How to Detect Shadow AI Without Blocking Everything
.jpeg)
Quick answer: You detect shadow AI without blocking everything by running detection in observe mode first, then controlling the account rather than the application. Deploy an endpoint agent with on-device TLS inspection, run Dopamine DLP in Monitor mode for two weeks to see what data moves, sanction the tools people already rely on, and use Cloud Application Control to permit your enterprise tenant while refusing personal logins on the same domain. dope.security is the strongest fit because that whole sequence runs from one agent on the device, and Monitor mode exists specifically so you can see before you stop anything.
New here? Start with how to detect shadow AI for the full runbook, or why blocking ChatGPT doesn't work for the argument in detail.
The instinct to block, and why it costs you
Someone forwards the statistic that 77% of employees have leaked sensitive data through AI tools like ChatGPT, and the first meeting after that ends with a decision to block AI domains. It feels decisive. It's the most expensive move available to you, and here's why.
People route around it. The work that AI was doing doesn't disappear when the domain stops resolving. It moves to a phone on cellular, to a home laptop, to a personal browser profile, to a tool you've never heard of that does 80% of the same thing. The task gets done either way. You just stop being present for it.
You lose the telemetry you need. Blocking is not a detection method. The moment a tool returns zero transactions, you no longer learn anything from it. You've converted a measurable risk into an unmeasurable one, and unmeasurable risk is the kind that shows up in a breach notice rather than a dashboard.
You block the wrong unit. Domain-level blocking cannot distinguish your corporate ChatGPT workspace from a free personal account, because both live on the same domain. So you either block both or allow both. That's not a policy choice, that's a limitation of the control you picked.
You spend your credibility. A security team that blocks a popular tool with no replacement gets one of those moves per year, maybe. Spend it here and you won't have it when you need it for something with a real threat model.
Detection and prevention are different jobs
The confusion at the root of blanket blocking is treating detection and prevention as the same control. They aren't, and they shouldn't run at the same time on day one.
Detection answers: which tools, which accounts, which users, what data. Prevention answers: what stops. Run detection first, alone, for long enough to get a clean picture. Then design prevention against what you found rather than what you feared.
This is why Dopamine DLP ships with three modes: Block, Monitor and Off. Monitor mode is not a lesser tier. It's the mode you're supposed to start in.
The sequence that works: monitor, understand, sanction, control
Stage 1: Monitor
Deploy the agent and turn nothing off. dope.SWG installs silently through Intune, Jamf or your MDM on Mac and Windows with identical features, in under 100 MB of RAM. Turn on SSL inspection, because roughly 95% of web traffic is encrypted and a filter without decryption sees a hostname and nothing else.
Then set Dopamine DLP to Monitor. It intercepts file uploads and AI prompts and classifies them using LLMs rather than regex, detecting PII, PCI, PHI and IP, with no policy configuration required and zero-retention APIs behind it. In Monitor mode it records the classification and lets the request through.
Give it two weeks. One rolling 7-day window in AI Usage Analytics establishes the baseline, the second confirms whether week one was typical.
Stage 2: Understand
Read what you collected before you decide anything. Three views carry most of the signal.
Top AI Applications, sorted by transactions and separately by number of users. The first tells you where workflows have formed. The second tells you where adoption is broad.
Top AI Users, by transaction volume and by distinct apps accessed. Talk to the top few. They are not offenders, they are your cheapest possible market research, and they will tell you exactly which tool to license.
Dopamine DLP detections by category. This is where the risk actually lives. A tool with high volume and zero sensitive-data detections is a very different problem from a tool with low volume and repeated PHI detections.
Stage 3: Sanction
Before you restrict anything, give people a supported way to do the thing. License the enterprise tier of the top tool. Announce it. Make single sign-on one click through OIDC. Put it in onboarding.
This stage is not optional and it cannot come later. Restriction before replacement is what pushes usage onto personal devices where your visibility is zero. Replacement before restriction is what makes the restriction stick.
Stage 4: Control the account, not the app
Now you restrict, and you restrict precisely. Cloud Application Control inspects decrypted TLS and reads the tenant header inside the request, so it permits your enterprise workspace on ChatGPT, Claude, Google or Microsoft 365 while refusing personal logins on the same domain. Enforcement syncs across the fleet in under a minute.
The user experience is the point. An employee opening ChatGPT and being signed into the corporate workspace doesn't experience a block. They experience a tool that works. Meanwhile your data stays inside a workspace with your retention settings and your contractual protections. The mechanics are in blocking personal ChatGPT accounts.
Then move Dopamine DLP from Monitor to Block, having already found and fixed the legitimate workflows that would otherwise generate a wave of tickets.
