Discovering Shadow AI, 30-Day SaaS / DLP / Browser / IdP Discovery Sprint
The AI Officer at a Fortune 500 financial-services firm thought she had her AI inventory under control. Twenty-seven systems classified, tiered, and signed off by the AI Governance Committee. Then in February 2026 she ran a discovery sprint against the Microsoft Defender for Cloud Apps console and the Okta application catalogue. Six weeks later the inventory was 312 systems. The original 27 were what governance knew about. The remaining 285 were SaaS AI features quietly enabled by vendors (Power BI Smart Insights, Salesforce Einstein, Notion AI, Slack AI, Google Workspace Gemini), browser-side AI tools installed by employees (ChatGPT extensions, Copilot.ai, Jasper), department-procured AI tools that bypassed Procurement (a Marketing-deployed Jasper account paid on a corporate card), and internal AI side projects on Databricks notebooks that never made it through the AI Officer's intake form. This lesson is the 30-day discovery sprint that surfaces the 285: the source-data extraction, the AI-tool taxonomy, the data-exposure analysis, the business-unit footprint, the risk classification, and the CIO-facing report with remediation backlog. The output is the second L2 artifact in Chapter 1: the shadow AI report that closes the gap between what governance knows and what the workforce actually uses.
What Counts as Shadow AI in 2026
Shadow AI is not a single thing. It is at least five distinct categories, each with a different discovery path and a different remediation pattern. A discovery sprint that addresses only one category, typically the employee-installed browser-tool category that gets the most press, misses the bulk of the inventory gap. The 2026 working definition spans:
- SaaS AI features quietly enabled by vendors: Power BI Smart Insights (Microsoft enabled by default in late 2025), Salesforce Einstein Copilot (auto-enabled on Salesforce Spring '26 release), Notion AI (added to all Notion Enterprise tenants without per-feature opt-in), Slack AI (Salesforce-owned Slack enabled AI summarization on Enterprise Grid by default), Google Workspace Gemini (Google made Gemini accessible to every Workspace user with the Gemini Business / Enterprise add-on autoprovisioned on many tenants). These features ride on existing SaaS licenses that Procurement already approved. The governance gap is the AI-feature flag, not the SaaS license itself.
- Employee-installed browser-side AI tools, ChatGPT browser extensions, Microsoft Copilot.ai for browser side-panel assistance, Jasper browser extension, Grammarly Generative Write, Otter.ai meeting transcription that runs as a Chrome extension, individual ChatGPT Plus / Claude Pro subscriptions paid on personal credit cards. These tools intercept content rendered in the browser and ship it to AI APIs. SaaS-discovery tools that work at the network layer see the API egress but often misattribute it. Browser-based detection requires CASB browser-isolation or endpoint-managed extension allowlists.
- Department-procured AI tools without governance review, Marketing buying Jasper or Writer.com on a department card; Sales buying Gong or Chorus.ai for call-recording AI analysis; HR buying HireVue or Modern Hire for asynchronous video interviewing; Customer Service buying Cresta or Observe.AI for agent assistance. These tools were procured by the department on a department budget, never routed through the AI Officer's intake form, and operate on production data.
- Data exfiltrated to AI APIs via prompts: Employees pasting customer data, source code, financial statements, deal terms, board materials, and HR records into ChatGPT, Claude, Gemini, or Bing Copilot to ask for summaries, translations, edits, or analysis. The data egress to the AI API is the shadow AI exposure even when no AI tool was formally deployed. This pattern is the Samsung 2023 incident at scale: and in 2026 it is institutional, recurring, and largely undetected without DLP signal integration.
- Internally-built AI side projects that bypass the AI Officer, Data scientists fine-tuning open-source models on Databricks or SageMaker notebooks; engineers wrapping OpenAI API calls into internal microservices; product teams shipping AI features into customer-facing products without a tiering review; analytics teams building forecasting models that auto-decision on inventory restocking. These projects were never registered through the AI Officer's intake form because they were classified internally as "data science" or "automation" rather than "AI."
