Do you know which AI applications your employees are really using?
Employees are using more and more AI tools outside IT's view. Campai shows you which AI applications and integrations are active, who is using them, and which risks need attention — so you can decide, with confidence, what to allow, phase out or block.
A practical explanation, the key risks, and a step-by-step plan for more control.
For organisations that want to accelerate AI adoption without losing control over data, security and compliance.
- CGUnauthorised
ChatGPT (Personal)
Browser · 68 users · risk medium
- ACProduction
Anthropic Claude
SSO · 24 users · risk low
- CUTest
Cursor
Desktop · 17 users · risk medium
- DSPhasing out
DeepSeek
Browser · 9 users · risk high
Shadow AI usually starts with good intentions
Employees use AI to summarise documents, work out meeting notes, write texts, run analyses and speed up processes. Sometimes they pick applications on their own that haven't been formally reviewed by IT, security or privacy.
Shadow AI is the business use of AI applications, AI functionality or AI integrations without formal review, approval and oversight from the organisation.
How Shadow AI shows up inside an organisation
Unknown AI use can arise in several ways. Here are four common examples.
Public AI chatbots
Employees use personal or free accounts to process business information.
Meeting assistants
A third-party application processes conversations, participants, transcripts and action items.
Browser and desktop apps
AI functionality gets installed independently, outside central application management.
SSO and Microsoft 365 integrations
An AI app gains access to email, calendar, files, SharePoint or Teams.
The gap between policy and practice
The official application landscape only covers what's known and approved. The actual landscape also includes personal accounts, standalone applications and unreviewed integrations.
Official AI landscape
What's visible
- known applications
- business accounts
- approved vendors
- clear ownership
- central management
Actual AI landscape
What's also happening
- unknown browser tools
- personal accounts
- standalone desktop apps
- unreviewed integrations
- no recorded owner
An AI policy describes what should happen. Shadow AI Discovery shows you what's actually happening.
Shadow AI is no longer a fringe issue
External research shows that the use of unapproved AI is growing faster than the governance around it.
71%
of surveyed UK employees said they had used an unapproved consumer AI tool for work at least once.
Source: Microsoft, survey among UK employees, 202563%
of the organisations surveyed by IBM that had suffered a data breach had no AI governance policy in place.
Source: IBM Cost of a Data Breach Report 2025The studies use different audiences and methods, but point the same way: AI use is growing faster than formal review and control.
Unknown AI use creates more than just a technical risk
Unwanted data sharing
Company information, customer data and intellectual property can end up in unreviewed AI tools.
Unknown data location
It's not always clear where data is stored, processed, or accessed by subprocessors.
Overly broad access
SSO and OAuth integrations can grant access to email, calendar, SharePoint, OneDrive or Teams.
Vendor risk
Not every AI vendor offers mature security, clear terms, or central management features.
Compliance and demonstrability
A policy alone doesn't prove that applications are actually reviewed and periodically reassessed.
Sprawl and duplicate costs
Departments can end up with similar subscriptions outside central contract and licence management.
Shadow AI can lead to investigation costs, remediation work, legal support, contractual disputes, duplicate licences, and loss of customer trust.
From unknown AI use to demonstrable control
Discover why Shadow AI arises, which risks organisations often overlook, and how to set up a practical governance process in five steps.
- how to make Shadow AI technically visible
- how to assess and classify applications
- how leadership and IT reach demonstrable decisions together
Free · practical · written for directors and IT
How much control does your organisation currently have?
Tick the statements that apply to your organisation. The result is an indication only; no data is stored or sent.
You may have some policy measures in place, but technical visibility is missing. As a result, it's unclear which AI applications are actually being used and whether your policy is being followed.
Get the whitepaperOne central overview of AI applications, users, risks and decisions
Campai combines signals from Microsoft 365, Entra, SSO connections, browser usage and endpoint software. That gives you one up-to-date overview of the AI usage found across the available data sources.
From technical signal to a documented management decision.
Vendors in one central view
See which AI vendors are being used within the organisation.
Applications and users
See who's using which application, and via browser, desktop or SSO.
