All articles
    AI Security
    Vendor Discovery

    Shadow AI: How to Find the AI Vendors Nobody Told Security About

    VendorBreach Team · 8/19/2026 · 6 min read

    Ask a security team how many AI tools their company uses and you'll usually get a number. Ask their identity provider the same question and you'll get a longer list. That gap, between the AI vendors that went through review and the ones employees signed up for on a Tuesday afternoon, is shadow AI, and it is now one of the fastest-growing categories of unmanaged third-party risk.

    Why Shadow AI Is Different From Ordinary Shadow IT

    Unsanctioned SaaS has been a problem for a decade. AI tools make it sharper for three reasons:

    • The data leaving is unstructured and sensitive. People paste contracts, customer tickets, source code, and incident notes into a prompt box. None of that shows up in a DLP rule written for file uploads.
    • Training policies vary wildly. Some vendors never train on customer input, some train by default unless you're on an enterprise tier, and some change the policy between releases. The same product can be acceptable or unacceptable depending on which plan an employee clicked.
    • Adoption is bottom-up. Free tiers mean no invoice, no procurement ticket, and no security review. The usual signals that a new vendor exists never fire.

    Where the Evidence Already Lives

    You probably don't need new tooling to find shadow AI. Read the logs you already collect:

    1. SSO and identity logs. Okta system logs, Entra ID sign-in logs, and Google Workspace audit events record every app an employee authenticates into, including ones IT never provisioned.
    2. OAuth grants. Third-party apps that requested access to mail, files, or calendars leave a durable consent record. An AI "meeting assistant" with mailbox scope is a vendor relationship, whether or not anyone signed a contract.
    3. Egress and DNS data. Useful as a backstop for tools used without any login at all.

    Export a month of SSO events, match app names and domains against a catalog of known AI vendors, and you generally have a usable picture within an hour.

    Turning a List Into a Risk Decision

    A list of detected tools isn't the deliverable; a decision per tool is. For each vendor found, the questions that matter are:

    • How many people use it, and who? Three users in marketing is a different problem from forty across engineering and legal.
    • What data can it reach? Prompt-only access is not the same as OAuth scopes into email and documents.
    • What's the training and retention policy? Whether inputs train the model, how long data is retained, and where it's processed drive most of the risk rating.
    • Is there a sanctioned equivalent? The fastest remediation for most shadow AI is redirecting users to an approved tool that already passed review, not a blanket block that pushes usage to personal devices.

    Then triage: approve, approve-with-conditions, replace, or block. Anything you approve should join your regular vendor inventory with the same monitoring as the rest.

    Making It Continuous

    A one-off discovery scan ages badly, since the AI vendor market shifts monthly. Re-run discovery on a schedule, alert on newly seen vendors rather than re-reviewing the whole list, and keep the reviewed decisions attached to each vendor so a second scan doesn't reopen a settled question.

    Where VendorBreach Fits

    VendorBreach's AI Vendor Detection scans SSO and SaaS audit log exports (Okta, Entra ID, Google Workspace, or generic CSV) against a maintained catalog of AI vendor fingerprints, rolls up per-vendor usage with first- and last-seen dates, and links each detection to vendor intelligence: training policy, retention, data residency, attestations, and breach history. Detected vendors can be promoted into your monitored inventory in a click.

    If you're building the broader program around it, start with what third-party risk management covers, and see the platform overview for how discovery, assessment, and monitoring fit together.