The rapid proliferation of generative AI tools has created a new governance challenge for mid-market organisations. Employees, often with good intentions, are using unsanctioned AI platforms to draft emails, summarise documents, and generate code. This practice, known as shadow AI, poses significant risks to data security and regulatory compliance. In response, IT leaders are developing shadow AI inventories: systematic maps of the AI tools in use across their organisations, designed to identify, assess, and control data leakage.
This case study examines how mid-market IT leaders are approaching this task, the methods they employ, and the commercial implications of their efforts. It draws on publicly available guidance from industry bodies and security vendors, as well as editorial analysis of emerging practices. No proprietary or non-public data is used.
The Rise of Shadow AI
Shadow AI refers to the use of artificial intelligence tools and services without explicit organisational approval or oversight. Unlike shadow IT, which typically involves unsanctioned hardware or software, shadow AI is often invisible because many tools are accessed via web browsers and require no installation. Employees may use a free AI writing assistant, a code completion plugin, or a customer relationship management (CRM) tool with built-in AI features, without realising that these tools may process sensitive data on external servers.
A 2024 survey by Gartner estimated that 40% of AI-related data breaches could be traced back to shadow AI usage, though this figure is an estimate and not a verified statistic. The actual prevalence is likely higher, as many organisations do not yet have visibility into their AI usage. For mid-market companies, the risk is acute: they often lack the dedicated security teams and budgets of larger enterprises, yet they handle sensitive customer data, financial records, and intellectual property.
The Inventory Approach
Mid-market IT leaders are responding by creating shadow AI inventories. These are not simple lists of tools; they are structured assessments that combine technical discovery, employee engagement, and policy development. The process typically involves three stages: discovery, assessment, and remediation.
Discovery: Finding the Tools
The first step is to identify which AI tools are being used. This is often achieved through network traffic analysis, browser extension audits, and single sign-on (SSO) logs. For example, an IT team might use a cloud access security broker (CASB) to monitor traffic to known AI domains, or they might review proxy logs to see which AI websites are accessed. However, this approach has limitations: many AI tools are embedded within other applications, such as Microsoft 365 Copilot or Salesforce Einstein, making them harder to detect.
Some organisations are turning to dedicated shadow AI discovery tools, which use machine learning to classify AI traffic and identify data exfiltration attempts. These tools can flag when an employee uploads a file containing customer data to an external AI service. However, they are not foolproof and may generate false positives, requiring manual review.
Assessment: Evaluating Risk
Once the tools are identified, IT leaders assess the risk they pose. This involves evaluating the data types that are being processed, the security posture of the AI vendor, and the compliance implications. For example, a tool that processes personal data of EU citizens may trigger GDPR obligations, while a tool that stores data on servers in the US may raise data residency concerns.
A common framework is to categorise AI tools into three risk levels: low, medium, and high. Low-risk tools might include those that process only non-sensitive data and have strong security certifications. Medium-risk tools might process some sensitive data but have adequate safeguards. High-risk tools are those that process sensitive data without clear security guarantees, or that are used in violation of regulatory requirements.
Remediation: Controlling Usage
After assessment, IT leaders implement controls. These can range from blocking high-risk tools outright, to providing approved alternatives, to implementing data loss prevention (DLP) policies that restrict what can be uploaded to AI services. Some organisations are also creating internal AI sandboxes, where employees can experiment with AI tools in a controlled environment, with data sanitisation and audit trails.
A key part of remediation is employee education. Many employees are unaware of the risks of shadow AI. IT leaders are developing training programmes that explain the risks and provide clear guidelines on acceptable use. This is not about punishing employees, but about enabling them to use AI safely and productively.
Why It Matters
The shadow AI inventory is not just a security exercise; it is a business imperative. Data leakage can lead to regulatory fines, loss of customer trust, and competitive disadvantage. For mid-market companies, a single breach can be catastrophic, potentially leading to bankruptcy or acquisition at a depressed valuation.
Moreover, shadow AI can create legal liabilities. If an employee uses an AI tool that generates copyrighted content, the organisation may be exposed to infringement claims. Similarly, if an AI tool makes a biased decision that affects a customer, the organisation may face discrimination claims. An inventory helps organisations understand these risks and take proactive measures.
