shadow AIunapproved AI tools at workhow to find out which AI tools employees are usingshadow AI discoveryGoogle Workspace third-party app auditMicrosoft Entra shadow AI discoverymonday.com app approvalmonday MCP permissionsAI governance policysanctioned AI tools

How Do I Find Out Which AI Tools My Employees Are Using Without Permission?

You can answer this in an afternoon with admin consoles you already pay for. In Google Workspace, open Security, then Access and data control, then API controls, and read the list of accessed apps. In Microsoft 365, review consented app permissions in Entra ID. In monday.com, check installed apps and automation connections. Then read your card statements for small recurring software charges. Discover first, decide second, and expect the picture to be incomplete.

How Do I Find Out Which AI Tools My Employees Are Using Without Permission? — discovering shadow AI with admin consoles you already pay for
Peter Marroquin
Peter Marroquin

Implementation Support Consultant

August 24, 2026 · 10 min read

Helps business teams design, deploy, and govern monday.com systems and the AI that runs on top of them — from native AI agents and Sidekick to Claude agents connected through MCP.

If you have started wondering which AI tools your team is already using, you are asking a good question at a good time. Your people found useful tools faster than any approval process could keep up, and that is what capable teams do.

The numbers you will meet along the way do not all survive checking, so we start there.

Why is the most repeated shadow AI statistic worth checking first?

The number you meet everywhere is that 98% of organisations are affected by shadow AI. Two named publishers do print 98% here, and neither prints that.

Varonis, a data security vendor, prints this finding from its 2025 State of Data Security Report: “We found that 98% of organizations have unverified apps, including unsanctioned AI, also known as shadow AI, which increases the risk of exposure and data breaches.” That counts organisations with unverified apps of any kind, with unsanctioned AI named as one thing inside the category, and Varonis prints no shadow-AI-only percentage anywhere. The work behind it is an analysis of 1,000 real-world IT environments rather than a survey, so the population is organisations that ran a Varonis assessment, not a random sample of every business.

Ten days later, on its own shadow AI page, Varonis restates the figure from that same report: “In fact, our 2025 State of Data Security Report revealed that 98% of employees use unsanctioned apps across shadow AI and shadow IT use cases.” Organisations became employees, and unverified became unsanctioned. Same publisher, same report, two different statistics.

A separate 98% exists in Mimecast’s The State of Human Risk 2026, a survey of 2,500 IT security and IT decision makers across nine countries. There it means organisations that use AI in their own defensive security operations, which is not a count of staff using unapproved AI. When that same Mimecast article reaches for prevalence, it says only that research suggests the vast majority of organisations now have employees using unsanctioned AI apps. No number of its own, and “the vast majority” links to a statistics roundup whose headline figure counts workers, whereas Mimecast’s clause counts organisations.

The same 98% shadow AI statistic means three different things: Varonis counts organisations with unverified apps of any kind, its shadow AI page counts employees using unsanctioned apps, and Mimecast counts organisations using AI in their own security operations

It happens again with a second publisher. UpGuard, a security firm, published a State of Shadow AI report in November 2025, with fieldwork by Dynata and Prolific. Its press release says 90% of security leaders report using unapproved AI tools and 41% of employees find a way around blocks, from 542 security leaders and 1,020 employees. Its own report landing page says 88% and 45%, from 500 and 1,000.

None of this is a gotcha. Where two pages disagree, we use the one that publishes its method.

What do the numbers that survive actually say?

The strongest evidence is a global study of more than 48,000 people across 47 countries, led by the University of Melbourne with KPMG. Almost half of employees admit to using AI in ways that contravene company policies, including uploading sensitive company information into free public AI tools.

Then the finding that should shape your approach. Only 47% of employees say they have received AI training, and only 40% say their workplace has a policy or guidance on generative AI use. If a majority work somewhere with no published guidance, there is no approval process to route around.

University of Melbourne and KPMG study of more than 48,000 people across 47 countries: almost half of employees admit using AI against company policy, only 47% say they have received AI training, and only 40% say their workplace has a policy on generative AI

Where do you look first in Google Workspace ?

In the Google Admin console, go to Menu, then Security, then Access and data control, then API controls. Accessed apps are third-party apps used by users that have accessed Google data, which is where an AI tool signed into with a work Google account appears. Google’s documentation says details about third-party apps typically appear 24 to 48 hours after authorisation.

