Shadow AI Inventory
Discover and inventory every AI surface in your environment — sanctioned and unsanctioned — by observing network egress and identity traffic, so you can govern the AI you didn't know you had.
What it is
Shadow AI Inventory is the discovery surface that answers "what AI is actually running in my environment?" It correlates network egress (which destinations are receiving AI-shaped traffic) with identity telemetry (which humans and NHIs are calling them) to build a live inventory of AI usage — including the browser-AI, unsanctioned-API, and rouge-agent traffic that no one registered. Each discovered surface becomes a governable object you can route through a Guardian.
Why it matters
- You can't govern what you can't see. Most organizations undercount their AI surfaces by an order of magnitude. Shadow AI Inventory closes that gap.
- Discovery → governance in one step. A discovered surface can be immediately wired into Network-Layer DLP, the LLM Proxy, or the MCP Gateway.
- Identity-aware. Discovery isn't just "traffic to openai.com" — it's "this NHI in this workload is calling this model with this frequency," which is what you actually need to govern.
- Auditable. The inventory is a versioned, signed artifact — defensible to an auditor asking "do you know where your AI traffic goes?"
How it works
- Observe. Ingest network egress and identity (NHI) telemetry.
- Classify. Identify AI-shaped destinations and the identities calling them.
- Inventory. Build a live, versioned map of every AI surface, sanctioned and not.
- Route. Promote a discovered surface to a governed surface with one action.
Get started
- Connect your egress and NHI telemetry sources.
- Review the discovered inventory in the dashboard.
- Promote unsanctioned surfaces into a governance path.
→ NHI Federation — the identity side of discovery. → Network-Layer DLP — govern discovered browser-AI surfaces. → Observability — where the inventory lives.