TerrierTerrier

How to Find Out What AI Tools Your Employees Are Using (Without IT Access)

Last updated: June 2026


To find AI tools your employees are using without IT access, check three places: your Google Workspace OAuth log (Reporting → Audit and investigation → OAuth log events), your corporate card statement filtered for AI vendor names, and your expense reimbursements. The first catches tools connected with a work Google account. The second catches tools on a company card. Neither catches tools on a personal card — that requires a different approach covered below.


The Problem

An associate at your firm needed to draft a contract faster. She opened ChatGPT, pasted in the client details, and asked it to generate a first draft. It took four minutes instead of two hours. She kept using it. By March, three other associates had started doing the same thing. Nobody asked for permission. Nobody told IT. Nobody checked whether ChatGPT's privacy policy allowed client data to be processed this way.

In a law firm, that's a potential attorney-client privilege violation. In a staffing agency, that's candidate data in a system your clients never consented to. In an accounting firm, that's financial information in a third-party AI training pipeline.

This is not a hypothetical. According to IBM research, 20% of global organizations suffered a data breach in the past year due to security incidents involving shadow AI — employees using unapproved AI tools for work tasks. And the scale is accelerating: research published in 2025 found that sensitive data now makes up 34.8% of employee ChatGPT inputs, up from 11% in 2023.

The tools work well. That's exactly why they spread.


Why This Happens

AI tools are the easiest software ever built to adopt without approval. There's no installation, no IT ticket, no procurement conversation. An employee goes to a website, clicks "Sign in with Google," and they're in. The charge shows up as $20/month on their expense report under "productivity tools." Nobody questions it.

Traditional software procurement assumed friction. Someone had to buy a license, configure an account, provision users. AI tools have none of that. A tool like Otter.ai — which records and transcribes meetings — can be connected to an employee's Google Calendar in under two minutes, giving it access to every meeting they attend, every participant, every agenda item. The employee never thought of it as a security decision. They thought of it as a productivity hack.

The result is that most organizations have a gap between what IT knows is running and what's actually processing company data. According to Zylo's 2026 SaaS Management Index, shadow IT accounts for 34% of an organization's total SaaS portfolio — and AI tools are now the fastest-growing category within that number.


How to Find Shadow AI in Your Organization: Three Methods

Method 1 — Google OAuth Audit (finds tools connected with work Google accounts)

This is the most comprehensive method for Google Workspace organizations. Every time an employee clicks "Sign in with Google" on a third-party app, Google logs it.

Go to: Google Admin Console → Reporting → Audit and investigation → OAuth log events

Extend the date range to at least 90 days. Then look for AI-related app names. Search or filter for:

  • OpenAI / ChatGPT
  • Anthropic / Claude
  • Otter.ai
  • Fireflies / Grain (meeting recorders)
  • Runway (video AI)
  • Jasper / Copy.ai / Writesonic
  • GitHub (Copilot — if employee signed up to GitHub via Google)
  • Notion (AI features are included in the main Notion app)
  • Grammarly (which requests broad text access)

Note: Google's own AI products (Gemini built into Workspace, Google AI Studio) and tools that use non-Google login methods (Midjourney uses Discord; Cursor uses email or GitHub) will not appear here. For those, check the card statement in Method 2.

Export to CSV. You now have a list of every AI tool any employee has connected to their work Google account, when they connected it, and what permissions they granted.

For a domain-wide view of every third-party app connected across your entire organization — not just one user — go to: Admin Console → Security → Access and data control → API controls → Manage third-party app access

This shows every app authorized across your domain, sortable by number of users and scope of access. Any app with broad scopes (Drive, Gmail, Contacts) is worth reviewing regardless of whether it's an AI tool.

Method 2 — Card Statement Review (finds tools paid for on company cards)

Pull 90 days of corporate card statements. Search for these vendor names — they appear on statements when employees pay for AI tools directly:

  • OPENAI (ChatGPT Plus, Teams, API — DALL-E is also billed here)
  • ANTHROPIC (Claude Pro, Teams)
  • MIDJOURNEY (Discord-based, only catchable via card)
  • RUNWAY (may appear as RUNWAYML)
  • JASPER (may appear as JASPER.AI)
  • OTTER (may appear as OTTER.AI)
  • FIREFLIES (may appear as FIREFLIES.AI)
  • GITHUB (Copilot)
  • NOTION
  • GRAMMARLY

Note: exact billing names vary by card network. Search for partial matches, not exact strings. Flag any recurring charge from a vendor you didn't formally procure. The charge amount tells you the tier: $20-30/month is usually an individual subscription; $25-40/month per user suggests a Teams plan someone set up for their department.

Method 3 — Expense Reimbursement Review (finds tools on personal cards)

This is the hardest category to catch and the most common way AI tools actually spread. An employee signs up using their personal card and expenses it monthly. The $20 charge appears in your expense system as "productivity software" or "subscription" with no vendor name.

