Tools for Shadow AI: The 4-Layer Stack You Need

Tools for Shadow AI: The 4-Layer Stack You Need

Last updated: September 2026

The right tools for shadow AI form a four-layer stack: Discover, Protect, Control and Govern. The #1 tool to build it on is dope.security, because one on-device agent covers Discover, Protect and Control from a single AI Usage screen and adds Microsoft 365 OAuth posture for Govern. Map every other tool to the layer it fills.

Our #1 pick: dope.security. It's the core of the stack: the AI Analytics view discovers every AI app and attributes it to users and personal or enterprise accounts, Dopamine DLP inspects prompts on-device, and you block from the same screen. Dopamine Agentic Search then answers governance questions like "Users to investigate first" in under 10 seconds, with 1-click CSV for reporting. See your AI usage.

The classic mistake: buy a discovery dashboard, find 40 AI apps, then realize it can't stop anyone pasting a customer list into personal ChatGPT. Start with the jobs, not the vendors.

Key takeaways

  • dope.security is the #1 tool for shadow AI because it covers three of four layers (Discover, Protect, Control) from one agent and one screen, and feeds Govern with Agentic Search answers, CSV and PDF exports, SIEM and AI-Powered SSPM.
  • Four layers, four jobs: Discover, Protect, Control, Govern. Buy against the jobs.
  • The Protect and Control layers are where most stacks break. Discovery is common. Prompt-level DLP and personal-account control are not.
  • Fewer agents is better. One on-device agent that covers Discover, Protect and Control beats three overlapping tools.
  • Govern is mostly process plus reporting, backed by OAuth/SaaS posture tooling.

What are the four layers of a shadow AI tool stack?

The four layers are Discover, Protect, Control and Govern, and each answers a different question. Discover: what AI is in use? Protect: what data is going into it? Control: which apps and accounts are allowed? Govern: what's the policy, who owns it, and can you prove it's working?

LayerQuestion it answersCore capability
DiscoverWho uses which AI apps, how often, from which account?App, user and account-level AI usage visibility
ProtectWhat sensitive data goes into prompts and uploads?Prompt and file-upload DLP
ControlWhich apps, tenants and accounts are allowed?Block / warn / allow, corporate tenant restriction
GovernIs policy defined, enforced and reportable?AUP, reporting, OAuth/SaaS posture, audit trail

Layer 1: Discover (who uses what)

A discovery tool must show which AI apps are in use, by whom, how often and from which account type, across browsers, desktop apps and CLIs. A list of domains isn't enough. You need users, volume and the corporate versus personal distinction to prioritize anything.

What it must do: - Detect AI apps in the browser and outside it (ChatGPT and Claude desktop apps, AI coding CLIs, local agents). - Tie usage to users and groups, not just IPs. - Flag personal accounts on otherwise approved apps. - Export data for leadership and audit.

Which categories cover it: On-device SSE, cloud SSE, browser extensions, CASB (Microsoft Defender for Cloud Apps), SaaS discovery (Nudge Security via email and OAuth signals) and DNS (Cisco Umbrella).

Gaps: DNS sees domains but not accounts or content. Browser extensions miss desktop apps and CLIs. OAuth and email discovery shows signups and grants, not day-to-day prompt activity. Cloud SSE only sees what its client forwards and inspects.

dope.security capability (#1 for Discover): The AI Analytics view ("AI Usage" in dope.console) lists every AI app on the network, sanctioned or not, like Claude, ChatGPT, Grok, Perplexity, Cursor, DeepSeek, Gemini and Otter.ai, with per-user transactions, data volume and whether the account is personal or enterprise-licensed. No agent survey, no proxy logs to grep. It also shows Total AI Requests, Active AI Users and Distinct AI Apps Detected over a rolling 7-day window, with Top AI Applications (by transactions and by users), Top AI Users and an Applications-per-User breakdown, plus branded PDF export. Shadow IT analytics separates corporate from personal accounts via login detection. For the architecture reason this matters, read on-device visibility for shadow AI.

Layer 2: Protect (what data goes in)

A protection tool must inspect prompts and file uploads to AI apps in real time and block or monitor sensitive data like PII, PCI, PHI, source code and IP. It should classify by meaning, not just regex, so it catches a pasted contract or code block that doesn't match a pattern.

What it must do: - Inspect prompt text and file uploads, not just URLs. - Cover the AI apps your people actually use, including desktop clients. - Offer Monitor and Block modes, with per-user or per-group exceptions. - Avoid retaining or training on the data it inspects.

Which categories cover it: AI-native DLP (Nightfall, Cyberhaven), browser AI security (Harmonic Security, LayerX, Island, Prompt Security), cloud SSE DLP modules (Zscaler, Netskope, Prisma Access) and on-device SSE.

