Your organisation is already using AI tools nobody approved.
Shadow AI — AI tools and models in active use outside any governance framework — is the fastest-growing governance gap in enterprise AI. Most organisations discover it too late.
You can't govern AI you don't know about.
Shadow AI isn't a fringe problem. In most organisations, it's the majority of AI activity. Employees using ChatGPT to draft client communications. Finance teams using AI spreadsheet tools with access to sensitive data. Marketing teams building AI-assisted workflows without IT involvement.
Each of these represents a governance gap: unreviewed data exposure, unapproved processing of personal data, unmonitored AI influencing business decisions. Under the EU AI Act, some of these gaps carry regulatory consequences.
Data exposure risk
Employees processing customer data, financial data, or personal data through unapproved AI services — often with unclear data retention and processing terms.
Regulatory exposure
Under the EU AI Act, high-risk AI use without governance documentation creates compliance liability regardless of whether the tool was formally approved.
Portfolio blindspot
Leadership making AI investment decisions without visibility over what's already running informally. Duplication, conflict, and wasted investment follow.
Felix asks. People tell. The registry builds itself.
VERDIX doesn't require a separate Shadow AI discovery project. Felix, the AI advisor that guides initiative submissions, asks about informal AI use as part of the standard intake process.
When someone submits an AI initiative for governance, Felix asks: what AI tools is the team currently using informally? Are there other AI tools in your department we should be aware of? The answers are logged automatically to the Shadow AI Registry. Discovery happens as a byproduct of normal governance activity.
Guided intake
Felix guides every initiative submitter through a structured intake process. Shadow AI questions are embedded naturally — not as a separate survey.
Automatic logging
Every Shadow AI declaration is automatically logged to the portfolio-level registry, attributed to the submitter and their business unit.
Continuous discovery
As more initiatives pass through governance, the registry fills. Shadow AI that isn't captured in one submission cycle gets captured in the next.
A living portfolio-level Shadow AI inventory.
The Shadow AI Registry is not a one-time audit output. It's a living document that grows as governance activity continues. Each entry includes the tool name, the business unit, the use case, the data types involved, and the current governance status.
Declaration finds what scanning misses.
Infrastructure scanning finds tools that touch your network. Declaration-based discovery finds tools that touch your organisation — whether or not they appear on your network.
| Infrastructure Scanning | Declaration (VERDIX) | |
|---|---|---|
| Scope | Network-visible tools only | All tools, including web-based and personal accounts |
| Coverage | Misses SaaS, personal devices, home working | Captures human-level AI use regardless of device or network |
| Data types | Tool presence only — no use-case context | Includes use case, data types, and responsible party |
| Overhead | Requires IT infrastructure access and ongoing scanning | Embedded in standard governance intake — zero additional overhead |
| Accuracy | High false-negative rate for web-based tools | Captures what employees actually use, not what IT can see |
Common questions.
Start discovering what's already running.
The Shadow AI Registry builds itself as you govern. Request a demo to see how Felix surfaces informal AI use during standard governance intake.
Already a client? Client Login →