The discovery sprint must address all five categories. A sprint that finds only the SaaS-vendor-AI-feature category leaves the data-exfiltration risk and the internal-side-project risk uncovered. A sprint that finds only browser extensions misses the vendor-feature-flag risk. The 30-day sprint plan below is engineered to cover all five.
The 30-Day Sprint Plan - Days 1 Through 30
The sprint is structured in six five-day phases. Each phase has a deliverable. The 30-day timebox is intentional. It sets executive expectations that this is not a four-month project but a focused discovery effort with a defined output. Recurring sprints quarterly after the first run keep the inventory current.
Days 1-5: Source-Data Extraction
The sprint starts with extracting raw signal from the existing security and identity stack. The five primary source-data extractions are:
- SaaS-discovery / CASB: Microsoft Defender for Cloud Apps (the most common deployment in Microsoft 365-heavy enterprises), Netskope (the most common deployment in mixed-cloud enterprises), Zscaler Internet Access / ZIA (common where Zscaler is the SSE), Palo Alto Cortex Xpanse / Prisma Access. Extract the full SaaS-applications catalogue with traffic volumes, user counts, and risk scores for the trailing 90 days. Most CASB consoles maintain a "discovered apps" list of 8,000-15,000 SaaS applications. Export it.
- IdP application inventory: Okta universal directory application catalogue, Microsoft Entra ID enterprise applications, Ping Identity application list, Google Workspace third-party app access list. Extract every SAML / OIDC / OAuth application with user-assignment counts. Most enterprise IdPs carry 300-1,500 connected applications.
- SSO logs and OAuth consent grants, Beyond the application inventory, pull the per-user OAuth consent log. Employees granting third-party AI applications access to their corporate Google Drive or Microsoft 365 mailbox is a major shadow-AI vector. Microsoft's "Application Consent and Permissions" report and Google Workspace's "Third-party apps and services" log are the source. Pull the trailing 365 days.
- DLP signals: Microsoft Purview Data Loss Prevention, Symantec / Broadcom DLP, Forcepoint DLP, Netskope DLP. Pull alerts for the trailing 90 days where the destination domain matches a known AI API (openai.com, anthropic.com, generativelanguage.googleapis.com, copilot.microsoft.com, perplexity.ai, mistral.ai, cohere.ai, x.ai, etc.), even where the alert was suppressed or auto-closed. The DLP signal is the smoking gun for the data-exfiltration-to-AI category.
- Browser management telemetry: Microsoft Edge for Business management console (extension installation telemetry), Google Chrome Enterprise (force-installed and permitted extensions inventory), Island browser, Talon Cyber Security browser, LayerX. Extract installed-extension inventory across the managed-browser fleet. Look specifically for extensions that match the AI tool taxonomy in Days 6-10.
Days 1-5 produces five raw exports. The sprint should also pull the Procurement and Finance system for any vendor that matches a known AI tool, a Marketing department buying Jasper on a corporate card will surface in the AP ledger before it surfaces in CASB. Pull the trailing 12 months of vendor payments for any vendor whose name is on the discovery taxonomy.
Days 6-10: AI-Tool Taxonomy and Vendor-Feature-Flag Identification
The raw exports from Days 1-5 are noise. The Days 6-10 work is converting noise into signal by matching discovered SaaS, OAuth grants, extensions, and DLP destinations against an AI-tool taxonomy. The taxonomy is organized in four tiers:
- Tier A: Pure-AI tools, OpenAI ChatGPT (chat.openai.com), Anthropic Claude (claude.ai), Google Gemini (gemini.google.com), Microsoft Copilot consumer (copilot.microsoft.com), Perplexity (perplexity.ai), Mistral Le Chat (chat.mistral.ai), Character.AI, Replika, HeyGen, Synthesia, ElevenLabs, Runway ML, Midjourney, Stable Diffusion deployments, DeepL Write, Grammarly, Jasper, Writer.com, Copy.ai, Otter.ai, Fireflies.ai, Krisp, Notta. The tier-A list is well-documented and maintained by Harmonic Security, Lakera AI Risk Mapping, Nightfall AI, and Wiz AI-SPM among others. Every CASB vendor maintains its own AI-tool category as well; the lists overlap substantially.
