> ## Documentation Index
> Fetch the complete documentation index at: https://docs.beyondguard.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Shadow AI: Discover Unauthorized AI Usage

> Detect third-party AI services used without IT approval by analyzing network traffic — logged, scored, filterable, and exportable — then bring that usage under policy.

Employees using third-party AI services — ChatGPT, Claude, Gemini, and others — without IT approval creates a data-leakage risk the organization can't see. The **Shadow AI** module is the discovery layer that makes that traffic visible by analyzing network activity.

## Traffic ingestion

Choose how Shadow AI observes traffic:

| Method | How it works |
| - | - |
| **HTTP Mirror** | Captures traffic via HTTP mirroring |
| **Kafka** | Consumes from a Kafka topic |
| **Database** | Periodically scans a database table |

Detection sensitivity is set with the **Confidence Threshold** (0.0–1.0): lowering it brings more traffic into scope as potential AI usage. The service can be started and stopped instantly with the **Running / Stop** controls.

## Detection logs

All detected AI traffic is recorded on the **Logs** screen, detailed per request. Each row includes:

* **Timestamp**
* **Target host** (for example, `chatgpt.com`)
* **Label** (for example, `CONFIRMED_LLM`)
* **Confidence** score
* **Provider**
* **HTTP Method**

Records can be filtered by host, label, provider, method, and date range, and exported as **CSV**.

## From invisible risk to managed risk

<Info>
  Shadow AI's output feeds directly into the [Multi-Policy](/platform/policies) module: once you know which user group the unsanctioned usage belongs to, you can define a dedicated policy for that group. Step by step, "invisible risk" becomes "managed risk."
</Info>

## Related

<CardGroup cols={2}>
  <Card title="Policies & Multi-Policy" icon="sliders" href="/platform/policies">
    Bring discovered usage under a group policy.
  </Card>

  <Card title="Logs & Telemetry" icon="file-lines" href="/platform/logs">
    The broader logging and SIEM pipeline.
  </Card>

  <Card title="Dashboard & Monitoring" icon="chart-line" href="/platform/dashboard">
    Track usage trends over time.
  </Card>

  <Card title="AI Risks Index" icon="bug" href="/resources/ai-risks-index">
    Why shadow AI is a governance risk.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.