Someone asks for a list of the AI tools your company uses. It might be a customer's vendor form, a new partner, or you. You write down the three you know about and send it.
That list is almost always short. The gap between it and the real one is where much of a small company's AI exposure sits, and you cannot govern what nobody has written down.
This is the method I use to close that gap. How long it takes depends on the size of the company, but the steps stay the same. Nothing gets switched off blindly along the way, because in this first pass the goal is to see what is running. The one exception is an exposed secret, covered below. It expands the first decision in the seven-decision minimum: know what tools are in use. It also produces the inventory that the forms in the questionnaire piece and What the Bank Is Actually Asking keep asking for.
The real list is longer than yours
Microsoft's 2024 Work Trend Index found that 78 percent of AI users bring their own AI tools to work. At small and medium-sized companies the figure was 80 percent. The survey covered 31,000 knowledge workers in 31 countries.1 It dates from early 2024, so read it as direction, not a current count.
Sapio Research ran a more recent survey for the security vendor BlackFog in November 2025. It asked 2,000 workers in the US and UK at companies with 500 or more employees. Of those, 49 percent said they used AI tools their employer had not sanctioned. Separately, 51 percent said they had connected AI tools to other work systems without IT approval. Among people using unapproved tools, 58 percent relied on free versions. Respondents also reported putting company information into unapproved tools. That included research or datasets (33 percent), employee data such as payroll and performance (27 percent), and financial statements or sales data (23 percent).2 BlackFog sells security software and the answers are self-reported, so treat this as a vendor survey, not a census.
Those are companies with IT departments. A twelve-person company may have fewer centralized tools and fewer people watching, and I would not assume it runs cleaner.
IBM's 2026 Cost of a Data Breach report shows what the gap can cost. It covers 602 organizations that had a breach, and the share of incidents involving shadow AI more than doubled, from 20 percent to 43 percent. Those incidents averaged $5.39 million, up from $4.63 million a year earlier, and 49 percent involved data loss or compromise. Regular audits for unsanctioned AI were reported by 29 percent of organizations, down from 34 percent.3 IBM does not state the base for the 43 percent, and the sample only includes breached organizations, so read it as a trend, not a rate.
Start with what leaves a trail
People will not remember everything they use, but software records more than memory does. Work through three sources.
Payments
Pull ninety days of company card statements, expense reports, and vendor invoices. Search for the obvious names, then look for small recurring charges you do not recognize. This finds paid tools, the ones someone already decided were worth a subscription. It misses free tools and anything bought on a personal card.
Connected apps
If you run Google Workspace, open the Admin console and go to Security, then Access and data control, then API controls, then Manage app access. It lists the third-party apps connected to your accounts, how many users each has, and which data each one requested.4 On Microsoft 365, open the Entra admin center, go to Enterprise apps, then All applications, and check the Permissions tab on anything unfamiliar.5 If someone connected a tool to a mailbox, calendar, or shared drive with a "sign in with Google" or "sign in with Microsoft" click, it usually shows up here. Nobody has to have mentioned it.
This has already caused a breach. In April 2026, Vercel disclosed that an attacker had compromised Context.ai, an AI tool one of its employees used. The attacker used that access to take over the employee's Google Workspace account. From there the attacker reached a Vercel environment and decrypted environment variables that were not marked sensitive. Vercel said the tool's Google Workspace OAuth app was part of a broader compromise and told Workspace administrators to check for it. It also told customers to treat unmarked variables as potentially exposed and rotate them.6
Write down what you find and do not revoke anything blindly yet. Microsoft's documentation notes that revoking a permission does not stop a user from granting it again, and that user-level consents cannot be revoked in the portal at all.5 Revoking blindly also breaks someone's workflow before you know what it does. If an app is plainly malicious or has far more access than its job needs, act on it now.
Products you already approved
Open the admin settings of the five or six tools everyone uses: email, chat, video calls, document storage, your CRM, and your accounting system. Look for an AI assistant, summarizer, or meeting recorder that is switched on, whether by default or by one person's choice. These tools are sanctioned already. They still process the same data, and they go unlisted because nobody thinks of them as AI tools.
Ask people, and make it safe to answer
Software trails miss browser tabs and personal accounts. Only people can fill that in, and they will only do it if answering carries no penalty.
Send one short message to everyone, contractors included. Ask five things. Which AI tools do you use in a normal week? What for? What kind of information goes into them? Is the account free, paid, or personal? Does it connect to anything else? Say in the first line that nobody is in trouble, and mean it.