Google Workspace third-party app audit click path: Security, then Access and data control, then API controls, then Accessed apps — details appear 24 to 48 hours after authorisation

If your Chrome browsers are enrolled in Chrome management, a second report at Devices, then Chrome, then Reports, then Apps and extensions usage can be searched by permission, which is how you spot an extension that can read every page. Unmanaged browsers return nothing.

Where do you look first in Microsoft 365 ?

Start on the identity side. In Microsoft Entra ID, go to Enterprise apps, then All applications, then an application, then Permissions, and read both the Admin consent and User consent tabs. Reviewing needs at least the Cloud Application Administrator role. Microsoft prints two caveats: User consent permissions cannot be revoked in the portal, and revoking a permission does not stop the user consenting again tomorrow.

Then the network side. Microsoft ships a feature called Shadow AI discovery in Microsoft Entra Global Secure Access. It is network-based, identifying traffic to AI services including ChatGPT, Claude, SaaS MCP servers and AI model provider APIs such as the Anthropic Claude API. You view it under Global Secure Access, then Applications, then Insights and Analytics, using a Generative AI apps and tools filter.

Two limits before you plan around it. Global Secure Access only sees traffic forwarded to it, and Microsoft states that traffic which does not match a configured profile is not forwarded. The internet access profile also needs Microsoft Entra ID P1 or P2 plus Microsoft Entra Internet Access or the Microsoft Entra Suite, so it is not something you own by having Microsoft 365.

Microsoft Entra shadow AI discovery: review consented app permissions in Entra ID Enterprise apps, and network-based Shadow AI discovery in Global Secure Access, which sees only traffic forwarded to it

Microsoft has a deeper feature in preview too, Generative AI Insights, which uses TLS inspection and deep packet inspection to log actual prompt content.

What does monday.com already show you?

If you run monday.com, this part is reassuring. Account admins are the only users who can install apps, and when someone else tries, every admin receives an approval request by email and in the marketplace, with the app staying uninstalled until it is approved.

One exception to know about: on Enterprise accounts, admins can create a custom role that lets a named non-admin install and manage apps. Check Administration, then Apps, then Installed apps, and Administration, then Connections, then Automation connections, which shows what is actually connected. One honest limit: uninstalling an app does not automatically delete automations built with it.

monday.com app approval flow: a non-admin’s install attempt sends an approval request to every admin and the app stays uninstalled until approved — check Installed apps and Automation connections to see what is actually connected

On the Enterprise plan, admins also get an Audit Log under Administration, then Security, then the Audit tab. It displays events including failed logins, attachment downloads and the export of board data. That last one matters most, because the real concern is whether company data left.

What does the expense report tell you that no console can?

Individual AI subscriptions are bought on a card, so give finance the specific amounts. ChatGPT lists Go at 6 US dollars a month, Plus at 20 and Pro from 100. Claude lists Pro at 17 US dollars a month on an annual subscription billed at 200 up front, or 20 billed monthly.

Finding shadow AI subscriptions in the expense report: recurring monthly AI charges on personal cards that no admin console can see

What will none of these methods find?

Every method above finds AI tools that touched your accounts, your devices or your network. None of them sees an employee using a personal AI account on a personal phone, and no vendor here claims otherwise. The gaps are printed by the vendors themselves: Google’s app details lag 24 to 48 hours, Chrome reports lag up to 24 hours, and Global Secure Access sees only traffic that matches a forwarding profile. Even Anthropic’s Compliance API, whose session endpoints are in beta and open to Claude Enterprise organisations only, states that local session transcripts show what Claude was asked to do and what it returned, not what happened on the device.

So treat discovery as a strong sample, not a complete inventory. That is not a reason to skip it. A strong sample of what your team already reaches for is plenty to write a good policy on, and it is far more than you have today.

What shadow AI discovery cannot find: a personal AI account on a personal phone is invisible to every method — treat discovery as a strong sample, not a complete inventory

What do you do once you know ?

Give people a sanctioned version of what they were already using. By default, Anthropic does not use inputs or outputs from its commercial products, which include Claude for Work and the Anthropic API, to train its models, unless you report feedback or bugs or otherwise choose to allow it.

On monday.com, permissions carry across. monday.com publishes a connector for Claude, and its own monday MCP, which its support documentation says comes preinstalled on every account and, in the newer of two dated articles, is available on all plans at no additional cost.