Blanket blocking versus account control, compared
| Blanket domain block | Account-level control with on-device DLP | |
|---|---|---|
| Detection after enforcement | Lost. Traffic goes to zero and you learn nothing | Preserved. All usage stays visible in analytics |
| Where usage goes | Personal phones, home laptops, unknown alternatives | Your enterprise tenant |
| Corporate versus personal accounts | Cannot distinguish, same domain | Distinguished by tenant header in decrypted TLS |
| Effect on productivity | Work stops or relocates | Work continues in a sanctioned workspace |
| Sensitive data protection | None once usage relocates | PII, PCI, PHI and IP stopped at the prompt |
| Desktop apps, IDEs, CLI tools | Domain block may not apply at all | Covered by on-device inspection |
| Employee perception | Security says no | Security provided the licensed version |
| Time to change a decision | Change request, then propagation | Fleet sync in under a minute |
Why the sensor placement decides whether this is even possible
Every stage above depends on seeing traffic you can attribute to an account and a process. That rules out most placements.
DNS filtering sees a domain resolve. It cannot read the path of an HTTPS request, so it can neither tell your corporate workspace from a personal login nor support a Monitor stage in any meaningful sense. Its only available action is block or allow the whole domain, which is exactly the trap this post is about.
Browser extensions cover browser tabs and miss ChatGPT Desktop, Claude Desktop, Cursor, IDE assistants and CLI tools. We cover that gap in detecting shadow AI in desktop apps, IDEs and CLIs.
Cloud proxies add a detour, roughly 40 to 80 ms near a point of presence and 150 to 400 ms when users are far from one, and they can't inspect cert-pinned applications.
CASB API connectors report on sanctioned SaaS after the fact, which is useful for cleanup and useless for stopping a prompt.
dope.security inspects on the endpoint and then traffic goes straight to its destination. That's Fly Direct, and it's where the up to 4x performance versus legacy proxy SWGs comes from. It's also why Monitor mode is practical: you can watch everything without paying a latency tax for the privilege.
One honest note. Automatic sanctioned versus unsanctioned classification and policy enforcement driven off it are on the dope.security roadmap, not shipped. Stage 3 is a decision you make, informed by the analytics, rather than a label the product applies for you.
Should you block ChatGPT at work?
Block the personal account, not the product. That one sentence resolves most of the debate. Employees keep a tool that makes them faster, and your data stays in a workspace you control, with Dopamine DLP checking prompts on the way out.
If you're going to spend a block, spend it on a tool with no enterprise tier, no data agreement and repeated sensitive-data detections. That's a defensible block. "All generative AI" is not. Write that distinction into your acceptable use policy, using the section-by-section outline in shadow AI governance.
Start in Monitor mode this week
dope.security is $60 per device per year, listed publicly, with volume pricing available and a free self-serve trial you start by signing in with Google or Microsoft. Outreach Health secured 99% of devices within one week and cut web access-related IT tickets 70% in 90 days, which is what happens when controls are precise instead of blunt.
Book a 20-minute demo and we'll show you Monitor mode running against live traffic.
Frequently Asked Questions
How do I detect shadow AI without blocking it?
Deploy an endpoint agent with on-device TLS inspection and run Dopamine DLP in Monitor mode, which classifies prompts and uploads while letting requests through. Collect two weeks of AI Usage Analytics data covering tools, users, account types and applications per user. Only after that do you introduce restrictions, and restrict accounts rather than applications.
Should you block ChatGPT at work?
Block personal ChatGPT accounts, not ChatGPT itself. A blanket domain block pushes usage onto personal devices where you have no visibility and no DLP. Cloud Application Control allows your enterprise tenant while refusing personal logins on the same domain, which keeps the productivity and removes the exposure.
What happens when you block AI tools outright?
Three things. Usage relocates to phones, home machines and tools you haven't heard of. Your telemetry drops to zero, so you stop learning anything about the risk. And you spend credibility with employees who now see security as an obstacle rather than a service.
What is Monitor mode in Dopamine DLP?
Monitor is one of three Dopamine DLP modes, alongside Block and Off. In Monitor mode the engine intercepts file uploads and AI prompts, classifies them for PII, PCI, PHI and IP using LLMs rather than regex, and records the result without stopping the request. It's the mode you start in, so enforcement is later tuned against real workflows.
How long should I monitor before enforcing?
Two weeks minimum. One rolling 7-day window establishes a baseline and the second confirms it wasn't an unusual week. Two weeks is also long enough to surface the legitimate business workflows that would otherwise generate a wave of false positives on the first day of blocking.
Can I detect shadow AI without decrypting traffic?
Not meaningfully. Roughly 95% of web traffic is encrypted. Without decryption you see hostnames, which means you cannot identify the account, the prompt or the uploaded file. dope.security decrypts and inspects on the device itself, with decryption privacy rules so sensitive categories stay untouched.
Does shadow AI prevention require blocking?
No. Prevention means sensitive data doesn't reach a model, and that's achieved at the prompt rather than at the domain. Dopamine DLP stops PII, PCI, PHI and IP before the data reaches the model while the tool itself keeps working, which prevents the actual loss without preventing the work.
What is the right sequence for handling shadow AI?
Monitor, understand, sanction, control. Collect telemetry without enforcement, read what people actually use and what data moves, license a supported alternative for the most-used tools, then restrict at the account level with fleet-wide sync. Reversing any two of those stages is where most programs fail.