The amnesty matters more than the wording. In the BlackFog survey, 60 percent of respondents agreed that using unsanctioned AI tools is worth the security risk if it helps them work faster or meet deadlines.2 People who believe that will not hand their list to someone who might take the tools away.
Give a short deadline and keep the ask to ten minutes of effort. A rough list is enough. Expect a few follow-up conversations with the people whose answers raise a question.
Triage by data, not by tool
You now have a list, probably longer than the one you started with. Ranking tools by how worrying they sound is tempting, but the same tool can be harmless for one task and a problem for another. So I sort by what goes into each one. Data covers part of the risk. The rest depends on what the tool can do and what it connects to. Something that only drafts text carries less risk than something that can send email or publish on its own, whatever data it sees.
A third question comes later: what happens if the output is wrong? Drafting meeting notes and recommending who gets hired may use similar data. They do not carry the same consequence. Treat this sort as triage, and fill in the rest from the connected-systems and consequence columns later.
Public or published material. Marketing copy, public research, your own website text. The data itself carries little risk.
Internal and low harm. Routine internal drafts, generic meeting notes, and brainstorming that contain no confidential, regulated, or commercially sensitive material. Low risk, though an account your company controls is better than a personal one.
Restricted. Anything your contracts limit, customer records, employee records, financial figures, and confidential client material. Part 1 of the series lists the same categories.
Secrets. Passwords, private keys, access tokens, and API keys. These get their own group because a better plan does not fix them. A leaked credential may let someone else use whatever access it carries, so treat any key that went into an AI tool as exposed and rotate it.7
Public and internal work usually does not need a change based on the data alone. Restricted work gets reviewed first. If the tool supports that data under a company-managed plan whose data handling and contractual terms you have reviewed, move the work there. If it does not, pause that use until you have a suitable option. The terms can differ by plan. OpenAI, for example, says it may use content from its individual services, such as ChatGPT, to train its models unless the user opts out.8 It says it does not use data from ChatGPT Business, Enterprise, or Edu, or from its API, for training by default.9 That is one vendor's published policy and policies change, so read the current terms for each tool on your list.
Secrets are the one place where I would act first. If a password or key went into an AI tool, rotate it, then record that you did.
Write it on one page
The output is a single page. A spreadsheet works. Give each tool one row and these nine columns:
- The tool
- What it is used for
- Who uses it
- The account type: personal, free, or company-managed paid
- The data group
- What it connects to, and the permissions it holds
- What happens if it gets something wrong, in one sentence
- A named owner
- The date you last checked it
The owner column is the one people skip. The NIST AI Risk Management Framework includes an inventory practice, GOVERN 1.6, and its playbook suggests defining a specific individual or team responsible for maintaining the inventory.10 A list that nobody owns goes stale.
This page is where AI governance starts. Risk tiers, usage policies, and bank vendor reviews like the one in What the Bank Is Actually Asking all start from a named list of tools and data. Part 1 of the series puts this first among its seven decisions for that reason. The other six are hard to make about tools nobody has written down.
In a large company, the same logic becomes formal discovery, application inventories, procurement records, identity telemetry, and ongoing controls. The sequence is still the same: find what exists, then decide what matters.
Put a review date on the calendar. Part 1 recommends revisiting these decisions twice a year, and sooner when a tool, its purpose, or its data changes.
It is also your answer the next time a customer form asks which AI tools you use. The reviewer in What the Bank Is Actually Asking reads those answers looking for something verifiable, and a dated inventory with named owners is verifiable.
Five moments when I would run it
The inventory does not need a reason, but in practice something usually forces it. These are five moments where it earns its keep.
A new operations or product lead starts. Someone joins a 10 to 50 person company and inherits logins, seats, and card charges with no list. The inventory is their first deliverable, and it gives them a baseline before they cancel anything.
A customer or bank sends a vendor questionnaire. The AI section asks which tools you use and what data goes into them. The inventory is the answer, built ahead of time instead of during the week the form is due. The questionnaire piece covers how to word the answers, and What the Bank Is Actually Asking covers what the reader does with them.
I have seen the same need from the bank side. At one bank where I worked, we had to strengthen our third-party risk management. That meant working out the exact list of third parties we used and how we used each one. Then we reviewed at least the critical and high-rated ones to confirm the risk attached to them was appropriate. Sorting by what is at stake, before the long tail, is the same move as the data sort above.
