Shadow AI Inventory in 30 Days (No Budget Required)
Shadow AI Inventory in 30 Days (No Budget Required)
Your SaaS inventory is lying to you.
Not maliciously. It was built for a world where software came in boxes and licenses. That world is gone. Today, half your employees use AI tools you never approved, embedded AI features hide inside software you did approve, and autonomous agents are starting to act on your network with credentials nobody inventoried.
You cannot govern what you cannot see. So here is how to see it, in 30 days, with zero budget, using logs you already have and one conversation technique that actually works.
Why your SaaS inventory lies
Three reasons, in increasing order of sneakiness.
1. The obvious shadow
Employees sign up for AI tools with their work email or personal email, expense the subscription or use the free tier, and never tell IT. Your SaaS inventory, which tracks procured software, never sees them.
2. Embedded AI
Your approved tools now ship with AI features: the CRM has an AI assistant, the helpdesk has AI triage, the code editor has AI completion. Nobody procured an “AI tool.” The AI came inside software that was already on the list. Your inventory says “approved.” Your risk posture says otherwise, because each embedded feature sends data somewhere.
3. Agents
This is the new layer. AI agents with tool access, MCP servers connecting models to your internal systems, automation workflows chaining AI decisions together. These do not look like software at all. They look like API calls and OAuth grants. If your inventory model is “list of applications,” agents are invisible to it by design.
The fix is not a better spreadsheet. It is a different detection model, built on signals instead of procurement records.
The five signal sources
You already have everything you need. Here are the five sources, in order of signal quality.
SSO and OAuth grants
Pull every OAuth grant and SSO-connected app in your identity provider for the last 90 days. Look for grants to AI platforms: the obvious ones (ChatGPT, Claude, Gemini, Copilot) and the long tail of AI startups. Sort by user count, then by data scope: a grant with “read all emails” is a different animal than a grant with “basic profile.”
One afternoon of log work usually surfaces 60 to 70% of the footprint. This is the highest-signal, lowest-effort source you have. If you do nothing else on this list, do this.
CASB and egress logs
Your secure web gateway or CASB already sees the traffic. Query for AI domains: api.openai.com, claude.ai, and the few hundred AI SaaS domains in the long tail. Look at upload volume, not just visits. Someone pasting a customer list into a chatbot is an upload event, and uploads are what you care about.
If you do not have a CASB, DNS logs work. If you do not have DNS logging, your firewall logs work. The principle is the same: follow the data leaving the building.
Expense and procurement records
Finance sees what IT does not. Pull expense reports and corporate card transactions for AI subscriptions: $20/month charges are the fingerprints of shadow AI. Procurement records catch the bigger buys that bypassed security review. I once found an entire department’s AI workflow platform in expense reports, expensed as “software,” live for eight months, touching customer data.
Repository and code scans
Your developers are the heaviest AI users and the least likely to ask permission. Scan your code repositories for API keys and SDK usage: openai, anthropic, and friends in environment files, CI/CD secrets, and committed code. Check for MCP server configurations and agent frameworks. A single committed API key can mean an entire shadow pipeline.
The amnesty
The four technical sources will find most of it. The amnesty finds the rest, including the things no log captures: the personal-email signup, the tool used on a personal device for work tasks, the “AI” that is actually a contractor pasting your data into a chatbot offshore.
The amnesty: exact framing that gets honest answers
Here is the email. Adapt it, but keep the structure.
Team,
We know AI tools help you get work done, and we want to support that. This week, we are running a one-time amnesty: tell us every AI tool you use for work, including free tiers, personal accounts, and browser extensions. Reply to this form [link].
Two promises. First, nobody gets in trouble, and no tool gets banned as a result of this survey. Second, the most-requested tools go to the top of our list for proper licensing, which means you get the paid version with company data protections.
What we need from you: tool name, what you use it for, and whether it touches customer data, employee data, or source code.
Thank you for helping us help you.
