Shadow AI discovery
Finding the AI is the easy part.
Plenty of tools will give you a list of AI in use. A list is not governance. What matters is what happens next.
Intake queue
11 waiting
| Tool | Detected by | First seen | Users | Status |
|---|---|---|---|---|
| Notion AI | Discovery | 3 Mar | 14 | In review |
| Perplexity | Discovery | 3 Mar | 6 | In review |
| Claude | Discovery | 28 Feb | 23 | Registered |
| Grammarly | Discovery | 26 Feb | 41 | Dismissed |
| Otter.ai | Discovery | 24 Feb | 9 | In review |
| Midjourney | Discovery | 21 Feb | 2 | Registered |
The problem
AI arrives one person at a time.
A writing assistant, an embedded feature or a direct model API may never pass through procurement. When someone asks what AI you run, nobody knows.
What happens next
One queue, one process.
A discovered tool enters the same intake queue as a system registered by hand. It gets an owner, risk tier and recorded approval, then follows the same seven steps.
Detected
Matched to catalogue
Intake queue
Registered with an owner
Same seven steps
No separate shadow AI list. One queue, one process.
What we do not do
Discovery supports decisions; it does not make them.
Vigil24 does not block tools, intercept traffic or enforce at the network layer. Decisions and enforcement stay with your team.
See Vigil24 on one of your own AI systems.
A 25-minute walkthrough from registration to sign-off.
