AI Assessment and Shadow AI Audit
We find the AI already in use across your organisation, classify each item as approved, restricted or not reviewed, and turn that into decisions you can evidence.
Find it, classify it, decide, then keep looking
In short: We inventory the AI in use across your organisation with EtherInsights: Microsoft Copilot, AI services in Azure, AI applications on devices, visits to AI websites and devices built to run AI locally. Each item is classified approved, restricted or not reviewed, and that becomes your policy, guardrails and evidence. Right for organisations whose clients, insurers or board have started asking what AI they use.
Microsoft's UK research found that 71% of UK employees have used unapproved consumer AI tools at work. That is rarely defiance. It is what people do when the work in front of them is tedious and nobody has offered an approved tool that helps.
Who this is for
The problem
Microsoft's UK research from October 2025, a Censuswide survey of 2,003 UK employees, found that 71% have used unapproved consumer AI tools at work and 51% do so weekly. The Work Trend Index 2024 found that 78% of AI users bring their own AI tools to work, rising to 80% at small and medium-sized companies. Each tool is somewhere company information may have gone with no contract, so when a client asks what AI touches their data, nobody can say.
What we would do
If AI is in use and nobody holds a list of it, start with an inventory, not a policy. A policy written blind either bans tools people rely on or approves things nobody has checked. Find it, classify it, offer approved options for what people genuinely need, then write the policy.
- If you are a ten-person firm with one approved AI tool and nothing else in use, a short AI use policy may be all you need.
- If your only question is whether Microsoft 365 Copilot is safe to switch on, start with our Copilot and AI adoption service instead.
- If you already review generative AI apps in Defender for Cloud Apps and keep a current policy, repeat sweeps may be enough.
When we are not the answer: If you want a report that says you are compliant with the EU AI Act or certified to ISO/IEC 42001, we are the wrong provider. We find and classify AI use and prepare evidence. Certification is issued by certification bodies, and no inventory makes anyone compliant.
We start by finding what is already there, in the five places AI shows up: Microsoft Copilot seats, agents and connectors; AI services deployed in Azure, including Microsoft Foundry resources and agents; AI applications on devices; devices reaching AI websites; and devices with NPU or GPU hardware or local model runtimes.
More on how we deliver our AI assessment and shadow AI audit
Each item is classified as approved, restricted or not reviewed. Then we help you decide which tools to offer properly, which guardrails to apply and what your AI use policy should say. The same inventory becomes evidence for client and insurer questionnaires, an AI risk register, EU AI Act scoping and ISO/IEC 42001 preparation. Sweeps repeat, because new AI keeps arriving.
The AI inventory and classification are delivered with EtherInsights from our partner EfficientEther, which keeps each finding on a timeline so repeat sweeps show what is new.
Systech is founder-led by Ryan Mangan, a Microsoft MVP for Azure Virtual Desktop and Windows 365, a Chartered Fellow of the BCS (FBCS) and author of Packt's two-edition Mastering Azure Virtual Desktop.
If you would rather take a first look yourself, our guide to finding shadow AI sets out four places to check in a morning.
Once the inventory exists, our guide to writing an AI use policy covers what makes people follow one.
Everything you need, managed for you
What is a shadow AI audit?
It is a structured answer to one question: what AI is in use across your organisation, by whom, and with what data? Shadow AI is the part nobody approved, such as a personal chatbot account, a browser extension or a note-taking app joined to client meetings.
It is almost always well intentioned. People use unapproved tools when no approved option is offered and the work in front of them is real. The risk is not the intent. It is that information has left your control without a contract, and the NCSC advises against including sensitive information in queries to public large language models. An audit replaces guesswork with a list you can act on.
Where do we look for AI?
Five places, because AI no longer lives only in a browser tab:
- Microsoft Copilot: who holds a seat, which agents have been published and to whom, and which connectors bring other data into reach
- Azure: AI services in your subscriptions, including Microsoft Foundry resources and agents, who owns them and what they can reach
- Devices: AI applications installed on laptops and desktops, such as assistants, note-takers and browser extensions
- The web: managed devices reaching AI websites, which shows the tools people use without installing anything
- Hardware: devices with an NPU or GPU, or with local model runtimes installed, which can run AI without any traffic to a cloud service
Copilot+ PCs carry NPUs capable of more than 40 trillion operations per second, so running AI locally is now an ordinary laptop feature rather than a specialist workstation. That is why the hardware view sits alongside the others: a local model leaves no web traffic to spot.
How is each item classified?
Every item lands in one of three states:
- Approved: reviewed, with a named owner, a stated purpose and data terms you are comfortable with
- Restricted: allowed only for named people, purposes or data, or blocked with an approved alternative offered
- Not reviewed: found, but nobody has decided yet, which is where most items start
Not reviewed is not an accusation. It is a queue. The aim is to move items out of it quickly, because a long not-reviewed list is the thing an auditor or client will reasonably question.
What happens after the inventory?
Decisions, in an order that keeps people working. First, offer approved tools for the jobs people already do with unapproved ones. A ban without an alternative tends to move use onto personal devices, where you can see none of it.