- Tier B: AI-enabled SaaS features: Microsoft 365 Copilot (the Microsoft 365 add-on), Microsoft Power BI Smart Insights, Microsoft Power Automate AI Builder, Salesforce Einstein Copilot, Salesforce Einstein GPT, Slack AI (Slack-native summarization and search), Notion AI, Google Workspace Gemini (the Workspace add-on), Atlassian Intelligence (Jira / Confluence), Zoom AI Companion, Asana Intelligence, Monday.com AI, ClickUp Brain, ServiceNow Now Assist, Adobe Firefly and Adobe Sensei GenAI, Canva Magic Studio, HubSpot AI Assistants, Mailchimp Email Content Generator, Intercom Fin, Zendesk AI agents, Drift Conversation AI, Box AI, Dropbox AI / Dash. The tier-B list has exploded in 2025-2026 as essentially every enterprise SaaS vendor has added an AI feature. Maintaining this list is the most labor-intensive part of the discovery program.
- Tier C: AI-development platforms: Databricks Mosaic AI, AWS Bedrock and SageMaker, Google Vertex AI, Microsoft Azure OpenAI Service, Anthropic API (api.anthropic.com), OpenAI API (api.openai.com), Mistral API, Cohere API, Together AI, Anyscale, Replicate, Hugging Face Inference Endpoints, OctoAI, Fireworks AI. Discovery of these typically means engineering teams are building internal AI applications. Tier C maps to the internal-AI-side-project category.
- Tier D: AI-augmented productivity browser extensions: ChatGPT for Google, Merlin AI, Compose AI, Wiseone, Glasp, Webcatalog, Sider, Monica, MaxAI, Harpa AI. These are typically installed individually and need browser-management telemetry to detect.
The most important Day 6-10 finding is usually the vendor-feature-flag inventory. Power BI Smart Insights, Salesforce Einstein, Notion AI, Slack AI, Google Workspace Gemini, and Microsoft 365 Copilot are typically enabled either by vendor default or by tenant-admin configuration without per-feature governance review. A spot check on tenant configuration for each of the top-20 SaaS applications in the IdP catalogue will surface most of the tier-B exposure. The Power BI Smart Insights case, where Microsoft enabled the feature by default in tenants that already licensed Power BI Pro / Premium, without notifying the IT department, is the canonical example. Three months of vendor-feature-flag review per SaaS is appropriate ongoing cadence; for the discovery sprint, do the top-20 in Days 6-10.
Days 11-15: Data-Exposure Analysis
Days 11-15 take each discovered tool from Days 6-10 and answer: what data classifications does this tool have access to? The four-classification taxonomy used in most enterprise environments is:
- PII: Personal data under GDPR Article 4(1), CCPA, state-equivalents. Customer email addresses, employee personnel records, prospect contact lists, candidate applications.
- PHI, Protected health information under HIPAA, health-related sensitive personal data under GDPR Article 9 and EU AI Act Article 10(5) special-categories. Patient records, claims data, clinical trial data, employee benefits PHI.
- Financial / regulated: Material non-public information, SOX-relevant financial data, PCI-DSS cardholder data, customer financial records, deal terms, M&A workstream data.
- Confidential / IP: Source code, trade secrets, board materials, strategy documents, legal privileged communications, attorney work product, internal research.
For each discovered AI tool, the data-exposure analysis answers: (1) what data classifications does the tool have access to through OAuth grants, SaaS-tenant integrations, or browser-content interception; (2) what is the per-day or per-week volume of data exposure based on DLP signals and traffic logs; (3) does the vendor's terms of service permit or prohibit training on customer data and what is the opt-out posture; (4) does the vendor offer enterprise data-residency, zero-retention API access, or other enterprise-grade controls and has the organization purchased them. The output of Days 11-15 is a per-tool data-exposure profile that drives the risk classification in Days 21-25.
