Shadow-AI discovery sprint
The hardest part of AI governance is knowing what exists. This guide runs a focused sprint to surface shadow AI, GenAI tools, vendor AI and emerging agentic workflows in use but never registered, and bring it under governance.
When to use this
Section titled “When to use this”You suspect (or know) that AI is being used across the organisation faster than governance can track, and you need an honest inventory before you can govern anything.
What you will produce
Section titled “What you will produce”A reviewed set of discovered AI, with the real systems promoted into the registry, tiered and routed, and a clear picture of coverage.
- Set up sources. In Discovery, configure discovery sources, connector-based collectors or manual imports, with an owner and cadence.
- Run discovery. Each run produces candidates (suspected AI in use) and artifacts (the underlying usage signals), normalised against rules into canonical apps and vendors.
- Triage candidates. Review each candidate’s confidence, signal and guessed owner, and decide: promote, dismiss or investigate. Artifacts carry a reconciliation status so each signal is tied to a known asset or flagged.
- Promote the real ones. Promote confirmed candidates into AI System Records, where they enter intake and risk tiering like any other system.
- Tier and route. Run intake on the newly registered systems and route the higher-risk ones to GTSAF and the EU AI Act.
- Report coverage. Use reporting to show leadership what was found, what was registered, and where coverage still has gaps.
Sprint controls and completion criteria
Section titled “Sprint controls and completion criteria”- Define included business areas, sources, accounts, regions and time period.
- Use least-privilege collection and an approved lawful basis.
- Record rule versions, scan health and known detection limitations.
- Give every candidate and alert an attributable disposition.
- Reconcile duplicates before promotion.
- Route promoted systems through normal intake rather than auto-approving them.
- Report unresolved artifacts and uncovered areas.
A zero-candidate run is not proof that no shadow AI exists. The conclusion must explain source coverage, collector health and detector limitations.
Modules and frameworks involved
Section titled “Modules and frameworks involved”Registry & Discovery, intake & risk tiering, GTSAF, EU AI Act and reporting.
- Govern a GenAI chatbot: a common discovery find.
- Vendor AI due diligence: for the vendor tools you surface.
- Scenario guides: the full set.