Audit any reimbursed software subscription under $100/month where the vendor isn't recognizable. Ask the employee directly what it is. This is uncomfortable but necessary — these are the tools most likely to be processing company data without any IT visibility at all.


Where This Breaks Down

The OAuth audit shows you what's connected to your Google account. The card statement shows you what's being paid for. Neither tells you what data employees are actually putting into these tools.

An employee can use ChatGPT on a personal account — no company card, no "Sign in with Google" — and paste in client details, contract drafts, or financial data. That usage is completely invisible to every method above. The tool never appears in your Google audit log. The charge never appears on your statements. From a company visibility standpoint, it doesn't exist — until something goes wrong.

For professional services firms specifically — law firms, accounting firms, staffing agencies — this is the exposure that matters most. The tools you can see and audit are a fraction of the AI usage actually happening with company data.


How Terrier Handles This

Terrier surfaces the visible layer: AI tools connected via Google OAuth and AI subscriptions appearing on corporate cards, cross-referenced against your employee directory. It shows which tools have been granted broad access — to Drive, Gmail, or Contacts — so you know where to look first.

It does this without reading email content, client files, or any data protected by attorney-client privilege or financial confidentiality rules. It reads OAuth grant records and transaction metadata only.

The invisible layer — personal account usage — requires a written policy, which we cover in our companion guide: Shadow AI Policy Template for Professional Services Firms.

terrierops.com — free to scan your first month.


One Thing You Can Do Right Now

Open Google Admin Console → Reporting → Audit and investigation → OAuth log events. Set the date range to the last 90 days. Filter the App Name column for "AI" and "GPT" and "Claude."

Look at the Scopes column next to each result. Any tool with auth/drive, auth/gmail.readonly, or auth/contacts has access to sensitive company data. That's your immediate risk list — those tools are reading files, emails, or contacts right now, and you may not have reviewed whether their privacy policies allow it.

That list, from your own Google data, is the starting point.


Frequently Asked Questions

Q: What is shadow AI?

Shadow AI refers to AI tools employees use for work tasks without IT or management approval. Unlike traditional shadow IT (unauthorized software), shadow AI is uniquely risky because employees frequently input sensitive data — client details, financial records, legal documents — into these tools, which may store, process, or use that data in ways the organization hasn't reviewed or consented to.

Q: How do I find AI tools employees are using on personal accounts?

You can't detect personal-account usage through technical controls alone. The OAuth audit and card statement review only catch tools connected to work accounts or paid with company money. Personal-account usage requires a written policy that employees acknowledge, combined with periodic reminders. Some organizations also use network-level filtering, but this is complex and often bypassed on remote or mobile devices.

Q: What AI tools are most commonly used without approval in professional services firms?

Based on the OAuth scope data visible in Google Workspace audits, the most commonly unauthorized AI tools in professional services tend to be: ChatGPT (individual accounts), Otter.ai and Fireflies.ai (meeting recorders with broad calendar and contact access), Grammarly (which requests broad text access), and AI writing assistants like Jasper or Copy.ai. Meeting recorders are particularly high risk because they access participant names, email addresses, and conversation content automatically.

Q: Do I need to tell employees I'm running this audit?

In most jurisdictions, reviewing OAuth grants and corporate card statements on company accounts and company cards does not require employee notification — these are company-owned resources. However, policies vary by country and company size. For non-US organizations especially, consult your employment counsel before conducting a review. The audit itself reads system-level metadata, not email content or private communications.

Q: What should I do when I find an unauthorized AI tool?

First, understand what data it has accessed — check the OAuth scopes granted. Then assess the risk: does this tool's privacy policy allow training on user inputs? Does it store data? Can you request deletion? For tools with broad sensitive scopes (Drive, Gmail), consider revoking access immediately via Admin Console → Security → Access and data control → API controls → Manage third-party app access, and then follow up with the employee to understand what they were using it for and whether a sanctioned alternative exists.

Q: What's the difference between shadow AI and shadow IT?

Shadow IT is any unsanctioned software. Shadow AI is specifically AI tools used without approval. The distinction matters because AI tools carry a unique risk that traditional shadow IT doesn't: they're designed to process and learn from the content they receive. A rogue project management tool holds your data but doesn't train on it. An AI writing tool may use your legal documents or financial data to improve its model — depending on the plan and privacy settings.

Q: Is there a policy template I can use once I've found what tools are in use?

Yes — see our companion guide: Shadow AI Policy Template for Professional Services Firms. It covers how to define approved vs. prohibited AI tools, data classification rules, and how to communicate the policy to your team without triggering a backlash.


Terrier is a SaaS spend optimization platform for Google Workspace companies. It finds ghost seats, shadow AI, and unauthorized tool connections in minutes without accessing email content or client data. terrierops.com