Tools · Hero

How to reduce AI tool sprawl

The useful detailsList every AI tool your team uses, including free accounts, browser add-ons and apps connected to work email or files. Note what each is for, what information goes in and who owns it. Then keep a short approved list, cut the overlap, and give people one simple way to ask for something new.

Make the list from people, not only from receipts

Invoices show what you pay for. They miss free accounts, personal subscriptions, browser extensions and AI features switched on inside software you already use. So ask two groups: whoever pays the bills, and the people doing the work. An anonymous question works best: "Which AI tools have you used for work in the last month, including free ones?"

Free downloadSetting rules for your team? Start from the free one-page AI use policy template.

Where to look for connected apps

Apps connected to work accounts can read far more than a single chat. Ask your administrator to check:

  • Microsoft 365: the Microsoft Entra admin center, under Enterprise applications, lists apps people have signed in to or granted access with their work account.
  • Google Workspace: the Admin console, under Security, then Access and data control, then API controls, shows third-party apps with access to your domain's data.
  • Individual Google accounts: each person can check Security, then "Your connections to third-party apps and services", in their Google Account.
  • Chat and file tools (Slack, Teams, Dropbox and similar): the admin settings list installed apps and integrations.
  • Browsers: each person's extensions page. AI writing helpers and "summarize this page" add-ons often read everything on screen.
  • AI tools themselves: the settings, usually under apps or connectors, show what a ChatGPT, Copilot or Gemini account can reach.

Menu names change from time to time. If you can't find these, search the vendor's help centre for "third-party app access".

An inventory you can copy

Tool and planWho holds the loginUsed by, for whatInformation that goes inCost and renewalStatusOwner
Example: Copilot Chat, work accountsIT adminEveryone, drafting and summariesInternal documents; no red-list dataIncluded in Microsoft 365ApprovedOffice manager
Example: free AI websitePersonal accountTwo people, rewording client emailsClient names and detailsFreeStopOffice manager
Example: meeting note-taker add-onOne manager, personal sign-upTeam meetingsEverything said in meetingsMonthly card chargeReviewOffice manager

The examples are illustrative. Use one row per tool and per plan: a personal and a business account of the same brand are different rows.

A next stepNot sure what your team already puts into AI tools? An AI security assessment finds out. Start with a free 30-minute call.

Sort the list

Put every row into one of five groups:

  • Core: the approved tool most people use. Usually one.
  • Specialist: a tool a few people need for a specific job, with a named owner.
  • Experiment: allowed for a set period with an end date. An experiment with no end date becomes clutter.
  • Duplicate: does what a core tool already does. Plan to move people off it.
  • Remove: risky, unexplained or unowned. Especially anything personal that handles client or employee information.

One door for new requests

Give people one short way to ask for a new tool: what task, who will use it, what information goes in, and how they do it today. Low-risk requests should get a quick answer. Anything touching client, employee or health information gets a slower, careful yes or no. If requests vanish into silence, people go back to personal accounts.

If you remove a tool, say what replaces the work

Cancelling a subscription while the team still depends on it just moves the work to someone's personal account. For every tool you remove, name the approved way to do that job, and show people how before the old one goes.

Related: What information should not go into AI · AI use policy template · AI security assessment

A CLEAR NEXT STEP STARTS HERE

Find out what your team already puts into AI.

A free 30-minute call is the start. We’ll tell you honestly whether an AI security assessment, training, or a one-page policy is the right first step.

Free 30-minute call with our founder · Video call, camera optional