You buy or merge with a small business. The seller's team has been running whatever worked, often on free or personal accounts. That is when you learn what customer data sits in tools you do not control.
The person who built your automations leaves. Their logins, API keys, and connected apps are an inventory nobody wrote down. Years ago I left a bank, and some processes kept running under my user ID for months afterward. I only found out when a former colleague told me, and the fix came well after I had gone.
Build the inventory around someone's last week, while they are still here. It is the ownership decision from Part 1 in practice: ownership transfers on the way out, the same as a client relationship would.
You are about to switch on a company-wide AI assistant. Before enabling Copilot, Gemini, or something similar, check what people already use and what data those tools can reach. Otherwise the rollout sits on top of the gaps the inventory would have found.
What I would leave for later
Resist doing more than this during the initial inventory. Do not write a full acceptable use policy, do not block websites, and do not buy a discovery platform. I would expect an early block to push people onto personal devices, which makes the next list harder to get. Dedicated discovery products exist for larger organizations. At this size I would start with the sources above.
The next step is to make the decisions the list raises: which tools to approve, which to replace, which need a contract or a setting changed, and which automations need an owner and an off switch.
The first list will be wrong in places. That is fine. A dated list with a named owner is something you can correct, and a list that lives in someone's head is not.
Where Agent Micho Fits
An inventory like this usually turns up a few automations that someone built and nobody owns. Those are the ones that need an owner, a log, and an off switch first. If your list has gaps you would rather not close alone, that is work we do.
Sources
- AI at Work Is Here. Now Comes the Hard Part, Microsoft Work Trend Index, 2024. Source of the 78 percent bring-your-own-AI figure and the 80 percent figure for small and medium-sized companies. Survey of 31,000 knowledge workers in 31 countries, fielded February 15 to March 28, 2024, by Edelman Data & Intelligence.
- Shadow AI Threat Grows Inside Enterprises as BlackFog Research Finds 60% of Employees Would Take Risks to Meet Deadlines, BlackFog. Survey of 2,000 employees in the US and UK at companies with 500 or more employees, conducted by Sapio Research in November 2025. Vendor-commissioned and self-reported.
- Cost of a Data Breach Report 2026, IBM and the Ponemon Institute, released July 29, 2026. Source of the shadow AI figures: incidents more than doubled to 43 percent from 20 percent, an average cost of $5.39 million against $4.63 million the year before, 49 percent with data loss or compromise, and 29 percent of organizations with regular audits for unsanctioned AI, down from 34 percent. The research covers 602 organizations breached between March 2025 and February 2026. The report does not state the base for the 43 percent.
- Control which apps access Google Workspace data, Google Workspace Admin Help. Covers the Admin console path to Manage app access and the trusted, limited, specific-data, and blocked access levels.
- Microsoft Entra documentation on reviewing and revoking permissions granted to enterprise applications, Microsoft Learn. Covers the admin consent and user consent tabs, the limit on revoking user consent in the portal, and the fact that revoking does not prevent re-consent.
- April 2026 security incident, Vercel Knowledge Base bulletin, updated April 19 to 24, 2026. Source for the compromise of Context.ai, the takeover of an employee's Google Workspace account, the decryption of environment variables not marked sensitive, the advice to Workspace administrators to check for the compromised OAuth app, and the advice to rotate variables not marked sensitive.
- Best practices for managing API keys, Google Cloud Documentation. Says publicly exposed keys can lead to unauthorized access, describes API keys as bearer credentials, recommends restrictions to reduce the impact of a compromised key, and recommends periodically creating new keys and deleting old ones.
- How your data is used to improve model performance, OpenAI Help Center. States that content from individual services such as ChatGPT may be used to train models unless the user opts out, and describes the opt-out. Cited as one vendor's example of terms that differ by plan, not as a statement about any other vendor.
- Enterprise privacy at OpenAI, updated January 8, 2026. States that data from ChatGPT Business, Enterprise, Edu, and the API Platform is not used for training by default unless a customer opts in.
- NIST AI RMF Playbook, GOVERN 1.6, National Institute of Standards and Technology. "Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities." The playbook's suggested actions include defining who is responsible for maintaining the inventory.
The four-group data triage and the nine-column inventory are my own working method, not a published standard.
A note on the images in this piece: the hero and the listing illustration are both AI-generated.