Risk information
Record data location, risk classification and known incidents, among other things.
Shadow AI signalling
Managed serviceCampai compares discovered applications against the whitelist and flags deviations.
Lifecycle management
Managed serviceCampai helps assess applications and manages their status: Test, Production, Phasing out, or Unauthorised.
See the lifecycle model ↓Technical blocking
Managed serviceCampai can block unauthorised applications once the customer has made an authorised decision to do so.
26 / 29
devices with AI signals
125
signals detected
18
unique AI applications
| Device | Status | AI applications found | Signals | Last seen |
|---|---|---|---|---|
| DEVICE-014 | Needs attention | ChatGPTAnthropic ClaudeCursor+4 more | 12 | Today |
| DEVICE-027 | To review | Microsoft CopilotChatGPTDeepSeek | 8 | Today |
| DEVICE-031 | Needs attention | CursorClaude CodeGitHub Copilot+2 more | 7 | Yesterday |
| DEVICE-044 | To review | ChatGPTMicrosoft Copilot | 4 | Yesterday |
Not everything allowed. Not everything blocked. Deliberate decisions instead.
- Lifecycle statusTest
Test
Limited trial use with clear users, purposes and conditions.
- Lifecycle statusProduction
Production
Reviewed and approved for business use.
- Lifecycle statusPhasing out
Phasing out
Controlled replacement or discontinuation according to an agreed plan.
- Lifecycle statusUnauthorised
Unauthorised
Not allowed under policy or due to an unacceptable risk.
De juiste reactie op Shadow AI is niet automatisch blokkeren. Eerst moet duidelijk zijn waarom medewerkers de applicatie gebruiken en welk veilig alternatief beschikbaar is.
From initial inventory to structural AI governance
Shadow AI Quick Scan
Initial technical insight and priorities
- connecting a limited number of available data sources
- initial inventory of AI applications and vendors
- initial risk and management overview
Result
An initial, limited view of scope, risks and immediate points of attention — not yet an assessment per application.
Discovery & Governance Assessment
In-depth assessment and decision-making
- risk and vendor analysis
- comparison with AI policy and whitelist
- lifecycle decisions and governance roadmap
Result
An up-to-date AI application register and a well-founded improvement plan.
Managed Shadow AI Governance
Ongoing management and follow-up
- continuous detection and assessment
- whitelist and lifecycle management
- reporting, follow-up and blocking
Result
AI use stays demonstrably under control as applications, vendors and usage evolve.
This is what the inventory delivers in practice
AI application register
Overview of vendors, applications, users, owner and lifecycle stage.
Risk overview
Prioritisation based on usage, access, data location and vendor risk.
Decisions and actions
A record of what's allowed, tested, phased out or blocked, and who's responsible.
Management summary
A concise overview of the key risks, trends and decisions needed.
Built on security, compliance and AI governance
Campai works to recognised standards and combines technical discovery with governance follow-up.





Developed from real-world experience in Microsoft 365 management, cybersecurity, compliance and AI governance.
Shadow AI: from unknown use to demonstrable control
Discover why Shadow AI arises, which risks organisations often overlook, and how to set up a practical governance process in five steps.
- what Shadow AI actually is
- risks for data, security and compliance
- why an AI policy alone isn't enough
- how to technically discover AI applications
- a practical lifecycle model
- a step-by-step plan for directors and IT

Whitepaper
Shadow AI: from unknown use to demonstrable control
Risks, a lifecycle model, and a step-by-step plan for directors and IT.
Technical discovery and governance follow-up combined
Broad technical visibility
Signals from Microsoft 365, Entra, SSO, browsers and endpoints are combined.
More than a detection tool
Campai also supports risk assessment, policy, decision-making and lifecycle management.
Practical for SMEs
A managed governance process, without you needing to build a full CISO or AI governance function yourself.
Part of broader AI adoption
These insights can feed into AI policy, Microsoft 365 Copilot, training, use cases, compliance and licence optimisation.
What organisations usually ask us
From an AI policy on paper to control over actual use
Discover how to make AI applications visible, assess risks, and set up a practical governance process.