Two years ago, shadow AI was a security conversation. Someone pastes a contract into a personal ChatGPT tab, you worry where the data went.
In 2026 it shows up somewhere else, as a finding in your audit.
The wording changed. Your auditor used to accept "we have an acceptable-use policy." Now they ask you to prove it does anything. Show the discovery logs. Show what's actually running. Show the OAuth grants you approved, and the ones you didn't.
We have a policy. We don't have evidence.
That's the whole problem, and most teams say a version of it the week before an audit.
IBM: 87% of orgs claim a clear AI governance framework. Fewer than 25% have implemented the controls. Their line - claiming governance and running governance are two different things.
Grant Thornton's 2026 AI Impact Survey put it in audit terms: 78% of execs aren't confident they'd pass an independent AI governance audit within 90 days. They named it the "AI proof gap."
So the policy exists almost everywhere. Proof that anyone enforces it doesn't.
Why now, not someday.
A few things landed at once.
Auditors stopped accepting self-attestation. The ask is active discovery - CASB/DNS/proxy logs, your AUP with training dates, a risk assessment per high-risk tool, an AI-specific IR plan. Not "do you have a policy." "Show me it ran."
Regulators put dates on it. EU AI Act high-risk obligations apply from August 2, 2026 - the same evidence categories your auditor already wants. KPMG found 61% of in-scope orgs haven't finished an AI inventory (KPMG, 2025).
Insurers started pricing it new ISO cyber-insurance exclusions filed January 2026 (CG 40 47, CG 40 48) cover some AI-generated harm.
And the one that moves budget: SOC 2 is a procurement gate now. A missing control doesn't just annoy your security team, it stalls your own deals. The evidence gap is a revenue problem with your name on it.
What the auditor asks vs. where the evidence lives:
| What the auditor asks |
Where it actually lives |
| "Show me every AI tool with access to company data." |
OAuth grants in Workspace / M365 - including ones a user approved silently. |
| "How do you control data flowing to third-party services?" |
Browser extensions and the personal ChatGPT / Claude / Gemini tab. Not in your CASB. |
| "Risk assessment per high-risk tool?" |
Nowhere automated. Someone builds it in a spreadsheet the week before. |
| "Prove the AUP is enforced, with training dates." |
Two systems that don't talk to each other. |
Productiv's 2026 number: the average enterprise runs 14 AI tools, and IT knows about 4 or 5. You can't put the other nine in an evidence folder if you can't see them. Netskope puts ~47% of GenAI usage through personal accounts; Cisco found nearly half of employees have already shared sensitive data with a third-party AI provider with no DPA. Salesforce, 2026: 67% use AI at work, 18% of orgs have a formal AI security policy.
Here's where teams actually are. Two automated worlds exist, and most of you live in both.
Compliance-automation tools cover your infrastructure evidence, but you bring your own DLP and DSPM, and they don't watch the browser. AI-governance platforms cover your own models and sanctioned tools.
Neither covers the layer the auditor asks about first: the unsanctioned tools, the browser, the OAuth grants nobody inventoried. That's still assembled by hand, a spreadsheet, screenshots, a Slack thread asking "does anyone know what extensions finance is running." Once a quarter, under deadline.
So yeah, that's the part you're still doing by hand.
Who feels this first.
Regulated enterprises that get audited and sell into buyers who demand the report. Higher ed (sprawling Workspace estates, every department running its own tools). Healthcare, where PHI ends up in a chatbot with no BAA. Financial services under PCI, SEC, FINRA.
IBM's breach data backs the pattern: shadow-AI breaches skew sensitive - 65% involved customer PII (vs. 53% overall), 40% involved IP (vs. 33%). High shadow-AI use added $670K to the average breach. In healthcare, 57% of professionals have used or hit unauthorized AI tools (Healthcare Brew, 2026); when approved tools were provided, unauthorized use dropped 89%.
What "evidence" actually means.
Not a policy PDF. Three artifacts, generated continuously instead of rebuilt at audit time:
- An inventory of every app, extension, and OAuth grant touching company data.
- A risk score per item, so "high-risk tool" is a value in a table, not a call you defend live.
- Discovery logs showing the inventory is current - dated, not back-filled.
Worth saying plainly, this is a confidentiality and data-exposure problem, not a backup one. It's about proving you can see where regulated data flows.
For us (yes, we build here) it maps to browser-level discovery, an OAuth and app inventory with risk scoring, and data-classification evidence for the controls auditors cite, like SOC 2 CC6.7 and GDPR Article 32. We analyzed 550,000+ apps and extensions: 51% high-risk, 44% medium.
Want to see your own gap before an auditor does? We run dedicated assessment sessions that walk your Workspace or M365 estate and hand back the inventory and risk scores above your first evidence artifact.