Unsanctioned AI: How to Find It on Every Machine You Manage
Unsanctioned AI is any AI tool doing company work that nobody in charge of the company's machines approved: the chatbot tab, the coding agent installed from a terminal, the browser extension that reads every page. It is the reason a Samsung engineer's bug fix became a policy memo in 2023, and it is why IBM now counts it as its own line item in breach costs. Most guides tell you to write a policy and buy a monitoring product. This one starts on the machine, because that is where the tools live, and a policy cannot see a config file.
TL;DR
- Unsanctioned AI (also called shadow AI) is any AI app, extension, agent or API key used for work without IT approval.
- Shadow AI is growing fast. IBM's 2025 breach study put shadow AI involvement at 20%. The 2026 edition, published in July, reports 43%, with shadow AI breaches averaging $5.39 million.
- We swept one working developer Mac on 2026-10-03: the Applications folder showed three AI entries, and the full sweep found AI in four more places, including 116 MCP server entries across 71 config files.
- You will be able to run the same sweep on Windows, macOS or Linux in about ten minutes with the commands below, then keep the results from drifting with an application control baseline.
What is unsanctioned AI?
Unsanctioned AI is the use of an AI tool for work without the knowledge or approval of whoever manages security and IT. IBM defines shadow AI as the unsanctioned use of any AI tool or application by employees without formal approval or oversight from the IT department, and the two terms mean the same thing in practice. "Unsanctioned" is the more useful word for an admin, because it describes a status you can change: a tool moves from unsanctioned to sanctioned the moment someone reviews it, decides what data it may touch, and writes it down.
Definition: Unsanctioned AI
Any AI model, app, browser extension, coding agent, plugin or API key that processes company data without an approval on record. It differs from ordinary shadow IT in one way that matters: the tool does not only store your data, it reads it, reasons over it and, in the case of agents, acts on it.
The category is wider than the chatbot tab people picture. It includes desktop assistants, command-line coding agents, AI features switched on inside software you already approved, browser extensions that summarize the page you are reading, and the Model Context Protocol (MCP) servers that give an AI agent access to databases, files and other tools. Each one has a different footprint on the machine, which is why one kind of inventory never finds all of them.
How common is unsanctioned AI at work?
Common enough that the large surveys now treat it as a default condition. A Gartner survey of cybersecurity leaders in 2025 found that 69% have evidence or suspect that employees are using public generative AI at work, and Gartner predicts that by 2030 more than 40% of global organizations will suffer security and compliance incidents due to unauthorized AI tools, as reported by Infosecurity Magazine on 20 November 2025.
The cost side comes from IBM's Cost of a Data Breach Report, and two editions side by side tell the story better than either alone. The 2025 report studied 600 breached organizations (March 2024 to February 2025). The 2026 report, released on 29 July 2026, studied 602 (March 2025 to February 2026):
FindingIBM 2025IBM 2026 Shadow AI involvement20%43% Average cost of a breach involving shadow AI$4.63 million$5.39 million Global average cost of a breach$4.44 million$4.99 million (a record) Breached organizations without an AI governance policy63%68% Shadow AI incidents that compromised personal data65% (all breaches: 53%)not in the public summaries Shadow AI incidents that compromised intellectual property40% (all breaches: 33%)not in the public summariesIn one year the share more than doubled while governance went backwards: the slice of organizations with no AI policy grew. IBM's 2026 press release covers the headline numbers (the $4.99 million average, the 602 organizations, and one in four malicious breaches now being AI-enabled). The shadow AI rows come from the full report, and we checked them against two separate write-ups, Baker Donelson's and Insurance Portal's, which agree on every figure.
The best-known single case is still Samsung. In spring 2023, engineers pasted sensitive internal source code into ChatGPT while checking it for errors. At the end of April the company sent a memo restricting generative AI tools on company devices and networks. Bloomberg broke the story on 2 May 2023 (as carried by Forbes Australia). Nobody in that story was malicious. They were debugging, which is the most ordinary thing an engineer does all day.
