Shadow AI Tools
Home How It Works The Report Coverage Pricing FAQ Contact
Run a Free Audit Sample Report (PDF)
detection database updated daily · 2026-09-19

Find Every AI Tool Your Employees Already Use

Upload a DNS, proxy or firewall export. Get back every AI tool reached from your network, matched against 20,399+ AI-tool domains. No agent, no SSL inspection, first results in minutes. By Alpha Quantum, the team behind the AI Tools Blocklist.

Every finding flagged:   trains on your data   data sovereignty   NSFW / deepfake   who used it
0AI tools detected
0Train on data by default
85.5%Silent on training
$99Full audit report
shadow audit · live replayparsing
reading export · 4,412 linessample report →
Our AI data products are trusted by 300+ companies worldwide Tier 1 telcos Fortune 500 enterprises Cybersecurity corporations K-12 school districts MSPs & consultancies
The audit runs on the same platform as the AI Tools Blocklist and our 120M-domain Web Filtering Database, in production since 2022.
The visibility gap

Shadow AI is a visibility problem first

Staff adopt chatbots, code assistants and file converters long before IT hears about them. Policy documents and blocking rules come second. The first question is what is actually in use today.

Nobody files a ticket for a free AI tool

Staff sign up with corporate email the moment a tool trends, and grant OAuth access to mailboxes and drives. Most of it never touches procurement. By the time IT notices, sensitive data has already crossed the perimeter.

Your data is the payment

700+ AI tools train on customer input by default, and 85.5% say nothing about training at all. For GDPR, HIPAA or client-confidential data, a single paste can be a reportable event.

Auditors now ask about AI

Compliance frameworks and cyber-insurance questionnaires increasingly demand evidence of AI-usage controls. "We blocked ChatGPT" is not an answer when thousands of alternatives exist.

Surveys measure honesty, not usage

Asking staff which AI tools they use produces the list they think you want to hear. DNS and proxy logs record what actually happened, hostname by hostname.

Discovery should not cost five figures

Consulting-led shadow AI assessments take weeks and are quoted in the thousands. The same evidence already sits in the logs your network writes every day.

The audit, in one picture

From raw log to evidence pack, one upload

Your log exportfrom the DNS filter, proxy or firewall you already run
umbrella_dns_export.csv zscaler_web_last7d.log gateway_http_requests.json fortigate.syslog (key=value) pihole_queries.txt hostnames_one_per_line.txt
What the audit engine does with it, in order
1 · Parse any of 11 formatsCSV with headers, key=value syslog, vendor exports or a plain hostname list. Read once, then discarded.
parse
2 · Match 20,399 AI-tool domainsEvery hostname checked with subdomain walk-up, against the same database refreshed daily from 300K new registrations.
match
3 · Enrich every findingFunctional category, risk level, sovereignty, abusive-use flags and the vendor training verdict with the date checked.
enrich
4 · Split against your policySanctioned vs unsanctioned from your own approved-tool list, plus the per-user, per-device or per-IP breakdown.
report
Inventoryevery AI tool reached, by category and risk
Peoplewho used what, when your export carries identities
EvidenceCSV export and PDF pack, shareable with the board or an auditor
your account · 90 days
Why log evidence beats every other method: agents need deployment, CASB needs licensing, surveys measure honesty. Your network already wrote down every AI hostname it resolved. The audit just reads that record against a database large enough to recognize the tools nobody has heard of.
Inside the report

An AI inventory you can hand to management

Every finding is tied to a hostname seen in your own logs. These example rows use the same real classifications as the 4-page sample report: flip through it before you upload anything.

report rows  function, four risk flags and users on every finding

domaincategorysovereigntyabusivetrains_on_your_datauserssanctioned
chatgpt.comGeneral assistants & chatbotslownoneyes41yes
openai.comFoundation models & APIslownoneno7yes
deepseek.comFoundation models & APIshighnoneyes3no
fireflies.aiMeeting assistantslownoneopt-out12no
deeplivecam.netFace swap & effectsunknowndeepfakeunknown1no
crushon.aiAI companions & character chatunknownnsfwyes2no

Note rows one and two: chatgpt.com trains on your data and openai.com's API does not. That nuance, on every row, is what turns a domain list into a decision.

free preview that shows its work

Category totals, risk counts and a fifth of the tools found, at least five. Every withheld tool appears as its own masked row, so you count exactly what is missing. Preview PDF included.

$99 full report

Every tool named, the per-user breakdown, the sanctioned vs unsanctioned split against your own approved list, CSV export and the PDF evidence pack.

dated training verdicts

Each vendor verdict carries the date its terms were checked, from a register of 13,000+ reviewed policies. Evidence an auditor can actually cite.

How it works

From log export to AI inventory in four steps

The audit runs on files your network equipment already produces. Nothing is installed and nothing is inspected in transit.

step 1

Export a log

Take a DNS, proxy or firewall export covering a normal week. A CSV, syslog file or plain hostname list all work.

step 2

Upload it

Create a free account with an email address and upload. The file is parsed in one pass and discarded.

step 3

Read the preview

Minutes later: totals by category, risk counts and the top findings, with the rest shown as withheld rows.

step 4

Unlock and repeat

Unlock the full report when it finds something worth chasing. Re-run quarterly to track drift.

Cisco Umbrella Zscaler Palo Alto Fortinet Cloudflare Gateway DNSFilter NextDNS Pi-hole SonicWall Squid Any CSV or hostname list
Pricing

Free preview. Full reports from $99. No subscription.

Start free and unlock the complete report only if the preview finds something worth chasing. Reports are one-time PayPal purchases; credits stay in your account until used.

