<?xml version="1.0" encoding="UTF-8"?><oembed><type>video</type><version>1.0</version><html>&lt;iframe src=&quot;https://www.loom.com/embed/de0b8cc2c3ad47d7b5c2bd1a7525b3f1&quot; frameborder=&quot;0&quot; width=&quot;1280&quot; height=&quot;960&quot; webkitallowfullscreen mozallowfullscreen allowfullscreen&gt;&lt;/iframe&gt;</html><height>960</height><width>1280</width><provider_name>Loom</provider_name><provider_url>https://www.loom.com</provider_url><thumbnail_height>960</thumbnail_height><thumbnail_width>1280</thumbnail_width><thumbnail_url>https://cdn.loom.com/sessions/thumbnails/de0b8cc2c3ad47d7b5c2bd1a7525b3f1-ecf975eab18a0dc1.gif</thumbnail_url><duration>488.273</duration><title>Detect and Manage Shadow AI in Workspaces</title><description>This Loom explains an approach to detect and manage Shadow AI in a Google Workspace by using an AI coworker that reviews connected apps and access levels. The author notes that employees often sign up for many third-party AI tools independently, so IT and SecOps need control without simply blocking everything. In a demo run, the coworker scans 27 third-party apps, identifies 6 AI apps, and flags 5 at risk, including Shortwave with full mailbox access that could enable email compromise if compromised. It also generates an executive HTML report with user level findings and recommends reviewing business need rather than removing access immediately, citing examples like Lisa using Read AI, Fathom, and Fireflies and Luke using Shortwave and Otter.</description></oembed>