Know how AI is being used in your company
Find the tools your team uses, the data they share and the risks to address. You get a practical plan for approved AI use.

Shadow AI is the AI tools and models employees use for work without the company approving them — a chatbot handling customer records, a personal API key inside a production script, a code assistant nobody logged. A shadow AI audit produces an inventory of what is actually in use team by team, a map of what data leaves the company and where it lands, and a short list of sanctioned tools that cover the same jobs. Oleg Sotnikov runs these audits. He works from an AI-first company of his own, so the outcome is safe adoption rather than another ban.
What the Audit Looks For
Six areas I go through. The first two usually change the conversation on their own.
The AI inventory
What is actually in use, team by team: chat assistants, code assistants, meeting recorders, browser extensions, agents somebody wired up on a Friday. Names, owners, and how often each one is opened.
Data-exposure map
For every tool, what goes in and where it lands: which vendor, which region, whether that plan trains on your inputs, how long conversations are retained, who at the vendor can read them.
Personal keys and personal accounts
API keys billed to somebody's card, free-tier accounts holding production data, a personal login behind a workspace tool. The company carries the risk without seeing the traffic, and the access walks out with the person.
AI-generated code without provenance
Generated code merged with no record of what a model wrote and no second pair of eyes on the parts touching auth, payments, or personal data. License questions land in the same place.
Sanctioned alternatives
A legal way to do each thing people already do: an enterprise plan with training switched off, a gateway holding company keys, a self-hosted model for data that cannot leave. Usage stops hiding once the approved path is no slower than the hidden one.
Policy that matches reality
The findings become rules a person can follow: which tools are approved, what data may enter them, who reviews output before a customer sees it. That document is where AI governance starts, and it works far better written after the inventory than before it.
How It Works
Discover
The inventory comes from three angles: network and SaaS logs, expense and card statements, and a short anonymous survey. It runs as a count, not a witch hunt — nobody gets named, and the team hears that up front, otherwise the survey comes back false.
Assess
Every tool gets ranked on two axes: how sensitive the data going into it is, and how far the damage spreads if that vendor is breached. Most of the list turns out harmless. The real risk usually sits in two or three places.
Regularize
A sanctioned stack that covers the real use cases, a written policy that matches it, and a short training path so people know the rules and the reasons behind them. Then a repeat count a quarter later, because new tools keep shipping.
Why Me
- I run an AI-first company myself — AppMaster processes 11B+ tokens a month — so I know what employees actually do with AI, including the parts nobody writes in a ticket
- 25+ years in IT and 1,000+ projects, which keeps the inventory conversation technical instead of accusatory
- I aim for safe adoption: a ban only pushes the same work onto personal laptops and phones, where you can neither see it nor protect the data
What Usually Comes Next
Adjacent parts of the same problem.
Frequently Asked Questions
What is shadow AI?
Shadow AI is any AI tool or model used for work without the company approving it: a chatbot in a browser tab, a code assistant in somebody's editor, a personal API key inside a script that runs in production. It is the AI version of shadow IT, and it spreads faster because these tools need no install, no budget line, and no admin rights.
How common is shadow AI?
Usage varies by company. The audit checks which tools people use and what data they share. We start with a team survey and available usage records.
Is shadow AI dangerous?
The risk is concrete. Customer records and source code pasted into consumer accounts sit on a vendor's servers under terms nobody read, and some tiers use those inputs for training. Regulated data leaving that way can be a reportable incident under GDPR or HIPAA. Separately, AI-generated code merged without review puts logic no human has checked into authentication, payments, and data access.
Should we ban AI tools?
Restrictions are useful where the data and risks require them. For other work, approved tools and a clear request process can help. We choose the approach based on the findings.
How is this related to an AI policy?
The audit shows how tools are currently used. That information helps create rules that fit the company’s work. If a policy already exists, we check where practice differs from it.
Find Out What Your Team Is Already Using
A count of the tools in use, a map of what data leaves, and a policy people will follow. Start with a call. You do not need to prepare anything for it.
30 minutes. If shadow AI is not your problem, I will tell you that on the call.
Book a call
On a free 30-minute call, we’ll discuss what’s holding you back and work out where to start.
Prefer to write first?Message on TelegramSend a message
Related reading
AI adoption, governance, and what actually happens inside engineering teams.