Single report
$99 one-time
  • 1 full audit report
  • Every tool, per-user breakdown
  • Sanctioned vs unsanctioned split
  • CSV + PDF evidence pack
  • Up to 2,000,000 lines / 25 MB
Buy 1 report
3 reports
$199 $66 each
save 33%
  • 3 full audit reports
  • Before/after a policy rollout
  • Or three separate networks
  • Same full evidence pack per run
Buy 3 reports
Best value 5 reports
$299 $60 each
save 40%
  • 5 full audit reports
  • Quarterly cadence plus one spare
  • Consultants: one paid engagement each
  • Same full evidence pack per run
Buy 5 reports
Free previewFull report
Totals by category and risk flagsincludedincluded
AI tools nameda fifth of those found, at least fiveall of them
Per-user breakdownwithheldincluded
Sanctioned vs unsanctioned splitwithheldincluded
Vendor training verdicts, datedon named toolsevery tool
PDFpreview PDFfull evidence pack
CSV exportnoyes
Export size5,000 lines / 2 MB2,000,000 lines / 25 MB
Price$0$99, less in packs

Running audits monthly? The plans on aitoolsblocklist.com include 1 to 10 full audits a month, and the MSP plan labels each report with the client name. Larger exports are handled on request.

Detection coverage

Backed by a database engineered like a product

Detection is only as good as the list behind it. Ours is maintained daily as a commercial product, distilled from a 120M-domain corpus, not scraped once from a directory.

0AI-tool domains across 18 functional categories
0newly registered domains screened, so today's launch is on tomorrow's list
0vendor terms reviewed for training-on-your-data verdicts
0tools mapped to the model provider actually behind them

Explore the research behind the audit: the Policy Silence Index, training-terms verdicts and where AI tools send your data.

Who runs it

Built for the people who get asked "what AI are we using?"

The same audit answers a board question, a compliance finding or a client engagement.

CISOs and IT leaders

Turn a suspicion into a dated inventory before the next board or risk meeting. Track the unsanctioned count quarter over quarter.

Typical run: last week's DNS export, full report, PDF to the board

Compliance and privacy teams

Evidence of which vendors receive staff input and what their terms say about training, each verdict dated. Feeds DPIAs and AI registers directly.

Typical run: proxy export with usernames, CSV into the register

MSPs and consultants

Deliver shadow AI assessments as a paid engagement without building tooling. The MSP plan includes 10 audits a month, each labeled with the client name.

Per-report cost: from $24.90 on the MSP plan, $60 in the 5-pack

Network and firewall admins

You already own the log source. Twenty minutes end to end, no new vendor onboarding, and the findings map straight onto your existing filtering policy.

Follow-up: block the findings with the AI Tools Blocklist
Honest comparison

Where a log audit fits among the alternatives

CASB and endpoint platforms are excellent at continuous enforcement. The audit answers a different question: what is already happening, today, with zero deployment.

Shadow AI AuditCASB / SSE discoveryEndpoint agentsStaff survey
Time to first resultminutesweeks of deploymentweeks of rolloutdays, then follow-ups
Needs installationnothingproxy or API integrationagent on every devicenothing
AI-specific intelligence20,399+ tools, 4 risk flagsgeneric app catalogprocess-level onlynone
Training-terms verdicts13,000+ vendors, datednot coverednot coverednot covered
Measures actual behavioryes, from logsyes, once deployedyes, once deployedself-reported
Cost to try$0enterprise licensingper-seat licensingstaff time

Already running a CASB? Run the audit on its logs. The AI-specific enrichment stacks on top of whatever you have.

Data handling

Your logs are evidence, not our product

The audit is designed so the sensitive artifact, your raw log, never persists on our side.

Read once, then discarded

The uploaded export is parsed in a single pass and deleted. It is never stored, resold or used for anything else.

Reports expire

Finished reports stay in your account for 90 days, then they are removed. You can delete them earlier yourself.

Private to your account

A report is visible only to the account that produced it. Share it deliberately, as a PDF or CSV, or not at all.

FAQ

Shadow AI detection, answered straight

How do I find out which AI tools my employees are using?
Export a log from the DNS filter, proxy or firewall you already run and upload it. Every hostname is matched against 20,399 known AI-tool domains, so the report reflects real traffic from your own network, not a survey.
Which log formats are accepted?
Exports from Cisco Umbrella, Zscaler, Palo Alto, Fortinet, Cloudflare Gateway, DNSFilter, NextDNS, Pi-hole, SonicWall and Squid all parse directly. So does any CSV with a header row, key=value syslog lines, or a plain list with one hostname or URL per line.
Do I need to install anything?
No. There is no agent, no browser extension and no SSL inspection. The audit works entirely from a file you already have.
Is my log stored?
No. The export is read once, matched and discarded. Only the report is kept, for 90 days, inside your account, and you can delete it earlier.
What does it cost?
The preview is free: category totals, risk counts and a fifth of the tools found, with the rest shown as withheld rows. Full reports are $99 for one, $199 for three or $299 for five, one-time. Monthly plans include 1 to 10 audits.
Can I see who used which tool?
Yes, when your export carries an identity column: username, device name or internal IP. The full report breaks findings down per user, so follow-up goes to the right desk, not to everyone.
Can MSPs and consultants use it for clients?
Yes. The MSP plan includes 10 full audits a month and each report carries the client name you enter. Consultants often use the $299 5-pack: one report per engagement.
How is this different from CASB or DLP discovery?
Those platforms are excellent but need deployment, licensing and time. This audit needs one log export and gives an AI-specific answer today, including vendor training terms that network tools do not track.
Start now

Your logs already know the answer

Run the free preview on last week's export. If it finds nothing, you have your evidence. If it finds something, you will want the full report.