Everyone uses AI tools today, especially at work. And companies are introducing AI usage policies to ensure that employees don’t share company data with unauthorized tools. But before you decide which tools your team is allowed to use, you need the list of tools they are already using, and how much time goes into each one.

Getting that list is what most people mean when they ask how to detect shadow AI. It has very little to do with running a security program and a lot to do with reading your own usage data properly.

We did exactly this for our own workspace last week. Those numbers are further down, and they are real.

What Is Shadow AI?

Shadow AI is any AI tool your team uses for work without approval or oversight. Employees might unknowingly share customer records, contract terms, unreleased financials, or source code. They might even do that through a personal account, meaning you will have no record of what was shared and no way to audit it later.

ChatGPT in a browser tab. A coding assistant someone installed for a trial and kept. An AI browser extension. An AI feature switched on inside software you already pay for.

A tool gets used because it is there and it does the job. When the approved option arrives six months late, or arrives and handles the work badly, the unapproved one takes over. Shadow AI is usually a supply problem that shows up as a security one.

Why Shadow AI Is Hard to See

People sign in with personal accounts

The 2026 Verizon Data Breach Investigations Report found that 45% of employees now use AI regularly at work, up from 15% the previous year, and that 67% of those accessing AI services on corporate devices were signed in with non-corporate accounts. That’s why your Google Workspace admin console might not show you a personal ChatGPT login. 

AI arrives inside software you already approved

Your project tool, your CRM, and your design tool most likely already have their own AI tools. That is why you might not be able to detect these cause the main tool is already approved. 

This is also why blocking does not work as a first move. If you block a tool at the network level, employees might move to their phones, a personal laptop, or a personal account on the same machine. 

How to detect shadow AI in your team: four places to look

1. Your app and website usage data

Use AI detection and time tracking tools with monitoring capabilities. These can provide you with the list of which applications and websites people use during working sessions. And when you sort them, you can spot the AI tools: cursor, claude.ai, chatgpt.com, gemini.google.com, perplexity.ai, plus a long tail of smaller ones.

2. Browser detail, not just “Chrome”

If your usage report only shows the time spent in Chrome, naturally, you won’t see shadow AI. You need the website names underneath the browser, and ideally the URL-level records, so you can clearly see the usage of AI. 

3. The AI features inside software you already use and pay for

Detection tools might overlook tools that are not inherently AI since you have already approved these for their main functionality. This part you have to check manually. Go through the tools on your subscription list, open the admin settings, and write down which AI features are switched on, who enabled them, and which of your data they can reach.

4. Ask your team directly

Ask what people are using and what they use it for. This works far better when you say what you plan to do with the answer, which should be to approve most of it.

It is a good idea to ask this before you have the usage data in front of you cause otherwise it might come off as accusation. But even if you already have the list of tools and you know there are unauthorized ones among them, go ahead and talk to your team. 

Two Types of Shadow AI Detection Tools

These tools fall into two categories: security and workforce management tools.

Security and SaaS Governance Platforms

Shadow AI detection tools in the security category can detect, block, and enforce. Usually it is the security or IT teams that purchase these. 

Teramind works at the endpoint. It detects unsanctioned AI tools, AI-native browsers, browser extensions, desktop AI apps, and local models that never touch a network firewall, captures full prompt-and-response transcripts, and blocks source code or PII being typed or pasted into AI prompts. It is also a full employee monitoring and DLP product, so it comes with screen recording and everything that implies for your team. 

Reco covers the SaaS side. It runs agentless and read-only, integrating with your identity provider to get the list of known applications and analyzing email metadata for signs of sign-ups to unauthorized tools. It also finds AI tools and copilots reaching your data through OAuth grants and third-party integrations. Because it is read-only, it cannot stop anyone from entering sensitive data into an AI tool. 

Knostic is aimed at enterprise AI assistants rather than public chatbots. It provides need-to-know access controls for assistants like Microsoft Copilot, Glean, and Gemini, discovers shadow AI usage, and produces audit logs showing who accessed which data through which AI system. It is also positioned as an add-on to Microsoft Purview for oversharing detection. Relevant if your worry is internal data reaching the wrong colleague through a copilot. 

