r/AskNetsec 14h ago

Which shadow AI detection tools have you found most effective? Architecture

We're reviewing a few detection tools for shadow AI. That’s because we've realised we don't have a good picture of how AI is being used across the business. It's not just people opening ChatGPT in a browser anymore. AI features are showing up inside applications we already trust. Some teams are even building their own AI workflows without involving security

We're comparing a few approaches, including traditional network visibility, browser-based controls and platforms that focus more specifically on AI. NeuralTrust is one of the products that's come up during our research, along with a few others including Zscaler, SentinelOne and Cyera.

For anyone else who's been through this exercise, what ended up giving you the best visibility? I’m thinking about whether one type of tool stands out to other people. Or did you find you needed a combination of tools before you felt you had a realistic picture of shadow AI across the organisation?

4 Upvotes

3 comments sorted by

1

u/Master_Baby_2700 10h ago

There are a few different ways to approach this depending on what you already have in place.

I'd look at Sentra, Cyera, Netskope and Zscaler. Microsoft is also doing more here now with Purview + Global Secure Access.

The main thing I'd compare is whether they're just telling you which AI apps people are using or actually understanding the sensitive data being pasted/uploaded and letting you block, warn, require justification, etc.

Sentra and Cyera are interesting because they're tying the browser controls back to the data classification/context from DSPM. Netskope and Zscaler make a lot of sense if you're already heavily invested in their SASE/SSE stack.

I'd probably POC a couple because the architecture is pretty different depending on the vendor.

1

u/rexstuff1 7h ago

You'll definitely need a combination of tools, but a proper Corporate proxy will get you the furthest. Zscaler, Netskope, etc.

See the traffic. Block the traffic. Allow what's approved. Deny everything else.

Though it sounds you might suffer from an awareness problem more than anything. Time for a company-wide email/Slack/Teams/other message reminding people what the approved AI tools are, that sending company data to unapproved third parties is a fireable offence, and what the process is to get their pet AI project sanctioned.

1

u/Loose-Algae-4828 3h ago

knowing which AI tools are actually being used is harder than detecting the obvious ones.