Blog

August 26, 2026

Shadow AI Is Already Running on Your Company’s Computers

By INGITE Research Team2026-08-268 min readEndpoint Visibility

Quick answer

Shadow AI is any AI tool used on a corporate device without IT approval or visibility — a browser tab, an extension, an AI feature switched on inside licensed software, or a local assistant running with user privileges.

  • Only 31% of organizations have visibility into the AI software running in their environment.
  • The risk is not the tool. It is that corporate data leaves through it with no record on the company side.
  • A written AI policy is not a control. An automated software inventory is.

Your company has an AI policy.

Maybe it names two or three approved tools. Maybe it defines what can and cannot be pasted into a chatbot. Maybe it was reviewed by legal and signed off by the board.

It looks like governance.

But if that policy depends on people remembering it, there is a strong chance it no longer describes what is actually running on your corporate computers. Not because employees are careless — because AI arrived faster than any approval process could follow.

Approved AI and used AI are two different inventories

Every company can list the AI tools it decided to adopt. Very few can list the AI tools that are actually installed, opened, extended into browsers, and fed with corporate data every day.

That gap has a name: shadow AI. And it is not a marginal phenomenon.

31%of organizations have visibility into AI software — against 66% for their SaaS estateFlexera, 2026 State of ITAM Report
59%report that waste in AI software spending increased over the last yearFlexera, 2026 State of ITAM Report
86%lack visibility over how AI tools handle company dataShadow AI Behavior Report, 2025-2026

The policy exists. The visibility does not.

Why shadow AI is harder to detect than classic unauthorized software

Traditional unauthorized software was easy to spot. It required a download, an installer, administrator rights, disk space. AI does not behave that way.

How each type of software enters the endpoint
Entry vector Requires admin rights Trace left behind Detected by
Classic installed application Usually yes Registry entry, program files, uninstall record Any software inventory
AI web app in a browser tab No Browser history only Application and web usage monitoring
Browser extension No Browser profile folder Extension inventory on the endpoint
AI feature enabled in licensed software No None on the endpoint Vendor release tracking and license review
Desktop AI assistant / local agent No (user-scope install) User profile folder, running process Automated inventory and process monitoring
Personal account on a corporate device No None Policy enforcement on the endpoint

None of these events triggers a ticket. None of them appears in a spreadsheet. And by the time IT hears about it, the tool is already part of someone’s daily routine.

What usually becomes invisible

Corporate data leaving through prompts

Contracts, payroll files, customer lists, source code, and strategic documents get pasted into public models to summarize, translate, or rewrite them. The action takes five seconds and leaves no record on the corporate side.

Extensions with silent permissions

Many AI extensions request permission to read and modify everything on the pages the user visits. That includes internal systems, ERPs, dashboards, and email.

AI embedded in software you already own

Vendors keep adding AI features to existing products. Something the company approved two years ago may now be sending content to a model that was never part of the original assessment.

Licenses paid for and never used

The opposite problem also exists. Teams buy AI seats in a rush, adoption stalls, and the invoice keeps arriving.

Local AI agents running with user privileges

The newest layer: assistants that read files, execute commands, and act on the machine. They are legitimate software with a very real capacity to move data.

Why this matters in an audit

When an incident happens, the question is never what the policy said. It is what actually ran, on which machine, at what time, and with which data. A document cannot answer that. A history of endpoint activity can.

The cost of governing AI with policy alone

A policy nobody can measure produces three predictable outcomes.

The first is legal exposure — regulators and clients ask for evidence, not intentions. The second is financial: AI spending scattered across departments, on personal cards or trial accounts, never consolidates into a negotiable contract. The third is operational: IT becomes the last department to learn about the tools the company depends on, and ends up supporting an environment it never mapped.

Governance without measurement is intention. Governance with measurement is control.

This is not a people problem, it is a visibility problem

Blocking everything does not work. Employees who lose access to a productivity gain will find a way around the block, usually on a device the company controls even less. Allowing everything does not work either.

What works is measuring. Knowing which applications are installed, which ones are actually used, how often, by whom, and on which machines. With that data, the conversation changes: instead of guessing, IT can approve what already delivers value, cut what nobody uses, and act precisely where real risk exists.

How to get visibility over AI use in five steps

  1. Inventory what is installed, automaticallyStop relying on declarations. Collect installed applications, user-scope installs and browser extensions from every endpoint, including machines outside the corporate network.
  2. Separate installed from usedAn application that exists is not a risk profile. An application opened four hours a day is. Measure real usage before deciding anything.
  3. Classify into approved, tolerated and prohibitedThree lists, reviewed monthly. Anything that appears on an endpoint and is not on a list becomes a review item, not an incident.
  4. Enforce the policy on the endpointTurn the rules that matter into applied controls and monitored events, so a violation generates a record instead of a rumour.
  5. Keep the historyRetention is what turns “we think nothing left” into a defensible answer during an audit or an investigation.
Technical note

Most modern AI assistants install in user scope — under the user profile, with no administrator rights and no machine-wide registry entry. Inventories that only read the system-level uninstall keys will report a clean environment while the tools are running. Any inventory used for AI governance has to collect per-user installations and browser extension folders as well.

How INGITE helps

Cloud Asset Management

Automatic, always-current inventory of hardware and software — including AI applications and extensions that appeared without going through any approval process.

See the solution

Cloud Productivity Monitoring

Shows how those applications are actually used, separating a tool that creates real value from one that only creates cost and exposure.

See the solution

Cloud EndPoint Security

Applies and monitors policies on the endpoint, so a rule stops being a document and becomes an enforced, auditable control.

See the solution

Cloud Digital Forensics Investigation

Preserves the history and the evidence needed to reconstruct what happened, with full traceability.

See the solution

Seven questions that reveal whether you have real control

Forget the policy for a moment. Answer these instead — and count how many you can answer today, with evidence.

  • Which AI applications are installed on your endpoints right now?
  • Which browser extensions with page-access permissions are active in your environment?
  • Which of those tools are actually used, and by how many people?
  • How many AI licenses is the company paying for, and what is the real adoption rate?
  • Which machines are running AI tools while outside the corporate network?
  • If an incident happened today, could you show what ran on a specific machine last month?
  • How long would it take you to produce that list — and how confident would you be in it?

If the honest answer is that it would take days and the list would still be incomplete, the problem is not the policy. It is the visibility.

What exactly counts as shadow AI?
Any AI tool used for work on a corporate device without IT approval or visibility. That includes public chatbots in a browser tab, AI browser extensions, AI features enabled inside licensed software, desktop assistants installed in user scope, and personal AI accounts used on company machines.
Is blocking AI tools an effective strategy?
Rarely on its own. Blocking removes a productivity gain without removing the demand, and users move to personal devices the company controls even less. Blocking works when it is applied selectively to specific tools, based on measured usage data, and paired with an approved alternative.
Why does an IT inventory miss AI tools?
Because most inventories only read machine-level installation records. Modern AI assistants install in user scope, and browser-based tools install nothing at all. An inventory built for AI governance has to collect per-user installations, browser extensions and real application usage.
How does this relate to compliance frameworks?
Frameworks such as ISO 27001, GDPR and LGPD require an accurate asset inventory and demonstrable control over data processing. An AI tool that processes company data without appearing in any inventory is a gap in both requirements at the same time.

Find out what is really running on your endpoints

INGITE Cloud Asset Management turns AI governance into something you can measure, prove and control — with an automated inventory that does not depend on anyone remembering to report anything.

Discover Cloud Asset Management