Shadow AI Discovery
Shadow AI is the usage an organization cannot see: an employee pasting a customer list into a public chatbot from a managed laptop. It does not appear in gateway logs, because it never went through the gateway. AgentWatch closes that gap.
What is the shadow AI problem?
Section titled “What is the shadow AI problem?”Public AI assistants are reached directly over the browser, so they bypass any API gateway an organization has deployed. The result is that the most sensitive AI usage in the company is often the least visible: no record of what was shared, no policy applied, no attribution to a person, and no evidence for a regulator asking whether customer data left the environment.
How does AgentWatch discover it?
Section titled “How does AgentWatch discover it?”Through a lightweight endpoint agent deployed to managed devices, shipped as signed installers for macOS, Windows, and Linux and running as a managed system service. On the device it inspects traffic destined for known public AI services and reports it to the central gateway. Crucially, this works without requiring a corporate proxy — the usual blocker on shadow-AI visibility for remote and hybrid workforces, where traffic never traverses the corporate network.
For environments that do route traffic centrally, network-level steering is also supported, and AgentWatch integrates with existing corporate proxies and CASBs such as Zscaler, Forcepoint, and Netskope.
What does it show you?
Section titled “What does it show you?”- Which public AI tools are in use, across the managed fleet.
- Who is using them, mapped to an employee identity and a device.
- What is being shared — including risky document uploads — with the same DLP categories used on gateway traffic.
- Full conversation records where policy permits, subject to DLP redaction.
- Fleet health, so you know which devices are covered and which are not.
Can policy be enforced, not just observed?
Section titled “Can policy be enforced, not just observed?”Yes. Captured traffic runs through the same DLP, guardrail, and audit pipeline as API traffic, so sensitive uploads can be blocked or redacted rather than merely recorded. AgentWatch also supports an account identity policy: administrators define which AI accounts employees may use on managed devices — a corporate account rather than a personal one, for example — with dry-run testing of a policy before enforcement, an exemption list for legitimate cases, and a decision log of every enforcement outcome.
How is the endpoint fleet managed?
Section titled “How is the endpoint fleet managed?”Devices enroll through a token exchange and then check in on a heartbeat carrying version and health. Administrators can list enrolled devices, view coverage and version distribution on a fleet health view, send actions (restart, update, disconnect), deauthorize a device, and apply bandwidth limits. Device-to-gateway communication is mutually authenticated with certificates.
Does it work for servers and containers too?
Section titled “Does it work for servers and containers too?”Yes. The same agent runs in a sidecar mode designed for Kubernetes pods and Linux virtual machines, exposing explicit proxy endpoints that workloads opt into — used for governing AI traffic from applications rather than from people. It reports Kubernetes node, pod, and namespace context, and fails open, so a workload never blocks on AgentWatch being reachable. See Agent fleet and insider risk.
Sources and references
Section titled “Sources and references”- Policy engines applied to captured traffic: Data protection and guardrails.
- Fleet deployment options: Deployment.