[Shadow AI, the use of unapproved AI tools by employees, creates significant security and compliance risks. A dedicated endpoint governance solution like Bifrost Edge, working with an AI gateway, can detect and govern these tools before they lead to a data breach.]
The use of unapproved applications by employees, often called "shadow IT," is a long-standing challenge for security teams. Its modern equivalent, shadow AI, has emerged as a more acute enterprise risk. When employees use public AI tools like ChatGPT, Claude, and various coding assistants for work, they can inadvertently expose sensitive company data, create compliance gaps, and introduce security vulnerabilities. A 2023 report by Cisco noted that while employees use AI to boost productivity, their organizations often lack visibility into which tools are being used. This ungoverned usage makes it critical for enterprises to find a reliable way to detect shadow AI. One approach is to combine a central AI gateway with an endpoint governance agent. An open-source AI gateway like Bifrost acts as the control plane, while an endpoint agent extends visibility and policy enforcement to every employee's machine.
What is Shadow AI and What Are the Risks?
Shadow AI refers to any AI application, service, or tool used by employees without the organization's explicit approval and oversight. This includes using personal accounts for large language models (LLMs), integrating unvetted AI plugins into browsers, or using AI-powered desktop applications that process corporate data.
The risks associated with shadow AI are substantial:
- Data Leakage: Employees may paste proprietary code, customer information, financial data, or strategic plans into public AI tools. This data can be used to train models or may be stored insecurely by the service provider, creating a high risk of exposure.
- Compliance Violations: Industries with strict data handling regulations like healthcare (HIPAA) and finance (GLBA) face significant compliance risks. Using unapproved AI tools can violate data residency, privacy, and security requirements, leading to heavy fines. A recent report from KPMG highlights that 68% of executives are concerned about the lack of a clear AI governance program.
- Security Vulnerabilities: Unvetted AI tools, especially browser extensions and desktop apps, can have security flaws or malicious code that exfiltrates data or compromises the user's machine. AI applications that connect to external tool servers using protocols like MCP (Model-Context Protocol) can also create new attack surfaces if those servers are not managed.
- Lack of Audit Trails: Without centralized governance, there is no record of what data was shared with which AI model, by whom, or when. This makes it impossible to conduct forensic analysis after a security incident or to demonstrate compliance to auditors. The Bifrost AI gateway addresses this by creating immutable audit logs for every request.
The Challenge of Detecting Ungoverned AI
Traditional network monitoring and cloud access security brokers (CASBs) struggle to effectively detect and manage shadow AI. Many AI tools use standard web protocols (HTTPS) that blend in with normal web traffic, making it difficult to distinguish between approved and unapproved usage based on network data alone. Furthermore, with the rise of desktop applications for AI, much of the activity happens on the endpoint, outside the visibility of network-based tools.
Attempting to block popular AI domains at the network firewall is often a losing battle. It is an overly broad approach that can stifle productivity and is easily circumvented by employees using VPNs or personal devices. A more effective strategy requires visibility directly on the endpoint.
An Endpoint-First Approach to AI Governance
A modern solution to shadow AI combines a central policy engine with an endpoint agent that runs on every employee machine. This is the model used by Bifrost, which pairs its AI gateway with an agent called Bifrost Edge.
Hereβs how this combined approach works:
- AI Gateway as the Control Plane: The Bifrost AI gateway serves as the central point for defining all AI policies. Administrators configure virtual keys with specific budgets, rate limits, and access rules. They also set up security policies, such as guardrails that detect secrets or PII in prompts.
- Endpoint Agent for Discovery and Enforcement: The Bifrost Edge agent is deployed to all company laptops and desktops via MDM solutions like Jamf, Intune, or Kandji. The agent runs silently on each machine, inspecting AI traffic from desktop apps, coding assistants, and browsers.
- Fleet-Wide Visibility: Edge discovers every AI application and MCP server in use across the entire fleet of devices. This data populates a central admin dashboard, providing the security team with a real-time inventory of all shadow AI tools. This turns an unknown risk into a manageable list.
- From Visibility to Control: From the dashboard, administrators can create an application governance policy, explicitly allowing or denying specific tools. They can also govern which MCP servers employees are allowed to connect their AI tools to.
- Enforcement on the Device: Once a policy is set, Edge enforces it on each machine. Traffic from approved apps is automatically and transparently routed through the Bifrost gateway, where all the pre-configured security rules, budgets, and audit logging policies are applied. Traffic from denied apps is blocked before it can leave the endpoint.
This model allows organizations to embrace the productivity benefits of AI without sacrificing security or control. Instead of blocking AI altogether, it brings shadow AI usage out of the dark and into a managed environment.
Implementing a Shadow AI Detection Strategy
For enterprises looking to get ahead of the risks, the first step is gaining visibility. Deploying an endpoint governance solution provides an immediate inventory of the AI tools currently in use. Organizations are often surprised by the number and variety of applications employees have adopted.
Once visibility is established, security and IT teams can work with business units to create a formal AI usage policy. The data from the discovery phase informs this policy, ensuring it addresses the tools employees find most valuable. With a platform like Bifrost and Bifrost Edge, that policy can be enforced consistently, from the data center to every employee's laptop.
This endpoint-first approach provides a scalable and effective way to detect, govern, and secure AI usage across the enterprise, preventing shadow AI from escalating into a full-blown data breach. Teams evaluating solutions for AI governance can review the Bifrost documentation or explore its capabilities in the open-source repository.
Sources
- Cisco. (2023). 2024 Data Privacy Benchmark Study. https://www.cisco.com/c/dam/en_us/about/doing_business/trust-center/docs/cisco-data-privacy-benchmark-study-2024.pdf
- KPMG. (2023). Generative AI risk management. https://kpmg.com/xx/en/home/insights/2023/11/generative-ai-risk-management.html
- ISACA. (2023). Shadow IT in the Age of AI. https://www.isaca.org/resources/isaca-journal/issues/2023/volume-6/shadow-it-in-the-age-of-ai



Top comments (0)