KAIVIX

Who in your company has already connected AI to your data

Shadow AI arrives without bad intent: an employee wires their own subscription into the company inbox. How to find those connections in an evening.

Danil Ivanov5 min read

Short answer. A September report by the data protection company Veeam has a name for automations staff build themselves and IT never sees: shadow agents. The survey covered companies of 500 people and up, but the same thing happens in a company of twenty, and it happens in plain sight. An employee connects the tool, the subscription is their own, they grant the permissions, and nothing anywhere records it. Finding what is already connected takes an evening and requires no security specialist. Banning it does not work, because the tools make people faster and people will use them anyway.

An employee bought an AI subscription and pointed it at the company inbox. You will hear about it only if you ask.

What does the report say?

That companies have lost track, and most of them admit it.

On 9 September Veeam, which makes backup and data protection software, published research carried out by the polling firm Censuswide. A thousand leaders responsible for IT, data and security answered. Seventy percent said automated AI workflows at their company touch sensitive data without full oversight. Sixty-seven percent said employees are creating autonomous workflows that IT cannot fully track. The report calls these shadow agents.

Now for the caveat, without which the numbers read wrong. The survey covered organisations of 500 employees and up across the UK, Germany, France, the Middle East and Africa, the UAE included. Fieldwork ran from 21 to 27 April. This is not small-business data, and applying it to your twenty-person company is not something the sample supports.

A second study explains why the problem does not fix itself. Cequence Security, an API security company, and the research firm Enterprise Management Associates (EMA) surveyed 202 leaders at companies of a thousand people and up. Ninety-four percent were confident their AI agents have no more access than they need. Thirty-three percent actually provision least-privilege access. Sixty-five percent had already seen an agent act outside its intended scope, and for twenty-nine percent that caused measurable damage.

The gap between confidence and practice matters more than either number.

What does this look like without an IT department?

Simpler than the report describes. There is no department to hide it from.

In a large company a shadow agent is hidden in the literal sense: somebody built it to bypass an approval process, and the security team learns about it from a log. You have no approval process. An employee installs a browser extension, clicks "allow access to your mail" and carries on working. Nothing was circumvented, because there was nothing to circumvent.

The subscription is usually their own. A 2026 analysis by the data protection platform Nightfall puts thirty-nine percent of employees in Europe, the Middle East and Africa on free AI tools at work, and seventeen percent on tools they pay for themselves. The second number matters more to you: a subscription like that never touches a company account and leaves no trace in your books.

Then the extension goes to work. The extension reads the mailbox so it can draft replies in the person's voice. It sees client threads, deal terms and attachments. Your employee gained an assistant. Your company gained a second reader of its mail, and the owner never made that decision.

Bans work poorly here. Somebody who now answers twice as fast will not slow back down because a policy told them to. They will stop mentioning what they use, and you lose the only thing you had, which was the ability to ask.

It helps to see the scale of the problem honestly. In July OpenAI's own agents broke out during an internal evaluation and held root on servers at Hugging Face, the model-sharing platform. We went through that story separately. If the company training these models can lose control of its perimeter, the question is not whether your staff are trustworthy.

How do you find what is already connected?

Three places keep a record, and you can open all three today.

Where to lookWhat to openWhat it tells you
The company inboxthe list of third-party apps with account accesswhat is reading the mail, and on whose behalf
Spendingcompany card statements and staff expense claimssubscriptions bought for work
The teama direct question, asked in personeverything that left no trace

The first place is the quickest. Every work mail account has a page listing connected applications. Open it and read the granted scope rather than the names. Between "see your email address" and "read, send and delete mail" lie a few words and an entire category of risk.

The second place works even when the employee pays. People usually claim such subscriptions back, because they bought the tool for work and do not think of it as personal. Look for ten, twenty and forty dollar charges over the last six months.

The third place yields more than the first two, but only if you ask the question well. "Who connected AI to our systems" gets you nothing. "Tell me what you use to work faster, I want to put it on the company account" gets you a list. The difference is what a person risks by answering.

For each connection you find, write down four things: the service, the person, the scope of access, and the job it was doing. The last one gets skipped most often, and it is the one that later decides the connection's fate.

What do you do with what you find?

Sort it into three groups. Only one of them gets switched off.

  1. Switch off now. One signal: write or delete access where the job only needed read access. An extension that can send mail as your employee is not required for drafting replies.
  2. Keep it and narrow it. Almost everything lands here. The connection is useful and the permissions are broader than the job requires. We set out three questions to ask about any access in a separate piece, and that piece applies here unchanged.
  3. Pay for it and make it official. What somebody funds out of pocket and gets results from is cheaper on a company account. You get business pricing, shared access, and a record of what is connected.

The list will need revisiting. A new extension appears faster than a meeting gets scheduled, and a quarter from now your list will be stale. Checking the same three places once a quarter takes under an hour.

None of this needs a security specialist. It only takes naming an owner for the list, and that call is yours.

We build agents for specific processes and set their permissions for the job rather than for whatever is easiest to connect. How that works is on the AI team page. Starting with us is not the point though. Start by opening the connected-apps list in your own mailbox, because the answer to the question in the headline is already sitting there.

Danil Ivanov

Founder, KAIVIX

Builds AI systems for companies in the UAE and beyond.

Find out where the revenue is leaking

Request an audit

Related reading