top of page
Search

Shadow AI Is Already Inside Your Business: How to Discover Who Is Using ChatGPT, Gemini and Other AI Apps

  • Hanna Korotka
  • 6 days ago
  • 4 min read

Artificial intelligence has become part of everyday work. Employees use ChatGPT to draft emails, Gemini to summarize documents, and other AI tools to speed up research, coding, or content creation.


While these tools can improve productivity, they also introduce a new security challenge that many small and medium-sized businesses don't realize they already have.


The problem isn't AI itself. The problem is Shadow AI. When employees use AI applications without IT approval or security oversight, sensitive company information can leave your Microsoft 365 environment without anyone noticing.


The good news is that Microsoft provides tools to help organizations discover which AI applications are being used and evaluate whether they present a risk.


What Is Shadow AI?


Shadow AI refers to employees using artificial intelligence applications that haven't been reviewed or approved by the organization's IT or security team.


Examples include:

  • ChatGPT

  • Google Gemini

  • Claude

  • Perplexity AI

  • DeepSeek

  • AI browser extensions

  • AI writing assistants

  • AI coding assistants


Most employees have good intentions. They simply want to complete their work faster. For example, someone may copy a customer contract into an AI chatbot to summarize it, upload financial reports to generate charts, or ask an AI assistant to rewrite confidential emails.


Without proper governance, the business has no visibility into where that information goes or whether it complies with company policies.


Why Businesses Should Care


Many business owners assume their employees only use Microsoft 365 applications. In reality, Microsoft notes that organizations often underestimate the number of cloud applications employees use. IT teams commonly estimate 30–40 cloud apps, while the actual number is frequently well over 1,000. Many of these applications have never been reviewed or approved by the organization.


When AI applications are added to the mix, several security risks appear.


Sensitive information may be shared


Employees might submit customer information, contracts, financial reports, HR documents, source code, or internal business strategies to an AI service. Even if the AI provider is legitimate, sharing this information may violate company policies or regulatory requirements.


IT loses visibility


If nobody knows which AI tools employees are using, the organization cannot assess security risks, understand where company data is going, or make informed decisions about approved AI services.


Not all AI applications provide the same level of protection


Different AI providers have different security controls, privacy practices, and compliance certifications. Without visibility, it's impossible to know whether employees are using trusted business services or consumer tools with fewer safeguards.


How Microsoft Helps You Discover AI Applications


Microsoft Defender for Cloud Apps includes Cloud Discovery, a feature that helps organizations identify cloud applications being used across the business.


Instead of guessing which AI tools employees use, administrators can view actual usage data across their environment.


Cloud Discovery can identify:

  • AI chat applications

  • AI model providers

  • SaaS AI services

  • Other cloud applications accessed by employees


It also provides valuable information such as:

  • Number of users

  • Usage frequency

  • Traffic volume

  • Application categories

  • Microsoft risk score


Microsoft evaluates thousands of cloud applications using security, compliance, and legal risk factors, helping organizations better understand which applications may require additional review.


How to Investigate AI Usage


After discovering AI applications, the next step is understanding how they are being used.


Start by asking these questions:

  • Which AI applications are being used?

  • Who is using them?

  • How often are they being used?

  • What is the Microsoft risk score for each application?


This information helps determine whether an application should be approved, monitored, or restricted.


Heavy usage of an AI tool may also indicate that employees have a legitimate business need that should be supported with a secure, approved solution.


To review AI application usage, sign in to the Microsoft Defender portal  (https://security.microsoft.com) and navigate to Cloud Apps → Cloud Discovery → Discovered apps. From there, you can filter applications by category, review usage statistics, identify users, and evaluate Microsoft's risk score for each application.


Should You Block Every AI Tool?


Usually, no.

Blocking every AI application without understanding why employees use them often creates new problems. Users may simply find alternative tools that are even less secure.

Microsoft recommends first understanding business requirements before deciding whether an application should be allowed, monitored, or blocked.


A practical approach for SMBs is to:

  • Discover which AI applications employees use.

  • Evaluate the security and compliance of those applications.

  • Approve trusted AI services.

  • Block high-risk or unnecessary applications.

  • Educate employees about what company information should never be shared with AI tools.


Create an AI Usage Policy


Technology alone cannot solve the problem.


Employees need clear guidance about acceptable AI usage.


Your AI policy should answer questions such as:

  • Which AI applications are approved?

  • Can employees use personal AI accounts for work?

  • What company information can be entered into AI tools?

  • Is customer data allowed?

  • Can financial information be uploaded?

  • Who approves new AI applications?


Simple rules help employees make better decisions while reducing the risk of accidental data exposure.


Final Thoughts


Artificial intelligence is already part of the modern workplace.


The important question is no longer whether employees use AI. Instead, organizations should understand which AI applications are being used, who is using them, and what business information is being shared.


Microsoft Defender for Cloud Apps provides visibility into cloud and AI application usage, helping organizations identify unsanctioned applications, evaluate their risk, and make informed decisions before sensitive business information is exposed.


For small and medium-sized businesses, gaining visibility is the first step toward embracing AI safely while protecting customer data, intellectual property, and business operations.


Whether you're looking to improve security, strengthen compliance, or better protect your Microsoft 365 environment, our experts can help you assess your current security posture, implement industry best practices, and build a security strategy tailored to your business.




 
 
 

Comments


Get the Latest News to Your Inbox

bottom of page