Enterprise AI Measurement Guide
AI Governance · AI Tool Compliance
Top Unapproved AI Tools
Which unapproved AI tools should our IT and security teams focus on first, and how do we rank them by actual activity rather than just by number of accounts?
What it shows
The Top Unapproved AI Tools list ranks every unapproved tool in the environment by daily active users, showing which shadow AI tools have the most consistent, active usage rather than the most accounts (which may be dormant). DAU-ranked rather than total-users-ranked, this view surfaces the tools that are genuinely embedded in daily work, not just installed once.
Why it matters
Total user count and daily active users tell different stories about governance risk. A tool with 50 total users and 1 DAU is dormant. It shows up on the compliance list but represents minimal operational exposure. A tool with 5 total users and 4 DAU is a different risk profile entirely: a small team is using an unapproved tool intensively, which creates data exposure, policy, and potential regulatory risk even at low headcount. Ranking by DAU shifts the governance conversation from "how many tools are unapproved" to "which ones actually need our attention today."
The Larridin angle
Sorting unapproved tools by activity volume rather than user count reverses the expected governance priority list. Larridin customers regularly find that the highest-DAU unapproved tool is not the one that appears first on a user-count-sorted compliance report. A DAU-first view prevents the most active shadow AI from being buried in the long tail.
Related AI Governance Metrics
Common questions
Why is ranking unapproved AI tools by daily active users important?
Ranking by daily active users (DAU) highlights which unapproved AI tools are most embedded in daily operations, providing a clearer picture of actual usage and potential governance risks compared to merely counting total users.
How does the DAU ranking affect governance priorities?
A DAU-first approach shifts focus to tools with significant daily usage, ensuring that governance teams address those with the highest operational exposure and potential risk, rather than being misled by high total user counts that may include inactive accounts.
What additional context is needed beyond DAU to assess the risk of unapproved AI tools?
While DAU indicates active use, understanding the specific activities performed, the departments involved, and the nature of data handled is crucial for assessing the full risk profile, which can be explored using the Shadow Stack Table and Department Map.
How should governance teams respond to tools with similar DAU?
When multiple tools have similar DAU, governance teams should compare additional usage metrics and departmental context to prioritize actions, as DAU alone may not provide sufficient insight into the relative risk or importance of each tool.