Skip to main content
Employees using third-party AI services — ChatGPT, Claude, Gemini, and others — without IT approval creates a data-leakage risk the organization can’t see. The Shadow AI module is the discovery layer that makes that traffic visible by analyzing network activity.

Traffic ingestion

Choose how Shadow AI observes traffic: Detection sensitivity is set with the Confidence Threshold (0.0–1.0): lowering it brings more traffic into scope as potential AI usage. The service can be started and stopped instantly with the Running / Stop controls.

Detection logs

All detected AI traffic is recorded on the Logs screen, detailed per request. Each row includes:
  • Timestamp
  • Target host (for example, chatgpt.com)
  • Label (for example, CONFIRMED_LLM)
  • Confidence score
  • Provider
  • HTTP Method
Records can be filtered by host, label, provider, method, and date range, and exported as CSV.

From invisible risk to managed risk

Shadow AI’s output feeds directly into the Multi-Policy module: once you know which user group the unsanctioned usage belongs to, you can define a dedicated policy for that group. Step by step, “invisible risk” becomes “managed risk.”

Policies & Multi-Policy

Bring discovered usage under a group policy.

Logs & Telemetry

The broader logging and SIEM pipeline.

Dashboard & Monitoring

Track usage trends over time.

AI Risks Index

Why shadow AI is a governance risk.