Learn / Detection methods

Five ways to detect shadow AI, compared honestly

Log audits, CASB, endpoint agents, browser extensions and surveys all claim the same job. They see different worlds. This page maps what each method genuinely covers, where it wins, and where it quietly fails.

Try the log-audit method free
The matrix

Coverage properties, side by side

Nine properties that decide real-world usefulness. Bookmark this table for the meeting where someone proposes buying something.

PropertyLog auditCASB / SSEEndpoint agentBrowser extensionSurvey
Deployment effortNone, uses existing logsHighHighMediumLow
Sees history before installYes, full log windowPartialNoNoMemory only
Covers BYOD on the networkYesPartialNoNoIf they answer
Covers native apps and API useYes, hostnamesSanctioned apps bestYesBrowser onlyRarely recalled
Catches embedded AI featuresVia subdomainsCatalog-dependentProcess-level blurSomeUsers unaware
Long-tail tool coverageRegister updated dailyCatalog lagsCatalog lagsCatalog lagsPoor
Sees prompt contentNo, by designWith inspectionPossiblePossibleNo
Privacy intrusion levelLow, hostnames onlyMediumHighHighLow
Cost to first resultFree previewProcurement cycleProcurement cyclePilot rolloutMeeting time

No column sweeps the board. The honest claim: log audits dominate on effort, history and breadth; agents and extensions dominate on content depth; CASB dominates on inline enforcement for sanctioned SaaS.

Method by method

What each one sees, what each one misses

1. Log-based hostname audit

Wins when: you need the full inventory this week
Sees
  • Every AI hostname reached from the logged network, browsers, apps, scripts and service accounts alike.
  • Weeks or months of history retroactively, from logs you already keep.
  • Per-tool context when matched against a maintained register: risk, dated training verdicts, sanctioned split.
Misses
  • Prompt content, deliberately: exposure is measured by tool and terms, not by reading what staff typed.
  • Off-network use on cellular or home connections outside logged VPN/DNS.
  • Traffic on unlogged paths, such as third-party DoH, unless the network forces resolution.

2. CASB / SSE platforms

Wins when: inline control of sanctioned SaaS is the goal
Sees
  • Deep session context inside the SaaS apps it brokers: users, actions, files.
  • Policy enforcement inline: block uploads, quarantine shares, step-up auth.
  • Mature app-catalog scoring for known applications.
Misses
  • The AI long tail until the catalog classifies it, and new tools appear daily.
  • Anything outside brokered channels: personal accounts on BYOD, native desktop apps.
  • Months of history before deployment, plus a procurement cycle before day one.

3. Endpoint agents / DLP

Wins when: regulated content needs blocking at the point of paste
Sees
  • Process-level activity on managed devices, including clipboard and file movements with DLP.
  • Prompt-level interception on configured apps, the deepest content visibility available.
Misses
  • Every unmanaged and BYOD device, which is where shadow behavior concentrates.
  • Anything before rollout, and rollout is a project with exceptions and performance politics.
  • Its own blind spot: agents get disabled, bypassed or simply not installed on the machines that matter.

4. Browser extensions

Wins when: a browser-first workforce needs prompt-level guardrails
Sees
  • In-browser AI use with page-level context, including some embedded AI features.
  • Real-time nudges: warn, redact or block at the moment of prompt.
Misses
  • Native apps, mobile apps and API traffic entirely.
  • Any browser without the extension: personal profiles, other browsers, incognito depending on policy.
  • Users who object to per-keystroke visibility, a consent conversation that can sink the rollout.

5. Surveys and interviews

Wins when: you need context and intent, not counts
Sees
  • The why: which problems drove people to tools, what they would accept as sanctioned alternatives.
  • Cultural readiness for policy, invisible to every technical method.
Misses
  • Most of the inventory: people underreport tools they suspect are borderline, and honestly forget embedded AI.
  • Anything quantitative: results decay immediately and cannot be trended.
Combinations

The stacks that actually work

Mature programs combine two or three methods with distinct jobs. Three proven pairings:

Audit + existing filter

The lean stack: quarterly log audits for inventory and trend, your DNS filter or firewall for enforcement of the verdicts. Zero new procurement, covers most mid-market needs.

Audit + CASB

The enterprise stack: CASB governs the sanctioned SaaS estate; the audit sweeps the long tail the catalog has not classified and provides dated training verdicts for vendor reviews.

Audit + survey

The change-management stack: the audit finds the what, a short survey of the affected teams finds the why, and the sanctioned list that results actually gets adopted.

