Shadow AI in Our Own Company: 15 Tools, 3 Approved
Every morning a bot in Slack gives me my briefing. It preps me for my meetings, and when those meetings are done it pushes the transcripts into Asana and assigns work out to the team. If I drop a voice recording into it, it goes and finds the email I'm talking about and drafts the reply for me. Once a week it tells me which statements of work are still pending and who I haven't spoken to in a while. To do all of that it needs access to Asana, Google Drive, HubSpot, Slack, and Fellow, where all of our call recordings live.
I built it myself in Claude Code, and it never went through an approval process, because at the time we didn't have one.
What the shadow AI audit found
15 distinct AI tools in use across the company. Three approved.
7 of the 15 people surveyed put client, personal, or financial data into AI tools.
3 people doing company work on personal Claude Pro accounts.
23 of our 35 active tools have AI in them. Five of those can't be turned off, and they're our finance and HR systems.
2 tools influencing decisions about people.
Two contradictory answers from leadership on whether we disclose our AI use to customers.
Why we went looking for shadow AI
We joined Anthropic's partner network this year and we use Claude every day across the company. Earlier this year I started telling customers we could help them adopt AI safely, and somewhere in the middle of saying that out loud I realized I couldn't answer for my own company the questions I was about to start asking them. So in May we ran a full assessment on ourselves. Survey the whole team, inventory every tool, review the vendors, and find out what was actually happening. The findings came back on June 23rd.
Three parts, then. A survey the team answered themselves. An inventory of all thirty-five of our active tools. A review of what the vendors behind them are doing. Fifteen people responded to the survey, across sales, delivery, customer success, leadership, and back office.
Fifteen distinct AI tools in use across the company. Only three of them were approved.
Seven of the fifteen people who responded said they put client, personal, or financial data into AI tools, and that's spread across sales, delivery, customer success, leadership, and back office. One of them, a solutions engineer, said plainly that he wasn't sure whether he was allowed to. That answer told me more than the number did, because it means someone was doing good work and quietly hoping it was fine.
Three people were doing company work on personal Claude Pro accounts
I've said on YouTube that a lot of teams right now are connecting all of their organization's tools to individual plans, and it turns out I was describing my own company while I said it.
The AI we never chose
Twenty-three of our thirty-five active tools have AI in them. Five of those have vendor AI that can't be turned off, and those five are our finance and HR systems, the ones holding employee records and financial data. We never chose that. It arrived in product updates.
That's the one I'd look at first if you're reading this and wondering what your own number is. It isn't something your team did. It showed up in a release note.
Two tools are influencing decisions about people
Two of our tools are influencing decisions about people, which puts them in scope for a human rights impact assessment under the Ontario framework. I'm giving that one its own post, because it deserves more than a paragraph and it's the finding with live regulatory exposure attached.
We don't agree on what we tell customers
And when we asked leadership whether we disclose our AI use to customers, the two answers that came back contradicted each other. One said no. The other said informal and verbal.
None of this happened through carelessness
Our consultants started using Claude as a thinking partner to work through customer solutions, which is exactly what I do, and it made them faster at it. From there it's a short step to putting the real project context in, and a shorter one to connecting the tool where that context already lives, because that's where it starts being useful. Every one of those steps was a good decision on its own. We just never wrote down where the line was, so everyone drew their own.
What the team asked for
The team's own answers pointed the same direction. Nine of the fifteen asked for clear rules about what data can go where. Six said they already double-check AI output before relying on it. Seven expected that whatever policy came out of this would end up too restrictive and take away tools they'd come to depend on. What they were asking for was a green light with boundaries on it, and we hadn't given them one.
What we changed
We've been working through it since. There's an approved tool list now, and a classification framework that tells people which data is allowed in which tool. There's a disclosure statement customers can actually read, and an incident process that isn't just someone messaging me. Our fractional CTO owns tool approvals, which is where that decision should have been sitting the whole time. The AI risk now sits inside the risk register we started building over the Christmas break rather than off to the side of it.
Why I'm publishing the numbers
I'm publishing the numbers because I think they're more useful than advice. Most leaders I talk to have a rough sense that their team is using AI and no way to say where. I had that same rough sense, and I was wrong about the shape of it in most directions. Fifteen tools was higher than I'd have guessed. Seven people putting client data in was higher. The five vendors quietly running AI inside our finance and HR systems hadn't occurred to me at all.
The assistant still runs every morning. It has a much shorter list of things it's allowed to touch now.
Get the Kit
You can't set rules for tools nobody has written down. The AI readiness kit walks you through the same five steps we used here, so your team can put real numbers against its own AI use. About thirty minutes, and it's free.
If you'd rather have it run across the whole company, that's the AI Readiness Assessment.
Questions I've been asked since
How many unapproved AI tools should I expect to find?
I can only tell you ours. Fifteen in use, three approved, and I'd have guessed lower on both counts. The number that surprised me more was thirty-five, which is how many active tools we have in total. Twenty-three of them have AI in them somewhere.
Can you actually turn vendor AI off?
Not always. Five of ours couldn't be, and those were the finance and HR systems. When a vendor ships AI as part of the product rather than as a feature you switch on, the only controls you have left are the contract and what you put in.
Does writing a policy mean taking tools away from people?
No. Seven of the fifteen people we surveyed expected it would, and I understand why. A policy isn't a list of bans. It's what lets you say yes to a new tool quickly, because you already know what class of data it would be handling and where that class is allowed to go. Without one, every request is a judgment call made from scratch.