Then guardrails, matched to what you already hold:
- Defender for Cloud Apps, whose catalogue includes a Generative AI category covering more than a thousand apps, to mark them sanctioned or unsanctioned
- Microsoft Purview data security policies, with Purview Data Security Posture Management showing where sensitive data meets AI
- Copilot agent and connector settings, so every published agent has an owner, an audience and a review date
- An AI use policy short enough to read, naming approved tools and a route to request new ones
Where Purview is already in place, the newer Data Security Posture Management replaces the earlier DSPM for AI (classic), so we work with the current version rather than configuring the one being retired.
Does the EU AI Act apply to a UK business?
Sometimes, and it is worth knowing which side you are on. The EU AI Act, Regulation (EU) 2024/1689, can reach organisations outside the EU when they place AI systems on the EU market or when the output of their AI is used in the EU. It does not apply to every UK business simply because it uses AI.
The timetable has moved. The AI Omnibus entered into force on 27 July 2026, and obligations for Annex III high-risk systems now start on 2 December 2027. The AI literacy duty in Article 4 was softened to taking measures to support AI literacy, but it still applies to organisations in scope.
The UK has no AI Act of its own. Government policy rests on DSIT's five principles applied by existing regulators, and the ICO's guidance on AI and data protection applies wherever personal data is involved. In both cases, the inventory is the starting point.
Can this get us ready for ISO/IEC 42001?
It can get you prepared, which is not the same thing. ISO/IEC 42001:2023 is the certifiable management system standard for AI, and certification is issued by certification bodies after their own audit. Systech prepares organisations for that audit. We do not certify anyone.
An inventory, a classification, a policy and a risk register are early building blocks of an AI management system, because you cannot manage AI you have not found. ISO/IEC 42001 certification does not by itself make an organisation compliant with the EU AI Act either. They overlap, but one is a voluntary standard and the other is law.
What evidence do clients and insurers ask for?
The questions are converging on a short list:
- Which AI tools do you use, and which are approved?
- Does any of our data go into them, and on what terms?
- Who reviews AI output before it reaches us?
- How do you stop staff using tools you have not approved?
- When did you last check?
The classified inventory answers the first two with evidence rather than assurance. The policy, the guardrails and an AI risk register answer the next two, and dated repeat sweeps answer the last one.
Is this a one-off assessment or an ongoing service?
Either. Some organisations want one assessment, a classified inventory and a set of decisions, then run it themselves. Others keep us on for repeat sweeps, because new AI keeps arriving: a new Copilot agent, a new Azure deployment, a new AI feature switched on inside software you already own.
We scope each engagement first and then quote it, itemised, so you can see what each part covers and compare it line by line with anyone else's.
| Where AI shows up | What we check | Typical guardrail |
|---|---|---|
| Microsoft Copilot | Seats, published agents and their audiences, connectors | A named owner and audience for every agent, connectors reviewed, permissions tidied first |
| Azure | AI services, Microsoft Foundry resources and agents, their owners and data reach | Named owners, access reviewed, resources included in a regular review cycle |
| Device applications | Installed AI apps, assistants and browser extensions | An approved list, with unwanted apps removed through device management |
| AI websites | Managed devices reaching AI sites | Defender for Cloud Apps sanctioning and Purview data security policies |
| Local AI hardware | NPU or GPU devices and local model runtimes | A policy on which local models may run and what data they may use |
Questions we hear a lot
Will the assessment change anything?
No. The assessment reads inventory, configuration and usage signals and reports on them. Nothing is blocked, removed or reconfigured until you have seen the classified inventory and agreed what should change. We agree the read access the tooling needs with you first.
Can you find every AI tool in use?
No, and anyone who claims to is overselling. We cover the places most AI use leaves a trace: Copilot, Azure, managed devices and their web traffic, and local AI hardware and runtimes. Personal phones and home computers used for work sit outside that view, which is why an approved option people actually want does more than detection alone. We say plainly where the coverage stops.
Is this about catching individual staff?
No. The inventory is about tools and data, and findings are reported as patterns: which tools, how widely, and with what data risk. People use unapproved tools when no approved option is offered, so the answer is usually a better approved option rather than a disciplinary process. How you handle any individual case stays your decision.
Does the EU AI Act apply to us?
Not automatically. It can reach UK organisations that place AI systems on the EU market or whose AI output is used in the EU. The inventory shows which AI systems you run and how they are used, which is the information you need to answer that question, with legal advice where the answer matters.
Can you certify us to ISO/IEC 42001?
No. Certification is issued by certification bodies after their own audit. We help you prepare: the inventory, classification, policy, risk register and evidence that an AI management system is built on.
Does this depend on which Microsoft licences we have?
The inventory does not. Some guardrails do: Defender for Cloud Apps and parts of Microsoft Purview depend on your licence tier. The plan shows what your current licences already include, and where a guardrail needs a licence you do not have, it sets out the alternative so you can decide whether the upgrade is worth it.
Our AI assessment and shadow AI audit is delivered UK-wide from our office in Brough, East Yorkshire, with on-site support across the county where it helps. We work with businesses in Doncaster, Wakefield, Harrogate, Huddersfield, Scarborough and Bradford and 6 more Yorkshire towns and cities, and remotely with clients right across the UK.
Tell us what you need
A short call to talk through how your IT works today, what your team handles, and what you need from a provider. We will tell you plainly how we would approach it.
