DEV Community

Cover image for Best Tools to Discover Unsanctioned AI Apps on Employee Devices
Soren Lindqvist
Soren Lindqvist

Posted on

Best Tools to Discover Unsanctioned AI Apps on Employee Devices

Best Tools to Discover Unsanctioned AI Apps on Employee Devices

Unsanctioned AI tools on employee devices pose significant data security and compliance risks. This post explores effective shadow AI discovery tools, focusing on how Bifrost and Bifrost Edge provide comprehensive endpoint AI governance to identify and manage these applications.

The rapid adoption of AI tools by employees, often outside of IT oversight, has created a significant challenge for enterprises: "shadow AI." This phenomenon refers to the unauthorized use of AI applications, models, agents, or services within an organization, leading to substantial security, privacy, and compliance risks. Research indicates that nearly half of employees use AI tools without IT approval, with over a third sharing confidential data with these platforms. To mitigate these growing threats, organizations require robust tools to discover and govern unsanctioned AI apps across their employee devices.

Understanding the Shadow AI Challenge

Shadow AI emerges when employees leverage AI tools—such as generative AI chatbots, coding assistants, or embedded AI features in SaaS platforms—without formal IT approval or security review. This usage is often driven by a desire for increased productivity and efficiency, as employees seek to optimize workflows and meet deadlines using the latest technological advancements. However, the lack of sanctioned, accessible AI tools and slow approval processes often pushes employees towards public, ungoverned options.

The unsupervised nature of shadow AI creates critical vulnerabilities:

  • Data Leakage and Privacy Breaches: Sensitive corporate data, customer PII, financial projections, or proprietary code can be inadvertently entered into public AI models, which may store this data, use it for model training, or expose it in subsequent user outputs. This can lead to violations of privacy laws like GDPR and significant reputational damage.
  • Compliance and Regulatory Gaps: Unsanctioned AI usage can bypass established data governance and cybersecurity controls, making it difficult to maintain compliance with frameworks like ISO 27001, SOC 2, or HIPAA. Without audit trails, incident response becomes nearly impossible.
  • Intellectual Property (IP) Risks: Proprietary algorithms, unpatented designs, or confidential business strategies fed into AI tools could become exposed or lose their protected status, especially if AI providers' terms of service are unclear on data ownership.
  • Security Vulnerabilities: Integrated but unapproved AI platforms, if compromised, could serve as an attack vector into the corporate network.

With 98% of organizations reporting unsanctioned AI use and 76% actively experiencing "Bring Your Own AI" (BYOAI) within their workforce, the need for comprehensive discovery and governance tools is paramount.

A cityscape at night where some buildings have brightly lit, uniform windows (sanctioned AI), while other windows in var

Traditional Approaches to Shadow AI Discovery

Organizations have historically relied on various security and IT management tools to gain visibility into their digital environments. While these tools offer some level of insight, they often fall short in comprehensively addressing the unique challenges posed by shadow AI.

  • Network Monitoring and Proxy Logs: These tools can track network traffic to known AI service domains. However, they may struggle to identify new or less common AI services, deep AI usage within browser sessions, or AI applications that operate locally on a device before sending data externally. They provide a perimeter view, missing much of the endpoint activity.
  • SaaS Discovery Tools: Designed to inventory and manage SaaS applications, these tools can identify cloud-based AI applications connected through OAuth grants, APIs, or third-party integrations. While effective for SaaS environments, they often lack visibility into desktop AI apps, command-line coding agents, or Model Context Protocol (MCP) servers that users might configure locally.
  • Endpoint Detection and Response (EDR) / Data Loss Prevention (DLP): EDR and DLP solutions monitor activity on employee devices. Modern endpoint DLP can detect and block sensitive data from being submitted into external LLM tools. They offer context-aware, on-device security and can identify sensitive data in prompts. However, many traditional DLP systems were not purpose-built for the nuances of AI interactions and may not offer full visibility into all AI tool usage, rather focusing on data exfiltration pathways. Integrating DLP directly into EDR can improve context, but a comprehensive AI app inventory may still be a blind spot.
  • Mobile Device Management (MDM): MDM platforms are essential for enrolling, configuring, and managing fleets of devices, including pushing applications and enforcing policies. MDM is crucial for deploying endpoint agents, but it generally focuses on device-level control rather than deep introspection into which AI applications or MCP servers are actually running and being used by employees within their local environments. While some MDM solutions are integrating AI for adaptive policies and anomaly detection, they are typically a foundational layer rather than the dedicated AI app discovery mechanism.

