Your AI Policy Is Useless If You Don’t Know Which AI Tools Employees Are Using
- Martin Snyder

- May 13
- 5 min read
The fastest way to lose control of AI is to pretend a policy can see what your security stack cannot.
Here is the uncomfortable part: AI policy without AI discovery is not a far-off roadmap item. It is already sitting inside browser tabs, OAuth grants, meeting notes, support workflows, CRM fields, and half-forgotten free trials. The security team may call it an AI governance initiative. Employees call it Tuesday. That gap is where the risk lives, because the organization cannot manage a tool it has never inventoried and cannot protect data flows it has never mapped.
Let’s be honest: most AI policies read like someone printed a PDF, held a meeting, and hoped employees would suddenly stop pasting sensitive work into whatever tool made their day easier. That is not a control. That is a wish with a header.
The modern AI problem is not only ChatGPT. It is the note taker that joined a customer call. It is the spreadsheet assistant that summarized finance data. It is the CRM feature that started generating account notes. It is the project management add-on nobody approved. It is the browser extension that promises to rewrite every email. Some of those products are perfectly legitimate. Some may be safe enough with the right settings. Others may be unacceptable. But none of that matters if you do not know they exist.
The policy-first trap
Security teams often start with a document: acceptable use, no confidential data, approved vendors only, maybe a ban on personal accounts. The document matters, but it is not the starting line. The starting line is visibility. A policy that cannot be tested against actual usage becomes a poster on the wall. Employees will keep choosing convenience unless the organization gives them safe, visible, approved alternatives.
The NIST AI Risk Management Framework is useful here because it frames AI risk management around real systems, real use, and real organizational processes. That is the right mental model. AI governance is not a philosophy club. It is a management system for tools that process data, generate output, influence decisions, and increasingly take action.
Blocking one AI site is not a strategy
A lot of teams still think they can solve this by blocking one famous chatbot. Cute. Also wildly incomplete. AI is getting embedded into the SaaS stack your company already uses. Employees may never visit a standalone AI website, but they may still use AI through document platforms, ticketing systems, sales tools, analytics products, HR tools, cloud services, and marketing automation.
That is why SaaS Discovery matters. AI discovery has to sit on top of SaaS discovery, identity mapping, OAuth review, vendor classification, and employee usage signals. The same account that looks like a simple SaaS login may become an AI data path the moment a vendor enables a summarizer, assistant, classifier, agent, or training workflow.
What actually breaks
When companies do not know which AI tools are in use, three things break fast. First, data classification becomes fiction. Sensitive information may move into tools where training settings, retention terms, or vendor subprocessors have never been reviewed. Second, access governance becomes incomplete. You may revoke a user from core systems while leaving them active inside an AI-enabled workflow nobody tracked. Third, compliance evidence becomes weak. An auditor will not be impressed by a policy if the organization cannot show an inventory.
The OWASP Top 10 for Large Language Model Applications is a reminder that LLM applications introduce concrete security risks, not just abstract ethical concerns. Prompt injection, insecure output handling, sensitive information disclosure, excessive agency, and supply-chain issues all become more important as AI moves from chat windows into business workflows.
The uncomfortable inventory questions
Which AI tools are employees using with corporate email addresses?
Which approved SaaS products have AI features enabled?
Which vendors use customer data for model training, improvement, or evaluation?
Which AI tools can take actions, not just generate text?
Which tools have admin controls, audit logs, opt-out settings, and enterprise data protections?
Which teams are using personal accounts for work data?
If you cannot answer those questions, the AI policy is not wrong. It is just lonely. It needs evidence, enforcement, ownership, and a living inventory.
Shadow IT is the right lens for this because Shadow AI is a form of Shadow IT with a faster risk curve. The user experience is easier, the data flow is less obvious, and the adoption speed is absurd. Employees do not need a procurement cycle to create an AI risk. They need a browser tab.
The vendor promise problem
Another reason discovery matters: vendor promises vary. Some vendors say they do not train on customer data. Some say enterprise customers are excluded. Some require an opt-out. Some distinguish between prompts, outputs, metadata, telemetry, and product improvement. Some bury the key sentence in a help article. Some change settings by plan. The FTC guidance on AI privacy and confidentiality commitments is a useful reminder that privacy and confidentiality commitments around AI need to be accurate, specific, and honored.
That means your AI inventory should not stop at “uses AI: yes/no.” It should track training usage, external LLM providers, data retention, admin controls, audit logs, automation scope, and whether humans approve high-impact actions. The boring fields are the governance.
The better approach
Start with discovery. Map users to tools. Identify AI features in the SaaS stack. Separate approved, unknown, sanctioned, and prohibited usage. Flag tools with customer-data training exposure. Prioritize tools with external LLMs or weak admin controls. Then update policy based on reality. That order matters. Reality first, policy second, enforcement third.
Use No, We Do Not Train Any AI on Your Data as part of the trust conversation. If you are asking employees and customers to trust your AI governance process, you should be equally clear about how your own platform handles data. That is the tone modern AI governance needs: specific, testable, and boring in the best possible way.
Final take
Your AI policy is not useless because policies are bad. It is useless if it floats above reality. Discovery turns it into a control. Without discovery, you are just asking people to behave perfectly in an environment you have not measured.
What good looks like after the first month
After the first month, the organization should have moved beyond guessing. The security team should be able to show a current list of AI-enabled applications, the users tied to each tool, the business owner where one exists, the data categories likely involved, and the current approval status. Compliance should be able to reuse the same evidence instead of requesting a separate spreadsheet. IT should have a clearer path for offboarding, access review, and vendor cleanup. Business teams should understand which tools are approved and how to request new ones without waiting forever.
The program should also have a cadence. New tools should be reviewed regularly. High-risk vendors should be reassessed when terms change. Unknown training positions should be converted into documented answers. Exceptions should have owners and expiration dates. This is how AI governance becomes operational instead of ceremonial.
Metrics to track
Number of AI-enabled applications discovered.
Percentage of AI tools with identified owners.
Number of tools with unknown training or retention terms.
Number of applications without admin controls or audit logs.
Departments with the fastest AI adoption.
High-risk tools remediated in the last 30 days.
These metrics give leadership a practical view of progress. They also keep the program from drifting back into policy-only mode. A living AI inventory, reviewed on a regular schedule, is the foundation for safer adoption.
Turn policy into visibility
Want to know which AI tools employees are actually using before the next policy review? Start with Waldo Security SaaS Discovery or book a demo to see Shadow AI usage mapped to real users and applications.



Comments