Days 16-20: Business-Unit Footprint
Days 16-20 reconcile the tool inventory with the business-unit user assignment. The output is a heatmap that answers: which departments use which AI tools, ranked by user count and data sensitivity. Pulling from IdP user-attribute data (department, cost center, manager), the SSO authentication logs (which users authenticated to which tool in the last 90 days), and the CASB traffic logs (per-user traffic volume), the heatmap typically reveals:
- Marketing, Sales, and Customer Service as the top three departments by tool count and user count. These departments adopt productivity AI fastest and have the largest customer-data footprint.
- Engineering and Product as the largest tier-C AI-development-platform consumers. These teams are building internal AI applications and consuming Bedrock, Vertex AI, Azure OpenAI, and direct OpenAI / Anthropic API calls.
- Finance, Legal, and HR as low-volume but high-sensitivity users. These departments have lower tool counts but the data classifications are typically MNPI, attorney-privileged, or special-categories personal data, raising the risk profile.
- Executive and Board users, typically using consumer ChatGPT Plus / Claude Pro accounts on personal credit cards for personal-productivity use, with high-confidentiality data exposure that often does not show in corporate SSO logs.
The business-unit heatmap is the CIO-facing artifact that shifts the conversation from "is there shadow AI" to "where in the org is the highest-risk shadow AI", a question the CIO can act on.
Days 21-25: Risk Classification
Days 21-25 apply the Article 3(1) AI-system scope test and the four-tier risk classification from earlier lessons to each discovered system. The classification step asks four questions per discovered tool: (1) does the tool meet the Article 3(1) definition of an AI system (most do; some narrow rule-based automation does not); (2) does the use case land in the Article 5 prohibited list (rare but worth screening); (3) does the use case land in an Annex III high-risk category (most enterprise use cases do not, but employment / HR uses, credit-scoring uses, and law-enforcement uses do); (4) does the use case land in Article 50 transparency triggers (chatbots interacting with natural persons, synthetic-content generation). The output is a per-system risk classification that flows into the AI inventory and tiering memo from lesson 020. Discovered systems that are unclassified after the sprint flow into the standard intake process for owner identification and full tiering.
Days 26-30: CIO Report and Remediation Backlog
Days 26-30 produce the CIO-facing shadow AI report, the second L2 Chapter 1 artifact, and the remediation backlog. The report is described in detail in the next section. The remediation backlog is a prioritized list with owners, deadlines, and risk-rationale per item. Typical Day 30 deliverables:
- Executive summary deck (10-12 slides) for the CIO, AI Officer, and Audit Committee.
- Full shadow AI report (40-80 pages) with appendices covering every discovered system.
- Remediation backlog (Jira / ServiceNow / Asana ticket pack) with owner, deadline, severity, and remediation-action per item.
- Updated AI inventory file with newly-discovered systems added through the standard intake-form flow.
- Briefing pack for the AI Governance Committee covering policy gaps and proposed policy changes (typically AUP refresh, GenAI use policy refresh, vendor risk policy refresh).
- Recurring-cadence proposal, typically quarterly discovery sprints with a smaller scope and a 10-day timebox after the initial 30-day baseline.
Discovery Tooling - CASB, SSE, and Dedicated Shadow-AI Platforms
Three tooling categories serve the shadow-AI discovery use case in 2026, with significant overlap and complementary coverage:
- CASB / SaaS-discovery tools repurposed for AI: Microsoft Defender for Cloud Apps (MDA), Netskope CASB, Zscaler, Palo Alto Prisma Access, Cisco Umbrella. These tools were designed for general SaaS discovery and have added AI-tool categorization over the last 18 months. Coverage is broad but the AI-tool taxonomy is typically less complete than dedicated tools. Strength: already deployed in most enterprises; no new procurement. Weakness: limited browser-side visibility, less detailed AI-feature-flag detection, no per-prompt content analysis.
- Secure Service Edge with AI inspection, Zscaler Internet Access has AI-specific inspection profiles; Netskope has Netskope GenAI; Palo Alto has AI Access Security; Skyhigh Security has AI controls. SSE-with-AI-inspection adds per-prompt content analysis, data classification on prompts, and AI-API-specific policies. Strength: per-prompt visibility. Weakness: requires SSE deployment with content inspection, which has performance and privacy implications.
