Ask an enterprise IT team how many AI tools their organization uses and you will usually get three answers. The one from the survey, which lists a dozen approved platforms. The one from the finance system, which shows forty recurring charges nobody remembers approving. And the one from the network, which shows a couple of hundred distinct AI services receiving traffic, several of them at three in the morning from a server nobody has logged into for months.
None of those answers is wrong. They are measurements taken with different instruments, and each instrument sees a different slice of the same estate. The gap between them is what security teams mean by shadow AI, and it has grown considerably harder to close since employees stopped merely pasting text into chatbots and started installing agents that hold credentials and act on their own.
Every Shadow AI Tool Leaves a Different Footprint
Discovery is a detection problem, and detection depends on evidence. Unsanctioned AI leaves seven kinds of trace, and no product currently reads all of them.
- Network egress. Traffic to a model provider or AI service, visible to anything inline on the path.
- OAuth grants. An AI tool connected to a corporate identity or SaaS account, recorded in the identity provider or the SaaS platform itself.
- Sign-up evidence. A verification email, a password reset, or an invoice showing an employee created an account with a work address.
- Browser activity. Extensions, tabs, and pasted content, visible only from inside the browser session.
- Local processes. A coding agent, desktop assistant, or MCP server running on a workstation, which may never touch a corporate network path.
- Spend records. Card charges, expense claims, and renewals, often the earliest evidence that something exists.
- Machine-to-machine connections. API keys, service accounts, and MCP servers wired into internal systems with no interactive user at all.
An organization that only inspects network traffic will build a confident inventory that omits every local agent. One that only reads spend will miss everything on a free tier, which is most of it.
The 7 Shadow AI Discovery Platforms
1. Dash Security
Dash reads the signal most other approaches cannot reach, which is what is running locally and what it is connected to. Its Agentic FootPrint discovery covers workstations, cloud environments, and networks, identifying more than 60 unique platforms alongside the supporting ecosystem of MCP servers, skills, plugins, models, tools, identities, applications, and data stores that shape how an agent behaves.
That ecosystem coverage is the meaningful difference. Most discovery products return a list of AI applications. Dash returns the agentic supply chain around them, which matters because an approved agent connected to an unvetted MCP server is a shadow AI problem wearing a sanctioned label, and no application inventory will describe it as one.
Discovery also feeds directly into the rest of the platform rather than ending in a spreadsheet. Findings flow into AI Governance, AI Security Posture Management, AI Detection and Response, AI DLP, and AI Spend, so an unknown agent becomes a profiled agent with an owner, a purpose, a permission set, and a policy. Its intent-based detection then evaluates whether sessions stay aligned with that purpose, and graduated enforcement covers informing a user, preventing an action, remediating an exposure, or inserting human approval inside a live session.
Deployment is agentless and modular, using a single sensor across Linux, macOS, and Windows, and organizations report moving from initial discovery to active enforcement in roughly a week. The founding team came from Palo Alto Networks, Akamai, and IBM, and the company is backed by YL Ventures, Wing, and Vesey Ventures.
Discovery signals it uses:
- Local processes and coding agents on developer workstations
- MCP servers, skills, plugins, and tools connected to agents
- Cloud-hosted and network-resident autonomous agents
- Identities, permissions, and data stores each agent can reach
2. Zscaler
Zscaler discovers AI usage from the traffic path. Because managed devices route through its cloud regardless of location, every request to an AI service is visible without anyone onboarding the service first, which is precisely the property shadow discovery requires.
The resulting inventory tends to be the broadest available for interactive AI usage. Security teams see which services are being used, by whom, how often, and what volume of data is moving, and they can apply policy immediately on the same path, whether that means blocking a category, restricting uploads, or steering users toward a sanctioned alternative.
Its data protection capabilities extend that visibility into content, identifying sensitive information heading toward an AI service before it leaves. For the workforce dimension of shadow AI, meaning employees using tools the organization never evaluated, this is a direct and mature control with a long operational track record behind it.
Discovery signals it uses:
- Inline network traffic from managed devices to AI services
- Volume, frequency, and user attribution per service
- Sensitive data detection in content sent to AI tools
- Policy enforcement applied on the same path as discovery
3. Microsoft Defender for Cloud Apps
Defender for Cloud Apps approaches shadow AI discovery as cloud application discovery, a discipline that predates the current wave by a decade. It analyzes traffic logs from firewalls and proxies against a large catalog of cloud services, producing an inventory of which applications are in use with a risk score attached to each.
Its second signal is more distinctive. By reading OAuth grants against corporate identities, it surfaces AI tools that employees have connected to company accounts, including permissions granted to read mail, files, or calendars. That class of finding is important because an OAuth-connected tool has standing access that persists whether or not anyone is actively using it.
Its catalog orientation means it recognizes what it has categorized. A newly launched AI service or a self-hosted model endpoint may appear as generic traffic rather than as an AI tool, and locally running agents remain outside its view entirely, since they authenticate to nothing and traverse nothing.
Discovery signals it uses:
- Firewall and proxy log analysis against a cloud application catalog
- OAuth grants connecting third-party AI tools to corporate identities
- Risk scoring per discovered application
- Session and access controls for sanctioned services
4. Nudge Security
Nudge Security built its discovery on an unusual and effective signal: the email trail that account creation leaves behind. Verification messages, welcome emails, invoices, and password resets reveal that an employee signed up for something with a corporate address, which is evidence that exists regardless of network, device, or whether the tool was ever used again.
That approach catches the long tail other methods miss. Free-tier accounts, trials, tools used entirely from a personal device, and services accessed once and forgotten all leave the same trace, and the record extends historically rather than beginning on the day the product was deployed.
