[Discovering unsanctioned or "shadow" AI applications running on employee devices is a critical first step toward effective AI governance. Endpoint visibility tools, including agents like Bifrost Edge, can inventory AI apps and Model Context Protocol (MCP) servers across a fleet to close this security gap.]
The proliferation of AI tools has created a significant blind spot for enterprise security and IT teams: shadow AI. When employees install and use AI applications on their laptops without corporate approval or oversight, it introduces risks related to data security, compliance, and cost control. A recent report from Cisco highlights that while many organizations attempt to block AI applications, employees often find ways to circumvent these blocks. The first step to managing this risk is discovering what is actually running on the endpoint.
Simply blocking AI domains at the network level is often ineffective. An analysis by the security firm Netskope found that generative AI app usage in enterprises grew by 22.5% in a single two-month period, with employees frequently using personal accounts or less common tools that fly under the radar. Effective discovery requires visibility directly on the device. Tools like Bifrost, an open-source AI gateway from Maxim AI, extend governance to the endpoint with an agent that inventories and controls AI usage at its source.
The Challenge of Endpoint AI Visibility
Traditional network monitoring tools and cloud access security brokers (CASBs) can identify traffic to well-known AI services like ChatGPT or Claude. However, they often miss a large and growing segment of the AI landscape:
- Desktop Applications: Standalone applications like Claude Desktop, the ChatGPT desktop app, or AI-native code editors like Cursor operate outside the browser and can be difficult to track with web-centric tools.
- Coding Agents: Developers use powerful command-line interface (CLI) agents like Claude Code and Codex CLI that make direct API calls from the terminal.
- Model Context Protocol (MCP) Servers: Modern AI tools connect to MCP servers to execute actions and access external data. An organization may have no inventory of which third-party tools its employees have authorized, creating a vector for data exfiltration.
Without endpoint visibility, IT and security teams are effectively blind to these applications. This makes it impossible to enforce acceptable use policies, apply data loss prevention (DLP) rules, or manage costs.
Methods for Discovering Unsanctioned AI
Gaining a complete picture of AI usage across a fleet of devices requires a multi-layered approach, with the most effective methods operating directly on the endpoint.
1. Endpoint Agent Deployment
The most comprehensive solution is an endpoint agent designed for AI governance. An agent resides on each company laptop (macOS, Windows, and Linux) and monitors for AI-related processes and network connections.
For example, the Bifrost Edge agent works as an extension of the Bifrost AI gateway. The gateway serves as the central policy and control plane, while the Edge agent performs discovery and enforcement on each device. This approach provides several advantages:
- Live Application Inventory: The agent identifies every supported AI desktop app, browser-based tool, and coding agent installed on the machine. This data is sent to a central admin dashboard, providing a real-time, fleet-wide catalog of AI software.
- MCP Server Discovery: Critically, the agent can inspect the configurations of tools like Cursor or Claude Code to discover which MCP servers employees have connected. This closes a major visibility gap in agentic workflows.
- From Discovery to Governance: Once an application is discovered, it appears in an approvals dashboard. From there, administrators can explicitly allow or deny its use across the entire organization.
2. Mobile Device Management (MDM) Queries
Mobile Device Management (MDM) platforms like Jamf, Microsoft Intune, or Kandji can be used to query installed applications on managed devices. Administrators can create scripts or policies to scan for the application bundles or executable files associated with known AI tools.
While useful for a baseline inventory, MDM-based discovery has limitations:
- Incomplete Picture: It may not detect web-only tools, browser extensions, or dynamically downloaded CLI agents that do not have a standard installation footprint.
- Lack of Context: MDM can see that an application is installed, but it cannot see how it is being used, what data it is accessing, or which MCP servers it is configured with.
- Delayed Data: Inventories are typically gathered on a periodic basis, so the data may not be real-time.
MDM is most effective when used to deploy and manage a dedicated AI governance agent, ensuring 100% coverage across the fleet. Bifrost Edge, for instance, is designed for silent, large-scale deployment via MDM.
3. Network and Proxy Log Analysis
Analyzing network traffic logs from firewalls, DNS servers, and web proxies can reveal connections to the APIs and domains of AI services. This can help identify usage from both sanctioned and unsanctioned devices on the corporate network.
However, this method is less effective in the era of remote work, where many devices operate primarily off the corporate network. It also struggles with encrypted traffic and cannot distinguish between different activities on a single domain. For example, it can show a connection to anthropic.com, but it cannot differentiate between an employee reading a blog post and using the Claude API in a desktop app.
Building a Fleet-Wide AI Inventory
A dedicated endpoint solution provides the ground truth needed for effective governance. With a tool like Bifrost Edge, an administrator can move from an unknown state to a comprehensive, actionable inventory.
The process typically involves these steps:
- Deploy the Agent: The Bifrost Edge agent is pushed to all macOS, Windows, and Linux devices using an existing MDM platform.
- Initial Discovery: As agents come online, they automatically populate the admin console with discovered AI apps and MCP servers from across the fleet. The system deduplicates entries, so each unique app or server appears only once for review.
- Review and Approve: Security and IT admins review the discovered inventory. They can see how many devices a particular app is installed on to gauge its prevalence.
- Set Policy: Admins approve applications that align with company policy and deny those that do not. This decision is then automatically enforced on every device running the agent. Allowed apps have their traffic routed through the central Bifrost gateway to apply security guardrails and cost controls, while denied apps are blocked.
From Discovery to Complete AI Governance
Discovering unsanctioned AI applications is the essential first phase of a broader AI governance strategy. Once visibility is established, organizations can implement controls to manage risk without stifling innovation. The combined AI Gateway + Bifrost Edge model provides a path to achieving this. The gateway acts as the centralized control plane for defining policy—such as configuring virtual keys with budgets or setting up audit logs for compliance—while the endpoint agent ensures those policies are enforced everywhere, for every app.
This approach allows teams to transition from a reactive, block-based posture to a proactive governance model that enables safe and productive AI adoption. Teams looking to get visibility into their fleet's AI usage can request a demo of Bifrost to see how the discovery and governance platform works.



Top comments (0)