What we found when we inventoried one Mac for unsanctioned AI
We ran an AI inventory on one working developer Mac and found AI in five places, only one of which an Applications-folder inventory would report. The Applications folder held three AI entries. The rest lived on the shell path, in browser profiles, in the shell environment and in project folders, where 71 MCP config files declared 116 server entries.
Method: one macOS 26.5 workstation used daily for web development, swept on 2026-10-03 with the stock commands in the next section (ls, command -v, env, find, grep, lsof). Counts only; no file contents, key values or browsing data were read. MCP configs were searched five levels below the home folder, excluding node_modules, vendor and ~/Library. One machine is a sample of one, so read the counts as a shape, not a rate.
ls /Applications ~/Applications | grep -icE 'chatgpt|claude|copilot|cursor|ollama|perplexity|gemini|codex'3 entries (two desktop AI apps and a URL handler for a coding agent)
Command-line agents on the PATHfor c in claude codex gemini ollama aider llm; do command -v "$c"; done3 AI agents
AI API keys in the shellenv | cut -d= -f1 | grep -E '(OPENAI|ANTHROPIC|GEMINI|GOOGLE)_API_KEY'1 key exported to every process the shell starts
Chrome extensionsfind ~/Library/Application\ Support/Google/Chrome -maxdepth 6 -path '*/Extensions/*/manifest.json'22 distinct extensions across 7 profiles; 3 are AI tools, and 2 of those 3 can read every site
MCP server configsfind ~ -maxdepth 5 \( -name .mcp.json -o -name mcp.json \) -not -path '*/node_modules/*'71 files in 47 project folders, 116 server entries, 8 distinct servers
Local listenerslsof -nP -iTCP -sTCP:LISTENNo local model server running at the time of the sweep
We expected the desktop apps to be the headline and the extensions to be a footnote. It went the other way. The two AI extensions with all-site access can read every page the browser opens, including the admin consoles and webmail tabs, and an app inventory never looks inside a browser profile. The MCP count surprised us more: 106 of the 116 entries name the same two servers, repeated project after project, which reads like a setup command run once per project rather than a person choosing a tool 116 times. Unsanctioned AI on a developer machine is often installed by other tooling, one scaffold at a time.
The extension risk is not hypothetical. In December 2025, researchers disclosed that the Urban VPN Proxy extension, installed by more than 8 million Chrome and Edge users, had been quietly collecting conversations from eight AI platforms, among them ChatGPT, Claude, Gemini and Copilot. The collecting code arrived in a silent auto-update in July 2025, so existing users never saw a new consent prompt, according to a Cloud Security Alliance research note. An extension you approved last year can become a different extension overnight.
For a business owner, the finding is this: when we checked our own machine, the list of installed apps showed one of the five places AI turned up, so an inventory that stops at installed software will tell you a much smaller story than the one on your staff's laptops.
Never print the key itself
Every key check in this article cuts the value off with cut -d= -f1 or counts with grep -c. Running env | grep API_KEY without the cut copies live credentials into your terminal scrollback, your shell history if you paste it, and any ticket you screenshot it into.
Where does unsanctioned AI hide on a machine?
Unsanctioned AI hides in five layers, and each layer needs its own check because each one is invisible to the tool that watches the layer above it. The table sets them side by side by what the tool can reach, which is the part that decides the risk.
LayerTypical exampleWhat it can reachSeen by an installed-apps inventory? Desktop appA chat assistant installed from a download page or app storeWhatever the user pastes or drags into it, plus any files or screens they grantYes Browser extensionAn AI sidebar or page summarizerEvery page on sites it has permission for; with all-site access, everything the user opensNo Command-line agentA coding agent installed with npm, pip or HomebrewThe working folder, the shell, and every credential the shell can readUsually no MCP server configA.mcp.json file in a project folderWhatever each listed server connects to: databases, file systems, browsers, APIsNo
API keyAn AI provider key exported in a shell profileBilling on the provider account, and a direct path for any script to send data outNo
Expert Tip: Count profiles before you count extensions
Chrome keeps a separate extension set per profile, and the machine we swept had seven of them. Run find ~/Library/Application\ Support/Google/Chrome -maxdepth 3 -type d -name Extensions | wc -l first. If the number is above one, an audit of the default profile alone has checked a fraction of the browser.
