Your Staff Is Using AI Tools You Don't Know About. Here's How to Find Out.

Shadow AI is employees using AI tools without approval and feeding them client data. Most firms have no idea how many AI apps touch their data.

A paralegal discovers an AI summarization tool that cuts brief review time in half, signs up with a work email, and starts pasting case documents into it. An associate finds a free AI transcription service and starts running client meeting recordings through it. A tax preparer uses an AI tax research tool a friend recommended and uploads a client’s financial statements to test it.

None of them asked permission. None of them read the tool’s terms of service. None of them checked whether the tool retains uploaded data or uses it for training. And nobody in firm management knows any of this is happening.

This is shadow AI, and by most estimates it’s happening at your firm right now.

The scale of the problem

Microsoft’s own research from earlier this year found that 78% of knowledge workers have used AI tools at work, and more than half of them never told their employer. Push Security, which tracks enterprise SaaS and AI adoption, has documented a steady increase in unauthorized AI app signups throughout 2026. The pattern is consistent: employees discover tools that genuinely make their work faster, adopt them without going through any approval process, and feed company data into them.

In a law firm, “company data” means privileged communications, litigation strategy, client financials, and case details. In a CPA firm, it means tax returns, financial statements, and client identifying information. The sensitivity of the data makes the shadow AI problem materially different from the shadow IT problem of five years ago, when the worst case was someone storing files in a personal Dropbox.

Why people don’t ask

It’s not malicious. Employees use unauthorized tools for the same reason they always have: the tool is faster than the approved alternative, or there is no approved alternative. If your firm doesn’t have an AI policy, there’s nothing to violate. If the firm’s official position is silence, employees fill the vacuum with whatever works.

We wrote in August about what a practical AI use policy needs to cover. But a policy only works if you can verify compliance, and that requires knowing what’s actually in use.

How to find out what’s in your environment

You don’t need to interrogate your staff or install surveillance software. There are practical ways to get visibility.

Check your M365 admin portal for OAuth consent grants. When employees connect an AI tool to their work account, it typically requests OAuth permissions to read email, access files, or both. These consents are visible in the Microsoft Entra admin center under Enterprise Applications. Sort by recently added and look for applications you don’t recognize. In June, we wrote about the specific risks of these OAuth tokens and how to review and revoke them.

Review sign-in logs for unfamiliar applications. Microsoft Entra sign-in logs show every application your users have authenticated to. Filter for the past 90 days and look for AI-related services. You may be surprised by what shows up.

Ask your staff directly (non-punitively). Send a brief survey: “What AI tools are you using for work? We’re building an approved list and want your input.” Frame it as inclusion, not enforcement. You’ll learn more from a voluntary survey than from an audit, and the employees using AI tools are usually the ones who would benefit most from an approved, secure alternative.

Look at network-level reports. Your firewall and web filtering tools can show which cloud services your users are connecting to, even when they’re using personal accounts. If someone is uploading files to an AI service from a work device on your network, it shows up in traffic logs regardless of which account they signed in with. Your IT provider can pull these reports without installing anything new.

Check browser extensions. AI assistants that run as browser extensions often have access to every page the user visits, including webmail, document management systems, and client portals. Browser extension audits are straightforward through endpoint management tools.

What to do with what you find

You will probably find more AI tools in use than you expected. That’s normal. The goal isn’t to ban everything. The goal is to sort what you find into three categories:

Tools you can approve with conditions. Some AI tools have enterprise plans with data retention controls, contractual protections, and the ability to disable training on your data. If the tool genuinely helps your staff and the vendor can meet your security requirements, approve it and set the terms.

Tools that need to be replaced. If an employee is using a consumer AI service with no data protections, find an approved alternative that does the same job. Banning the tool without providing a replacement just pushes the activity further underground.

Tools that need to be revoked immediately. Anything with OAuth access to your M365 environment that you didn’t authorize should be revoked. Anything that has access to email, files, or calendar data without a business justification should be revoked. This isn’t optional if you’re subject to attorney-client privilege obligations or handling regulated financial data.

After the initial cleanup, put a process in place. Block user consent for OAuth grants (require admin approval for new apps), establish an AI tool request process, and review the enterprise applications list quarterly. These aren’t dramatic changes. They’re the same vendor management discipline that your cyber insurance carrier is already asking about.

The risk is data you can’t account for

Every unauthorized AI tool that touches client data creates a data flow your firm can’t account for, can’t audit, and can’t produce in response to a discovery request or regulatory inquiry. If opposing counsel asks where a privileged document ended up, “we think a paralegal might have uploaded it to an AI tool we didn’t know about” is not an answer anyone wants to give.

The firms handling this well aren’t trying to stop their employees from using AI. They’re making sure the AI tools in use are approved, secured, and documented, so when someone asks where client data goes, they have an answer.


If you’re not sure how many AI tools have access to your firm’s data, we can help you find out and get it under control.