8 Shadow AI Checks — The AI Governance Checklist Mid-Market Companies Can Run in Two Weeks
- TecAce Software
- Aug 14
- 4 min read
Updated: 5 days ago

If you are a 30–300 person company where one or two people cover AI on top of their real jobs, there is something to do before you start evaluating models: find out what is already running inside your company. Two weeks is enough.
What is Shadow AI?
Shadow AI is any AI tool employees use for work without the company approving it or knowing about it. Chatbots accessed through personal accounts, document summarizers on a free plan, browser extensions installed without IT sign-off — all of it counts.
Who should care : companies of 30–300 employees with no dedicated AI team, where one or two people handle AI alongside another job
What is the problem : leaks do not start with an outside attacker. They start with an employee pasting in a little too much context to get a better answer
Why now : Korea's AI Framework Act, in force since January 2026, requires record-keeping and explainability. You cannot keep records of what you cannot see
Two numbers worth citing. First, a global breach study reported in 2026 found that the share of incidents involving shadow AI doubled from 20% to 43%, with an average cost per incident roughly USD 670,000 higher than a standard breach. Second, a domestic survey found that 74% of Korean companies named AI as their single largest data security risk.
Why a ban does not solve it
Shadow AI is not laziness — it is a speed gap. Sales needs the quote out today; the internal approval process takes three weeks. Put a blocking policy in place and the tools simply move to personal laptops and phones, and the company's visibility drops toward zero.
So the goal of an audit is not to catch people. The order is: build the inventory → define the tiers → offer a safe alternative.
The 8-point checklist, in two weeks
Week 1 — Find out what is actually running
1. Build an inventory of AI accounts and tools
Pull from three directions: corporate card statements, SSO login records, and voluntary reporting by team. Personally expensed tools surface most often here, so announce upfront that self-reporting carries no penalty.
2. Define data tiers for what must never be pasted
Three tiers is enough. Prohibited (contractual or legal liability if it leaves the company) / Conditional (allowed after de-identification) / Open. If the tier table runs longer than a single page, nobody will actually follow it.
Top prohibited items for manufacturers: design drawings, BOMs, price lists, tooling specs
Top prohibited items for IT services firms: client source code, production credentials and keys, copies of contracts
3. Audit browser extensions and MCP connectors
Extensions and MCP connectors often hold access to an entire mailbox or drive without the user ever realizing it. Export the installed list and sort it by what each one can actually read.
4. Reclaim accounts from departures and contractors
AI tools signed up for with a personal email are routinely missing from the offboarding checklist. What AI your outsourced dev shop is feeding your code into is also worth confirming in the contract.
Week 2 — Build the alternative and make it run
5. Create an approval channel
Set up somewhere people can ask "can I use this tool?" and a rule that you answer within two business days. The approved list needs at least two or three genuinely usable tools, or people will route around it.
6. Move to paths that leave logs
Same model, different plan: consumer tiers have no audit log, while business plans give you an admin console, a retention policy, and the option to exclude your data from training. Judge on visibility, not price.
7. Set a review rule for AI output
One line is enough: anything leaving the company — quotes, proposals, customer replies — gets a final human check. With roughly 60% of companies in one domestic survey reporting deepfake-based attacks, it is worth writing down how you verify inbound requests as well.
8. Write a one-page incident response
When someone reports "I think I pasted something sensitive," who does what, and within how many hours? Three items get you started: requesting deletion of the conversation, preserving logs, and the criteria for notifying customers.
What you have after two weeks
One AI tool inventory
One data tier table
An approved tool list plus an intake channel
One incident response page
These four are the minimum starting point for the record-keeping and explainability duties the AI Framework Act asks for, and the foundation you build AI governance and LLM evaluation on later. Skip this step and start with model evaluation instead, and you will not know what you are supposed to be evaluating.
Frequently asked questions
Q. We only have 30 employees. Do we need all of this?
Items 1, 2 and 5 alone clear a large share of the exposure. Add the rest when your tool count starts to grow.
Q. Can we not just ban AI outright?
A ban does not eliminate usage; it pushes it outside the company's line of sight. An approved list gives you more real control.
Q. Will the AI Framework Act fine us right away?
Since it took effect on January 22, 2026, a grace period of at least one year applies, so fines are not immediate — though corrective orders are possible. It is more realistic to treat this as time to get your records and transparency in order.
How TecAce helps
TecAce is an AI Transformation partner focused on mid-market companies. As a member of the Anthropic Claude Partner Network, we deploy 12 Claude-certified architects and Forward Deployed Engineers (FDEs) from our offices in Bellevue, WA and Seoul. Not remote advisory — our engineers sit with your team and run it with you, from the inventory audit through building out the governance framework.
Want your company's shadow AI exposure assessed in 30 minutes? → Request an AI governance assessment



Comments