Use Case · Shadow AI Discovery

Shadow AI & Agent Discovery System

Passive discovery of unsanctioned AI usage across the enterprise stack. Records only the unique usage needed for governance—no raw payloads stored. Extracts operational context to a clean governance state.

Works with every shadow ai discovery

AWS BedrockAWS BedrockAzure AI FoundryAzure AI FoundryGoogle Vertex AIGoogle Vertex AICloudflareCloudflarePalo Alto NetworksPalo Alto NetworksZscalerZscalerKubernetesKubernetesNextDNSNextDNSLiteLLMLiteLLMNative ScannerNative Scanner
Walkthrough demonstration

See Shadow AI Discovery in action

Watch Gödel discover unauthorized AWS Bedrock Agents, self-hosted models on Kubernetes, and unsanctioned model endpoints—reducing raw signals to clean, actionable governance states without storing sensitive prompts.

Passive Discovery Connectors

Seamlessly ingest passive metadata across Cloud AI Platforms (AWS, Azure, GCP), Gateways (LiteLLM, Cloudflare), Network Proxies (Zscaler, Palo Alto), and VPC flow logs without storing raw prompts or payloads.

Shadow AI Discovery Screenshot 1

AI Registry & Sanctions Governance

Manage organization-wide sanction decisions across discovered AI providers, foundation models, and local inference runtimes with deterministic enforcement rules.

Shadow AI Discovery Screenshot 2
GOVERNANCE MODEL

The Sanctions and Governance Model.

Once Shadow AI or an unknown agent is discovered, Atlas applies its global sanctions model to govern usage effectively.

01

Provider Sanctions

Apply to a specific API, cloud platform, or local runtime.

02

Model Sanctions

Global across all providers. For example, sanctioning Llama-3 applies whether it is hosted on AWS, Azure, or locally.

03

State: Undecided

Newly discovered, unknown AI providers and models are placed in the Authorization Queue for review.

04

State: Unsanctioned

Generates a violation when usage is detected. Built-in providers headquartered in high-risk regions can default to unsanctioned.

Caught at runtime

Six ways data walks out.
Six verdicts before it does.

Real traces from the enforcement path. Every action is attributed to its user and agent identity, checked against the data it actually touches, and decided in under 5 ms — locally, before the payload leaves the process.

Unapproved AWS Bedrock Agents

UNDECIDED

AWS Bedrock Connector → bedrock:ListAgents

Engineers spin up unapproved AWS Bedrock Agents. Atlas discovers the new agents via scheduled API sync and places them in the Authorization Queue for review.

Self-Hosted Model on Kubernetes

UNDECIDED

K8s Discovery → Self-Hosted HuggingFace

An agentless K8s cluster scan detects a pod running an unknown local model. Operators review the findings and can sanction it for internal testing.

Shadow API Usage on Corporate Device

UNSANCTIONED

Palo Alto Networks → api.anthropic.com

Developers use personal API keys to query Claude directly. HTTPS logs flag the outbound traffic, which is marked Unsanctioned as it violates enterprise agreements.

Discovery Mesh

Detected in milliseconds,
on the endpoint.

Detection runs in milliseconds across cloud APIs, gateways, network telemetry, and local infrastructure. Atlas extracts only operational context to govern usage — zero raw chat payloads or streams are stored.

Cloud API Connectors

Cloud AI Platforms

Direct API telemetry across managed cloud AI infrastructure

ConnectorType
AWS Bedrock & SageMaker
AWS Bedrock & SageMaker
Cloud API
Azure OpenAI & Foundry
Azure OpenAI & Foundry
Cloud API
Google Vertex AI
Google Vertex AI
Cloud API
Gateway Connectors

AI Gateways & Proxies

Traffic inspection through corporate AI routers and reverse proxies

ConnectorType
Cloudflare AI Gateway
Cloudflare AI Gateway
Gateway
LiteLLM Router Gateway
LiteLLM Router Gateway
Router
Custom Enterprise Proxies
Custom Enterprise Proxies
Reverse Proxy
Network Connectors

Internet Access & Security

Egress monitoring across Secure Web Gateways and live DNS

ConnectorType
Zscaler ZIA / NSS
Zscaler ZIA / NSS
SWG / NSS
Cloudflare Zero Trust Gateway
Cloudflare Zero Trust Gateway
Zero Trust
NextDNS Live Analytics
NextDNS Live Analytics
Live DNS
Palo Alto Networks
Palo Alto Networks
Firewall
Cloudflare Logpush & CASB
Cloudflare Logpush & CASB
CASB
Infrastructure Connectors

Infrastructure Discovery

VPC packet flow logs, cluster scanners and native host daemons

ConnectorType
AWS / Azure / GCP VPC Flow Logs
VPC Flow
Kubernetes Cluster Discovery
Kubernetes Cluster Discovery
K8s Daemon
Native Scanner (built-in scanner)
Native Scanner (built-in scanner)
Host Daemon

Connectors span multiple vectors to ensure a complete mesh of discovery.

Full coverage

The 4 core controls,
working on this outcome.

Discovery isn't an isolated scanner. Every phase feeds continuous posture into our policy and sanctions engine.

01

Ingestion

Connectors ingest raw source metadata from DNS queries, network flows, cloud APIs, and proxy logs across your infrastructure.

02

Normalization

Raw streams are buffered in-process and normalized into standard observations. Buffers are transient and emptied on restart to protect privacy.

03

Detection

The Axum API analyzes normalized observations to identify specific AI Providers, Foundation Models, and Agent Frameworks in use.

04

Governance State

Observations are reduced to a unique (provider, model) finding and linked to the host device and user, ready for policy enforcement.

Discovery Pipeline

End-to-End Discovery Pipeline

A strict four-step reduction process: raw source metadata is buffered in-process, normalized into standard observations, mapped to 162+ foundation models, and attributed to the host user.

1. INGESTION (SOURCES)2. PROCESSING PIPELINE3. GOVERNANCE STATECloud AI PlatformsAWS Bedrock, Azure, VertexAI Gateways & ProxiesCloudflare AI Gateway, LiteLLMInternet & SecurityZscaler, Palo Alto, NextDNSInfrastructure DiscoveryVPC Flow Logs, K8s ClustersMetadata NormalizationExtracts identity & telemetry signalsZero prompt or payload retentionCatalog ClassificationMaps activity against 1,000+ AI models,agents, and tooling profilesAI Registry & PolicySanctionedApproved enterprise use & monitoredUnder ReviewDiscovered & queued for auditUnsanctionedPolicy violation blocked / alertedNormalized Signal Stream

Put a gate in front of every shadow ai discovery.

Local-first enforcement, deployed in minutes. Your agents keep shipping — the unsafe actions don't.