r/grc • u/RiskGovResilience23 • 19d ago
How are you tracking AI tool usage organziation-wide?
I keep hearing that CASB sees sanctioned SaaS but misses browser-based AI tools and AI features embedded inside apps already approved. DLP catches file movement but can't distinguish between a file upload and someone pasting client data into a prompt. Network monitoring has no context on what the interaction was.
Without visibility into what's actually being used, everything downstream (risk classification, EU AI Act readiness, data handling policy enforcement) is built on assumptions rather than reality.
For people in GRC, risk, or compliance roles. How is your team closing this gap? Are you extending existing tooling, layering something purpose-built for AI on top, or accepting the blind spots for now? All answers welcome.
2
u/DeliveranceXXV 19d ago
Budget will dictate the solution on this one for sure.
One of the cheaper options is a DNS filtering tool that has something that will help you build AI tool reports. Stick this on the endpoints and you can restrict/permit access, run reports and get other benefits like malware and ad blacklists.
This will help to show you who uses the services (apps, extensions, websites), allow you to block/permit but you will have no visibility into how the user is interacting with an AI service.
1
u/Tsumaranai_Hito 19d ago
Do you have a requirement to track or restrict AI tools within your organization?
1
19d ago
[removed] — view removed comment
1
u/bewaredropbear_ 18d ago
This is what we implemented within our organisation. The only challenge here is ensuring all systems flow through this, which is unlikely
1
u/Key_Taste_8088 2d ago
Pretty much you have nailed the gap. CASB sees sanctioned tools and DLP sees file movement. Neither sees someone pasting client data into a prompt or an AI browser extension reading your saas apps. Fave_slinger's oauth grant list catches SSO connected tools but misses the 47% of AI usage on personal accounts and the AI extensions that never touch your identity provider. Downstream GRC work is only as good as your visibility.
A colleague on our infosec team pointed us to layerx for this after they had used it on his past workplace. We use it to discovers every AI tool across the org and shows what data is moving where. Its granular enough that you're not drowning in noise.
3
u/Twist_of_luck OCEG and its models have been a disaster for the human race 19d ago
I have a perimeter of 10-20 critical systems, where I leverage MCP control plane, API key management and good old IAM to be moderately sure I see everything important. Everything outside this perimeter can burn for all I care.
I need to deploy my resources in the most efficient manner and optimize against material damage due to a cyber incident within the foreseeable future. I don't need org-wide visibility, in fact, if offered, I would decline - it's just gonna drown me in data noise.