Skip to main content

Shadow AI Detection

Shadow AI Detection helps MSPs discover and govern unauthorized or unvetted AI services in use within client organizations. As AI tools proliferate, employees routinely adopt AI assistants, code generators, and data analysis tools without IT approval — creating data exposure and compliance risks.

How Shadow AI Works

The Shadow AI module provides a registry of AI service discoveries. Discoveries can be submitted manually by analysts or by integrations that detect AI service usage in network traffic or browser activity.

Navigate to SecOps → Shadow AI Discovery.

Summary Metrics

MetricDescription
Total DiscoveriesAll AI services identified
High/Critical RiskServices classified as high or critical risk
By CategoryBreakdown by AI service type
By Risk LevelBreakdown by severity

Service Categories

CategoryExamples
ChatbotChatGPT, Claude, Gemini, Copilot
Code GenerationGitHub Copilot, Cursor, Codeium
Image GenerationMidjourney, DALL-E, Stable Diffusion
Data AnalysisJulius AI, ChatCSV, OpenAI Assistants with file uploads
CustomAny other AI service

Risk Classification

Risk LevelCriteria
CriticalCan process regulated data (PHI, PCI, PII); no enterprise agreement; no data processing agreement
HighRetains user data for training; limited privacy controls; no BAA available
MediumConsumer tier of an enterprise product; data retention unclear
LowEnterprise-tier with DPA/BAA; data not used for training

Discovery Workflow

Reporting a Service

Click Report Service to manually add a discovery:

FieldRequiredDescription
Service NameYesName of the AI service (e.g., "ChatGPT", "Midjourney")
URLNoService URL for reference
CategoryYesService type (chatbot, code_gen, etc.)
Risk LevelYesInitial risk assessment
NotesNoContext about how it was discovered or used

Review and Decision

Newly reported services land in Discovered status. Move them through the review workflow:

StatusDescription
DiscoveredNewly identified, not yet reviewed
Under ReviewAnalyst is evaluating the service
ApprovedService approved for use (possibly with conditions)
BlockedService blocked; users should not use it

Approve — marks the service as approved (with conditions if needed). Users can continue using it.

Block — marks the service as blocked with a policy violation reason. This creates a record for policy enforcement conversations.

Filtering

Filter the discovery list by Risk Level, Status, or Category to focus on what needs immediate action (e.g., all Critical discoveries in Discovered status).

ℹ️The One Security records and tracks Shadow AI discoveries but does not automatically enforce blocks at the network level. Use your DNS filtering or network security tools to technically enforce AI service blocks where required.