One week · fixed scope
Shadow AI Discovery
Find every AI tool already touching your data — before someone else does.
What it is.
Your team is already using AI. The question is whether you know which tools, on which data, and against which compliance obligations. Shadow AI Discovery answers that in one week, with a fixed scope and a fixed price.
It’s a discovery engagement, not an audit.
I’m not assessing what you should build. I’m finding what’s already running — the ChatGPT tabs, the Copilot licenses, the browser extensions, the AI features quietly switched on inside tools you already pay for.
Sanctioned and unsanctioned, both.
Most “shadow AI” isn’t malicious. It’s a salesperson pasting a customer list into a chatbot to draft an email. The risk is the same whether or not it was approved, so the inventory covers both.
What you walk away with.
- A complete inventory of AI tools in use across departments
- A single-page visual risk map, organized by data sensitivity
- A short list of policy gaps to close in the next 30 days
- A plain-English readout your leadership team can act on without a technical translator
Who it’s for.
Best for organizations that suspect AI use has outpaced their visibility — usually 20-200 employees, often in a regulated or contract-sensitive industry, with no in-house AI specialist. If you can’t currently answer “what AI tools touch our customer data?” in one sentence, this is the place to start.