Sequencing rule: inventory before instrumentation. Knowing your actual tool list from logs makes every subsequent purchase, CASB included, better scoped and cheaper.

Decision guide

Pick by the question you are answering

Method selection gets easy when you name the question first.

"What AI tools do we actually have?"

  • Log audit, no contest: retroactive, complete for the logged network, first result free.
  • Start with the free preview and a month of DNS or proxy logs.

"How do we stop PHI reaching chatbots?"

  • Endpoint DLP or a browser extension for the paste moment, after an audit tells you which tools and which teams.
  • Blocking the top offenders at the filter closes most volume immediately.

"How do we govern our sanctioned SaaS's AI features?"

  • CASB for the inline control, the audit's subdomain findings to know which embedded features exist at all.

"Why is everyone using these tools?"

  • Survey the teams the audit's per-user table highlights. Ask about problems, not tools, and the sanctioned list writes itself.

Method-neutral privacy note: hostname-level auditing is the least intrusive technical option. Uploads here are read once and discarded, and reports are deletable before their 90-day expiry.

Judge the log-audit method by its output

The sample evidence pack is the method's closing argument: tiles, dated verdicts, per-user rows, from one log export. Compare it with any vendor's demo deck.

Open the sample report
Buyer's caution

Four claims to challenge in any detection pitch

Whatever method you buy, these four claims deserve a "show me" in the demo.

"We detect all AI tools."

Ask for the catalog size and its update cadence. Our register tracks 20,399 AI domains with ~300,000 new domains screened daily; anything static is already stale.

"Deploys in minutes."

Ask what it sees for the month before deployment. Only log-based methods answer with anything but silence.

"Complete visibility."

Ask about BYOD, native apps and the vendor's own bypass modes. Every method has a blind spot; distrust the ones that claim none.

"AI-powered risk scores."

Ask where training-terms data comes from and when it was last checked. A score without a dated source is an opinion with a number attached.

FAQ

Detection method questions

What is the fastest way to detect shadow AI?

A log-based audit of exports you already have. First totals arrive in minutes via the free preview, with no deployment.

Is a CASB enough for shadow AI?

For sanctioned SaaS governance, it is strong. For the AI long tail and pre-deployment history, pair it with a log audit; the two cover each other's gaps.

Do endpoint agents make audits unnecessary?

No. Agents only see managed devices from install day forward. Audits see every device on the logged network, including the months before.

Are surveys worthless for shadow AI?

Not worthless, just miscast as inventory. Use them after an audit to understand motivations and design a sanctioned list people accept.

Which method is least invasive for employees?

Hostname-level log auditing: it reads which tools were reached, never what was typed. Extensions and agents sit at the other end of that spectrum.

How does the log-audit method work in detail?

Hostnames from your export are matched against a daily-maintained register with subdomain walk-up. The full mechanics are on the methodology page.

By organization size

Sensible defaults per company size

Constraints, not preferences, decide most method choices. Defaults that respect them:

Under 50 people

Log audit alone, monthly free previews, one paid report when a client or insurer asks. Anything heavier outruns the risk and the budget.

50 to 500

Quarterly log audits plus enforcement in the existing DNS filter or firewall. Add a survey when building the first sanctioned list.

500 to 5,000

Monthly audits feeding a formal review, CASB where sanctioned-SaaS governance justifies it, DLP only for regulated content teams.

5,000+

All of the above exist already somewhere in the estate. The audit's job becomes reconciliation: one inventory across silos, one trend line for the board.

Year one

A detection program's first year, quarter by quarter

Programs fail from over-buying in Q1. The sequence that survives contact with budgets:

Q1: baseline and quick wins

  • First full audit, block the abusive tail, sanction the top three tools staff already chose.
  • Spend: audit reports and existing-filter configuration time. Nothing else yet.

Q2: policy and list

  • Publish the sanctioned list and the request path. Re-audit to measure adoption, not just exposure.
  • Survey the heaviest-using teams the report identified.

Q3: instrument the gaps

  • Now buy depth where the audits proved a need: DLP for the one regulated team, CASB if embedded-AI findings justify it.
  • Purchases scoped by evidence negotiate better than purchases scoped by fear.

Q4: routine and reporting

  • Quarterly cadence locked, trend slide in the board pack, verdict deltas feeding vendor reviews.
  • The program now costs a morning a quarter plus report pricing.

Start with the method that costs nothing to try

Run the log audit's free preview today. Whatever you buy later will be better scoped for knowing your actual inventory first.

Run the free audit