Shadow AI Discovery & Governance

Do you know which AI applications your employees are really using?

Employees are using more and more AI tools outside IT's view. Campai shows you which AI applications and integrations are active, who is using them, and which risks need attention — so you can decide, with confidence, what to allow, phase out or block.

A practical explanation, the key risks, and a step-by-step plan for more control.

For organisations that want to accelerate AI adoption without losing control over data, security and compliance.

AI Application Governance
Concept example
Signals fromMicrosoft 365EntraBrowserEndpointsSSO
42
AI applications detected
12
Potential Shadow AI
6
With SSO access
312
Users involved
AI landscape risk score64 / 100
  • CG

    ChatGPT (Personal)

    Browser · 68 users · risk medium

    Unauthorised
  • AC

    Anthropic Claude

    SSO · 24 users · risk low

    Production
  • CU

    Cursor

    Desktop · 17 users · risk medium

    Test
  • DS

    DeepSeek

    Browser · 9 users · risk high

    Phasing out
Conceptual illustration with sample applications and fictional usage data.
It's probably already happening

Shadow AI usually starts with good intentions

Employees use AI to summarise documents, work out meeting notes, write texts, run analyses and speed up processes. Sometimes they pick applications on their own that haven't been formally reviewed by IT, security or privacy.

Shadow AI is the business use of AI applications, AI functionality or AI integrations without formal review, approval and oversight from the organisation.

How Shadow AI shows up inside an organisation

Unknown AI use can arise in several ways. Here are four common examples.

Public AI chatbots

Employees use personal or free accounts to process business information.

Meeting assistants

A third-party application processes conversations, participants, transcripts and action items.

Browser and desktop apps

AI functionality gets installed independently, outside central application management.

SSO and Microsoft 365 integrations

An AI app gains access to email, calendar, files, SharePoint or Teams.

The gap between policy and practice

The official application landscape only covers what's known and approved. The actual landscape also includes personal accounts, standalone applications and unreviewed integrations.

Official AI landscape

What's visible

  • known applications
  • business accounts
  • approved vendors
  • clear ownership
  • central management

Actual AI landscape

What's also happening

  • unknown browser tools
  • personal accounts
  • standalone desktop apps
  • unreviewed integrations
  • no recorded owner

An AI policy describes what should happen. Shadow AI Discovery shows you what's actually happening.

Research

Shadow AI is no longer a fringe issue

External research shows that the use of unapproved AI is growing faster than the governance around it.

71%

of surveyed UK employees said they had used an unapproved consumer AI tool for work at least once.

Source: Microsoft, survey among UK employees, 2025

63%

of the organisations surveyed by IBM that had suffered a data breach had no AI governance policy in place.

Source: IBM Cost of a Data Breach Report 2025

The studies use different audiences and methods, but point the same way: AI use is growing faster than formal review and control.

Why this deserves your attention

Unknown AI use creates more than just a technical risk

Unwanted data sharing

Company information, customer data and intellectual property can end up in unreviewed AI tools.

Unknown data location

It's not always clear where data is stored, processed, or accessed by subprocessors.

Overly broad access

SSO and OAuth integrations can grant access to email, calendar, SharePoint, OneDrive or Teams.

Vendor risk

Not every AI vendor offers mature security, clear terms, or central management features.

Compliance and demonstrability

A policy alone doesn't prove that applications are actually reviewed and periodically reassessed.

Sprawl and duplicate costs

Departments can end up with similar subscriptions outside central contract and licence management.

Shadow AI can lead to investigation costs, remediation work, legal support, contractual disputes, duplicate licences, and loss of customer trust.

Free whitepaper

From unknown AI use to demonstrable control

Discover why Shadow AI arises, which risks organisations often overlook, and how to set up a practical governance process in five steps.

  • how to make Shadow AI technically visible
  • how to assess and classify applications
  • how leadership and IT reach demonstrable decisions together
Get the whitepaper

Free · practical · written for directors and IT

How much control does your organisation currently have?

Tick the statements that apply to your organisation. The result is an indication only; no data is stored or sent.

AI governance self-assessment
Your score
Limited visibility
0/9

You may have some policy measures in place, but technical visibility is missing. As a result, it's unclear which AI applications are actually being used and whether your policy is being followed.

Get the whitepaper
From blind spot to controllable process

One central overview of AI applications, users, risks and decisions

Campai combines signals from Microsoft 365, Entra, SSO connections, browser usage and endpoint software. That gives you one up-to-date overview of the AI usage found across the available data sources.

From technical signal to a documented management decision.

1

Vendors in one central view

See which AI vendors are being used within the organisation.

2

Applications and users

See who's using which application, and via browser, desktop or SSO.

