Resource
What AI is already running in your network.
Most leadership teams underestimate how many AI tools are in active use across the business. And what data is moving through them.
What you think is running is rarely what's actually running.
Most business leaders assume they know what AI tools their team is using. A few people have ChatGPT. Someone in marketing uses an image generator. The operations team looked at Copilot but hasn't fully rolled it out yet.
That's usually not what's actually happening.
When you do a real inventory of AI usage across a business network, every device, every browser, every application, the number of AI tools in active use is almost always larger than anyone expected. Sometimes significantly larger. Tools embedded in software the firm already pays for. Browser extensions nobody approved. AI features that turned on automatically in platforms that were purchased for something else entirely. Standalone tools staff adopted because they're useful and nobody said not to.
The data moving through those tools is the problem. Client files. Financial records. Customer information. Internal communications. Pricing models. Legal documents. When an employee pastes something into an AI tool to get help with a task, that content goes somewhere. Most of the time, nobody has reviewed where.

The tools you approved are not the only tools running.
Every business has a gap between the AI tools leadership knows about and the AI tools actually in use. This is sometimes called shadow AI. Not malicious, not deliberate, just the natural result of useful technology spreading faster than policy does.
Staff adopt tools that make their work easier. That's not a discipline problem. It's what happens when capable tools are freely available and nobody has built a framework for evaluating them. The paralegal who uses an AI summarization tool to get through discovery faster isn't trying to create a liability. The estimator who pastes a job spec into ChatGPT to help write a proposal isn't thinking about data handling agreements. They're trying to do their job well.
The governance problem isn't intent. It's visibility. Most businesses have no way to see what AI tools are running, what data is going through them, or whether any of it creates a confidentiality, regulatory, or insurance exposure.
What an actual inventory looks like.
When we run an AI visibility assessment in a client environment the results are rarely what leadership expected. The number of active AI tools is almost always higher than the approved list. The data being processed through those tools frequently includes information that should have been reviewed before it left the network. And the tools themselves vary widely in how they handle data. Some retain prompts for model training, some share data with third parties, some have data handling agreements that would not survive scrutiny against the firm's confidentiality obligations.
The inventory answers four questions leadership should be asking:
What AI tools are running across the network right now. Including tools embedded in existing software, browser extensions, and standalone applications staff adopted independently.
What data is going through those tools. Including whether client information, financial records, or regulated data is being processed through services the business never reviewed.
What the data handling terms actually say. Not what the marketing page says, but what the terms of service and data processing agreements say about retention, training use, and third-party sharing.
Where the gaps are between what's running and what a reasonable governance policy would allow.
Why this is an IT problem, not just a policy problem.
It's tempting to treat AI governance as an HR or compliance issue. Write a policy, send it to staff, consider it handled. The problem is that a policy without visibility is unenforceable. You can't govern what you can't see.
An acceptable use policy that says employees shouldn't use unapproved AI tools for client work doesn't tell you whether they're doing it anyway. It doesn't tell you which tools are running. It doesn't tell you what data has already moved through services that were never reviewed. And it doesn't give you the audit trail you'd need if a client, carrier, or regulator asked hard questions about how their information was handled.
Governance requires visibility first. The policy defines what's allowed. The controls enforce it. The monitoring shows whether it's working. That's the same model that applies to every other area of IT security. Identity, endpoints, email, backup. AI is no different. It just arrived faster than most environments were ready for.
What changes when governance is in place.
The goal isn't to block AI use. The efficiency gains are real and the tools are genuinely useful. The goal is to make sure the tools that are running have been reviewed, the data handling terms are understood, and the business has visibility into what's actually happening across the network.
When that's in place, a few things become possible that weren't before.
Staff can use approved AI tools confidently because the business has evaluated them and decided they're acceptable. The people doing the work aren't guessing about whether a tool is okay to use. The list exists and it's maintained.
Leadership can answer questions from clients, carriers, and regulators about AI tool use with documented evidence instead of approximations. When a client security questionnaire asks about AI governance, the answer exists.
The business has an audit trail. If something goes wrong, a data exposure, a confidentiality dispute, an insurance claim, there's a record of what tools were in use, what data went through them, and whether the controls were working.
And the list stays current. AI tools are evolving faster than any static policy document can keep up with. New tools appear constantly. Existing tools change their data handling terms. Governance requires ongoing monitoring, not a one-time review.
The question worth asking now.
If someone asked you today what AI tools are running across your network, what data is going through them, and whether any of it creates an exposure. Could you answer?
If the answer is no, or not completely, that's where an IT Environment Review starts. We look at what's actually running, evaluate what it means for your confidentiality obligations and insurance position, and help build a governance framework that lets your team use AI tools without the exposure.
The tools are already there. The question is whether you know what they are.
Common questions
Questions leadership usually asks first.
Continue reading
Related work and reading.
AI Readiness & Governance
The visibility, evaluation, and policy work that turns an unknown inventory into a governed one.
Read more: AI Readiness & GovernanceWhat Is Shadow IT and Why Does It Matter
The broader category shadow AI fits inside, including offboarding and personal cloud exposure.
Read more: What Is Shadow IT and Why Does It MatterWhat Business Leaders Should Know About AI Tools at Work
The leadership framing for what to do once you know what's actually running.
Read more: What Business Leaders Should Know About AI Tools at WorkNext step
Get a clearer view of your IT environment.
Find out what is working, where the risks are, and what needs attention next.
