Shadow AI Discovery
Build an AI inventory you can account for
Define the employee groups, covered devices and observation period behind your AI inventory. Use the baseline to assign the next review, with its gaps visible.
Employee AI inventory
- Population
- Example team
- Collection path
- Installed browser client
| AI tool | Sample signal |
|---|---|
| ChatGPT | Observed |
| Claude | Observed |
| Gemini | Not observed |
Review next: account, approved use and owner.
For IT and security owners who need a defensible starting inventory before setting policy. Observation requires the applicable Aona client on the devices in scope.
Evaluation workflow
Put the population behind the inventory
Agree which managed endpoints and employee groups are in scope. Review a synthetic inventory example, then identify the decisions the baseline can support: approved status, risk review, policy ownership, and a follow-up enforcement evaluation where appropriate.
Define the baseline
Record the intended employee population, deployed clients, observation dates and collection settings. Covered employees and active AI users are different counts.
Review observed versus known
Compare a synthetic inventory example with the difference between catalogued tools and activity observed on the deployed path.
Route the next decision
Assign approval or risk review owners, then identify which app actions need a separate enforcement test.
How to read a discovery baseline
- Catalogued means a tool is known to the Aona catalogue; it does not prove employee use.
- Observed use belongs to a stated period and deployed collection path. No observed activity does not establish that an employee used no AI.
- Discovery is not the same as enforcement: an inventory should not be read as proof that every action is prevented.
Buying questions
Questions to resolve before a pilot
Does a 10,000+ tool catalogue mean every tool is discovered on our devices?
Can discovery enforce policy?
What does the demo include?
What should an initial Shadow AI inventory record?
Review your AI visibility.
See how a scoped inventory is read, identify endpoint and privacy prerequisites, and decide what needs a separate enforcement evaluation.