← Back to library
Tighten operationsSecurityOpen4 min read · 30-minute inventory

Your Fastest AI Adopter Is Your Biggest Data Risk: The 30-Minute Super-User Inventory

Two research reports this summer point at the same person: the employee who uses AI the most has quietly wired tools into your business that nobody vetted. Here is the 30-minute inventory that finds them.


What's happening. Akamai's Enterprise AI Usage Risk Report, published August 5, found that nearly half of enterprise AI use bypasses corporate security entirely, and that the top 5% of AI users interact with models at 12 times the rate of the bottom half of the workforce. Those power users are the ones wiring AI into how the work actually gets done. The same report found 16.31% of AI browser extensions carry a known vulnerability, against 10.80% for browser extensions overall, and roughly 75% of AI extensions request high or critical permissions.

IBM's 2026 Cost of a Data Breach report, released July 29 and built on 602 organizations, put a price on the pattern. Shadow AI, meaning unapproved tools employees bring in on their own, now shows up in 43% of security incidents, more than double last year, at an average cost of $5.39 million. One in four malicious breaches was AI-enabled, up 56% year over year, averaging $6 million. And 68% of organizations said they have no governance in place to detect shadow AI at all.

The so-what for a 12-person company. Those dollar figures are enterprise numbers. Your version is smaller and much closer: the ops manager who found a niche AI tool that reads the shared inbox, pays for it on a personal card, and never mentioned it. That person is probably one of your best employees. Which is exactly why they have the most tools, the most access, and the most company data moving through accounts you have never seen.

The move: a 30-minute super-user inventory. Run it this week.

  1. Name them. Write down the one to three people in your company who use AI the most. You already know who they are.
  2. Ask for the full list, not the obvious one. Sit with each person for 10 minutes and ask: "Show me every AI tool you have used for work in the last 60 days." You are looking for the transcriber, the summarizer, the browser extension, the personal subscription, the automation nobody ever named.
  3. Three questions per tool. What data does it see? Whose account and whose card is it on? Can it act on its own, meaning send email, post publicly, move money, or write into a system of record?
  4. Sort into three piles. Turn off anything unvetted that can act on its own. Move anything genuinely useful onto a business account with training turned off. Leave the harmless ones alone and write them down so the list exists.
  5. Give them a fast lane. A super-user will route around a policy that takes two weeks. One rule covers it: new AI tool, ask me, I answer inside 24 hours.

What it's worth. Thirty minutes and one slightly awkward conversation, against a customer list sitting inside a tool you cannot name, cannot audit, and cannot cancel because it is on somebody else's credit card.

Example outputwhat you get back

Super-User Inventory: 11-person commercial cleaning company, run Aug 26

People named: office manager, lead estimator.

Tools surfaced: 9. Two were already known. Seven were not.

Turn off now (can act on its own):

  • Inbox assistant with send permission on the shared quotes@ address. Personal card, $29/mo. Drafts and sends without review.
  • Browser extension with read/write access on every page, including the payroll portal.

Move to a business account:

  • Meeting transcriber holding 14 months of client calls, including two pricing negotiations. Owned by the office manager's personal login. If she leaves, the archive leaves.
  • Proposal writer holding the full customer list.

Leave, but logged: three summarizers, no account data.

Unknown card total: $167/mo on two personal cards, none of it in the books.