AI Sec

Shadow AI: measure it before you try to block it

Unsanctioned AI usage is a data-egress problem with a productivity motive. Blocking first produces circumvention; measuring first produces a policy the business will actually follow.

Blog

August 15, 2026 · 9 min read

01

What discovery actually finds

Egress and identity telemetry reveal three populations: individuals using consumer assistants for work content, engineering teams calling model APIs directly with corporate credentials, and third-party SaaS features that forward customer data to a model provider under a subprocessor agreement nobody reviewed.

The third population is usually the largest data-protection exposure and the least visible, because the traffic goes to a vendor already on the allow list.

Endpoint Inventory reported by the EDR agents — where unsanctioned AI clients first become visible.
Endpoint Inventory reported by the EDR agents — where unsanctioned AI clients first become visible.
02

Classify the content, not just the destination

Destination-based policy produces a binary decision with no business context. Classifying submitted content — source code, customer records, financial data, health data — makes it possible to allow the majority of usage while stopping the specific categories that create regulatory liability.

  • Per-request classification of submitted content where inspection is lawful and configured
  • Identity and business-unit attribution for every session
  • Subprocessor mapping for SaaS features that forward data to model providers
03

Provide a sanctioned path before enforcing

Every enforcement program that lacks an approved alternative produces circumvention through personal devices, which removes visibility entirely. A sanctioned gateway with logging, retention control and data-residency guarantees converts shadow usage into governed usage.

Enforcement then targets a narrow, defensible set: unsanctioned destinations for classified data categories, with a self-service exception path and a published review time.

  • Sanctioned gateway with logging, retention and residency controls
  • Enforcement scoped to classified data categories, not to tools in general
  • Exception requests answered within a published service level
xFabric Research

Technical review with our engineering team

An architecture session against your real inventory of telemetry sources, workloads, APIs, models and identity surface. The first conversation is technical.

Request a technical review