Can I Find Out Which AI Tools My Employees Are Using?

Yes. Network logs, identity records, extension inventories and finance data name most AI tools within days. Where the evidence sits, and what UK law allows.

Yes, you can find out which AI tools your employees use. Our discovery engagements typically reach a credible picture within two to three weeks. The evidence sits in network logs, identity provider records, browser extension inventories and finance data. The fastest route pairs that technical evidence with a short amnesty window.

Reviewed by Jason Holloway, Director at QL Security, who leads our AI Security discovery and governance engagements.

Can I really find out which AI tools my employees are using?

Yes. Nearly every AI assistant is a web application or a browser extension, and both leave records. Outbound DNS and proxy logs show which AI domains your staff resolve and how often. Your identity provider records every third-party sign-in consent granted to an application, with the permissions attached. Card and expense data reveals subscriptions bought outside procurement.

Between those sources you can name the tools, count the users and see how heavily each is used, within days rather than months. Technical evidence will not reveal use on personal phones, home broadband or personal email. That is why the asking part matters. Shadow AI Discovery treats the technical half and the human half as one exercise.

Where does the evidence actually come from?

Six sources cover most of the ground:

  • Network and DNS or proxy logs, showing resolution to AI service domains and volume per user or subnet.
  • Your identity provider and SaaS admin consoles, listing OAuth grants to third-party AI applications and the scopes they hold over mail, files and calendars.
  • Endpoint management, for the browser extension inventory. This is the vector most often missed in the audits we run.
  • Finance records: card statements, expense claims and app store receipts.
  • Licences you already own. AI features inside productivity, CRM and support platforms are often on by default and rarely reviewed.
  • Staff, asked properly. A five-question survey run under a no-blame commitment surfaces tools no log captured.

Our AI Security Gap Analysis works these in that order, cheapest signal first. The query-level method sits in how to discover Shadow AI rather than here.

Reviewing your own corporate logs and admin consoles is lawful, but it is processing personal data and UK GDPR applies. Transparency: tell people what you are reviewing and why before you begin, and reflect it in your privacy notice. Proportionality: look at service usage and account grants rather than message content, and aggregate by team wherever a named individual is unnecessary. Documentation: systematic monitoring of workers normally warrants a data protection impact assessment.

The line to avoid is covert monitoring or reaching into personal accounts and devices. That is where legal exposure and trust damage sit. The position set out above is general information rather than advice on your circumstances, so involve your DPO or legal adviser at scoping and confirm your own lawful basis and DPIA requirement with them. We cover the wider framing under AI governance.

What is the difference between an AI usage audit and shadow AI detection?

Scope and purpose. Detection is the technical discipline: the queries, log sources, signatures and tooling that reveal unsanctioned AI traffic in your environment. For the method itself, read how to discover Shadow AI.

An AI usage audit is the wider exercise an employer commissions before writing policy. It uses detection as one input, then adds interviews, an amnesty window, a review of AI features inside tools you already pay for and a risk assessment of what each tool touches. Detection answers what traffic is leaving. An audit answers what you are relying on, who owns it, what data it holds and what you sanction. You need the second to make decisions; the first produces only a list.

Why does an amnesty work better than surveillance?

Because the tools that worry us most are the ones logs cannot see, and only the user can disclose them. Staff adopt AI to work faster, not to harm the organisation. If the first message they receive is disciplinary, disclosure stops and usage moves to personal devices, where you have no visibility.

An amnesty inverts that. You announce a fixed window, guarantee that nobody is penalised for declaring a tool and ask what people use and what for. Declared usage teaches you the business purpose, which is what you need to decide whether to sanction, replace or block. Run technical discovery in parallel and use it to check coverage rather than to catch people out. We set out the mechanics in should we ban ChatGPT.

What do these audits usually uncover that people do not expect?

The pattern below is illustrative rather than drawn from one case or from published figures. In a mid-sized regulated firm: a couple of paid subscriptions finance recognised; a considerably larger number of free-tier accounts registered with work email addresses; several OAuth grants to note-taking or summarising applications holding standing read access to mail and calendars, some of them granted by staff who have since left; meeting assistants storing client-call transcripts on infrastructure nobody has assessed; code assistants configured with default telemetry.

The surprise is rarely a rogue chatbot. It is the standing permissions, the orphaned grants and the AI features quietly enabled inside platforms approved years ago. See Shadow AI for how that pattern forms.

Can we do this in-house or do we need help?

If you have access to proxy or DNS logs, your identity provider admin console and endpoint management, you can produce a usable inventory in-house. Most IT leads can. The parts that go wrong are scoping, framing and interpretation: pulling six months of logs before deciding what question you are answering, launching the exercise with wording that reads as a crackdown or listing forty tools with no basis for deciding which three matter. External help earns its place on the framing and the risk judgement, not on the log queries.

What does a QL Security discovery engagement involve?

Typically two to three weeks, in four stages. We scope with your IT lead and DPO, agreeing the log sources, the retention position and the DPIA record. We pull and reconcile evidence across network, identity, endpoint and finance sources. We draft and support the amnesty communication, then run short interviews with the teams the evidence points to. We deliver an AI asset register: every tool named, owner assigned, data classification recorded, permissions listed and risk rated against confidentiality, integrity, availability, ethics, fairness and transparency.

Each tool carries a recommendation to sanction, replace, restrict or remove. The register aligns with the control expectations in ISO 42001 so the work supports a future certification effort. To discuss a discovery engagement, contact us.

Build the AI asset register

Two to three weeks from scoping to a register naming every tool, its owner, its data and its risk rating.