Why this works: it trades honesty for benefit. People hide tools because they fear losing them. The amnesty promises the opposite: tell us, and we might buy you the good version. The data-classification question (customer data? employee data? code?) is the triage input, and most people answer it accurately.
Run it for exactly one week. Publish the aggregated results back to the company: “You told us about 47 tools. Here is what happens next.” That closes the loop and makes the next amnesty, next year, even more effective.
Risk-rank, don’t alphabetize
An inventory sorted A to Z is a phone book. What you need is a risk ranking, and the formula is simple:
Data sensitivity: what does the tool touch? Public marketing copy is low. Customer PII, employee records, source code, financials, and anything regulated (FERPA, HIPAA, PCI) are high.
Agency: what can the tool do? Read-only assistance (summarize this document) is low agency. Systems that send emails, modify records, execute transactions, or make decisions about people are high agency. An AI that drafts is a tool. An AI that acts is a liability.
Plot every discovered system on those two axes. Your top-right quadrant, high sensitivity and high agency, is where you start. That quadrant gets immediate review: contract, data protections, human oversight, logging. The bottom-left quadrant gets documented and monitored. Everything in between gets a proportional response.
This two-axis model fits on one slide, which means you can brief it to a board. More on that below.
The sanctioned path must compete on speed
Here is the uncomfortable truth about shadow AI: people do not use unsanctioned tools because they are reckless. They use them because the sanctioned path is slow.
If your AI tool approval process takes three months, you do not have a governance program. You have a shadow AI incubator.
Erdal Ozkaya
Every week of delay is another team expensing another subscription. The fix: make the sanctioned path the path of least resistance.
Pre-negotiated enterprise AI licenses
With data protections already in place. The default should be “use this,” not “request permission.”
A request path measured in days
Publish the SLA. A new tool request gets a decision in ten business days or fewer. Miss the SLA and the requester gets a provisional yes with guardrails, because speed is a security control.
A pilot lane
Unproven tools get 90 days with defined users, defined data, and a defined evaluation. Pilots that pass become sanctioned. This turns “no” into “not yet, here is the path.”
Governance that is slower than shadow IT is just theater with extra steps.
Agents and MCP: the new inventory layer
Your 30-day inventory must include a layer most inventories miss: autonomous agents and the Model Context Protocol (MCP) servers connecting them to your systems.
Agents do not appear in SaaS lists. They appear as API keys, OAuth grants with broad scopes, service accounts, and scheduled jobs. Add these to your signal sources:
Service accounts and API keys
With access to production data. Each one is a potential agent you did not inventory.
MCP server configurations
In developer environments. An MCP server is a bridge between an AI model and your internal tools. Every bridge needs to be on the map.
Automation platforms
Zapier-style tools and internal workflow engines with AI steps. The AI step inside an approved automation is the embedded-AI problem wearing a different hat.
Record the same five fields as any AI system, plus two more: what actions can it take, and what stops it. An agent with write access and no kill switch is not a productivity tool. It is an incident waiting for a trigger.
The monthly refresh and the one board metric
An inventory is not a deliverable. It is a vital sign. AI footprints decay fast: new tools appear monthly, employees churn, vendors add AI features to existing products overnight.
SSO/OAuth pull + egress query
First Monday of every month. It takes an hour once the queries are saved. Review the delta, not the whole list: what is new, what disappeared, what changed tiers.
Expense scan
Re-run the expense and procurement scan.
Amnesty
Re-run the amnesty.
One number, trended monthly, going down. Boards do not need the full inventory. They need to know the exposure is shrinking and that you can prove it. I report this alongside my other board metrics every quarter, and it is the number that gets the most questions, which tells you it is the number that matters.
The bottom line
You do not need a budget to find your shadow AI. You need SSO logs, egress data, expense records, a repo scan, and one honest conversation with your company. Thirty days, five sources, one risk-ranked register, and a refresh cadence that keeps it alive.
Start with the OAuth grants this afternoon. By Friday, you will know more about your AI footprint than most CISOs learn in a year.