How to find unsanctioned AI on Windows, macOS and Linux
To find unsanctioned AI, check the same five layers on each operating system: installed apps, command-line agents, browser extensions, MCP configs and AI keys. We ran the macOS commands above on our own machine. The Windows and Linux versions below check the same layers with each platform's built-in tools; we did not run them for this article, so test them on one machine before you script them across every computer you manage.
Windows (PowerShell)
# Installed desktop apps, both registry hives and the 32-bit view
Get-ItemProperty 'HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\*','HKLM:\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*','HKCU:\Software\Microsoft\Windows\CurrentVersion\Uninstall\*' -ErrorAction SilentlyContinue |
Where-Object DisplayName -match 'ChatGPT|Claude|Copilot|Cursor|Ollama|LM Studio|Perplexity' |
Select-Object DisplayName, DisplayVersion
# Store apps for the signed-in user
Get-AppxPackage | Where-Object Name -match 'ChatGPT|Claude|Perplexity' | Select-Object Name, Version
# Chrome extensions with all-site access, every profile
Get-ChildItem "$env:LOCALAPPDATA\Google\Chrome\User Data\*\Extensions\*\*\manifest.json" |
Select-String -List '' | Measure-Object
# MCP configs in the user's folders
Get-ChildItem $HOME -Recurse -Depth 5 -Force -Include .mcp.json,mcp.json -ErrorAction SilentlyContinue |
Where-Object FullName -notmatch 'node_modules'
# AI key names (never values) in the user environment
[Environment]::GetEnvironmentVariables('User').Keys | Where-Object { $_ -match 'API_KEY' }
Linux
# Command-line agents on the PATH
for c in claude codex gemini ollama aider llm; do command -v "$c"; done
# Local model servers and anything else listening
ss -ltnp
# MCP configs under every home folder
find /home -maxdepth 6 \( -name .mcp.json -o -name mcp.json \) -not -path '*/node_modules/*' 2>/dev/null
# AI key names in shell profiles, file names only
grep -lE '(OPENAI|ANTHROPIC|GEMINI)_API_KEY' /home/*/.bashrc /home/*/.zshrc /home/*/.profile 2>/dev/null
Pro Tip: Save the counts with a date and diff them next month
Write each count to a file named for the day, for example ai-inventory-2026-10-03.txt, and keep it beside the machine's baseline. Next month, run the sweep again and diff the two files. A new line is a decision someone made without you, and catching it at month one is much cheaper than catching it in an incident report.
Should you ban unsanctioned AI or sanction it?
Sanction the tools people need and block the rest, because a blanket ban moves the use to personal phones and home laptops where you cannot see it at all. Samsung's 2023 response was a ban; the more durable pattern is the one Gartner now recommends, a written list of approved tools with regular audits against it.
"To address these risks, CIOs should define clear enterprise-wide policies for AI tool usage, conduct regular audits for shadow AI activity and incorporate GenAI risk evaluation into their SaaS assessment processes."
Arun Chandrasekaran, Distinguished VP Analyst, Gartner (via Infosecurity Magazine, November 2025)
For a small office, "sanction" can be one page. Name the approved assistant and the account type (a business plan with training on your data switched off, where the vendor offers that), list the kinds of data that may never be pasted in (client records, credentials, source code that is not yours to share), and say who approves a new tool. The approval step is the part that changes behavior, because it gives staff a yes path that is faster than going around you.
Expert Tip: Approve the agent and its config together
A coding agent is only as contained as the MCP servers it is given. When you approve one, approve its config file too, and keep a reviewed copy. A project that later grows a new server entry pointing at a production database has changed what the agent can do, even though the agent itself never changed.
