Shadow AI

Updated

Discover, control, and govern unsanctioned AI app usage across your organisation — from building visibility into shadow AI activity to blocking risky destinations, preventing data loss, and governing sanctioned use.

Shadow AI is the use of generative AI apps and agents outside of IT visibility and governance. Employees adopt consumer AI tools to be productive, but in doing so they can expose sensitive data, bypass compliance controls, and create unmonitored risk. Addressing it is a motion, not a single control: first discover what is actually being used, then layer protection to block unsanctioned destinations and prevent data leaving to AI apps, govern the apps you do sanction, and respond as user risk changes.

How to address Shadow AI

  1. Discover Shadow AI Usage

    Builds visibility into which AI apps users are accessing, who is using them, and whether sensitive data is flowing into AI prompts — before taking any blocking action.
  2. Block Unsanctioned AI Destinations

    Blocks access to unsanctioned AI apps at the network layer — enforcing org-wide blocking through Defender for Cloud Apps and applying user and group-level restrictions through Entra Internet Access.
  3. Control AI Apps on Managed Devices

    Prevents installation and execution of unsanctioned AI apps and local AI agents on managed devices using Intune app control policies and Microsoft 365 admin center shadow AI governance across Windows, iOS/iPadOS, Android, and macOS.

Control coverage

Control coverage for Shadow AI — where its 10 capabilities land across your security control domains and the AI surfaces they protect. Select any control domain to reveal the capabilities behind it.
Control domain
Agents
Users
Infrastructure
Endpoints
Data
Coverage
Discovery
7
Monitoring
7
Governance
4

Organisational and technical controls for managing the lifecycle of AI models, agents, and workloads — including inventory, policy, and accountability frameworks.

Agent Security
2

Controls that secure AI agents, their tools, plugins, and external connections — including MCP server trust boundaries, tool permission scoping, prompt injection defences, and runtime behaviour constraints for autonomous and assistive agents.

Network Protection
2

Controls that secure the network paths used by AI workloads — including private endpoints, egress filtering, secure web gateways, and traffic inspection to prevent data exfiltration and lateral movement.

Threat Detection
1

Capabilities that identify, alert on, and help respond to threats targeting AI models, inference endpoints, training pipelines, and supporting infrastructure.