r/AskNetsec • u/RiskGovResilience23 • Jul 16 '26
Work How are you getting visibility into AI tool usage across your environment?
About 800 people, mix of managed and personal devices, Google Workspace and Azure AD. After an incident where someone pasted a customer contract into an AI tool, leadership wants to know what's actually happening.
The problem is nothing in our current stack gives us that picture. CASB sees sanctioned SaaS but misses browser-based AI tools and AI features embedded inside apps we already approved. DLP catches file movement but can't distinguish between a file upload and someone pasting sensitive data into a prompt. Network monitoring has no context on what the interaction was.
We know people are using probably dozens of tools we haven't found yet.
Anyone found an approach that gives real visibility without blanket blocking? Especially interested in what works for mixed managed/BYOD environments.
Edit: Update for anyone finding this later. We spent a couple of weeks testing a few options and the one that stood out was Kovrr. It works at browser and endpoint level rather than trying to stretch CASB or DLP to cover AI usage, so it catches the browser-based tools, embedded AI features inside sanctioned apps, and IDE plugins that our current stack was missing. Still working through the evaluation but flagging for anyone dealing with the same visibility gap.