Skip to content
Atlas
GET IN TOUCH

B://ASSESS27Shadow AI/ML

Your staff already
use AI.

Shadow AI discovery finds the AI tools already in use across your organisation, establishes what company information has been going into them, then puts education and enforceable policy around it. It is for organisations that have not started with AI, and equally for those that have, since adopting one approved tool does nothing about the eleven others people are using on the side.

Staff adopted AI tools long before most organisations wrote a policy. Company information has been going into them ever since, and almost nobody can say what.

The cost of leaving this alone is rarely one visible failure. It is the slow accumulation: the workaround that became the process, the thing only one person knows, the renewal nobody questioned.

Our starting point is always the same: establish what is actually true today, then decide what to change. Work scoped against an assumption tends to solve a problem you do not have.

  • 01No policy, so no boundaryNobody has told staff what is and is not acceptable, so everyone has decided for themselves.
  • 02One approved tool, eleven unapproved onesAdopting an enterprise AI tool does not stop the personal accounts already in use.
  • 03You cannot answer the client questionWhen a customer asks whether their information has been put into an AI tool, the honest answer is that you do not know.

What the engagement covers

Scoped before it starts, so you know what is included and what is not.

  • 01

    Discovery

    Which AI tools are in use, by whom, and whether through a company account or a personal one. The personal accounts are the ones that matter, because nothing you do to your tenant affects them.

  • 02

    Exposure assessment

    What kinds of information have been going in: client documents, financials, personal information, source code. Then what each vendor’s terms actually say about training on it, retaining it, and who can see it.

  • 03

    Education that changes behaviour

    Short, specific training on what may and may not go into these tools and why, aimed at the people who are already using them. Most exposure is well intentioned, which means it responds to being explained rather than to being forbidden.

  • 04

    Policy and enforcement

    A written AI policy that people can actually follow, backed by technical controls on managed devices and accounts, so the policy is more than a document someone signed at induction.

Scope, assess, report, support

Four stages with a written output at each one. You always know which stage you are in and what comes next.

  1. 01Week 1

    Scope

    We agree what is being examined and what a useful answer looks like, so the work is not open-ended.

  2. 02Weeks 2 – 3

    Assess

    Evidence gathered from your systems and your people, because the documented process and the real one rarely match.

  3. 03Week 4

    Report

    Findings written for a decision maker: what is true, what it means, and what we would do about it, ranked.

  4. 04As needed

    Support

    We can hand the report over and step back, or stay and deliver the remediation. Both are normal.

What you should expect

  • Someone other than you owns it, with that written down.
  • The current state is documented and stays documented.
  • Cost is planned ahead rather than discovered at renewal.
  • Decisions are made against evidence rather than assumption.

Questions we get asked

01What is shadow AI/ML?

Shadow AI discovery finds the AI tools already in use across your organisation, establishes what company information has been going into them, then puts education and enforceable policy around it. It is for organisations that have not started with AI, and equally for those that have, since adopting one approved tool does nothing about the eleven others people are using on the side.

02Which AI tools count as shadow AI?

Staff using AI tools for work through accounts your organisation does not control and cannot see. It covers the obvious chat assistants, but also meeting transcription bots joining your calls, AI features inside browser extensions, and code assistants. The defining characteristic is that company information is leaving through a channel nobody approved and nobody is monitoring.

03We already use an approved AI tool. Do we still have a shadow AI problem?

Almost certainly, and this is the part organisations most often miss. Rolling out an enterprise tool does not remove the personal accounts people were already using, and it does not cover the AI features quietly embedded in other software. Approving one tool is necessary and nowhere near sufficient.

04Should we just ban AI tools?

You can, and staff will use them on personal devices where you have no visibility whatsoever. Prohibition converts a manageable problem into an invisible one. A sanctioned tool that is genuinely good enough, with a clear boundary around what may go into it, is the version people actually follow.

05What happens to company information pasted into a public AI tool?

It depends on the tool and the account type, which is exactly why this needs establishing rather than assuming. Consumer tiers have historically retained conversations and in some cases used them to improve models. Business and enterprise tiers generally commit not to train on your content and offer retention controls. The practical position is that information put into a personal account should be treated as having left your control, and in a professional services or health context that may be a notifiable matter.

06Can you tell which AI tools our staff are using?

To a useful degree, yes, using data you already hold: third-party application consents in your Microsoft 365 or Google tenant, network and DNS data, expense claims, and browser extension inventories on managed devices. Personal accounts on personal devices are genuinely outside what anyone can see, which is precisely why education and policy do the work that monitoring cannot.

07What should an AI policy actually say?

Which tools are approved and for what. What categories of information may never go in, named specifically rather than described vaguely. That AI output is checked by a person before it is relied on or sent. Who is accountable when AI-assisted work turns out to be wrong. And how someone requests a new tool, because without that route you are back to shadow use within a month.

08How much does shadow AI/ML cost in New Zealand?

We quote after scoping rather than before. Anyone pricing this work without looking at your environment is guessing, and the guess is rarely in your favour. Scoping itself is quick, and we tell you what it costs before we start it.

09How long does it take to get started with shadow AI/ML?

A first conversation takes about half an hour and costs nothing. Scoping is usually a week or two of our time depending on the size of the environment, and we agree the delivery dates with you before anything is booked in.

10Can you deliver shadow AI/ML alongside our existing IT team or provider?

Yes, and it is common. We are happy to work as an extra pair of hands under your internal team, or alongside an incumbent provider on a defined piece of work. We will set out in writing where the responsibilities split, so nothing falls between us.

11Do we have to use Atlas for the work the report recommends?

No. This can be delivered as a standalone piece of work for an organisation we have never worked with before, or folded into a managed agreement if you already have one with us. Plenty of clients use us for one thing and keep everything else where it is.

12Do you work with organisations outside Auckland?

Our team is based in Auckland and we attend sites across the wider region. Most of this work is delivered remotely, so we support organisations throughout New Zealand, and we will say up front where being on site genuinely matters.

13Who does the assessment, and who presents the findings?

Named people, not a queue. You get a lead who knows your environment and stays with it, which is the difference between explaining your business once and explaining it every time you make contact.

14What do we actually receive at the end?

You keep the documentation regardless, and anything registered in your name stays in your name. Whether we stay involved is your call. Some clients take it in house from there, others move it onto an ongoing agreement with us. We would rather you left cleanly than stayed because leaving was difficult.

Start with a conversation.

Tell us what you are dealing with and we will tell you whether this is the right service for it, and what it would take.

← All services