Back to blog
Discover·Jun 16, 2026·4 min read

How to discover every AI tool in your organisation, including the hidden ones

Ask your teams which AI tools they use and you will get an honest, incomplete answer. Not because anyone is lying, but because half of it no longer feels like a tool. It is just how they work now.

Discovering every AI tool in your organisation is the first move in any governance, security, or EU AI Act programme, and it is harder than it looks. The sanctioned tools are easy. The problem is everything else: the AI features switched on inside software you already pay for, the free tool someone adopted last Tuesday, and the ones people will not mention because they are quietly bending a policy to get work done.

Why a survey is not discovery

Asking people what they use is a fine place to start and a terrible place to stop. It misses three things at once. It misses embedded AI, the features now baked into your existing HR, CRM, and developer tools, which nobody thinks to report. It misses shadow AI, the unsanctioned tools people will not volunteer. And it misses the drift, because new tools appear faster than any survey cycle. People also under-report, not from malice, but because the tool feels too ordinary to mention or too grey-area to admit.

Where the hidden AI actually lives

That is precisely what Grasp automates: it discovers every AI tool in use from real signals rather than a one-off audit.

If you want to find it, you have to know where it hides: browser extensions on company laptops, personal accounts logged in on work devices, AI features inside SaaS you already own, subscriptions buried in expense reports, and OAuth grants connecting AI services to your Google or Microsoft environment. None of these show up on a list of approved software, which is exactly why they are the risk.

How to actually find it

No single method catches everything, so combine them. Use network and endpoint signals to spot connections to AI services. Review OAuth and single-sign-on logs for AI apps granted access. Scan expense data for AI subscriptions. Audit browser extensions. And run a survey, as a prompt rather than the answer. Detecting shadow AI and turning the result into a maintained AI inventory is what makes the rest of governance possible.

Why it has to be continuous

A discovery done once is wrong within weeks. People keep adopting, vendors keep adding AI features, and the picture you captured last quarter no longer matches reality. Discovery is not a project you finish; it is a capability you keep running, which is the same reason AI governance only works when it is built on what people actually do, not what a policy assumes.

Frequently asked questions

How do I find all the AI tools used in my company?

Combine methods rather than relying on a survey: network and endpoint signals, OAuth and single-sign-on logs, expense review, and browser-extension audits, with a survey as a starting point. The aim is to catch embedded AI features and unsanctioned tools, not just the apps people happily declare.

Why is discovering AI tools so difficult?

Because much of it is embedded inside software you already use, adopted without procurement, or quietly used against a soft policy. People under-report it, and new tools appear constantly, so a one-off survey is stale almost immediately.

Is a one-time audit enough?

No. AI adoption is continuous, so a single audit captures a picture that is out of date within weeks. Discovery has to run continuously to stay accurate.

What do I do once I have found the tools?

Classify each by risk, decide which need oversight, and give people a fast safe path so they stop reaching for unsanctioned tools. Discovery is the foundation the rest of governance is built on.

Grasp discovers every AI tool in use across your organisation, including the embedded and unsanctioned ones, and keeps the picture current as new tools appear. See how Grasp finds your AI →