- Dedicated shadow-AI discovery platforms: Harmonic Security, Lakera AI Risk Mapping, Nightfall AI, Wiz AI-SPM, Prompt Security, Glean Generative AI Workplace Search, Knostic. These platforms are purpose-built for shadow-AI discovery and typically have richer AI-tool taxonomies, vendor-feature-flag identification, and prompt-content classification. Strength: AI-specific signal richness; faster taxonomy updates. Weakness: new procurement, deployment overhead, vendor concentration risk in an emerging category.
The 2026 best-practice deployment is the existing CASB / SSE doing the bulk of the work for the first 30-day sprint, augmented by Procurement / Finance for vendor-payment discovery and browser-management telemetry for extension discovery. A dedicated shadow-AI platform is the right next investment after the first sprint has demonstrated the coverage gap.
CIO-Facing Shadow AI Report - Structure and Voice
The CIO-facing report is the second L2 Chapter 1 artifact (the first being the AI inventory and tiering memo from lesson 020). The structure that works in front of a CIO and an Audit Committee in 2026:
- Section 1: Executive summary (1-2 pages), Total systems discovered, gap vs. previously-known inventory, top three risk findings, top three remediation recommendations, total budget request to operate the recurring program. The executive summary is the only section many board members will read; it must stand alone.
- Section 2: Top-10 risk findings (5-10 pages): Each finding stated as a single risk with named system, named business unit, data classification, traffic volume, regulatory implication (EU AI Act, GDPR, HIPAA, CCPA, sector-specific), and recommended remediation with owner and deadline. The format is risk-register-style; the language is regulator-grade.
- Section 3: Business-unit heatmap (2-4 pages): Department-by-department view of tool count, user count, data exposure, and risk classification. Color-coded heatmap that the CIO can show the CFO and the COO.
- Section 4: Data-exposure analysis (5-10 pages): Per-data-classification breakdown of which tools have access to PII, PHI, financial / regulated, and confidential / IP data. Includes the DLP-signal trend (data egress to AI APIs over the trailing 90 days) and the per-tool training-data posture (vendor-trains-on-input vs. enterprise-zero-retention).
- Section 5: Vendor-feature-flag inventory (3-5 pages): Per-SaaS vendor disclosure of AI-feature-flag status (enabled / disabled / default / opt-in), governance-review status, and remediation action. The Power BI Smart Insights line item, the Salesforce Einstein line item, the Notion AI line item, the Slack AI line item, the Google Workspace Gemini line item, and the Microsoft 365 Copilot line item will appear in this section in virtually every enterprise environment.
- Section 6: Remediation recommendations (5-10 pages): Prioritized backlog with owners, deadlines, budget, and risk-rationale. Three tiers: (a) immediate (within 30 days), typically data-exfiltration controls on the highest-volume DLP findings, AI-feature-flag disablement on highest-risk SaaS, browser-extension allowlist updates; (b) tactical (within 90 days), vendor-contract amendments for enterprise-grade AI controls, policy updates, workforce training rollout; (c) strategic (within 12 months), dedicated shadow-AI platform deployment, recurring-sprint cadence operationalization, AI-tool acquisition catalog standup.
- Section 7: Integration with AI inventory and tiering (2-3 pages): How the discovered systems flow into the AI inventory file from lesson 020, what the tiering pipeline looks like, how the AI Officer will keep the inventory current. Includes the SLA for new-system onboarding.
- Section 8: Appendices: Full per-system data table, methodology, tooling deployment status, data-source extraction logs, stakeholder interviews conducted.
The report is signed by the AI Officer, the CISO, and the Head of IT / CIO direct report. It goes to the CIO, the Audit Committee, the AI Governance Committee, and the General Counsel. In ISO 42001-certified organizations, it is registered as evidence under Annex A.6.1.1 (impact assessment) and A.6.1.4 (third-party AI assessment).
Cross-Walks - ISO 42001, NIST AI RMF, EU AI Act, Prior Memos
The shadow AI discovery sprint maps cleanly to multiple framework controls and to prior lessons in this track:
- ISO/IEC 42001 A.6.1.1 (impact assessment), The discovery sprint is the input to organization-level AI-impact assessment; the report is the evidence of operating effectiveness. ISO 42001 Stage 2 auditors typically ask for the most recent shadow AI discovery output as evidence that A.6.1.1 is operating, not just designed.