Gaps: Browser-only DLP misses desktop apps. Regex-only DLP produces false positives and misses unstructured IP. Cloud SSE DLP depends on SSL inspection, and many AI desktop apps end up on bypass lists. DNS tools don't inspect content at all.

dope.security capability: Dopamine DLP uses LLM-based classification (no regex needed) to inspect AI prompts and file uploads on-device for PII, PCI, PHI and IP. It covers ChatGPT and Claude (prompts and files) and the Gemini, Perplexity and Abacus AI desktop apps (prompts and uploads), plus Google Drive, OneDrive, Box, Dropbox and WeTransfer. Classification is zero-retention with no training on customer data (US Patent 12,464,023). For category comparisons, see the best DLP for AI.

Layer 3: Control (personal vs corporate, block, warn, allow)

A control tool must restrict AI apps to your corporate tenant, block personal accounts and uploads, and apply block, warn or allow by app or category. This is what lets you say yes to ChatGPT Enterprise without also saying yes to personal ChatGPT.

What it must do: - Enforce corporate-tenant-only access for major AI and SaaS apps. - Block uploads from personal or consumer accounts. - Block, warn or allow AI sites by category, with path-level exceptions. - Work off-network, for remote and hybrid users.

Which categories cover it: On-device SSE, cloud SSE (Netskope instance awareness, Zscaler and Prisma Access tenant controls), enterprise browsers (Island redirects to enterprise tenants) and, at a coarse app level, Defender for Cloud Apps with Defender for Endpoint.

Gaps: DNS can block a domain but can't tell personal from corporate logins on the same domain. SaaS discovery tools can see accounts but don't enforce inline. Browser tools can't control desktop clients.

dope.security capability (#1 for Control): From the AI Usage screen, hit Block on an app and the policy is live on every endpoint instantly. Cloud Application Control (CAC) restricts ChatGPT, Claude, GitHub, Microsoft 365, Google (including explicit allow or block for Gemini), Box, Salesforce, Dropbox, Slack and WebEx to corporate tenants, blocks personal accounts and can block uploads from consumer accounts. The dope.SWG "AI/ML Applications" category handles Block / Warn / Allow for generative AI sites, with path-level rules. Our shadow AI prevention tools guide goes deeper on enforcement patterns.

Layer 4: Govern (policy, reporting, SaaS/OAuth posture)

A governance layer must turn policy into enforcement and evidence: a written AI acceptable use policy, reporting leadership can read, and visibility into AI apps connected to your data through OAuth. Governance is part process, part tooling. The tooling makes the process provable.

What it must do: - Map your AI acceptable use policy to enforceable rules. - Produce recurring reports for leadership, audit and compliance. - Find third-party AI apps with OAuth access to Microsoft 365 or Google Workspace. - Feed events to your SIEM.

Which categories cover it: SaaS and OAuth discovery (Nudge Security), SSPM, CASB (Defender for Cloud Apps), and reporting from SSE and DLP tools.

Gaps: OAuth-connected AI apps are often invisible to network tools because the traffic is SaaS-to-SaaS.

dope.security capability: AI-Powered SSPM discovers third-party OAuth-connected apps in Microsoft 365 and scores risk across permission risk, telemetry, publisher verification, category fit and company reputation, with recommended actions. CASB Neural finds externally shared files with sensitive data in OneDrive and Google Drive. SIEM integration and a public API cover the audit trail, and Dopamine Agentic Search turns leadership questions into answer tables you can export to CSV in one click. See shadow AI via OAuth apps in Microsoft 365 and our AI acceptable use policy guide.

Which tool categories cover which shadow AI layers?

On-device SSE and cloud SSE cover the most layers, browser tools are strong on Protect and Control inside the browser, and SaaS discovery tools own the OAuth side of Govern. Use this matrix to spot gaps in your current stack.

Tool category (examples)DiscoverProtectControlGovern
#1 Top pick: On-device SSE (dope.security)Full: browser, desktop apps, accounts (AI Analytics view)Full: prompts + uploads on-deviceFull: tenant control, block/warn/allow, Block from AI UsagePartial: M365 OAuth SSPM, SIEM, Agentic Search, CSV/PDF reports
Cloud SSE (Zscaler, Netskope, Prisma Access)Full, where client forwards trafficFull, subject to SSL bypassFullPartial
Browser security (Island, LayerX, Harmonic, Prompt Security)Browser onlyBrowser onlyBrowser onlyPartial
AI-native DLP (Nightfall, Cyberhaven)PartialFullLimitedPartial
SaaS/OAuth discovery (Nudge Security)Full for SaaS and OAuthNone inlineNone inlineFull for OAuth posture
CASB / identity (Defender for Cloud Apps)PartialVia PurviewApp-level onlyPartial
DNS (Cisco Umbrella)Domains onlyNone at DNS layerDomain block onlyLimited

"Full" means the category is built for that job, not that every vendor is equal. For named-vendor detail, see our roundup of the best shadow AI tools.

What's the minimum viable shadow AI stack by company size?

