Skip to main content

    Shadow AI discovery

    Shadow AI discovery, from the laptop to the control plane

    Coding assistants, desktop AI apps, and CLI tools reach AI services straight from the laptop, where gateways and browser tools may never see them. Find them with Behest Radar, free, then govern the usage you approve in Behest, the control plane for enterprise AI.

    The short version

    What is shadow AI discovery?

    Shadow AI discovery is the process of finding the AI tools, models, and services people in an organization use without IT or security approval. Behest Radar does it on employee and developer machines for free. Behest, the control plane for enterprise AI, governs the AI calls routed through it.

    New to the term? The glossary explains what shadow AI discovery means and what shadow AI is.

    Four places shadow AI hides, and what Behest Radar finds

    Behest Radar looks from the machine itself, so it finds shadow AI wherever it runs: known AI services and unknown ones.

    • Endpoint apps and CLIs

      Shadow AI by name, plus local model usage.
    • Network and SSE

      Traffic to known AI services, plus unknown hosts that look like AI, on or off the corporate network.
    • Browsers

      Which browsers reach AI sites, known or unknown, and how much.
    • AI browsers and browser plugins

      AI browsers by name or process name; plugin traffic shows up as its browser's.

    Behest Radar observes only: it never blocks or changes traffic. The guide to detecting shadow AI walks through free ways to check each place.

    What Behest Radar finds

    Behest Radar is a free, on-device shadow AI discovery tool that shows which AI services a machine is using and estimates what they cost. It is built for the laptop, where coding assistants, desktop AI apps, and CLI tools call AI providers directly.

    • Which apps reach AI services

      Radar discovers connections from coding assistants, desktop AI apps, and CLI tools to known AI services like OpenAI, Anthropic, Gemini, and others, and matches each connection to the app that made it, such as Claude Code or Cursor.

    • Apps it has not met before

      An app Radar does not recognize by name still appears under its process name when it connects to a known AI service, so a new coding agent does not stay invisible.

    • Tokens it can count and price

      With your permission, Radar reads the tools' own local records: token counts for Claude Code, Codex CLI, and Claude Cowork; list-price cost for Claude models. Codex usage shows tokens but no cost; other tools show model and tokens only with the optional certificate, and no cost.

    • Nothing done to your traffic

      By default Radar watches connections from the outside and does not change, slow, or stop them. With the optional certificate, AI API traffic passes through a local proxy on the machine that reads usage and never blocks or edits it.

    Install Radar and start it with administrator access. It needs no API keys and no changes to your AI tools. A standalone install sends nothing and has no telemetry, and Radar does not store or send prompts by default. Coverage has limits: it recognizes known AI services, counts connections rather than individual requests by default, misses connections opened before it started, and a machine without Radar is invisible to it. Learn more about Behest Radar.

    Estimating shadow AI cost

    Shadow AI spend rarely shows up as one line item. It hides in personal subscriptions expensed as software, API keys on a team credit card, and coding assistants billed per seat outside procurement. That is shadow AI spend, and nobody owns it until someone finds it.

    Behest Radar can put numbers on part of it. With permission, it reads the tools' own local records: token counts for Claude Code, Codex CLI, and Claude Cowork; list-price cost for Claude models. Codex usage shows tokens but no cost; other tools show model and tokens only with the optional certificate, and no cost. For someone on a subscription, the cost figure is a list-price equivalent, not the bill: it shows what the same usage would cost on metered API pricing.

    For the rest, start from the records you already have: expense reports, card statements, and provider invoices. The AI cost exposure calculator gives a first estimate of what ungoverned AI could cost at your scale. Once sanctioned calls run through Behest, AI Token FinOps, the cost-control layer, attributes that spend to teams and projects and holds it to a budget. The shadow AI cost guide goes deeper.

    From discovery to control

    Discovery tells you what is happening. Control changes it. Behest Radar is the first step, and the Behest control plane does the rest.

    1. 1

      Discover on each machine

      Install Behest Radar on employee and developer machines. A standalone install sends nothing: it shows the person at that machine which AI services it uses, and it does not store or send prompts by default.

