BackBrief launches fall 2026. Founding members lock in $79/mo — 10 spots.

How to tell if your team is already using AI tools you don't know about

Here is the number you should start with. In Microsoft's 2024 Work Trend Index, a survey of 31,000 knowledge workers across 31 markets, 75 percent said they use generative AI at work. Of that group, 78 percent are bringing their own tools to the job — a personal ChatGPT account, a free chatbot, a browser extension — with no official approval anywhere in the chain. At small and medium companies, the share is 80 percent.

Read that the way an owner should: if you have ten people, seven or eight of them are probably already using AI on the job, and most of it never crossed your desk.

That is not a judgment on your team. It is the shape of the tool market. Consumer AI walked in through the browser, not through procurement, so it left no paper trail. No ticket, no vendor review, no line item on an invoice. The tools are free or cheap, they improve weekly, and the employee who uses them is not doing anything they think of as wrong. They are doing their job with the best tool in reach.

So the real question is not whether your team uses AI. It is whether you can see it. Here is how to look.

The money trail (check it first, it is the shortest list)

Most shadow AI costs nothing, which is why it is invisible. But the paid layer leaves marks.

  • Recurring charges between $10 and $30 a month on expense reports and reimbursed personal cards: ChatGPT Plus, Midjourney, Canva Pro, Grammarly, Notion AI, Zapier, transcription services. Small charges, easy to miss, and they repeat every month.
  • Line items from vendors whose names you do not recognize, especially ones ending in ".ai" or containing "intelligence," "analytics," or "assistant."
  • API or usage-based charges on a company card. Somebody with an engineering background may have wired a tool into a workflow and the cost shows up as a floating cloud-services charge.
  • The free tier leaves nothing, so an empty expense report proves nothing. It just means the tool costs nothing.

The work product (the richest trail)

AI changes how output looks, and the change is visible if you know what to compare against.

  • Writing that suddenly sounds uniform. When everyone's emails, proposals, and docs start using the same sentence rhythm, the same transitions, the same slightly formal vocabulary, that is not a coincidence. People do not start writing alike by accident.
  • Documents that are grammatically perfect and factually shaky. AI is excellent at confident wrongness: the memo reads beautifully, and the number in paragraph three is from 2022.
  • Spreadsheets with formulas or macros nobody on the team can explain. Ask "who built this?" and watch people look at their shoes.
  • Slide decks that look noticeably better than anything the team produced six months ago. Design quality does not jump like that on its own.
  • Code with comments written in a voice that is not the author's. If an engineer's pull requests suddenly have uniformly phrased comments, the AI wrote the comments.
  • Images with small anatomical errors: extra fingers, text that squiggles, reflections that do not match. Real people notice these when they look, but nobody looks closely at a chart on slide twelve.

The machines (only if you have access, and only at the level you already have)

You do not need surveillance to find shadow AI, and you should not build any. But the ordinary admin access most owners already have will surface most of it.

  • Browser extensions on company devices: ChatGPT, Grammarly, translation helpers, writing assistants, "AI" anything. This is a five-minute check and it catches more than you would expect.
  • Personal accounts logged into company hardware. A Chrome profile with a personal Gmail is not evidence of anything, but a personal account connected to an AI tool on a work machine is exactly the pattern you are looking for.
  • Pasted prompts in support tickets, chat logs, and shared documents. When people use AI carelessly, the prompt itself ends up in a record somewhere. "Rewrite this in a friendly tone" above a customer reply is a very common find.
  • The telltale leftovers. Occasionally a draft ships with "As an AI language model" or an orphaned instruction in it. Those are rare, but when you see one, you have your answer.

The behavior (the least technical, often the most reliable)

  • Work that gets done suspiciously fast. A report that took a week last quarter comes back in a day, consistently. That is not a team getting better at the same job; that is a team that changed the job.
  • The tool whisperer. Every office has one person everyone routes their "can you just look at this" requests to. If that person started producing strangely fast output, the whole team is using AI through them, whether anyone says so.
  • Vocabulary drift. When people start saying "prompt," "hallucination," "context window," and "just feed it" in normal conversation, they are not reading about AI; they are using it.
  • Reluctance to explain the how. Ask "how did you get this done so fast?" and a normal person tells you. If the answer is vague and the eye contact drops, they are deciding whether the truth is safe to say.

How to look without turning the office against you

The difference between an audit and a witch hunt is where you look and what you say.

Look at artifacts, not people. Expense reports, extension lists, output patterns, shared files. Those are fair game for an owner and they tell you everything you need. Do not look at keystrokes, screen time, or private messages. The first kind of looking is inventory; the second is surveillance, and surveillance teaches people to hide.

Say what you are doing. Tell the team you are taking stock of which AI tools are actually in use, because you want the company's data to go only where the company has decided it can go. That is a defensible, honest reason, and it is the real reason. People who are told why you are looking will mostly help you; people who find out later will mostly assume the worst.

Ask without threat. Most employees will tell you exactly what they use if the question does not come with a punishment attached. Nobody confesses under a policy they expect to be enforced against them; everybody will describe a toolchain they are proud of. Ask "what are you using, and what is it good for?" and then actually listen to the answer. You will learn more in one conversation than in a month of looking.

What to do when you find it

Discovery is not a fire drill. It is the beginning of management, and the steps are small.

For each tool you find, ask three questions. What data goes into it? Who checks the output before it matters? What does the vendor do with what you feed it? The postcard test from the governance conversation applies here: if you would not write it on a postcard, it should not go into a general-purpose chatbot.

Then decide, out loud, in front of the team. Tools that touch customer data, contracts, or financials get either a sanctioned equivalent with controls or a plain reason why they cannot be used on company material. Tools that touch nothing sensitive stay, because banning them just moves them somewhere you cannot see. The goal is not fewer AI tools. It is fewer invisible ones.

And publish the path for getting something approved. If approval takes a quarter, the shadow tool keeps winning, because the shadow tool is already installed and it works today. The only thing that beats it is a sanctioned option that is easier to use than the thing they already have.

The honest close

The tell was never that your team uses AI. That ship sailed — 75 percent of knowledge workers are on board. The tell is that you found out from a receipt or a suspiciously good slide deck instead of from a conversation.

A team that uses ten AI tools openly is easy to manage. A team that uses two AI tools secretly is not. The difference is not the tools. It is the visibility, and visibility starts with looking at the boring signals and asking the questions without the threat.

Start there. The looking takes an afternoon, and the first conversation takes an hour. The company you are protecting is the one you will actually be able to see.


Back to all posts