The platform pairs discovery with lightweight engagement, prompting the employee directly to explain what a tool is used for or to migrate to an approved alternative. For enterprise IT teams facing hundreds of unsanctioned AI accounts, distributing that conversation is considerably more practical than centralizing it.
Discovery signals it uses:
- Email evidence of account creation, invoices, and password resets
- Historical discovery reaching back before deployment
- Identity and OAuth relationships between accounts and tools
- Automated outreach to the employee who created the account
5. Island
Island takes the position that most AI usage happens inside a browser, so the browser is where visibility belongs. Its enterprise browser sees the pages employees open, the extensions they install, and the content they paste, which is a level of detail no network-layer product can reconstruct from encrypted traffic.
That vantage point produces answers to questions other tools can only approximate. Which AI assistant is being used, what was actually submitted to it, whether source code or customer data was pasted into a prompt, and whether an extension is quietly reading page content are all directly observable rather than inferred.
Controls sit in the same place as the visibility. Copy, paste, upload, and download can be governed per site and per data type, which allows a workable middle position between banning a tool and permitting unrestricted use of it.
Discovery signals it uses:
- Browser sessions, visited AI services, and installed extensions
- Content pasted or uploaded into AI tools
- Per-site data movement controls
- User attribution tied to authenticated browser profiles
6. Zylo
Zylo approaches the problem from the ledger. Its SaaS management platform reads expense data, card transactions, contracts, and renewal records, which frequently makes finance the first system in the organization to know that an AI tool exists.
Spend evidence carries information the technical signals lack. It shows commitment rather than curiosity, reveals duplicate purchases across departments, and surfaces the renewal dates that give IT a natural moment to intervene. It also produces the number executives ask for first, which is what the unmanaged AI estate is costing.
For enterprise IT teams whose mandate includes rationalizing software spend, this is the discovery method that connects directly to a business case. Consolidating six departmental subscriptions to the same AI service is an easier conversation than an abstract argument about risk.
Discovery signals it uses:
- Expense reports, card transactions, and vendor invoices
- Contract and renewal records across departments
- Duplicate and overlapping subscription identification
- Cost attribution by team and business unit
7. Tenable
Tenable brings exposure management practice to shadow AI discovery, identifying AI software, libraries, and services present across the environment as part of the asset picture it already builds. Where other approaches ask what people are using, this one asks what is installed.
That distinction matters for infrastructure. AI frameworks and model runtimes deployed on servers, packages pulled into applications, and AI services enabled inside cloud accounts are all assets rather than user activity, and they frequently arrive through engineering channels that never touch a browser or an expense report.
Findings arrive in the same workflow as other exposure data, with associated vulnerabilities and misconfigurations attached, which suits organizations that would rather extend an existing programme than run a parallel AI-specific one.
Discovery signals it uses:
- AI software, libraries, and runtimes detected on hosts
- AI services enabled within cloud accounts
- Associated vulnerabilities and misconfigurations
- Integration with existing exposure management workflows
What Shadow AI Discovery Should Return, Beyond a Tool List
A list of application names is where discovery starts, not where it becomes useful. The fields that make an inventory actionable are consistent across organizations.
- An owner. A named person accountable for each tool or agent, since findings assigned to a distribution list are findings nobody resolves.
- A purpose. What the tool is used for, which determines whether its access is proportionate and whether a session later drifts from it.
- Access and permissions. Which systems, repositories, and data stores it can reach, and under whose identity it operates.
- Data exposure. What sensitive information has actually moved through it, as opposed to what theoretically could.
- Connected components. MCP servers, plugins, skills, and tools attached to it, because the agent is rarely the whole system.
- Cost. What it consumes, which converts a security conversation into a budget conversation and tends to accelerate decisions.
Discovery that produces these fields supports a policy decision. Discovery that produces a name and a timestamp produces a meeting.
Frequently Asked Questions
What is shadow AI?
Shadow AI is any AI tool, model, agent, or AI-enabled service used within an organization without security or IT approval. It spans chatbots and browser extensions at one end and autonomous agents holding credentials and taking actions at the other, which is why a single discovery method rarely covers it.
How is shadow AI different from shadow IT?
Shadow IT was mostly about where data was stored. Shadow AI adds two properties: data leaves the organization to be processed by a third party, and agents act on systems rather than merely holding files. An unapproved storage tool keeps a document, and an unapproved agent can change something.
Which shadow AI discovery method finds the most?
It depends on which population you are worried about. Network and browser methods find the most interactive employee usage, sign-up and spend evidence finds the long tail of accounts, and endpoint-level discovery finds locally running agents and MCP servers. Most enterprises need at least two of these.
Can shadow AI discovery run without agents on every device?
Yes. Several approaches derive findings from logs, email evidence, identity records, or financial data with nothing installed on the endpoint, and agentless sensor models cover local activity without a traditional endpoint rollout, which is usually what determines whether a deployment takes days or quarters.
How often should discovery run?
Continuously. A quarterly scan describes an estate that has already changed, since adopting a new AI tool takes minutes and requires no procurement. Point-in-time discovery is most useful as a baseline, and the operational value comes from noticing what appeared since yesterday.
What should happen immediately after discovery?
Triage by consequence rather than by count. Establish which findings hold credentials, reach production systems, or touch regulated data, and address those first. The remaining long tail is usually a governance and approval exercise rather than an incident, and treating it as an incident exhausts the team before the real risks are handled.
For broader context on how AI agents are reshaping enterprise security and IT governance in 2026, see our coverage of how AI tools are transforming enterprise security and operations.