These traditional tools provide partial visibility but often leave critical blind spots where shadow AI can thrive, making comprehensive governance challenging.

Purpose-Built Endpoint AI Governance: Bifrost Edge

Closing the shadow AI gap requires a solution that extends governance directly to the endpoint, covering all AI interactions regardless of whether they occur in a browser, a desktop application, or a coding agent. This is where dedicated endpoint AI governance solutions like Bifrost Edge become essential.

Bifrost Edge, the endpoint layer of the Bifrost AI gateway, is designed to bring visibility and control to AI usage on employee machines. It operates on the principle that the same robust governance policies configured in the Bifrost gateway should apply consistently across all AI traffic, including that originating from individual devices. Bifrost, an open-source AI gateway built in Go by Maxim AI, serves as the central control plane and policy engine for virtual keys, budgets, rate limits, routing, guardrails, and audit logs. Bifrost Edge then extends that same governance and security to AI traffic on employee machines, with endpoint enforcement on each device.

Core Capabilities for Shadow AI Discovery and Governance

Bifrost Edge is currently in alpha, offering a powerful approach to endpoint AI governance through several key capabilities:

  • Automated AI App Discovery and Inventory: Bifrost Edge runs silently on employee devices (macOS, Windows, Linux) and automatically identifies every AI application in use, as well as the MCP servers users have configured within those tools. This builds a real-time, fleet-wide inventory of all AI surfaces, turning shadow AI from a blind spot into a managed asset. Admins gain visibility into hostnames, owners, installed AI apps, and configured MCP servers.
  • Comprehensive MCP Server Discovery: AI apps increasingly connect to MCP servers, which allow them to read files, call APIs, and take actions. Edge inventories these MCP servers across the fleet, allowing administrators to make per-server allow/deny decisions. A denied server cannot be used, even if an app had it previously configured.
  • Policy Enforcement on the Device: Administrators can define which AI applications are permitted across the organization, and Edge enforces these decisions at the device level. Allowed apps are fully governed through Bifrost, while disallowed apps are blocked before any data leaves the machine. This policy is centrally managed and automatically synced to all enrolled devices.
  • Extension of Gateway Governance and Security: Because Bifrost Edge routes all AI traffic through the Bifrost gateway, every guardrail, budget, virtual key, and audit log configured at the gateway applies automatically to endpoint AI. This means sensitive content (e.g., secrets, PII) is caught before it leaves the machine, and compliance requirements are met for prompts and responses from desktop apps, browser AI, and coding agents.

A digital shield or a gate acting as a filter, with controlled data streams flowing through it on one side, and chaotic,

How Bifrost Edge Works in Practice

After a straightforward, MDM-native deployment via platforms like Jamf, Microsoft Intune, or JumpCloud, Bifrost Edge runs as an always-on agent. The user's initial single sign-on (SSO) links their machine to their identity and policies, requiring no API keys or sensitive data on the device itself.

When Edge detects a new AI app or MCP server, it automatically requests approval in the admin console. Administrators can then approve, deny, or configure pending statuses, with decisions taking effect across the fleet upon the next check-in. This continuous feedback loop ensures that policy is always current and enforced where AI is actually used.

The seamless routing means that applications like Claude Desktop, ChatGPT in the browser, Cursor, and various coding agents (Claude Code, Codex CLI, Gemini CLI) automatically fall under the organization's governance.

Conclusion

The proliferation of unsanctioned AI applications on employee devices presents a significant and evolving risk to enterprise security and compliance. While traditional security tools offer some layers of protection, they often lack the purpose-built capabilities required to comprehensively discover and govern AI usage at the endpoint.

Dedicated endpoint AI governance solutions are essential for mitigating shadow AI risks. Bifrost Edge, combined with the Bifrost AI gateway, provides a robust framework for identifying every AI application and MCP server in use, enforcing granular policies, and extending existing governance and security controls to every machine. This approach transforms shadow AI from an invisible threat into a managed, compliant part of the enterprise AI landscape, safeguarding sensitive data and intellectual property. Teams evaluating AI gateways can request a Bifrost demo or review the open-source repository to learn more about its capabilities and how Bifrost Edge extends governance to the endpoint.

Sources

Top comments (0)