Admins control it under Administration, then AI governance, then AI permissions, in the AI Connectors section, where a master toggle reads “Allow external AI agents to access your monday.com account data” and a Public Hosted MCP sub-permission covers agents including Claude and ChatGPT. You can limit it to chosen workspaces under Apps, then monday MCP, then Permissions. Each person who connects authorises individually, and monday.com says access never exceeds the permissions that person already has.

Then close the gap. Write the policy, because only 40% of employees say their workplace has one, and run the training, because only 47% say they have had any.

Shadow AI response plan: sanction the tools people already use, write the policy only 40% of workplaces have, and run the training only 47% of employees have received

Frequently asked questions

It becomes a problem when company data goes into a tool under an account you do not control. In the University of Melbourne and KPMG study, almost half of employees admit using AI in ways that contravene company policies.

Google’s documentation says details about third-party apps typically appear 24 to 48 hours after authorisation, and Chrome app and extension reports can take up to 24 hours.

Microsoft’s own deployment model puts discovery and monitoring before any blocking actions. UpGuard’s survey found that 41 percent of employees find a way around blocks, and its conclusion argues for guided enablement rather than restriction.

Not by default. Account admins are the only users who can install apps, and a request from anyone else goes to every admin, with the app staying uninstalled until it is approved. On Enterprise accounts, admins can grant a custom role that lets a named non-admin install apps.

No. monday.com’s support documentation says MCP comes preinstalled on every account, and the marketplace listing exists only for discoverability and documentation. Admins control whether it is on and which workspaces it covers.

Two publishers print 98% in this space and neither measures shadow AI prevalence. Varonis counts organisations with unverified apps of any kind, a category that includes unsanctioned AI. Mimecast’s separate 98% measures organisations using AI in their own defensive security operations.

Workiflow is a Platinum monday.com Partner and a member of Anthropic’s Claude Partner Network. If your admin can spend an afternoon in these consoles and a manager can write a one-page policy, do that first. When you want the sanctioned tools wired into the work itself.

Book a call
Sources & verification

Sources: Varonis, “2025 State of Data Security Report: Quantifying AI’s Impact on Data Risk”, report landing page and accompanying blog post (verified August 2026); Varonis, “Hidden Risks of Shadow AI” (verified August 2026); UpGuard, “State of Shadow AI” press release and report page, fieldwork by Dynata and Prolific (verified August 2026); The University of Melbourne and KPMG, “Trust, Attitudes and Use of Artificial Intelligence: A Global Study 2025”, University of Melbourne Faculty of Business and Economics newsroom (verified August 2026); Mimecast, “Shadow AI: the hidden threat quietly undermining your business” and The State of Human Risk 2026 (verified August 2026); Google Workspace Admin Help, “Control which third-party and internal apps access Google Workspace data” (verified August 2026); Google Chrome Enterprise and Education Help, “View app and extension usage details” (verified August 2026); Microsoft Learn, “Review permissions granted to enterprise applications” (verified August 2026); Microsoft Learn, “Shadow AI discovery in Global Secure Access” (verified August 2026); Microsoft Learn, “Generative AI Insights in Global Secure Access (preview)” (verified August 2026); Microsoft Learn, “Global Secure Access traffic forwarding profiles” (verified August 2026); Microsoft Learn, “Step 1: Discover AI apps, Prevent data leak to shadow AI” (verified August 2026); monday.com Support, “How to manage apps on your account” and “The Audit Log” (verified August 2026); monday.com Support, “Managing AI Connectors and MCP Access”, last modified 2 July 2026, and “Get started with monday MCP”, last modified 19 August 2026 (both verified August 2026), which are the sources used here for monday MCP, and the cost clause is the one printed in the 19 August article, because monday.com’s undated monday MCP product page still says an admin must install the app from the marketplace while both dated support articles say it comes preinstalled, and we have followed the dated operational documentation; OpenAI, ChatGPT pricing page (verified August 2026); Anthropic, Claude pricing page, Claude Enterprise solutions page, connector documentation, Privacy Center and Claude Platform documentation (verified August 2026); Anthropic, “Introducing the Services Track and Partner Hub of the Claude Partner Network” (verified August 2026); Google Search Central documentation updates and AI features guidance (verified August 2026).