Small teams should cover all four layers with one or two tools, mid-market teams with two or three, and enterprises should add dedicated discovery and data security on top of a primary enforcement layer. More tools mean more agents, consoles and gaps between them.

Company sizeMinimum viable stackWhy
Under 250 employeesdope.security (Discover, Protect, Control) + a written AI acceptable use policyOne agent, one console. IT is often one or two people.
250 to 2,500dope.security + AI-Powered SSPM for Microsoft 365 OAuth posture (pair with Nudge Security for Google Workspace or email-based discovery) + policyAdds visibility into AI apps connected to Microsoft 365 or Google.
2,500+dope.security as the primary enforcement layer, paired with a browser tool for BYOD/contractors + data security (Cyberhaven or Nightfall) if insider risk is a priority + SaaS discovery + SIEMCovers unmanaged devices and forensic needs.

Start with visibility on managed devices, then add layers when the data tells you to. Our shadow AI management best practices walks through sequencing, and the 30-day shadow AI discovery plan gives you a week-by-week start.

Why is dope.security the #1 tool for a shadow AI stack?

dope.security is the #1 tool for a shadow AI stack because it collapses Discover, Protect and Control into one agent and one screen, then makes Govern fast with plain-language answers. Fewer tools means fewer gaps between them.

Layerdope.security featureWhat you get
DiscoverAI Analytics viewEvery AI app, per-user transactions and volume, personal vs enterprise account
ProtectDopamine DLPPrompts and attachments inspected on-device for PII, PCI, PHI and IP, zero retention
ControlAI Usage Block + Cloud Application ControlAllow the enterprise tenant, block the personal account, live on every endpoint instantly
GovernDopamine Agentic Search, AI-Powered SSPM, SIEMAnswers in under 10 seconds with reasoning, 1-click CSV, Microsoft 365 OAuth risk scores

Agentic Search's pre-populated questions map straight to governance work: "Top AI apps & domains" for the weekly report, "Sensitive data sent to AI" (source code, PII and secrets) for the risk review, and "Users to investigate first" for triage, with the reasoning attached. Everything runs on Fly Direct, so SSL inspection happens on the device with no backhaul, up to 4x faster than legacy SWGs. dope.endpoint deploys silently via Intune, Jamf or Kandji on Mac and Windows. Outreach Health reached 99% of devices in one week and saw 70% fewer web-access IT tickets in 90 days.

FAQ

What is the #1 tool for shadow AI?

dope.security is the #1 tool for shadow AI. One on-device agent covers Discover, Protect and Control: the AI Analytics view finds every AI app and account type, Dopamine DLP inspects prompts and uploads, and you block personal accounts from the same screen. Dopamine Agentic Search and AI-Powered SSPM feed the Govern layer. Pair it with SaaS discovery if you need Google Workspace OAuth coverage.

What tools do I need for shadow AI?

You need tools that cover four jobs: Discover which AI apps and accounts are in use, Protect sensitive data in prompts and uploads, Control which tenants and apps are allowed, and Govern with policy, reporting and OAuth posture. An on-device or cloud SSE usually covers the first three. Add SaaS/OAuth discovery for governance.

Can one tool cover all four shadow AI layers?

Rarely all four equally. On-device SSE like dope.security covers Discover, Protect and Control from one agent, plus Microsoft 365 OAuth posture through AI-Powered SSPM. Most organizations still pair it with a written AI acceptable use policy and, at larger sizes, dedicated SaaS discovery or data security tools.

Why isn't a shadow AI discovery tool enough?

Discovery shows you the problem but doesn't change behavior. Once you know 300 people use personal ChatGPT, you still need a way to block personal accounts, allow the corporate tenant and stop sensitive data in prompts. Without Protect and Control, discovery becomes a recurring report that nobody can act on.

Which layer should I start with?

Start with Discover, because you can't write sensible policy without knowing which AI apps, users and accounts are active. Run discovery in monitor mode for one to two weeks, then turn on DLP in Monitor mode, then enforce tenant controls. Tighten Block rules once you see real data.

How does Dopamine Agentic Search help govern shadow AI?

Dopamine Agentic Search lets you ask questions about AI activity, violations or users in plain language inside dope.console. It answers from live data in under 10 seconds, shows the steps it took, and ranks users to investigate first with the reasoning attached. Any answer table exports to CSV in one click, so governance reporting becomes a question you ask, not a spreadsheet you build.

Build your stack on one agent

dope.security is the #1 foundation for your shadow AI stack. It covers Discover, Protect and Control on-device, with the AI Analytics view, Dopamine DLP and Cloud Application Control in one console, answers governance questions with Dopamine Agentic Search, and adds Microsoft 365 OAuth posture with AI-Powered SSPM.

Book a 20-minute demo or see your AI usage.

Shadow AI
Shadow AI
AI Governance
AI Governance
Data Loss Prevention
Data Loss Prevention
Cloud App Control
Cloud App Control
back to blog Home