- ISO/IEC 42001 A.6.1.4 (third-party AI relationships), The discovered SaaS-vendor AI features and vendor-procured AI tools constitute third-party AI relationships that the AIMS must govern. The discovery output drives the third-party AI relationship register.
- NIST AI RMF Map 1 (context), Map 1.1 (intended purpose), Map 1.2 (categorization), and Map 1.6 (system characteristics) are difficult to complete without a discovery output. The 30-day sprint is the operational answer to "how do you know what AI systems you have?"
- EU AI Act Article 3(1) scope memo, The discovered systems flow into the Article 3(1) AI-system scope test from lesson 001. Most discovered systems will be in-scope; the sprint output expands the scope memo from "systems we knew about" to "systems we know about."
- AI inventory and tiering memo (lesson 020), The discovery output is the principal feed into the inventory. The two deliverables, the AI inventory schema and the discovery sprint, are designed to operate together as the L2 Chapter 1 artifact pair.
- EU AI Act Article 4 (literacy), The discovery output identifies which employees are using which AI tools and is the primary input to the Article 4 literacy programme scope. Chapter 5 of L2 covers this in depth.
- EU AI Act Article 50 (transparency): Discovered AI tools that interact with natural persons (chatbots, AI agents, synthetic-content generators) trigger Article 50 disclosure obligations. The discovery output identifies the Article 50 inventory.
- Article 26(4) operational monitoring, For systems that are deployed as high-risk, the discovery output identifies the actual users and use patterns needed to operate Article 26 monitoring.
The L2 Artifact and Six Common Mistakes
The L2 artifact for this lesson is the package: the 30-day sprint plan (the playbook), the CIO report template (the deliverable structure), and the integration with the AI inventory and tiering memo (the operating model). Together they constitute the second L2 Chapter 1 artifact.
Mistake 1 - Relying Only on SaaS-Discovery Without Browser-Side Tooling
A CASB-only discovery program sees what employees connect to via the corporate network. It misses what employees install in their browsers when working from a coffee shop, what they install on personal devices that BYOD-connect to corporate SaaS, and what runs as a browser extension intercepting content client-side. The 2024 Samsung incident pattern, engineers pasting source code into ChatGPT, is largely a browser-side phenomenon. Browser-management telemetry from Edge for Business, Chrome Enterprise, or a managed-browser platform (Island, Talon, LayerX) is the gap-closer. Plan for browser-side tooling in the first 90 days post-sprint.
Mistake 2 - Ignoring Vendor-AI-Feature Flags (the Power BI Smart Insights Case)
The most consistent shadow-AI surprise in 2026 is the SaaS vendor that quietly enables an AI feature on customer tenants without per-feature opt-in. Microsoft enabled Power BI Smart Insights by default on tenants with Power BI Pro / Premium licenses. Salesforce enabled Einstein on Enterprise Edition tenants. Notion added Notion AI to Enterprise plans. Slack added Slack AI summarization. Google added Workspace Gemini. These are not new vendor procurements, the SaaS license already existed, but they introduce new AI processing on existing data with new vendor-side training, retention, and processing terms. A discovery sprint that does not separately audit vendor-AI-feature-flag status for the top-20 SaaS applications misses the bulk of the tier-B inventory. Repeat the vendor-feature-flag review quarterly.
Mistake 3 - Skipping the Data-Exposure Analysis
A discovery sprint that produces a tool list without per-tool data-classification analysis cannot drive prioritization. The CIO does not need to know there are 312 AI tools; the CIO needs to know which of the 312 have access to MNPI, attorney-privileged data, customer PII, or PHI, and what the daily exposure volume is. The Days 11-15 data-exposure analysis is the highest-effort, highest-value phase of the sprint. Allocating less than five days to it produces a tool list that the CIO cannot prioritize.
