The problem with shadow AI in mid-market companies
Shadow AI is what happens when the pace of AI tool adoption outstrips the pace of IT oversight. An employee signs up for an AI writing assistant, a developer integrates a code-completion API, a finance analyst starts running reports through a chatbot — none of it goes through procurement, none of it goes through you, and none of it shows up in your software inventory.
This isn't a discipline problem. These tools are fast, cheap, and genuinely useful. People adopt them for the same reason they adopted personal Dropbox accounts before the IT team had a file-sharing policy: they solve a real problem faster than the formal process does. The result is a sprawl of unapproved AI tools connected to company data, operating under terms of service nobody in your organization has read, with no one accountable when something goes wrong.
The risk profile here is different from ordinary shadow IT. Most unapproved SaaS tools expose you to data residency or license compliance issues — real problems, but bounded ones. AI tools often go further: they may train on the data your employees feed them, they may retain conversation history, and their outputs can create legal exposure around IP ownership, accuracy, and bias. When the EU AI Act's obligations start touching your supply chain or your EU customers, "we didn't know employees were using it" is not a defensible position.
For IT managers at companies in the 50 to 250 employee range, the challenge is that you're expected to govern this without a dedicated compliance team, without an enterprise GRC platform, and without a clear picture of what your employees are actually running. Most of the guidance written for this problem assumes you have resources you don't have.
What good enough looks like for shadow AI governance
You don't need to eliminate shadow AI — you need to make it visible and manageable. "Good enough" at this stage means three things: you know what AI tools are in use across your organization, you've made a documented risk decision on each one, and you have a lightweight process for handling new tools before they become entrenched.
That's it. A comprehensive AI tool inventory with a risk tier assigned to each tool and a named owner is more defensible than a policy document that nobody enforces. Regulators, auditors, and cyber insurers increasingly want to see evidence of active governance, not just written intent. An AI risk registry that you actually maintain is worth more than a framework you reference in a policy and ignore in practice.
The bar for mid-market companies right now is relatively achievable: document what you have, assess the highest-risk tools first, get policies in place for the tools your employees use most, and create an intake path so new tools don't slip through unreviewed. If you can do those four things, you're ahead of most organizations your size.
For a detailed look at what employees are actually using and where to start your inventory, the Insights post on the AI tools your employees are already using covers the most common categories and the data-handling risks attached to each.
A practical method for discovering and governing shadow AI
This is the method that works for resource-constrained IT teams. It's not a full checklist — the spokes off this page go deeper on each step — but here's the sequence that produces results.
- Pull browser extension and OAuth data first. Your identity provider and browser management tools already know a lot about what employees are connecting to. OAuth grants in Google Workspace or Microsoft 365 will surface AI tools that authenticated with company credentials. This takes an afternoon, not a project sprint.
- Run a self-reported survey in parallel. People will disclose tools they're using if you ask in a non-punitive way. Frame it as inventory, not audit. You'll catch tools that don't show up in your OAuth data because employees use personal accounts or browser-based tools that don't require a login handoff.
- Review expense reports and procurement data. Subscription AI tools purchased on company cards or submitted for reimbursement leave a financial trail. This step catches the tools that employees are paying for themselves and expecting the company to eventually formalize.
- Build a working AI tool register — even a spreadsheet. Every tool you find gets a row: tool name, business purpose, data it touches, vendor terms reviewed yes/no, risk tier, and a named owner. This is your AI risk registry. It doesn't need to be elegant on day one; it needs to exist.
- Triage by data exposure, not by tool category. A consumer AI chatbot that an employee uses for drafting internal memos is a different risk level than one they're pasting customer data into. Sort your inventory by what data the tool handles, and address the highest-exposure tools first.
- Create a simple intake path for new tools. Once your current inventory is documented, establish a lightweight approval process so new AI tools get reviewed before adoption, not after. A single-page intake form and a 48-hour response commitment is enough to change behavior.
If you want a step-by-step process for building out that tool register without enterprise software, the Insights post on how to build an AI tool inventory without enterprise software walks through the mechanics in detail.
From discovery to ongoing governance
Discovery is a one-time sprint. Governance is the ongoing discipline of keeping that inventory current, reviewing vendor changes, and making sure new tools get evaluated before they embed themselves in workflows.
Most IT teams at this size hit a wall when they try to move from a spreadsheet to something more structured. The spreadsheet stops getting updated, ownership gets murky, and the inventory drifts out of sync with reality within a few months. That's where purpose-built tooling starts to earn its keep — not by doing something you couldn't do in a spreadsheet, but by making the ongoing maintenance low-friction enough that it actually happens.
InfoDefenders' AI Risk Assessor lets you run structured vendor risk assessments against your tool inventory and export evidence when you need to demonstrate your governance posture to auditors or leadership. If you're past the initial discovery phase and ready to put a real process around what you've found, see what's included in each plan](/pricing) or [start a free trial and bring your existing inventory in on day one.