How a baseline keeps unsanctioned AI from coming back
A hardening baseline turns the one-time sweep into a standing rule: only approved software runs, only approved extensions install, and drift shows up as a reportable change instead of a surprise. Three controls carry most of the weight.
- Application control. On Windows, Windows Defender Application Control decides which executables may run; on macOS, Santa does the same job with allow and block rules. Both can start in audit mode, which logs what would have been blocked, so the first week tells you which AI tools are in use before anything breaks.
- Browser extension allowlists. Chrome and Edge both accept managed policies (
ExtensionInstallBlocklistset to*, thenExtensionInstallAllowlistfor the approved IDs). That one change closes the layer our sweep found hardest to see. - Network and credential limits. Network restrictions keep a local model server from being reachable from the rest of the office, and least privilege keeps an agent running as a standard user from reading what an admin account can.
Pair those with a machine inventory that records installed software per device, and run the five-layer sweep monthly for the parts an inventory cannot see. If you are starting from scratch on Windows, the Windows 11 security baseline guide covers the policy groundwork these controls sit on.
Key Takeaways
- Sweep five layers, not one: apps, command-line agents, browser extensions, MCP configs and API keys each need their own command.
- Start with browser profiles: extensions with all-site access are the widest reach and the least visible, and they are one managed policy away from being under control.
- Treat MCP configs as permissions: review them when you approve an agent, and diff them monthly.
- Publish a yes path: an approved tool list with a named approver reduces workarounds more than a ban does.
- Enforce with the baseline: application control in audit mode first, then enforcement, so the inventory stays true after the sweep.
Frequently asked questions about unsanctioned AI
Is unsanctioned AI the same as shadow AI?Yes, in practice. Shadow AI is the more common search term; unsanctioned AI describes the same tools by their approval status, which is the thing an admin can change. Some teams use "unsanctioned" for tools nobody reviewed and "prohibited" for tools that were reviewed and refused.
They can be. When an approved product adds an AI feature that sends content to a new model or a new vendor, the data flow you approved has changed. Check the admin console of each approved product for AI settings after major updates, and decide on each feature the same way you would decide on a new tool.
It can block the well-known web chat domains, and that is worth doing for tools you have refused. It cannot see a local model running on the laptop, an extension that sends data through a domain you allow, or an API call from a script using an approved provider with a personal key. Network blocking works best as one layer beside application control.
A model running entirely on the device avoids the data-sharing risk, but it is still software processing company data without review. It also opens a network service on the machine, and if that service is set to listen on all interfaces instead of the local loopback address, anyone on the same network can reach it. Treat local models as sanctioned or not like any other tool, and check listeners with lsof, ss or Get-NetTCPConnection -State Listen.
Monthly is a workable rhythm for a small office: often enough that a new tool is caught within weeks, light enough that the sweep takes minutes per machine. Check again after any onboarding, because a new hire's first week is when personal tools arrive on company laptops.
Find it before it finds your data
Unsanctioned AI is already on most work machines, and the surveys agree on why: tools arrive faster than approvals. The fix is a sweep across all five layers, a short approved list with a named approver, and a baseline that enforces the list so the next sweep finds less. Our own Mac showed how far an app inventory falls short; the commands above close that gap for Windows laptops, Macs and Linux servers alike.
If you would rather see where your machines stand before you open a terminal, score your machines in two minutes and get the three biggest gaps with a published price to fix them, or talk to us about baselining your Windows laptops, Macs or Linux servers.
Fact-checked 2026-10-03: every figure was traced to the publisher's own release or confirmed by two independent reports. Sources: IBM, Cost of a Data Breach Report 2026 press release · Baker Donelson, ten takeaways from IBM's 2026 report · Insurance Portal on IBM's 2026 shadow AI findings, 11 August 2026 · IBM, Cost of a Data Breach Report 2025 press release · Cloud Security Alliance, AI browser extension attack surface, April 2026 ·Infosecurity Magazine on Gartner's shadow AI prediction, 20 November 2025 · Forbes Australia on Samsung's generative AI ban, 2 May 2023 · IBM, What is shadow AI?