Auvik is the most IT-operation tool of the five. It deploys lightweight endpoint collectors and browser extensions that watch web activity, matches what it sees against a database of more than 125,000 applications, flags apps accessed multiple times a week as actively used, and notifies you when someone visits a newly discovered AI platform. It also tracks license waste and SaaS spend, which is often the easier internal case to make. 

Workforce Analytics and Time Tracking Tools

Detection tools in the workforce analytics category focus on showing AI tool usage. They do not block anything, and it is usually team managers who purchase these instead of the security department. 

For detection work, what matters is whether the tool gives you website-level names, time per tool, a per-person and per-team breakdown, and enough history that you can compare this month against last month. Plenty of time trackers have an app and website report. But not all give you the detailed reports you need for accurate AI tool detection. 

WebWork is in this category. It gives you an app and website report with details to the t, including time per tool per person and per team, along with URLs. It also connects to AI tools through MCP, meaning you can get answers about shadow AI in your team by directly asking your AI model. The next section is that report, run on our own workspace.

What a Week of AI Usage Looked Like in Our Own Workspace

We run WebWork on our own team, so we pulled the numbers rather than describing them in the abstract. This is one workspace over one week, the week of August 17-23, 2026, and it is an example of what the report looks like.

Across the workspace we tracked 36,721 minutes. AI tools accounted for 15.6% of that time, or 95.3 hours.

ToolHours% of AI time% of all tracked timePeople
Cursor AI54.156.8%8.8%3
Claude32.534.1%5.3%11
ChatGPT7.98.3%1.3%11
Google Gemini0.50.6%0.1%2
WebWork AI0.10.1%~0%1
platform.openai.com0.10.1%~0%1

By team, Engineering accounted for 48.3 AI hours, almost all of it Cursor. Website Production came next at 27.1 hours, mostly Claude. Management logged 12.8 hours, Product Marketing 10.8, Product Design 4.5, Quality Assurance 3.7, and Customer Success Management 3.5, where ChatGPT rather than Claude was the leading tool.

The apps and websites report records which applications and websites people use during tracked sessions, with time spent per tool, broken down per member and per team. Note that URL-level detail is available from the Plus plan.

Moreover, when you connect WebWork to AI tools through MCP, it gives you the breakdown above as percentages — AI tool usage across the team, split into authorized and unauthorized tools, with how often each one is used.

One thing to be plain about: WebWork gives you visibility and not enforcement. We do not block tools, inspect prompts, or catch copied and pasted data. If those are the capabilities you need, select from the security platforms in the section above. 

What we can tell you is which AI tools your team uses, who uses them, and how much time goes into each.

If you want to see this report on your own team, WebWork is free for 14 days, no card required. Give it a week of tracking and get the AI list.

What to Do with the Data Once You Have It

Approve the tools people already use

If your team already uses a tool and there is no serious objection to it, put it on the approved list and buy team accounts. A team account is visible, governed, and usually cheaper than the individual subscriptions people expense one at a time. It also moves the usage off personal accounts, which was the actual problem.

Name specific tools in the policy

Name the tools that are approved, name the ones that are not and say why, and say which categories of data must never go into any of them. These can be customer records, credentials, unreleased financials, and source code you do not own.

Say what you will do about a tool that isn’t on the list yet

Give people a way to ask, and answer within a week. This way you create transparency and build trust so team members can feel free to ask any questions they have about the tools they use. 

Re-check the numbers

Run the same report in a month and again in a quarter because new tools appear constantly. By rechecking you will see whether the policy landed or whether usage just moved somewhere else.

Start with What Your Team Is Already Doing

Detection is the cheapest step in any AI program, and it is the one that makes every later decision easier. To write a sensible policy, you need real data about what tools people in your team already use. 

We will run this report again next quarter and see what changed. Maybe new tools will appear, or maybe different teams will start using different tools. 

If you want the same view of your team, try WebWork free for 14 days or book a demo and we will walk you through the reports on your own data. Either way, start with the list. The policy gets much easier to write once you have it.