From a commercial perspective, shadow AI can also represent a hidden cost. Employees may be paying for AI subscriptions out of pocket, or using free tiers that limit functionality. By mapping usage, IT leaders can consolidate spending, negotiate enterprise licences, and ensure that the organisation is getting value from its AI investments.
Commercial Impact
The commercial impact of shadow AI inventories is twofold. First, they reduce the risk of costly data breaches and regulatory penalties. The average cost of a data breach in 2024 was estimated at $4.88 million, according to IBM's Cost of a Data Breach Report, though this is a global average and may not reflect mid-market specifics. For a mid-market company, even a fraction of that cost could be devastating.
Second, they enable more effective AI adoption. By understanding which tools are actually being used, IT leaders can make informed decisions about which AI investments to support. They can also identify opportunities to consolidate tools, reduce redundancy, and negotiate better pricing. In some cases, the inventory reveals that employees are using consumer-grade tools that lack enterprise features, such as audit logs or data retention controls. Replacing these with enterprise-grade alternatives can improve security and compliance, while also providing better functionality.
Risks and Unknowns
The shadow AI inventory approach is not without risks. One challenge is the rapid pace of AI development. New tools are released constantly, and existing tools are updated with new features that may change their risk profile. An inventory that is not regularly updated can quickly become outdated.
Another risk is employee pushback. If employees perceive the inventory as surveillance, they may resist or find ways to circumvent it. This can lead to a cat-and-mouse game, where IT leaders are constantly trying to catch up with new shadow AI usage. To mitigate this, some organisations are adopting a 'positive' approach, framing the inventory as a way to enable safe AI use rather than to restrict it.
There are also technical limitations. Network traffic analysis may miss AI tools that are embedded in other applications, and DLP tools may not be able to inspect encrypted traffic. Moreover, the rise of on-device AI models, such as those running on smartphones or laptops, may make shadow AI even harder to detect.
Finally, there is the question of regulatory uncertainty. The EU AI Act, which came into force in August 2024, imposes obligations on providers and deployers of AI systems, but its full implications for shadow AI are not yet clear. Similarly, the US has no comprehensive federal AI law, leaving a patchwork of state regulations. This uncertainty makes it difficult for IT leaders to know exactly what compliance measures are required.
FY Outlook
The shadow AI inventory is likely to become a standard practice in mid-market organisations over the next two to three years. As AI tools become more embedded in everyday work, the risk of data leakage will only increase. IT leaders will need to move from reactive discovery to proactive governance, integrating AI usage into their overall security and compliance frameworks.
We expect to see the emergence of specialised shadow AI discovery tools that are tailored to mid-market needs, with lower costs and simpler deployment than enterprise-grade solutions. These tools will likely incorporate AI themselves, using machine learning to identify anomalous behaviour and predict future risks.
We also anticipate a shift towards 'AI governance' as a distinct discipline, with dedicated roles such as AI risk officers or AI compliance managers. Mid-market companies may not have the resources for full-time roles, but they may assign these responsibilities to existing security or compliance staff, with additional training.
Finally, we expect to see more collaboration between IT, legal, and HR departments in managing shadow AI. This is not just a technical issue; it involves employee behaviour, contractual obligations, and regulatory compliance. A cross-functional approach will be essential.
Conclusion
The shadow AI inventory is a pragmatic response to a real and growing risk. Mid-market IT leaders are not trying to ban AI; they are trying to understand it, control it, and use it safely. The approach is still evolving, and there are significant challenges, but the direction is clear: organisations that fail to map their AI usage will be exposed to data leakage, regulatory penalties, and competitive disadvantage.
For founders, operators, and investors, the message is that shadow AI is a business issue, not just a technical one. It affects data security, legal liability, and operational efficiency. Those who take a proactive approach to shadow AI governance will be better positioned to harness the benefits of AI while managing its risks.
As the AI economy matures, the ability to manage shadow AI will become a competitive differentiator. The organisations that do it well will be able to innovate faster, with less risk, and with greater trust from customers and regulators.



