AI Governance

Shadow AI discovery: what your evidence can and cannot show

GovernSafe Team
Published
Last reviewed
8 min read
GovernSafe

An IT lead sees an AI application in a device report, a connection to an AI service in a network report and a declared use in the organisation's AI register. These may be unrelated. Start with a smaller question: what did each source observe, for whom and when? A missing record cannot establish that no AI use occurred.

Four questions that need different evidence

What activity was reported? Record the exact device or network signal, asset or path, period and collection scope. The report does not establish business purpose.

Was the use approved? Check the approval record and its scope with the business owner. A register entry can name a declared use, owner and approval reference. It cannot discover undeclared use or prove that current activity fits the approval.

What access was granted? A device or network signal does not list an identity's permissions. Check the relevant access or consent record under the organisation's authority; until then, access is unknown.

Was a restriction applied and verified? Policy configuration, deployment and observed effect need separate evidence. A discovery report proves none of them. Verify the intended scope and result through an authorised process before calling a restriction enforced.

Compare the sources before combining them

SourceWhat it can contributeWhat it cannot settle alone
Managed-device observationA reported application or agent signal on devices covered by that source during its observation period.Activity on other devices, what was entered into a tool, business approval, access grants or enforcement.
Network observationConnections or usage measures for traffic that passed through the configured collection path and matched a service catalogue.Traffic outside that path, prompt contents, sensitive disclosure, approval or a person's purpose.
Human-maintained AI registerDeclared systems and uses, accountable owners, intended purpose and recorded review or approval information.Undeclared use, current device or network activity, or whether a restriction is operating.

Microsoft's Global Secure Access shadow AI discovery and Application Usage Analytics show catalogue matches and usage measures in traffic the service sees. Transactions and bytes do not reveal prompt text or prove sensitive disclosure. A path outside collection stays outside the conclusion.

Microsoft's Shadow AI page in the Microsoft 365 admin center is a Frontier public preview. On 28 September 2026, its prerequisites included preview opt-in, Defender for Endpoint, Microsoft 365 E5, Intune-managed Windows devices and an eligible role. Global Secure Access adds some metadata. Check current prerequisites and supported agents before relying on its coverage. These Microsoft examples do not establish a GovernSafe integration.

The Australian National AI Centre's AI systems register guidance covers systems, use cases and accountable people, including embedded AI. A register is guidance for declared use, not automatic discovery or a legal mandate.

A worksheet for one evidence record

Copy one record per source. Join records only when evidence supports the link.

FieldRecord
Source or reportName, report ID or retained reference: ___
Authorised organisation or client scopeOrganisation or one client and the permitted review purpose: ___
Covered assets or usersNamed group, devices, identities or path; exclusions: ___
Observation periodStart and end, with timezone; or a point-in-time snapshot: ___
Collection date and timeWhen this record was obtained, with timezone: ___
Stated lag or unavailable freshnessSource's stated delay and last update, or unavailable: ___
ObservationThe exact reported signal, with no extra inference: ___
Unknowns and exclusionsUse the status terms below and state the unanswered question: ___
Accountable reviewerRole or named owner authorised for this review: ___
Next verificationOne permitted check, its owner and the decision it will inform: ___

Use distinct statuses: not observed in this source and period for no matching signal within collected scope; not collected when no report was obtained; outside scope for an uncovered person, device, path or period; unknown when evidence cannot answer the question. None means there was no AI use organisation-wide.

Worked example: three fictional records

All records below are fictional. Example Organisation has 120 people. Its seven-day review covers Managed Group A, one office network path and a human register. These are illustrative numbers, not GovernSafe or customer results.

Record D1: managed-device observation

FieldSynthetic entry
Source or reportDevice observation D1.
Authorised organisation or client scopeExample Organisation internal review; Managed Group A only.
Covered assets or users40 managed laptops in Group A; other devices outside scope. This is not a people count.
Observation period21 September 2026, 00:00 to 27 September 2026, 23:59 AEST.
Collection date and time28 September 2026, 09:00 AEST.
Stated lag or unavailable freshnessUnavailable; no ingestion delay or last-scan guarantee stated.
ObservationAn AI application was reported on one in-scope laptop.
Unknowns and exclusionsOther in-scope device states, purpose, content and approval unknown; other devices outside scope.
Accountable reviewerEndpoint reviewer for this internal review.
Next verificationConfirm device identity, scan time and signal; ask the business owner about approval within permitted scope.

Record N1: network observation

FieldSynthetic entry
Source or reportNetwork report N1.
Authorised organisation or client scopeExample Organisation internal review; office egress path A only.
Covered assets or usersTraffic on path A; distinct user/device count unknown; other paths outside scope.
Observation period21 September 2026, 00:00 to 27 September 2026, 23:59 AEST.
Collection date and time28 September 2026, 09:20 AEST.
Stated lag or unavailable freshnessUnavailable; no ingestion delay stated.
ObservationA connection to a catalogued AI service was recorded on path A.
Unknowns and exclusionsPrompt, disclosure, identity and approval unknown; other paths outside scope; activity there unknown.
Accountable reviewerNetwork reviewer for this internal review.
Next verificationConfirm path coverage, period and permitted identity attribution; seek business context.

Record R1: human-maintained register

FieldSynthetic entry
Source or reportAI register snapshot R1.
Authorised organisation or client scopeExample Organisation declared-use register; no automatic discovery.
Covered assets or usersOne declared use; undeclared uses outside the declared-use register's scope; their existence and activity unknown.
Observation periodPoint-in-time snapshot, 28 September 2026; no seven-day activity log.
Collection date and time28 September 2026, 10:00 AEST.
Stated lag or unavailable freshnessEntry update date unknown; no automated freshness claim.
ObservationOne declared use has an owner and a recorded approval reference.
Unknowns and exclusionsApproval scope/currentness, activity and enforcement unknown; undeclared uses outside the declared-use register's scope; their existence and activity unknown.
Accountable reviewerBusiness owner for the declared use.
Next verificationConfirm approval reference, scope and open questions with the owner.

Nothing links D1, N1 and R1 to one person or tool. Forty laptops in a 120-person organisation do not establish a percentage of staff using AI.

Investigate the open question

Confirm the triggering report's asset or path, period, collection time and lag. Separate observation from reviewer inference. Before using another source, check authority and whether asset, identity and period match. Ask the business owner about purpose and approval; check access and policy state in their own records. Name each follow-up owner and leave gaps open until evidence arrives.

For an empty collected report, record not observed in this source and period and its exclusions. If there is no report, write not collected.

If you review this for an MSP client

Agree each client's authorised scope, source access, reviewer and decision owner. Keep separate worksheets and outcomes per client. Client A's device observation cannot fill Client B's network gap, and their counts cannot be combined into a coverage claim. For an unavailable source, record not collected or outside scope and name the client's next check. This method grants no new data access or control-change authority.

Where GovernSafe fits

GovernSafe's public About page states: "See observed AI use on devices running the GovernSafe client. Broader agent ownership and approval workflows are on the roadmap." This worksheet is an educational method. The Microsoft examples do not establish GovernSafe coverage, approval decisions or enforcement.

Source notes

Sources checked on 28 September 2026. Recheck documentation before making a coverage decision. The records above are synthetic.

Tags:Shadow AIAI governanceEvidenceHuman review

Talk to GovernSafe

Ready to see it on your stack?

Show us the cloud problem. We will walk through the GovernSafe workflow that fits it.