to skip it. A strong sample of what your team already reaches for is plenty to write a good policy on, and it is far more than you have today.

What do you do once you know ?
Give people a sanctioned version of what they were already using. By default, Anthropic does not use inputs or outputs from its commercial products, which include Claude for Work and the Anthropic API, to train its models, unless you report feedback or bugs or otherwise choose to allow it.
On monday.com, permissions carry across. monday.com publishes a connector for Claude, and its own monday MCP, which its support documentation says comes preinstalled on every account and, in the newer of two dated articles, is available on all plans at no additional cost.
Admins control it under Administration, then AI governance, then AI permissions, in the AI Connectors section, where a master toggle reads “Allow external AI agents to access your monday.com account data” and a Public Hosted MCP sub-permission covers agents including Claude and ChatGPT. You can limit it to chosen workspaces under Apps, then monday MCP, then Permissions. Each person who connects authorises individually, and monday.com says access never exceeds the permissions that person already has.
Then close the gap. Write the policy, because only 40% of employees say their workplace has one, and run the training, because only 47% say they have had any.

Frequently asked questions
It becomes a problem when company data goes into a tool under an account you do not control. In the University of Melbourne and KPMG study, almost half of employees admit using AI in ways that contravene company policies.
Google’s documentation says details about third-party apps typically appear 24 to 48 hours after authorisation, and Chrome app and extension reports can take up to 24 hours.
Microsoft’s own deployment model puts discovery and monitoring before any blocking actions. UpGuard’s survey found that 41 percent of employees find a way around blocks, and its conclusion argues for guided enablement rather than restriction.
Not by default. Account admins are the only users who can install apps, and a request from anyone else goes to every admin, with the app staying uninstalled until it is approved. On Enterprise accounts, admins can grant a custom role that lets a named non-admin install apps.
No. monday.com’s support documentation says MCP comes preinstalled on every account, and the marketplace listing exists only for discoverability and documentation. Admins control whether it is on and which workspaces it covers.
Two publishers print 98% in this space and neither measures shadow AI prevalence. Varonis counts organisations with unverified apps of any kind, a category that includes unsanctioned AI. Mimecast’s separate 98% measures organisations using AI in their own defensive security operations.