A shadow AI engagement runs in three phases over roughly two to four weeks: discover the unsanctioned AI tools employees are already using, assess the data exposure each one creates, then build a governance policy your team will actually follow. Here is how to structure it and where a partner earns its keep.
What Is a Shadow AI Engagement, Exactly
Shadow AI is any generative AI tool an employee adopts without IT or security sign-off. Someone pastes a client contract into ChatGPT to summarize it. A developer feeds proprietary code into an AI coding assistant with default data-retention settings. A marketing coordinator uploads a customer list to an AI writing tool. None of it is malicious. All of it is unmonitored data leaving your perimeter, often into vendors with terms of service nobody reviewed.
A shadow AI engagement is a structured project to find that usage, quantify the risk, and put controls in place before a customer, auditor, or regulator asks the question you can't answer: "which AI tools have access to our data?" For Canadian companies, that question increasingly comes from US enterprise customers running vendor security reviews, from SOC 2 auditors, and from Quebec Law 25 or PIPEDA obligations around personal information processing.
Week One: Discovery, Not Interrogation
The first mistake teams make is treating discovery like a compliance audit with a clipboard. That produces silence, because employees assume admitting to using an unsanctioned tool gets them in trouble. A better approach combines three discovery methods run in parallel:
- Network and SaaS telemetry. Pull DNS logs, proxy logs, and expense reports for known AI domains and browser extensions. This catches tools people forgot they installed.
- Anonymous employee survey. A five-minute, no-names survey asking what AI tools help with daily work almost always surfaces more than the logs do, because personal accounts and mobile apps don't show up in corporate telemetry.
- Manager interviews. Team leads know which tools their group has quietly standardized on, especially in engineering and marketing.
Expect this phase to take four to seven business days for a company in the 30 to 300 employee range. A dedicated shadow AI audit compresses this by running the telemetry pull and survey simultaneously, with a security researcher interpreting results rather than a checklist form, which is where most internal attempts stall out.
Week Two: Classifying Risk by Data Type, Not Tool Name
Once you have a list of tools, resist the urge to rank them by brand reputation. Rank them by what data touched them. A free-tier transcription tool used on internal standup notes is a low priority. The same free-tier tool used to transcribe a sales call with a prospect's financial details is a different conversation entirely, because free tiers frequently retain input data for model training by default.
Build a simple three-column risk register:
- Tool and tier (free, paid, enterprise, with or without a data processing agreement)
- Data category exposed (source code, customer PII, financial records, internal strategy)
- Retention and training posture (does the vendor use inputs to train models, and can you opt out)
This is where most in-house attempts fall apart, because reading vendor data processing terms for a dozen AI tools is genuinely tedious and easy to get wrong. It's also the phase where a security-focused partner adds the most value, since the researcher doing this work should already know which mainstream AI vendors have enterprise-grade data controls and which don't, rather than starting from zero on each one.
Week Three: Writing a Policy People Will Actually Follow
A shadow AI policy that bans everything gets ignored within a month, because employees have already found these tools make them faster. The policies that stick draw a clear line between three tiers:
- Approved: enterprise-tier tools with signed data processing agreements and no training on your inputs, available to everyone.
- Approved with restrictions: tools usable for non-sensitive work only, with explicit examples of what counts as sensitive.
- Blocked: tools with no acceptable data handling terms, blocked at the network layer where feasible, not just written down.
Pair the policy with a fast-track request process for new tools. If employees can get a tool evaluated in two business days instead of waiting on a quarterly review cycle, they'll use the process instead of routing around it. This same tiered thinking underpins broader AI governance frameworks like ISO 42001, so if your company is heading toward that certification anyway, it's worth reviewing our ISO 42001 readiness work to see how the shadow AI policy slots into a larger AI management system rather than sitting as a standalone document.
Week Four: Rollout and the First Recheck
Announce the policy with the approved tool list front and centre, not the blocked list. Employees respond better to "here's what you can use freely" than to a memo that reads as a crackdown. Give teams a short grace period to migrate off blocked tools, and schedule a follow-up discovery pass 60 to 90 days out. Shadow AI adoption moves fast. New tools show up in that window every time, and the second discovery pass is usually much faster than the first because the survey and telemetry process is already built.
Realistic Timelines and Where This Fits Your Budget
For a lean team, the full cycle from kickoff to published policy runs three to four weeks. Larger organizations with multiple business units or a distributed workforce should plan for five to six weeks, mostly because manager interviews and department-specific tool exceptions take longer to coordinate. This isn't a one-and-done project either. Budget for a lightweight recheck twice a year, since new AI tools reach general availability faster than most governance cycles can track them.
Companies already working through a SOC 2 or broader security program often fold shadow AI discovery directly into that engagement, since auditors are starting to ask about AI tool usage as part of vendor management and data handling controls. If that's your situation, it's worth looking at how this connects to our broader security program work rather than running it as an isolated exercise.
Where the Regional Context Matters
Canadian companies face a specific wrinkle US-based AI governance content usually skips: PIPEDA and, for anyone with Quebec operations or customers, Law 25 both impose obligations on how personal information is processed, including by third-party AI vendors. A shadow AI audit that ignores this ends up with a policy that's technically thorough but legally incomplete. We run these engagements for teams across Toronto, Waterloo, Ottawa, Vancouver, Calgary, and Montreal, and the Quebec-facing companies in particular need the data residency and consent questions answered explicitly, not assumed.
Getting Started
The hardest part of a shadow AI engagement isn't the technical discovery, it's getting honest answers from employees who use tools they weren't told they could use. A structured, judgment-free process gets you there faster than an internal memo ever will. If you want help scoping a shadow AI audit for your team, get in touch and we'll walk through what discovery would look like for your environment.