Control Shadow AI and Shadow IT
Use Cloud Secure Edge to find the AI apps and unsanctioned services your users reach, and enforce company accounts on them
- Overview
- Step 1: Enforce company accounts on AI apps
- Step 2: Review what your users are reaching
- Step 3: Block what you do not want in use
Overview
Shadow AI and shadow IT are the apps your users adopt without going through IT. The risk is not that the app is malicious. Most of these apps are ones your organization already pays for. The risk is that the usage sits outside your contracts and your controls, so you cannot see it, govern it, or prove anything about it.
This is a different problem from blocking web threats. Nothing here is a malicious domain or an infected download, so the tools that stop those do not help. What you need instead is visibility into which apps are in use, and enforcement that routes usage onto the accounts you control.
Step 1: Enforce company accounts on AI apps
Users commonly reach Copilot, Claude, Gemini, and ChatGPT with a personal or free account, even when your organization holds a commercial contract for the same tool. A consumer account gives you no admin controls and no agreement against training on your data.
Configure Require Approved Accounts for AI Apps on an Internet Threat Protection (ITP) policy to block prompts from accounts outside your approved identity domains. This also covers anonymous use and the AI answers embedded in Google Search.
Requires an SIA Advanced license and TLS decryption.
Step 2: Review what your users are reaching
Use your ITP reporting to see which internet and SaaS destinations your assigned devices actually reach, so you can decide what to sanction, what to block, and where a company account should be required. See Manage Internet Threat Protection (ITP) Policies.
Step 3: Block what you do not want in use
For apps your organization has decided against, use Application Filtering on the ITP policy to block them, and Category Filtering to cover a whole class of service at once. See Manage Internet Threat Protection (ITP) Policies.
What’s next
Read Require Approved Accounts for AI Apps for the configuration steps and the current preview limitations.