See Which Known AI-Service Websites Appear in Your Chrome Profile
A Chrome extension that checks the browsing history available to your Chrome profile against a reviewed list of 60 AI services, and produces a Shadow AI Scan Preliminary Report you can read, print, and take to a leadership conversation.
It runs entirely inside your browser. Priority Governance does not receive, store, or transmit your browsing history or your scan results.
A Starting Point, Not a Verdict
Most organizations cannot answer a simple question: which AI services may be showing up in everyday work? This scan offers one narrow way to identify services worth asking about without treating browser history as proof of actual use.
1. You Choose a Period
30 days, 90 days, 6 months, or 12 months. Nothing is read until you pick one and click the button.
2. It Matches Locally
Chrome returns the history entries for the period you chose, and the extension compares each hostname — and where needed, the path — against the reviewed list inside your browser. Query strings and fragments are not used. Anything that does not match is discarded during processing and is never shown, stored, or sent anywhere.
3. You Get a Report
Which services appeared, when they were last seen, what each vendor documents its service can do, and what to verify next — plus a 30-day plan with nothing to buy.
Browser History Proves One Thing
A detection means a web address appeared in the history available to your Chrome profile. That is all it means. It does not mean the service was used, logged into, given a file, given a prompt, or connected to anything.
Detected
A web address matching a reviewed rule appeared in the history available to the Chrome profile. This is the only thing the scan establishes on its own.
Capability
A dated source from the service's own documentation says the service offers a particular capability. It does not mean the capability was used.
Confirmed
A person or an authorized administrator verified what actually happened — the account, the data, the settings. The free scan cannot reach this level.
Unknown
The scan cannot determine it. Most facts about vendor terms, retention and account type sit here until someone checks.
The report describes how much appeared as Limited, Moderate, or Broad, and prints the exact counting rule beside the label: Counting distinct services only, once each, however many times they appear: 0 = No detections; 1–2 = Limited; 3–6 = Moderate; 7 or more = Broad. That is a description of browser activity — not a risk score, a compliance conclusion, or a rating of your organization.
Your Scan Data Stays in the Browser
This is an architectural property of the scan path: the extension processes the selected Chrome-profile history locally, has no scan-data backend, initiates no background network requests, and sends no scan-derived data to Priority Governance or any third party.
No Background Network Calls
The extension initiates no analytics, telemetry, API, synchronization, or other background request. The detection list ships inside it. The only network activity it can cause is one you trigger: clicking the resources link opens a fixed address carrying a generic source tag and nothing from your scan.
No Storage, No Account
Results exist in the extension page’s memory only unless you choose to print or save them. There is no sign-up or account, and the extension does not transmit your browsing history, scan results, or scan-derived identifiers to Priority Governance. If you choose the resources link, the website receives only the generic source tag described below.
Permission Is Optional
Installing grants nothing. Chrome asks for history access only when you click the scan button, and the report includes a button to remove that permission when you are finished.
Reasons You Might Reasonably Say No
A tool that asks for your browsing history should be able to make the case against itself. Here is ours.
It is a broad permission, and Chrome says so
Chrome's prompt says the extension could read and change your browsing history on all your signed-in devices. That is Chrome describing the permission in general — this extension only reads, and only for the scan you start — but granting it still authorizes access to the history available to that Chrome profile. If that makes you uncomfortable, do not grant it.
The browser may not be yours to decide about
On a work-managed browser, running a scan may be your employer's call rather than yours. Ask first if you are unsure.
Your history is personal as well as professional
A Chrome profile may contain both personal and work-related browsing activity. The extension discards non-matching entries during local processing and does not display unrelated addresses, but declining the permission is reasonable if you do not want the extension to access that mixed history.
The answer may not be worth it to you
The scan produces a starting point for an inventory conversation, not a finding you can act on directly. If you already know which AI tools your team uses, it will not tell you much.
If you decline the Chrome permission, nothing is read and no report is produced. There is no fallback, no second prompt, and no reduced version that collects something else instead.
What the Scan Cannot See
This list is long on purpose. A short result does not mean there is little AI use, and a long one does not mean there is a problem.
- History that was cleared, or activity in Incognito windows.
- Other Chrome profiles, other browsers, and anyone else's computer.
- Desktop applications and mobile apps, including the mobile versions of the services on the list.
- AI features built into tools you already use — the assistant inside a document editor, email client or meeting platform usually leaves no separate web address behind.
- Anything a browser extension does, including AI extensions that work on every page without you visiting the vendor's site.
- Whether an account exists, who it belongs to, whether it is personal or organizational, and what was agreed to.
- Prompts, uploads, downloads, integrations, connected credentials, and vendor retention terms.
- A service you are not signed in to. Some products redirect a signed-out visitor to their marketing homepage, which this scan deliberately does not count as evidence of the product.
- Any AI service that is not on the reviewed list.
One example worth understanding: some AI tools work mainly through a browser extension that acts on every page without you ever visiting the vendor’s website. Heavy use of a tool like that can produce almost no history entries at all.
Availability
The extension is not yet published. It is built and tested, and the Chrome Web Store listing has not been submitted, so there is nothing to install today. We would rather say that plainly than point you at a link that does not work.
Detection list v0.5.0, updated 2026-08-21 — 60 services checked. Every service on the list carries a capability statement taken from that vendor’s own site on a recorded date. Service and product names are the trademarks of their respective owners and are used only to identify the services the scan can recognize; no affiliation or endorsement is implied.
Frequently Asked
- Does Priority Governance See My Results?
- No. The extension does not receive, store, or transmit your browsing history or your scan results. It makes no background network requests and never sends scan-derived data off the device. If you follow the resources link from the report to this website, the link carries only a generic source tag — never a service name, count, date, or identifier from the scan.
- Will This Tell Me Who Used What?
- No, and it is not designed to. It reads one browser profile and reports services, never people. If you want an inventory, the fastest route is still to ask your team directly — the report gives you a concrete list to ask about.
- Is This a Security or Compliance Tool?
- No. It is not legal advice, not a security assessment, and not a compliance certification. It does not verify vendor terms, prove what data was shared, or establish whether any policy was followed. Findings are directional and are meant to help you decide what to check next.
- Why is the list only 60 services?
- Because every service on it has a capability statement sourced from that vendor’s own site on a recorded date, and a match rule tested against lookalike domains. A longer list built on unverified entries would produce findings you could not act on. The list grows as records pass review.
- What If It Finds Nothing?
- That is a real result, and a narrow one. It means nothing on the reviewed list appeared in that profile during that period. Given everything the scan cannot see, it is not evidence that no AI is in use.
- Can I Share This with a Client?
- Yes. It is free, there is no lead capture inside the extension, and no browsing history or scan result is sent to Priority Governance. Advisors and managed service providers are welcome to pass it on.
Not legal advice, not a security assessment, and not a compliance certification. See the extension privacy notice, our data handling, privacy policy, and terms.