30 Days Gen AI Risk Trial -Start Now
Skip to main content

Shadow AI Discovery

Build an AI inventory you can account for

Define the employee groups, covered devices and observation period behind your AI inventory. Use the baseline to assign the next review, with its gaps visible.

Illustrative baseline

Employee AI inventory

Population
Example team
Collection path
Installed browser client
Synthetic inventory observations for an illustrative team and browser scope.
AI toolSample signal
ChatGPTObserved
ClaudeObserved
GeminiNot observed

Review next: account, approved use and owner.

Observation is not enforcement.
Synthetic example, not live activity. No observed activity does not prove no AI use.

For IT and security owners who need a defensible starting inventory before setting policy. Observation requires the applicable Aona client on the devices in scope.

Evaluation workflow

Put the population behind the inventory

Agree which managed endpoints and employee groups are in scope. Review a synthetic inventory example, then identify the decisions the baseline can support: approved status, risk review, policy ownership, and a follow-up enforcement evaluation where appropriate.

  1. Define the baseline

    Record the intended employee population, deployed clients, observation dates and collection settings. Covered employees and active AI users are different counts.

  2. Review observed versus known

    Compare a synthetic inventory example with the difference between catalogued tools and activity observed on the deployed path.

  3. Route the next decision

    Assign approval or risk review owners, then identify which app actions need a separate enforcement test.

How to read a discovery baseline

  • Catalogued means a tool is known to the Aona catalogue; it does not prove employee use.
  • Observed use belongs to a stated period and deployed collection path. No observed activity does not establish that an employee used no AI.
  • Discovery is not the same as enforcement: an inventory should not be read as proof that every action is prevented.

Buying questions

Questions to resolve before a pilot

Does a 10,000+ tool catalogue mean every tool is discovered on our devices?
No. Catalogue recognition and observed usage are different states. Review the deployed collection path and scope before drawing that conclusion.
Can discovery enforce policy?
Discovery establishes a baseline. Enforcement must be evaluated separately for the application, action, and deployment route in scope.
What does the demo include?
A sample inventory, the fields a reviewer can assess, and an honest discussion of the deployment and privacy prerequisites.
What should an initial Shadow AI inventory record?
Start with tool name, observed period, covered group, approved status and review owner, where those fields are available. Record deployment coverage and known gaps alongside the inventory. Business purpose, approval and review ownership may need your team's input; telemetry alone does not establish them.

Review your AI visibility.

See how a scoped inventory is read, identify endpoint and privacy prerequisites, and decide what needs a separate enforcement evaluation.