Mistake 4 - One-Time Sprint Without Recurring Cadence
The shadow AI landscape changes monthly. New SaaS vendors enable AI features. New browser extensions ship. New department-procured tools land on corporate cards. A one-time discovery sprint produces a snapshot that is outdated within 60 days. The discovery program must be operationalized as a recurring cadence, typically quarterly with a smaller 10-day scope after the first 30-day baseline. Resource the recurring program in the original budget request, not as an afterthought.
Mistake 5 - No Remediation Backlog With Owners
A shadow AI report without a remediation backlog with named owners, deadlines, and severity is a report destined for a shelf. The Days 26-30 work must produce ticketed remediation actions in the organization's ticketing system (Jira, ServiceNow, Asana) with named owners and tracked deadlines. The CIO should be able to ask for the remediation-backlog burn-down at the next quarterly review. Without the backlog, the discovery sprint is a one-time information event with no organizational consequence.
Mistake 6 - No Integration With AI Inventory and Tiering Memo
The discovery output and the AI inventory are two views of the same underlying reality. If the discovery output is a separate artifact that does not flow into the inventory, the inventory will diverge from the discovery output over time, and the AI Officer will be working from a different truth than the CIO. The integration between the discovery sprint and the inventory file from lesson 020 must be explicit: every discovered system that is confirmed in-scope gets an inventory row; the inventory row carries forward through tiering, owner assignment, and lifecycle management. Treat the discovery output as the input feed to the inventory, not as a parallel artifact.
Key Takeaways
- Shadow AI spans five categories. SaaS-vendor-enabled AI features (Power BI Smart Insights, Salesforce Einstein, Notion AI, Slack AI, Workspace Gemini); employee-installed browser-side AI tools; department-procured AI without governance review; data exfiltrated to AI APIs via prompts; internally-built AI side projects. A discovery program must address all five.
- The 30-day sprint runs in six five-day phases. Days 1-5 source-data extraction (CASB, IdP, SSO logs, DLP, browser telemetry, Procurement); Days 6-10 AI-tool taxonomy and vendor-feature-flag identification; Days 11-15 data-exposure analysis; Days 16-20 business-unit footprint; Days 21-25 risk classification; Days 26-30 CIO report and remediation backlog.
- Discovery tooling options are CASB / SSE / dedicated platforms. Microsoft Defender for Cloud Apps, Netskope, Zscaler, Palo Alto deliver the bulk of first-sprint coverage; SSE-with-AI-inspection adds per-prompt visibility; Harmonic Security, Lakera, Nightfall, Wiz AI-SPM, Prompt Security deliver AI-specific richness.
- The CIO report has eight sections. Executive summary, top-10 risk findings, business-unit heatmap, data-exposure analysis, vendor-feature-flag inventory, remediation recommendations, integration with AI inventory and tiering, appendices.
- Cross-walks span ISO 42001 A.6.1.1 / A.6.1.4, NIST AI RMF Map 1, EU AI Act Articles 3(1), 4, 26(4), 50. The discovery output is operating-effectiveness evidence for the impact-assessment control and feeds the third-party AI relationship register.
- The L2 artifact is the sprint plan + report template + inventory integration. Three components delivered together as the second L2 Chapter 1 deliverable.
- Six mistakes recur in 2026 programs. SaaS-only discovery without browser tooling; ignoring vendor-AI-feature flags (Power BI Smart Insights case); skipping data-exposure analysis; one-time sprint without recurring cadence; no remediation backlog with owners; no integration with the AI inventory and tiering memo from lesson 020.
- Recurring cadence is quarterly with a 10-day scope. The shadow AI landscape changes monthly; the discovery program must operate as a recurring cadence after the first 30-day baseline, not as a one-time effort.
- Vendor-feature-flag review is the highest-yield ongoing discipline. The top-20 SaaS applications get re-audited every 90 days for new AI features; the AI Officer maintains the vendor-feature-flag inventory as a living document.
- Remediation backlog must have named owners, deadlines, and severity. Three tiers: immediate (30 days), tactical (90 days), strategic (12 months). Tracked in the organization's standard ticketing system; reported to the CIO at quarterly review.
Skill.re