Concepts

Shadow AI Discovery

Shadow AI discovery is the practice of identifying every unsanctioned AI tool, model, and prompt in use across an organization β€” including consumer ChatGPT, Claude, Gemini, Copilot, and embedded AI features in SaaS β€” and attributing each usage back to a named user, team, and business context.

Why shadow AI discovery matters

Most enterprises sanction one or two AI vendors and assume that defines their AI footprint. In practice, employees use dozens more β€” consumer chatbots, AI features embedded in SaaS, browser plugins, and personal API keys. Each one is a data-exfiltration vector that bypasses every existing governance control.

Shadow AI discovery closes this gap. Without it, audit trails are partial, DLP coverage is partial, and compliance attestations are partial. With it, security and compliance teams gain a complete inventory: what tools are used, by whom, how often, with what data, and at what cost.

Discovery methods

A complete shadow-AI discovery strategy combines three capture vectors:

Egress capture. A transparent network capture point β€” typically a PAC file, transparent HTTPS interception via corporate root CA, or an egress proxy β€” surfaces every AI request leaving the corporate network, regardless of which tool generated it.

Browser extension. A managed Chrome/Edge extension captures usage of consumer AI tools (ChatGPT, Claude, Gemini, Copilot) that originate inside the browser and never touch corporate egress (off-network users, BYOD devices).

SSO and SaaS signals. Identity provider logs and SaaS audit feeds reveal AI features adopted inside sanctioned apps.

What "discovered" actually means

A useful discovery output goes beyond a list of domains. It must surface: which user invoked which tool, the prompt and response payloads (with sensitive data redacted), the inferred business context, the token cost, and any DLP findings on the content. Without these dimensions, discovery is a dashboard that cannot drive action.

Frequently Asked Questions

What is shadow AI?

Shadow AI is any use of an AI model, agent, or assistant inside an organization that is not on the IT-sanctioned list β€” including consumer chatbots, embedded AI features in SaaS, browser plugins, and personal API keys.

How is shadow AI discovery different from CASB?

A traditional CASB surfaces which apps employees use; shadow AI discovery surfaces the prompts, responses, costs, and per-user attribution inside those apps, including the AI-native content layer that CASBs do not parse.

Can shadow AI discovery be done without an endpoint agent?

Partially. Egress capture covers on-network traffic without an endpoint agent. A browser extension is required to cover off-network and BYOD usage of consumer AI tools.