How to Discover Shadow AI
Practical methods to inventory unauthorized AI usage across your healthcare organization
The Discovery Challenge
Shadow AI is designed to be invisible. These are web-based SaaS tools accessed through personal accounts, personal credit cards, and consumer-grade services.
Traditional IT discovery methods (network monitoring, procurement records, endpoint management) won't catch them. You need a different approach.
5 Discovery Methods
Combine multiple approaches to get a complete picture of shadow AI usage
How to do it:
- Frame it as "helping us enable AI safely" not "catching violations"
- Ask: What AI tools do you use? How often? For what tasks?
- Promise no individual consequences — focus on organizational learning
- Offer small incentive (gift card raffle) for completion
How to do it:
- Interview 2-3 people from each major department
- Ask about productivity pain points and workarounds
- Listen for AI tool mentions (ChatGPT, Claude, Grammarly, transcription services)
- Document workflows where AI could be or is being used
How to do it:
- Pull 30 days of DNS logs from your firewall/proxy
- Search for domains: openai.com, anthropic.com, claude.ai, gemini.google.com, etc.
- Look for unusual traffic spikes to AI service providers
- Correlate by department, time of day, user segments
How to do it:
- Export list of all Chrome/Edge extensions from endpoint management
- Flag AI-related extensions: Grammarly, Jasper, Copy.ai, Notion AI, etc.
- Check for ChatGPT desktop apps, Claude desktop apps
- Document which departments have highest adoption
How to do it:
- Pull 6 months of expense data
- Search for merchant names: OpenAI, Anthropic, Jasper, Copy.ai, etc.
- Look for recurring monthly charges ($20-50 range)
- Note: Most shadow AI is on personal cards, so this catches <10%
Recommended Approach
Combine three methods for maximum coverage
Start with Anonymous Survey (Week 1)
Fastest way to get broad visibility. Most staff will self-report if framed correctly.
Run Network Traffic Analysis (Week 1-2)
Validates survey data and catches usage staff forgot to mention or didn't realize counted as "AI".
Follow Up with Department Interviews (Week 2-3)
Deep dive into high-risk or high-usage departments to understand workflows and PHI exposure.
Result: 80-90% coverage of shadow AI usage in 2-3 weeks, with both quantitative data and qualitative context.
What to Document
Create a shadow AI inventory with these key data points
- 1
AI Tool Name
ChatGPT, Claude, Gemini, Grammarly — track this for each discovered AI tool to build a complete shadow AI inventory.
- 2
Department/Team
Clinical Documentation, Revenue Cycle, Admin — identify which teams are using which tools.
- 3
Number of Users
Estimated count or percentage of staff using each tool in each department.
- 4
Use Case
Summarizing notes, drafting appeals, patient education — document how each tool is being used.
- 5
Data Shared
Patient names, diagnosis codes, treatment details — what information is being entered into AI tools.
- 6
PHI Exposure Level
High, Medium, or Low — assess the sensitivity of data being shared with each tool.
- 7
Account Type
Personal account, free tier, or paid subscription — determines data retention and privacy policies.
- 8
Frequency of Use
Daily, weekly, or occasional — helps prioritize governance efforts by usage volume.
What Happens After Discovery?
Discovery is just the first step. Here is what to do with what you learned.
Prioritize Risk
Focus governance efforts where they matter most
- Rank discovered tools by PHI exposure level, number of users, and business criticality.
- Focus governance efforts on highest-risk areas first.
Communicate Findings
Make shadow AI visible to leadership
- Present shadow AI inventory to leadership with risk assessment, compliance gaps, and recommended actions.
- Make the invisible visible.
Build Governance Plan
Create a roadmap for safe AI enablement
Use discovery insights to create a roadmap: establish policies, deploy PHI protection, provide approved alternatives, and enable teams safely.
Need Help Discovering Shadow AI?
Our Shadow AI Risk Check includes a complete discovery process with expert facilitation and a detailed inventory report