Shadow AI discovery
Shadow AI discovery, from the laptop to the control plane
Coding assistants, desktop AI apps, and CLI tools reach AI services straight from the laptop, where gateways and browser tools may never see them. Find them with Behest Radar, free, then govern the usage you approve in Behest, the control plane for enterprise AI.
The short version
What is shadow AI discovery?
Shadow AI discovery is the process of finding the AI tools, models, and services people in an organization use without IT or security approval. Behest Radar does it on employee and developer machines for free. Behest, the control plane for enterprise AI, governs the AI calls routed through it.
New to the term? The glossary explains what shadow AI discovery means and what shadow AI is.
Four places shadow AI hides, and what Behest Radar finds
Behest Radar looks from the machine itself, so it finds shadow AI wherever it runs: known AI services and unknown ones.
| Where to look | What Behest Radar finds |
|---|---|
| Endpoint apps and CLIs | Shadow AI by name, plus local model usage. |
| Network and SSE | Traffic to known AI services, plus unknown hosts that look like AI, on or off the corporate network. |
| Browsers | Which browsers reach AI sites, known or unknown, and how much. |
| AI browsers and browser plugins | AI browsers by name or process name; plugin traffic shows up as its browser's. |
Endpoint apps and CLIs
Shadow AI by name, plus local model usage.Network and SSE
Traffic to known AI services, plus unknown hosts that look like AI, on or off the corporate network.Browsers
Which browsers reach AI sites, known or unknown, and how much.AI browsers and browser plugins
AI browsers by name or process name; plugin traffic shows up as its browser's.
Behest Radar observes only: it never blocks or changes traffic. The guide to detecting shadow AI walks through free ways to check each place.
What Behest Radar finds
Behest Radar is a free, on-device shadow AI discovery tool that shows which AI services a machine is using and estimates what they cost. It is built for the laptop, where coding assistants, desktop AI apps, and CLI tools call AI providers directly.
Which apps reach AI services
Radar discovers connections from coding assistants, desktop AI apps, and CLI tools to known AI services like OpenAI, Anthropic, Gemini, and others, and matches each connection to the app that made it, such as Claude Code or Cursor.
Apps it has not met before
An app Radar does not recognize by name still appears under its process name when it connects to a known AI service, so a new coding agent does not stay invisible.
Tokens it can count and price
With your permission, Radar reads the tools' own local records: token counts for Claude Code, Codex CLI, and Claude Cowork; list-price cost for Claude models. Codex usage shows tokens but no cost; other tools show model and tokens only with the optional certificate, and no cost.
Nothing done to your traffic
By default Radar watches connections from the outside and does not change, slow, or stop them. With the optional certificate, AI API traffic passes through a local proxy on the machine that reads usage and never blocks or edits it.
Install Radar and start it with administrator access. It needs no API keys and no changes to your AI tools. A standalone install sends nothing and has no telemetry, and Radar does not store or send prompts by default. Coverage has limits: it recognizes known AI services, counts connections rather than individual requests by default, misses connections opened before it started, and a machine without Radar is invisible to it. Learn more about Behest Radar.
Estimating shadow AI cost
Shadow AI spend rarely shows up as one line item. It hides in personal subscriptions expensed as software, API keys on a team credit card, and coding assistants billed per seat outside procurement. That is shadow AI spend, and nobody owns it until someone finds it.
Behest Radar can put numbers on part of it. With permission, it reads the tools' own local records: token counts for Claude Code, Codex CLI, and Claude Cowork; list-price cost for Claude models. Codex usage shows tokens but no cost; other tools show model and tokens only with the optional certificate, and no cost. For someone on a subscription, the cost figure is a list-price equivalent, not the bill: it shows what the same usage would cost on metered API pricing.
For the rest, start from the records you already have: expense reports, card statements, and provider invoices. The AI cost exposure calculator gives a first estimate of what ungoverned AI could cost at your scale. Once sanctioned calls run through Behest, AI Token FinOps, the cost-control layer, attributes that spend to teams and projects and holds it to a budget. The shadow AI cost guide goes deeper.
From discovery to control
Discovery tells you what is happening. Control changes it. Behest Radar is the first step, and the Behest control plane does the rest.
- 1
Discover on each machine
Install Behest Radar on employee and developer machines. A standalone install sends nothing: it shows the person at that machine which AI services it uses, and it does not store or send prompts by default.
- 2
Bring machines into one inventory
Machines an organization connects to Behest Control appear in one device inventory, so security and finance see shadow AI across the organization instead of one laptop at a time. Each machine sends usage data at the sharing level chosen in Behest Control. Usage data carries no name, email or account name of its own. Behest Control attributes it to the device, which your administrator registers with its serial number and hostname and, if they choose, the user's email. Tell people before you connect their machines, and agree the rollout with HR, legal, or your privacy team: data about a person's work machine can count as personal data, and employee-monitoring rules apply in many places.
- 3
Decide what is sanctioned
Sort what you found into approved, under review, and not allowed, and give approved tools a sanctioned path. The AI usage policy template is a starting point.
- 4
Govern and control the calls
Route sanctioned AI calls through Behest, the control plane for enterprise AI, with model allowlists that decide which teams use which models. AI Token FinOps, the cost-control layer, attributes spend and enforces budgets; cost-aware routing picks each model on cost and policy; and AI Governance keeps an audit trail, with PII scrubbing and prompt-injection defense on the Enterprise plan.
Want the full governance playbook? Read how to govern shadow AI.
Alongside CASB and SSE
If you already run a cloud access security broker (CASB) or a security service edge (SSE) platform, keep it. Endpoint discovery fills a different gap.
What CASB and SSE platforms cover
They sit in the path of web and SaaS traffic. They see AI websites and SaaS apps used through the corporate proxy, can apply data policies to that traffic, and report on it in one console.
What Behest adds
Behest Radar looks from the endpoint, so it sees coding assistants and CLI tools that call AI providers directly, including on laptops that are off the network. Behest then puts sanctioned AI calls under cost control and governance on the request path, which a traffic inspection tool is not built to do.
Use them together: CASB and SSE for web and SaaS traffic, Behest Radar for the endpoint, and Behest for the AI calls you sanction. They complement each other rather than overlap.
Frequently asked questions
Find your shadow AI, then control it
Start free on your own machine with Behest Radar. When you are ready to see the whole organization and put AI calls under budgets and policy, book a demo of Behest Control and the control plane.