Meta Pixel

Shadow AI, and how to see what your staff do with AI.

How to monitor how staff use ChatGPT and Claude without reading their prompts, where monitoring stops, and what actually makes shadow AI shrink. For businesses in New Zealand and Australia.

The short answer

Shadow AI is AI that staff use without the business's knowledge or governance, usually personal ChatGPT or Claude accounts fed with company data. It happens when the approved route is slower than the unapproved one, so monitoring alone does not fix it. What works is an approved AI tool good enough that people prefer it, clear rules on what data can go in, and usage data per person on that tool, so leadership can see who uses it, for what and at what cost without reading anyone's prompts. Sentry AI sets this up for businesses in New Zealand and Australia with the Sentry AIOS, which records usage per seat and never captures prompt text, answers or file contents.

Policy, controls, monitoring

AI governance comes in three levels, and each one answers a question the one before cannot. Most businesses stop at the first, which is why most do not know how their staff use AI.

01

Policy

What it is

Which AI tools are approved, and what data must never go into them.

Where it stops

Cannot tell you whether anyone follows it.

02

Controls

What it is

Company accounts, single sign-on, a register of every AI tool and agent, and human approval before AI acts in your systems.

Where it stops

Shows what is allowed, not what is used.

03

Usage monitoring

What it is

Who uses the approved AI, which models and tools, how much, and at what cost, per person and over time.

Where it stops

Covers the tools you provide, which is why levels one and two come first.

What we can see, and what we never capture

The line is drawn in code, not in a policy. Every usage record is reduced to a named list of fields before it is stored, so a field nobody has approved is dropped rather than kept by accident. That line is the reason teams agree to switch the data on.

What the Sentry AIOS records
  • Which people are active, on which seats, and when
  • Which models they use, and how many tokens
  • What that use costs, per person and per week
  • Which tools and skills they reach for, and which fail
  • Whether people accept or reject what the AI proposes
What it never captures
  • The text of any prompt
  • Any answer the AI gives
  • The contents of any file
  • What a tool was asked to do, or what it returned

Today that data comes from Claude, per person, on Claude Team and Enterprise seats using Cowork and Claude Code. The Sentry AIOS is built to take other vendors' agents the same way, but every organisation sending it live data right now runs Claude, so that is where our evidence is. MacroActive had its first usage data within the hour of install. If you are still choosing a plan, our Claude Team vs Enterprise comparison sets out which admin controls come with each.

What the first week usually shows

Not misuse. Uneven use. When Nature Baby switched its usage data on, eight of thirteen seats had been opened in the previous week and one person accounted for two thirds of the usage. Nobody was breaking a rule. Most roles had nothing built for their work, so they either used AI occasionally or used something else.

That is the real shadow AI risk in most businesses: not a rogue employee, but a team quietly using a personal account because the company one does not do their job. The fix is a Claude rollout with skills written for each role, and the usage data is how you see the unapproved route stop being worth it.

Where we stop

When you need someone other than us

  • You need to detect AI tools on staff devices or your network. That is data-loss prevention, browser and endpoint control, and it belongs with your IT or security provider. We do not read network traffic, and we work alongside whoever does.
  • You want to read what staff type into AI. We never capture prompts or answers, by design, so we are the wrong firm for that.
  • You are a small team with no customer data in AI yet. A one-page policy on approved tools and forbidden data is enough for now, and you can write it this afternoon.

Monitoring is one part of governance

Usage data answers who is using AI and how much. The rest of AI governance answers what is allowed to run and who can stop it: an agent register, human approval before AI acts in your systems, and a kill switch. Together they are what ISO/IEC 42001 asks a business to show. When the AI in question is agents rather than people, the same problem has a name of its own: agent sprawl.

Frequently asked questions

What is shadow AI?

Shadow AI is AI used inside a business without the business's knowledge or governance: personal ChatGPT or Claude accounts fed with company data, AI features switched on inside approved tools, or automations someone set up on their own. It is rarely malicious. It is what people do when the approved route is slower than the unapproved one.

Can we monitor how staff use ChatGPT or Claude without reading their prompts?

Yes. On the AI tools the business provides, usage data can show who is active, which models and tools they use, how much they use and what it costs, without storing a single prompt or answer. That is how the Sentry AIOS works: every record is reduced to a named list of fields before it is saved, and prompt text, answers, file contents and tool arguments are not on that list.

Does monitoring stop shadow AI?

Not on its own. Monitoring shows you what happens on the tools you provide. Shadow AI shrinks when those tools are good enough that people prefer them: a company account with the skills and connections for their job, clear rules about what data can go in, and a register of what is running. The usage data is how you find out whether that is working.

Can you detect AI tools staff use on their own accounts?

Not by reading network traffic or devices; that is the job of your IT or security provider's data-loss prevention, browser or endpoint controls, and we work alongside them. What we do is make the approved tool the one people choose, and measure its use per person, which is what shows whether the unapproved one is still needed.

Which AI tools report usage to the Sentry AIOS?

Claude today, per person, from Claude Team and Enterprise seats using Cowork and Claude Code. The AIOS is built to take other vendors' agents the same way, but every organisation sending it live data right now runs Claude, so that is where our evidence is. We will show you what your own vendor exposes before you commit to anything.

What does usage data usually show in the first week?

That use is uneven. When Nature Baby switched its usage data on, eight of thirteen seats had been opened in the previous week and one person accounted for two thirds of the usage. That is not a discipline problem. It shows which roles have nothing built for their work yet, which is where the first skills go.

Is an AI usage policy enough?

For a small team, a one-page policy on which tools are approved and what data must never go into them is a good start and may be all you need this year. It stops being enough once AI touches customer data or acts in your systems, because a policy cannot tell you whether anyone follows it.

Do you work in New Zealand and Australia?

Yes. Sentry AI is based in Auckland and sets up AI governance and usage monitoring for businesses across New Zealand and Australia, prepared against ISO/IEC 42001. We are not a certification body and do not certify anyone.

See how your team actually uses AI

In a short call we will show you what the usage data measures and what it would show for your business, before anything is switched on.

Ask an AI about this page

Opens the assistant with this page loaded: read it, summarise it, cite it.