How to Investigate Employee Use of AI Tools: Prompts, AI-Generated Content, and More
Most employees using AI at work are not doing anything malicious. They are trying to move faster, and they are reaching for whatever tool gets the job done. Microsoft and LinkedIn's 2024 Work Trend Index, based on a survey of 31,000 people across 31 countries, found that 78% of AI users bring their own AI tools to work rather than waiting for IT to sanction one. That convenience creates a problem the moment an investigation, audit, or legal matter requires reconstructing exactly what an employee did with AI, and most organizations have no repeatable way to answer that question.
A shadow AI employee investigation is the process of identifying, collecting, and analyzing an employee's use of unsanctioned or unmonitored AI tools, including the prompts they entered, the content those tools generated, and how that output was used in their work. Without a defined process for this, investigators are left piecing together fragments of evidence after the fact, often too late to prevent the underlying exposure.
Why Shadow AI Complicates Internal Investigations
Shadow AI is not a hypothetical risk. IBM's 2025 Cost of a Data Breach Report found that organizations with significant shadow AI usage paid substantially more per breach than those with controlled AI environments, largely because unmonitored tools create data exposure that goes undetected until an incident forces a review. Onna's overview of governance gaps in enterprise AI covers how these blind spots form in the first place, typically through a combination of unclear policy, unmanaged browser extensions, and AI features embedded inside everyday collaboration tools.
The legal stakes compound the problem. In February 2025, a federal court ruled that a defendant's conversations with an AI chatbot about his own legal defense were not protected by attorney-client or work product privilege, according to a legal alert from McCarter & English, and prosecutors were permitted to use those chat logs as evidence at trial. That ruling is a clear signal that AI conversations are treated as discoverable, reviewable records, not private scratch pads, once a matter is underway.
What to Look for When Investigating Employee AI Use
Prompts and Conversation History
The prompt itself often reveals intent and context that the output alone does not. Investigators need access to the full conversation thread, not just a final AI-generated document, to understand what was asked and why.
AI-Generated Content Embedded in Work Product
AI-generated text, code, or analysis frequently ends up embedded in reports, emails, or presentations without any label identifying it as AI-assisted. Onna's guide on how to identify AI-generated content in enterprise collections walks through the markers investigators can use to trace that content back to its source.
Metadata and Model Version
Timestamps, account identity, and the specific AI model or version used all matter for establishing a timeline and for assessing whether the tool in question was even sanctioned at the time of use.
Privilege and Legal Risk Considerations
As the McCarter & English case illustrates, employees sometimes treat AI chat windows as a confidential outlet, including for discussing legal strategy or workplace disputes. Investigators need to flag this risk early, since it directly affects what is discoverable and what may already have waived privilege.
A Step-by-Step Approach to Investigating AI Tool Use
- Inventory every AI tool in use, sanctioned and unsanctioned, including browser-based assistants and AI features built into existing SaaS platforms.
- Collect through enterprise compliance connections rather than manual export. Onna's ChatGPT and Google Gemini connectors pull full conversation history, attachments, and metadata through each platform's compliance API.
- Correlate prompts with the work product they produced, so the investigation can show not just that a tool was used, but how its output was applied.
- Document chain of custody for every collected record, including who collected it, when, and through which authorized connection.
- Assess the finding against policy, distinguishing between a genuine violation and an employee using an unsanctioned tool for a low-risk task.
Building AI Governance to Prevent Repeat Investigations
A single investigation should inform the policy that prevents the next one. Organizations that close the loop typically:
- Update AI usage policy to name specific tools, data types, and disclosure requirements rather than issuing a general prohibition.
- Extend legal hold language to explicitly cover AI prompts, outputs, and conversation history.
- Give compliance and IT visibility into AI tool usage on an ongoing basis, rather than only during an active investigation.
Getting ahead of shadow AI risk means the next investigation starts with existing visibility rather than a blind search.
If your organization needs a structured way to investigate employee AI tool use or close existing governance gaps, Onna's team can walk through the right approach for your environment. You can also see how collection and investigation support work in practice by requesting a demo.
Subscribe to our newsletter
Get Complete Visibility into Your Unstructured Data, Today
Complete initial setup and first collection in one business day. No lengthy implementations. No IT backlog. Just full visibility into your collaboration data when you need it most.

