Playbook

The 7-day playbook to find the AI you don't know you have

You cannot govern AI you cannot see. Here is a week-long process to find every unsanctioned AI tool in your organisation using logs you already collect. No new tools. No consultants. No budget line.

The question CISOs ask me has changed. It used to be "is AI risky?" Now it is "how do I even find out what my people are using?" The second question is the one that matters, and it is answerable in a week.

The reason most teams stay stuck is that they think discovery requires a new product - a shadow AI scanner, a browser agent, a CASB upgrade. It doesn't. Your firewalls, proxy, identity provider, DNS and expense system already record the answer. They are just not being pointed at this question.

Netskope's 2026 Cloud and Threat Report counted an average of 223 AI data-policy violations per enterprise per month. You are not looking for one big incident. You are looking for the long tail of small, habitual leaks - and the logs to find them already exist.

Day Source What you are looking for What it tells you
1 DNS + firewall/proxy logs Requests to AI domains Which tools, who uses them, at what volume
2 Identity provider + CASB sign-ins OAuth grants and personal-account logins Sanctioned vs shadow usage split
3 Browser extensions + installed apps AI extensions and agent tools The AI you don't see in the proxy at all
4 Expense and procurement records AI subscription charges Paid tools purchased outside IT
5 DLP/egress telemetry Sensitive data moving to AI domains Which leaks are real, not hypothetical
6 Ten conversations How people actually work The reason behind every row above
7 The consolidated inventory One decision per tool Block, sanction, or monitor - with a name attached

Day 1 - DNS and proxy logs: map the AI domains

Start where you already look. Pull your DNS queries and firewall or proxy logs for the last 30 days and search for the known AI domains - openai.com, chatgpt.com, anthropic.com, claude.ai, gemini.google.com, perplexity.ai, and the long tail of writing, image and coding tools behind them.

Three numbers matter here: how many distinct users hit AI domains, which domains dominate, and whether the traffic is going through a corporate device or a personal one. The volume surprise is usually not that people use AI. It is how much of it never touches a corporate machine.

Your DNS logs are the one source that catches personal devices on the office Wi-Fi and VPN, so they are the most honest map of the whole estate - not just the laptops IT manages.

Day 2 - Identity sign-ins: find the personal accounts

Pull your identity provider's sign-in logs and look for two things: OAuth grants to AI applications, and logins to AI apps using personal identities ("Sign in with Google" on a Gmail address). Your CASB's cloud app catalogue will already know many of these apps; the sign-in log tells you who connected them.

This is the split that matters: of all AI use, how much is on a sanctioned, corporate account, and how much is on a personal one. Harmonic Security's 2026 AI Usage Index found that 64.5% of activity on personal AI accounts is business work. The personal accounts are not the fringe. They are where the work is happening.

Day 3 - Browser extensions and installed apps: the AI your proxy never sees

Query your endpoint management or browser policy for installed extensions and look for anything with AI in the name - grammar tools, transcription bots, meeting summarisers, "copilot for X" widgets. An extension that reads every page you visit is a data leak by design, and it never appears in the proxy as a separate domain.

Do the same for mobile device management if you have it. The phone is where most personal AI use actually happens, and it is almost never in the perimeter view.

Day 4 - Expense and procurement records: follow the money

Ask finance for a month of corporate-card and expense claims and search for AI vendors: ChatGPT Plus, Claude Pro, Perplexity, Midjourney, Copilot Pro, and the dozens of smaller ones. People expense what they use heavily, and the expense line is a confession the proxy never saw.

You will find subscriptions paid on personal cards and expensed back, which means a sanctioned-looking reimbursement for an unsanctioned tool. That is not fraud. It is an employee telling you, in the only ledger you actually read, which tool they refuse to work without.

Day 5 - DLP and egress telemetry: find the real leaks

Re-run your DLP alerts for the same 30-day window and filter for destinations that look like AI - or simply for the highest-volume paste-and-upload events to unrecognised domains. Even a basic DLP deployment catches more than teams assume once you ask it the AI question.

The goal here is not to catch anyone. It is to rank your risk. Which teams move the most sensitive data, through which tools, how often. That ranking is what you bring to the board - not a scare number, a measured one.

Day 6 - Talk to ten people

This is the highest-signal day and it costs nothing. Pick ten people from the heavy-use list - a relationship manager, an analyst, a developer, someone in legal, someone in operations - and ask one question: "What do you actually use AI for, and why doesn't the approved tool work for you?"

The answer is almost never "I want to leak data." It is "the approved tool is slow," or "it can't read PDFs," or "I didn't know we had one." You now know whether your problem is a policy gap, a product gap, or an awareness gap. Those need different fixes, and you cannot tell which is which from logs alone.

Day 7 - Build the inventory and decide

Put it on one page: tool, users, account type (corporate or personal), data sensitivity observed, and one decision - block, sanction, or monitor - with a name next to each decision. A block with no owner is a press release. A decision with a name is governance.

Most organisations land on fewer than ten sanctioned tools, a handful of explicit blocks, and a monitored grey list for the long tail. The exact split matters less than the fact that next month you will know the number, and you can report it upward.

What you will find

In our experience, three things show up every time: a long tail of free tools nobody sanctioned, a few heavy business uses running on personal accounts, and at least one finding that makes the room go quiet. Usually it is the one about the extension that can read every page, or the expense line that proves a team has been running its own AI for months.

None of that is a reason to panic. It is a reason to have finished the inventory before the regulator, the auditor or the board asks for it.

Where this gets you

Discovery is step one, not the destination. Once you know where the AI is, you need to understand what it can leak, then put enforcement at the point where the data actually moves - not four systems downstream. The inventory you built this week is the same one the RBI and the EU AI Act already expect you to hold.

The point of this playbook is not the list. It is that in seven days you stop guessing and start measuring. From there, every decision - what to block, what to sanction, what to tell the board - is a decision about a thing you can see.