An employee wants a meeting summarized, an email drafted, or a calendar managed. There's an extension for that, free to install in the browser, with a few clicks giving access to the mailbox. The extension doesn't ask IT whether this is allowed. It asks the employee whether he wants to grant access, and most people click accept without reading the permissions. With that, a piece of external software gains read access to correspondence, attachments, and contact details, entirely outside the organization's view.
This is not an exception. It is the ordinary way AI enters an organization: not through a project with a sponsor and a budget, but through an individual choice to make a task easier. The extension is not on an IT list, because IT did not install it. It is not in a risk register, because no one reported it. It works, and for the user that's reason enough to keep clicking.
An overview of approved software says something about what has been requested and permitted. It says nothing about what is actually being used. Between those two lies a gap that grows as AI tools become easier to install and less visible in operation. An extension in the browser leaves no trace on the network the way a new application would. It runs along within a session that otherwise looks perfectly normal.
What this produces is not a single data breach, but a scattered pattern: here an extension with mail access, there a free chat window where company data gets pasted in, somewhere else a department that has taken out its own subscription on its own initiative. Separate decisions, made with no ill intent, that together form a shadow layer of AI use the organization cannot oversee because it never asked about it.
A ban on extensions with mail access sounds like a solution, but a ban nobody enforces is a rule on paper. The employee who used the extension did so because it made the work go faster. That problem still exists after the ban. He may remove the extension, or he may leave it in place and simply stop mentioning it. Both outcomes are worse than what you had before the ban: at least before, you knew the extension existed; now you either don't know anymore, or the reason it existed remains unresolved.
The only way to know what is actually running is to ask. Not as a control measure, but as an inventory. Anyone afraid of being punished will not answer honestly, or will not answer at all. That makes how you ask just as important as the question itself. This pattern, and how an organization can address it without a witch hunt, is described on the page about what you do about employees using a tool nobody approved.
As long as an extension with mail access stays out of sight, there is also no oversight of what it does with the data it processes. Not because nobody wants to arrange that, but because oversight can only exist for something that is known. For tools that are known, the question of what oversight means in practice is already difficult enough: who reviews it, how often, and what happens with a deviation. That question is addressed on the page about what human oversight means in practice. For an extension nobody has reported, the answer to that question is: nothing yet, because the first step, knowing it exists, has not yet taken place.
The same pattern of something arising alongside the existing structure, instead of being incorporated into it, plays out on a larger scale when a supplier builds AI into its product without this being reflected in the contract or the risk assessment; how that appears and why it slips past existing agreements is described under what you do about a supplier that has built AI into its product. And if a process has indeed been set up to report this kind of use, but that process gets ignored because it sits alongside the existing work instead of within it, that is a recognizable pattern worked out on the page about why a second process alongside the existing one gets ignored.
An inventory of extensions, subscriptions, and tools that nobody approved shows where AI is already running alongside the work. That information naturally raises a follow-up question: if someone has already entrusted part of his tasks to AI, exactly which part of that work is it, and how does that relate to what is possible or desirable for the rest of the organization? The work scan from FTE TO AI calculates per task which part of the work can be taken over by AI, providing a numerical reference point alongside the governance picture an inventory produces.
Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.