    2. 2

      Bring machines into one inventory

      Machines an organization connects to Behest Control appear in one device inventory, so security and finance see shadow AI across the organization instead of one laptop at a time. Each machine sends usage data at the sharing level chosen in Behest Control. Usage data carries no name, email or account name of its own. Behest Control attributes it to the device, which your administrator registers with its serial number and hostname and, if they choose, the user's email. Tell people before you connect their machines, and agree the rollout with HR, legal, or your privacy team: data about a person's work machine can count as personal data, and employee-monitoring rules apply in many places.

    3. 3

      Decide what is sanctioned

      Sort what you found into approved, under review, and not allowed, and give approved tools a sanctioned path. The AI usage policy template is a starting point.

    4. 4

      Govern and control the calls

      Route sanctioned AI calls through Behest, the control plane for enterprise AI, with model allowlists that decide which teams use which models. AI Token FinOps, the cost-control layer, attributes spend and enforces budgets; cost-aware routing picks each model on cost and policy; and AI Governance keeps an audit trail, with PII scrubbing and prompt-injection defense on the Enterprise plan.

    Want the full governance playbook? Read how to govern shadow AI.

    Alongside CASB and SSE

    If you already run a cloud access security broker (CASB) or a security service edge (SSE) platform, keep it. Endpoint discovery fills a different gap.

    What CASB and SSE platforms cover

    They sit in the path of web and SaaS traffic. They see AI websites and SaaS apps used through the corporate proxy, can apply data policies to that traffic, and report on it in one console.

    What Behest adds

    Behest Radar looks from the endpoint, so it sees coding assistants and CLI tools that call AI providers directly, including on laptops that are off the network. Behest then puts sanctioned AI calls under cost control and governance on the request path, which a traffic inspection tool is not built to do.

    Use them together: CASB and SSE for web and SaaS traffic, Behest Radar for the endpoint, and Behest for the AI calls you sanction. They complement each other rather than overlap.

    Frequently asked questions

    Four places: the endpoint, where coding assistants, desktop AI apps, and CLI tools call AI providers directly; network traffic, on or off the corporate network; the browsers people use to reach AI sites; and AI browsers and browser plugins. Behest Radar finds shadow AI in each of them from the machine itself, and it observes only.

    All four places in the table: the endpoint, where it finds apps and agents by name plus local models; connections to known AI services, plus unknown hosts that look like AI, on or off the corporate network; which browsers reach AI sites, and how much; and AI browsers and plugins, which show up by name or as their browser's traffic. It does not see what was typed in a browser.

    With Behest Radar, connect machines to Behest Control. A standalone Radar install covers one machine and sends nothing. Machines an organization connects to Behest Control appear in one device inventory, and each sends usage data at the sharing level chosen there. Tell people before you connect their machines. That inventory, not a single laptop, is the organization-level view.

    A CASB or SSE platform sees SaaS activity and web traffic that passes through your security stack. Behest Radar looks from the machine itself, so it also sees coding assistants and CLI tools on laptops that are off the corporate network or never touch the proxy. The two are complementary: many organizations use both.

    They are list-price estimates for Claude models only, not invoices. With permission, Radar reads exact token counts from the local records of Claude Code, Codex CLI, and Claude Cowork. Codex usage shows tokens but no cost; other tools show model and tokens only with the optional certificate, and no cost. For subscription users the figure is a list-price equivalent, not the bill.

    Yes. Behest Radar is observe-only: it shows usage and does not enforce anything. Policy lives in the Behest control plane, where AI calls you route through Behest get model allowlists, budgets, cost-aware routing, and an audit trail, with PII scrubbing and prompt-injection defense on the Enterprise plan.

    Not by default. A standalone install sends nothing and has no telemetry, and Radar does not store or send prompts by default. If an organization connects a machine to Behest Control, it sends usage data at the sharing level chosen there. Only the full sharing level adds Git branch names, session titles, and redacted prompt excerpts; the discovery and metadata levels send no prompt content.

    Find your shadow AI, then control it

    Start free on your own machine with Behest Radar. When you are ready to see the whole organization and put AI calls under budgets and policy, book a demo of Behest Control and the control plane.

    Behest Radar: Find the shadow AI on your machines. Free download.

    Get Radar free