Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Shadow AI: Govern, Detect & Audit Unsanctioned AI Use
New
120 students

Shadow AI: Govern, Detect & Audit Unsanctioned AI Use

Find, govern and audit unsanctioned AI use with templates you can run on Monday
Last updated 8/2026
English
English [Auto],

What you'll learn

  • Define Shadow AI precisely and distinguish it from sanctioned AI and Shadow IT
  • Recognise embedded AI that arrives inside tools you already approved
  • Assess agentic AI risk using blast radius rather than intent
  • Discover Shadow AI across network, endpoint, SaaS, finance and human-source signals
  • Score and tier AI risks with a defensible five-dimension framework
  • Draft an AI acceptable use policy tied to your data classification scheme
  • Build a sanctioned-alternative programme that redirects demand instead of fighting it
  • Plan, execute and report a risk-based Shadow AI audit
  • Map controls to risks and expose the gaps nothing currently covers
  • Run a thirty-sixty-ninety day implementation roadmap end to end

Course content

8 sections32 lectures4h 13m total length
  • Welcome & Course Roadmap7:50
  • What is Shadow AI? Definition & Boundaries7:50
  • Embedded AI: The Blind Spot Inside Approved Tools7:32
  • Why Employees Bypass IT for AI Tools7:38
  • The Scale: Industry Data & Survey Evidence8:05
  • Meet NovaBridge: Our Running Case Study7:17
  • Section 1 Quiz: Foundations

Requirements

  • General familiarity with IT governance, risk or compliance concepts
  • No coding, data science or technical AI background required
  • Access to your own organisation policies is useful but not essential

Description

This course contains the use of artificial intelligence.

Every organization now runs on AI it never approved. Employees paste customer data into public chatbots, teams generate work with unvetted tools, and AI features switch themselves on inside software you approved years ago. This is Shadow AI, and it has become one of the fastest-growing governance gaps of the decade.

This course is a practical playbook for the people who are accountable for oversight. You will learn to find Shadow AI, assess it, govern it, and audit it, without stifling the productivity that drives adoption in the first place.

What makes this course different

  • It is deliverable-heavy. You leave with a discovery checklist, an AI tool inventory register, a risk register, an acceptable use policy, an intake and approval workflow, a control-to-risk mapping, and a complete audit program.

  • It covers the categories most courses miss entirely: embedded AI that arrives inside tools you already approved, and agentic AI that takes actions rather than producing drafts for review.

  • A full audit section is included, so the course serves internal, IT and external auditors directly, not only security teams.

  • Every concept is worked through NovaBridge Financial Services, a mid-market bank whose chief information security officer has ninety days to bring Shadow AI under control after a serious near-miss involving customer financial data.

How the course is structured

Thirty-two lectures across eight sections: Foundations, Data and Privacy Risks, Security Risks, Compliance and Intellectual Property, Detection and Discovery, Governance and Mitigation, Auditing Shadow AI, and a thirty-sixty-ninety day roadmap you can adapt directly to your own organisation.

The control language and structure map to the NIST AI Risk Management Framework, ISO/IEC 42001 and current AI regulation, so that you can defend your approach to regulators and to your audit committee.

By the final lecture you will have moved from understanding the problem to holding a defensible, executable programme.

Who this course is for:

  • CISOs, security leaders and risk managers
  • Internal, IT and external auditors adding AI to their scope
  • GRC, compliance and privacy professionals including DPOs
  • IT managers and enterprise architects
  • Executives and board members accountable for AI oversight