Title card: How to build a shadow AI register in a regulated firm. Find the tools, Record the account, Trace the data, Decide, Review.

How to build a shadow AI register in a regulated firm.

Short answer. A shadow AI register lists every AI tool touching your firm’s work, approved or not. Each row records who uses the tool, what data goes into it, the type of account it runs on, and where the output ends up. You build the list from expense records, sign-in logs and browser extension inventories, then by asking staff directly. Every entry then gets a decision: approve, contain, or retire.

Start from the approved-tools list, if the firm has one. Few have checked it against what staff actually use. The gap between the two is where the risk sits, and you cannot manage a gap you have not measured.

What is shadow AI, and why build a register for it?

The UK’s National Cyber Security Centre defines shadow AI as AI technology in use that is not captured in an organisation’s approved systems and processes. It calls this a form of “shadow IT”: tools staff adopt because they solve a real problem faster than the approved option does, or because no approved option exists yet.

A register does not exist to catch anyone out. It exists to make visible what is already happening, so a partner or practice owner can make a real decision about each tool instead of guessing. NCSC’s own guidance makes the same point: organisations that understand why staff reach for a tool are better placed to manage the risk than organisations that simply ban it and hope the habit stops.

What do you record for each tool?

Seven pieces of information turn a vague sense of “people are probably using AI somewhere” into something you can act on. The table below sets out each column, why it matters, and where you actually find the answer.

Register column Why it matters Where the answer comes from
Tool name and vendor You cannot set a rule for a tool you cannot name The user, or the line item on an expense claim
Primary user or team A client-facing team’s use carries more risk than an internal one Expense records, or a short survey
Account type: personal or firm-provisioned With a personal account, the vendor controls where the data goes next. Your firm has no say in that The billing name on the card statement, the sign-in log, or asking which login screen the user sees
What data goes in This decides whether a problem at the vendor becomes your firm’s problem Asking the user to describe or show one real example
Where the output lands A draft pasted into a client email carries different risk from a note the user keeps to themselves Asking the user to walk through their last use of the tool
Status: approve, contain, or retire This is the decision the register exists to produce The 30-day sequence below
Owner and next review date A register nobody owns goes stale within a quarter Whoever runs the register, set at the moment of decision

How do you find the tools without a witch-hunt?

Four sources cover most of what staff actually use. None of them requires an interrogation.

Expense lines come first. Search company card and reimbursement records for the last ninety days for subscription charges to AI vendors. A recurring charge is often the first clue a tool exists at all.

Sign-in logs come next, if your firm uses single sign-on, meaning staff reach approved apps through one company login. That log shows which AI tools staff reached through it. Tools that never show up there are also useful information: they tell you where a gap in visibility sits.

Browser extension inventories help too. If you manage staff laptops through an endpoint tool, meaning software that lists what is installed on company devices, pull the list of installed browser extensions. Many AI writing and meeting-note tools install one.

Asking staff directly closes the gap the other three leave. A short, anonymous form beats an announced audit. Three questions do the work: which AI tools do you use for work, what do you use them for, and whose account is it running on.

Treat an early, honest answer as useful data for the register. A person who names a tool they were not supposed to use has just done the register a favour. Punishing that answer teaches everyone else to stay quiet next time.

What do you do with each entry?

Every tool on the register gets one of three decisions, and the decision is the point of the whole exercise.

Approve means the tool, the account type and the data boundary are all acceptable as they stand. Register it as approved, note who signed off, and set a review date.

Contain means the tool is useful but something about it is wrong today, for example the account type or an unclear data boundary. Keep it in use, but move it to a firm-provisioned account, or restrict what goes into it, until that gap closes.

Retire means the tool duplicates something the firm already provides, or the risk outweighs the benefit. Tell the person why, and point them to the approved alternative so the decision does not just push them back into the shadows.

Run the whole build in thirty days. Longer than that, and the register is out of date before it is finished.

  1. Days 1 to 2: name one owner for the register, even if IT staff do the legwork of gathering the data.
  2. Days 2 to 5: pull ninety days of expense and reimbursement records and flag every recurring charge that looks like an AI subscription.
  3. Days 3 to 7: pull sign-in logs for AI-labelled apps reached through single sign-on, and note which known tools never appear there.
  4. Days 5 to 10: pull the browser extension inventory from your endpoint tool, if you have one. If you do not, record that gap itself as a finding.
  5. Days 7 to 14: send the three-question anonymous survey, and give staff a week to answer.
  6. Days 14 to 18: build the first draft of the register from everything gathered so far, one row per tool per team.
  7. Days 18 to 24: spend ten minutes with each tool’s primary user, confirming what data goes in and where the output lands.
  8. Days 24 to 27: decide approve, contain, or retire for every entry, with the practice owner or partner present.
  9. Days 27 to 30: publish the register internally, tell staff what changes for them, and set a quarterly review date.

How does the register connect to the EU AI Act and to your audit?

Article 4 of the EU AI Act asks anyone providing or using an AI system to take measures supporting a sufficient level of AI literacy among staff who operate it, scoped to their role. The Digital Omnibus, in force since 27 July 2026, softened the wording from a guaranteed result to a documented effort, without moving the duty’s start date of 2 February 2025. See Article 4 on the Commission’s AI Act Service Desk (reviewed through 3 October 2026), reviewed today. You cannot scope a literacy programme to tools you do not know your staff are using. The register is what makes that scoping possible.

The same register earns its keep at audit time. We set out the evidence discipline behind an AI control in how to prove AI controls to an auditor. A policy describes what should happen. An auditor samples what actually happened in the period you pick. If you cannot first list which AI tools touched work in that period, the sample starts with a gap before it reaches the interesting questions. The register is the record that closes that gap, and the account-type column feeds directly into the question we cover in before client data enters ChatGPT, identify the account.

Questions buyers ask.

Do we need a shadow AI register if we already have an approved-tools list?

An approved list states what should be in use. A shadow AI register states what is actually in use, including tools outside that list. Check whether the two agree. Where they disagree, the gap is the register’s first entry. Build the register before you trust the approved list on its own.

Should staff be disciplined for using AI tools we had not approved?

Not for a first honest answer given during discovery. NCSC’s own guidance recommends understanding why staff use unapproved tools, instead of banning them outright and hoping the habit stops. Discipline belongs to a separate policy conversation, held after the register exists.

How often should the register be updated?

Review it every quarter at minimum, and add a tool the moment anyone mentions a new one. AI tools change faster than most compliance calendars run, and a register a year out of date tells you little more than nothing.

Does a free trial of an AI tool count as shadow AI?

Yes, if the firm did not approve it and it touches firm or client data. Trials often carry the most risk of all, since they run on the loosest account type available and get the least scrutiny before someone starts using them for real work.

This is the method behind the twelve tests in the Agentic AI Procurement Handbook. It is the first step I would take on AI governance before any framework work. It is an evaluation method. It is not legal advice. Pull one team’s expense report this week and count how many AI tools show up that nobody approved.

Josh Olayemi · Founder, Handvantage · September 2026 · About the author

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *