SeeShadow AIx, found

Shadow AI: find what nobody approved, then decide once.

Gateway traffic, log collectors and a browser sensor find the AI people use; one decision becomes a standing rule.

How it works

Specs

Shadow AI, in detail

Delivery and data

Delivery
SaaS, from one login.
Isolation
Each customer runs in an isolated workspace with its own database.
Certifications
None held. Frameworks are mapped to and assessed against.

Frameworks

NIST AI RMF
Mapped to: Inventory under Map and Govern.
ISO/IEC 42001
Mapped to: The same inventory control, with evidence.
EU AI Act
Mapped to: An owned inventory of AI, cross-mapped.
See the frameworks

Last reviewed 6 Oct 2026

Found, then matchedIllustrative

Found, then matched: traffic to your approvals; collectors to your approvals; sensor to your approvals; your approvals found calling chat tool (bypass); your approvals held for a person before plugin (undecided); your approvals to provider A (approved).

In shortShadow AIShadow AI is AI used in an organisation without approval from its security and data teams: a chat assistant on a personal account, a browser extension that summarises pages, or a model running on a laptop. The risk is not the tool itself but the path: data leaves through a route nobody reviewed or recorded. In the glossary

Shadow AI detection in ColossalX finds the AI tools, services and agents your people use that nobody approved, from gateway traffic, 13 collector types and a browser sensor that never reads prompts. Each is matched against what you already approved and assessed, and one decision becomes a standing rule that defaults to monitor, never allow.

A team pastes client data into a web chat tool that nobody has ever assessed.

ColossalX finds the tool, shows it went around your approved provider, and a person sets a standing rule.

How it works

From a log line to a standing rule, decided once.

A proxy log pushed to ColossalX shows a web chat tool in use. It is matched, decided by a named person, and carried out where ColossalX can.

Workflow · a web chat tool, from log line to ruleIllustrative

01 Pushed in

A proxy collector pushes a sighting, without the raw log line.

02 Matched

Its provider is approved at the gateway, but this traffic went around.

03 Allowed until a date

A named person allows it until a date, with a reason.

04 Rule, honestly enforced

Real at the gateway; elsewhere a blocklist export, labelled recorded intent.

What you see

Each finding, matched to what you approved.

Each AI service found in use is checked against the providers approved at the gateway and the apps you assessed, with the people and requests behind it.

  1. Found without setup
  2. Collected where people work
  3. Matched to approvals
  4. Decided once
Read the detail, step by step4
  1. Found without setup. Gateway traffic is scanned for AI nobody registered, with nothing to configure. Traffic that reaches a provider nobody registered is found automatically. Agents calling through the gateway without a registration are found the same way and listed as discovered in traffic.
  2. Collected where people work. 13 collector types push findings in; raw log lines are never stored. Network flow, DNS, proxy, firewall, single sign-on, SaaS audit, email sign-ups, cloud audit, endpoint inventory, expense feeds, code repositories and SIEM queries push in with a token. Only the AI services found, who used them and a receipt are kept.
  3. Matched to approvals. Traffic that went around an approved provider ranks first, as a bypass. Each finding is checked against the providers you approved at the gateway and the apps you already assessed, so it reads as a bypass, as never assessed, or as known.
  4. Decided once. Approve, allow until a date, block or dismiss, as a standing rule. A decision on one finding writes a rule for the service, applied to later sightings. Allowing for now needs a reason and an end date. Nothing matched defaults to monitor.
Shadow AIIllustrative

An illustrative Shadow AI list: a public chat assistant and a code assistant went around the gateway although their provider is approved there, a meeting notetaker and an image generator were never assessed, and a research assistant was assessed, each with the users seen.

3notes
  1. Approved provider, traffic went around
  2. No risk assessment on file
  3. Users seen for each app

How it connectsx, found

Where a found tool goes next.

A finding moves on from the list, carrying its rule and the place where that rule takes effect.

  1. Approved providers run through the gateway, where a block is real and recorded.

  2. A shadow agent joins the map, labelled discovered in traffic, waiting for an owner.

  3. A new AI service in use raises an alert in the inbox, by email, webhook or SIEM.

  4. AI vendors in use but not assessed are flagged in the risk register.

Honest by design

What it does, and what it does not.

Standing ruleIllustrative

Standing rule: Decision Block; In the gateway Refused, recorded; At your proxy Blocklist export; On laptops Recorded intent; Decided by Head of AI governance. Reason on record.

What it does not do

x, not measured

A block takes effect only where ColossalX sits in the path; elsewhere it is recorded intent.

All 4 limits
  • Of the log sources, only proxy logs name the person behind a sighting.
  • The browser sensor and endpoint sources report only once they are deployed and enrolled.
  • Shadow AI findings raise alerts; they do not yet open owned issues in the queue.

How we know

  • Nothing matched defaults to monitor, never to allow.
  • A tool that went around an approved provider ranks first, as a bypass, not as a new discovery.
  • Raw log lines are never stored: only the AI services found, who used them and a receipt.
  • The browser sensor is tested never to send prompt text, page content or full URLs.

Questions

Questions buyers ask

What is shadow AI?

Shadow AI is the AI people use at work that nobody approved or assessed: a web chat tool, a browser plugin, a local model, or an agent calling a model without being registered. The risk is not the tool itself but the data that reaches it unseen, and the decisions nobody can account for afterwards.

How do you detect shadow AI in an enterprise?

ColossalX finds it three ways: in gateway traffic with nothing to configure, through 13 collector types such as proxy, DNS, single sign-on and expense feeds that push findings in, and with a browser sensor rolled out by browser policy. Each finding is matched against the providers you approved and the apps you assessed.

What are shadow agents?

Shadow agents are AI agents that act in your estate without being registered: a script calling a model with a shared key, or an agent a team built and never declared. ColossalX finds them calling through the gateway, gives each one an identity and queues it for a person to review and assign an owner.

Should companies block unapproved AI tools?

Not by default. In ColossalX, a tool nothing matches is monitored, never allowed, until a named person decides: approve, allow until a date, block or dismiss. A block is real at the gateway. Elsewhere it is recorded intent, with a blocklist your proxy or resolver can apply, and the product says which is which.

Does the browser sensor read what employees type?

No. The browser sensor reports which AI tools are in use, including local models, and is tested never to send prompt text, page content or full URLs. It authenticates with a device key and never holds a person's session, and IT can roll it out across the fleet by browser policy.

Related

Next step

Know your x.

See the AI your own people use: what nobody approved, what went around, and where a decision takes effect.

  1. 01Tell us what you run
  2. 02See the four verbs on it
  3. 03Decide where to start