3

Risk information

Record data location, risk classification and known incidents, among other things.

4

Shadow AI signalling

Managed service

Campai compares discovered applications against the whitelist and flags deviations.

5

Lifecycle management

Managed service

Campai helps assess applications and manages their status: Test, Production, Phasing out, or Unauthorised.

See the lifecycle model ↓
6

Technical blocking

Managed service

Campai can block unauthorised applications once the customer has made an authorised decision to do so.

AI-signalen per device
Concept example

26 / 29

devices with AI signals

125

signals detected

18

unique AI applications

DeviceStatusAI applications foundSignalsLast seen
DEVICE-014Needs attention
ChatGPTAnthropic ClaudeCursor+4 more
12Today
DEVICE-027To review
Microsoft CopilotChatGPTDeepSeek
8Today
DEVICE-031Needs attention
CursorClaude CodeGitHub Copilot+2 more
7Yesterday
DEVICE-044To review
ChatGPTMicrosoft Copilot
4Yesterday
Conceptual illustration with fictional devices, sample applications and fictional usage data.
Lifecycle management

Not everything allowed. Not everything blocked. Deliberate decisions instead.

  1. Lifecycle statusTest

    Test

    Limited trial use with clear users, purposes and conditions.

  2. Lifecycle statusProduction

    Production

    Reviewed and approved for business use.

  3. Lifecycle statusPhasing out

    Phasing out

    Controlled replacement or discontinuation according to an agreed plan.

  4. Lifecycle statusUnauthorised

    Unauthorised

    Not allowed under policy or due to an unacceptable risk.

De juiste reactie op Shadow AI is niet automatisch blokkeren. Eerst moet duidelijk zijn waarom medewerkers de applicatie gebruiken en welk veilig alternatief beschikbaar is.

How Campai helps

From initial inventory to structural AI governance

Step 1

Shadow AI Quick Scan

Initial technical insight and priorities

  • connecting a limited number of available data sources
  • initial inventory of AI applications and vendors
  • initial risk and management overview

Result

An initial, limited view of scope, risks and immediate points of attention — not yet an assessment per application.

Step 2

Discovery & Governance Assessment

In-depth assessment and decision-making

  • risk and vendor analysis
  • comparison with AI policy and whitelist
  • lifecycle decisions and governance roadmap

Result

An up-to-date AI application register and a well-founded improvement plan.

Step 3

Managed Shadow AI Governance

Ongoing management and follow-up

  • continuous detection and assessment
  • whitelist and lifecycle management
  • reporting, follow-up and blocking

Result

AI use stays demonstrably under control as applications, vendors and usage evolve.

Concrete deliverables

This is what the inventory delivers in practice

AI application register

Overview of vendors, applications, users, owner and lifecycle stage.

Risk overview

Prioritisation based on usage, access, data location and vendor risk.

Decisions and actions

A record of what's allowed, tested, phased out or blocked, and who's responsible.

Management summary

A concise overview of the key risks, trends and decisions needed.

Secure and demonstrable

Built on security, compliance and AI governance

Campai works to recognised standards and combines technical discovery with governance follow-up.

ISO 27001ISO 9001NEN 7510CCV Keurmerk Digitale BasisveiligheidNIS2 Supply Chain

Developed from real-world experience in Microsoft 365 management, cybersecurity, compliance and AI governance.

Free whitepaper

Shadow AI: from unknown use to demonstrable control

Discover why Shadow AI arises, which risks organisations often overlook, and how to set up a practical governance process in five steps.

  • what Shadow AI actually is
  • risks for data, security and compliance
  • why an AI policy alone isn't enough
  • how to technically discover AI applications
  • a practical lifecycle model
  • a step-by-step plan for directors and IT

Get the whitepaper

Fill in your business details. You'll receive the whitepaper straight to your inbox.

  • Free
  • Delivered straight by email
  • No mandatory sales call

We use your details to send you the whitepaper. With your consent, we may also keep you informed about relevant AI and security topics. Read our privacy statement.

Why Campai

Technical discovery and governance follow-up combined

Broad technical visibility

Signals from Microsoft 365, Entra, SSO, browsers and endpoints are combined.

More than a detection tool

Campai also supports risk assessment, policy, decision-making and lifecycle management.

Practical for SMEs

A managed governance process, without you needing to build a full CISO or AI governance function yourself.

Part of broader AI adoption

These insights can feed into AI policy, Microsoft 365 Copilot, training, use cases, compliance and licence optimisation.

FAQ

What organisations usually ask us

From an AI policy on paper to control over actual use

Discover how to make AI applications visible, assess risks, and set up a practical governance process.

Get the whitepaper