Shadow AI audit

Shadow AI is staff doing client work in AI tools the firm never approved and cannot see.

A free ChatGPT account. A browser extension that summarises pages. A personal Claude login used on a client matter. No policy covers it and nobody mentions it in a meeting. It is rarely malicious and almost never visible to the people who run the firm. We find it from your own Microsoft 365 tenant, before we ask anyone a question.

Book your audit
  • £3,000 + VAT, fixed
  • Two weeks
  • Tenant evidence pulled first
  • Five written deliverables

Why it is a live risk

File permissions are now AI controls.

An AI assistant sees exactly what the account running it can see. Nothing more, nothing less. That one fact changes what governance means for a small firm.

Your permissions were set for people, not for something that reads everything

Most firms have never tidied SharePoint permissions, shared mailboxes or Teams membership, because no person was going to open every file at once. An assistant signed into that account can. If a fee-earner's login reaches the whole client share, so does any AI tool connected to it. Permissions set in a hurry years ago are the controls your AI runs under today.

What goes in is usually the thing that matters

Nobody pastes the lunch order into a chatbot. They paste the contract clause, the client's accounts, the rota with staff names on it. Free tiers may keep what they are given. For privileged material, handing it to a third-party tool outside your control raises a real question over whether privilege survives. You do not want that settled on your own file.

The rules already apply

Both UK GDPR and the EU AI Act bear on how you can use AI. Your sector body (SRA, FCA, ICAEW or CQC) expects you to know which tools handle client information. In UK financial services the FCA expects AI governed now, under Consumer Duty, SMCR, model risk management and operational resilience. There is no bespoke AI regulation to wait for. "We did not know" describes the gap. It is not a defence.

How we find it

Evidence first. Interviews second. The gap between them is the finding.

Enterprise shadow-AI discovery is sold at $65,000 to $95,000 for four to five weeks (Kriv AI's AWS Marketplace listing is one example), because finding it from outside a company means scanning browsers and endpoints across thousands of staff. We manage Microsoft 365 tenants for a living. Once you have granted access, the evidence is a query, not a project.

We read the tenant

With your permission, before we ask anyone anything: OAuth app consents, enterprise app registrations, sign-in activity against known AI domains, DLP matches, licence state and managed browser extensions.

Then we talk to your people

Working sessions with up to five of your team. Which tools they use, for what, and what goes into them. People tell an outsider things they do not tell IT.

We reconcile the two

The tenant shows which AI services were signed into and which apps were granted access to mail and files. Your people say what they use. Where the two disagree is where the risk sits, and where the policy needs writing.

What you get

Five documents. The shadow-AI inventory is one of them.

This is the same two-week audit we run for AI readiness. Shadow AI is not a separate exercise. It is what the security review and the policy are built on.

An AI policy and shadow-AI inventory

One page each. Which AI tools your team actually uses, what data goes into them, and a policy a client or regulator could read. Our free one-page AI policy template is the starting point.

A security and data-handling review

Built from your tenant: app consents, sign-in activity, file permissions and what your AI tools can already reach. This is where the permissions question gets answered.

A workflow inventory

A written record of every workflow we reviewed and how it runs today, including where AI is already in it, approved or not.

An opportunity map

Every candidate for AI ranked on impact against effort. The tools people reached for on their own are often the best clue to what is worth doing properly.

A 30/60/90-day roadmap

Sequenced and costed, with a named first project, so the shadow-AI fixes have a date rather than a good intention.

FAQ

Straight answers.

What is shadow AI, exactly?

Staff using AI tools for work that the firm has not approved and does not oversee: free ChatGPT, a browser extension, a personal Claude subscription. No policy behind it, no record of what went in, and usually nobody in charge who knows. It is almost always well-meant, and invisible until a client, a regulator or a leak makes it visible.

We are eight people. Are we too small to bother?

No. Size changes how long the check takes, not whether it matters. In a small firm each person tends to hold broader access, so one account with an AI tool connected to it can reach a larger share of everything you hold. The review is sized for small firms: up to five people interviewed, two weeks from agreed access, one fixed fee.

What do you look at, and what do you not?

How your systems are used and configured: which apps have been granted access, which AI services accounts have signed into, what your DLP has flagged, which licences and browser extensions are in place, and who can reach what. We do not read the contents of client files, emails or documents. The finding is about access and behaviour, not what is in the files.

What does it cost?

A fixed fee of £3,000 plus VAT. That covers the tenant evidence work, sessions with up to five of your team, and all five written deliverables. Two weeks from receipt of the agreed access and information.

What happens next?

You book, we agree the access we need, and the evidence pull starts. Interviews follow. Two weeks from agreed access you have the five documents, including the AI tool register and a policy your staff can read. Going further with us is a separate decision; the documents are yours either way.

Book your audit

Know what is in use before a client or regulator asks.

Two weeks, £3,000 plus VAT, five documents you keep. The shadow-AI inventory is built from your tenant, so you get what is happening rather than what people remember.

Book your audit

We separate observed activity, potential exposure and areas we cannot verify, and we label each finding accordingly. Personal accounts, unmanaged devices and unavailable logs limit what any review can see: we record those gaps rather than claim to identify every instance of AI use. Access is granted by you, limited to the agreed scope and read-only where supported. This is a scoped advisory review, not a certification, a legal opinion or a guarantee of compliance.