Shadow AI Detection: How to Find It on Your Network
Domain blocklists miss most shadow AI. See how TLS fingerprinting, NAC, asset reconciliation, and OAuth audits actually find it on your network.
Domain blocklists miss most shadow AI. See how TLS fingerprinting, NAC, asset reconciliation, and OAuth audits actually find it on your network.
Finding shadow AI already on your network takes four techniques working together, because no single scan catches all of it: TLS fingerprinting to spot AI client traffic even when it is encrypted, network access control to catch unmanaged devices before they connect at all, asset inventory reconciliation to catch the drift between what is documented and what is actually there, and an identity-side audit to catch the AI tools that never touched the network layer in the first place.
Table of Contents
ToggleA decade ago, finding an unauthorized asset meant finding a physical thing: a rogue access point, a personal laptop, a forgotten test server. Attackers are still finding easy entry through exactly that kind of gap. Research presented at RSA Conference 2025 by Trend Micro, surveying more than 2,000 cybersecurity leaders, found that 74% had experienced a security incident caused by an unknown or unmanaged asset, and 91% said attack surface management is directly tied to their organization’s actual business risk.
AI adds a category that does not fit the old picture at all. Shadow AI, an AI browser extension, a SaaS AI feature quietly switched on by a vendor, or an agent connected through an API key, never shows up as a device on a network diagram. It shows up as traffic, as a login, or as nothing visible at all if it operates entirely inside a tool you already approved. Any discovery approach still built only around finding physical or virtual devices will miss most of this by design.
The oldest layer is still worth doing well against shadow AI’s less exotic cousin: the physical or quasi-physical unmanaged device. Network access control, enforced through the 802.1X port-based authentication standard, checks a device’s credentials before it is allowed onto the network at all, rather than discovering it was there after the fact. Paired with DHCP fingerprinting, which identifies a device type from the pattern of its network configuration request, and a periodic wireless survey for access points nobody provisioned, this layer catches the physical and quasi-physical assets that started the shadow IT problem in the first place and never actually went away.
Zero trust’s core principle, never extend trust based on network location alone, is the same logic under a different name: a device earns access through verification, not by being physically plugged into the right port.
Discover how Threatcop protects your workforce from modern cyber threats.
Domain blocklists are the obvious next step, and they fail faster than most teams expect. AI services rotate infrastructure, sit behind shared CDNs, and multiply by the week, so a blocklist is permanently behind the services it is trying to catch.
TLS fingerprinting solves a narrower but more durable version of the problem. A technique called JA3, originally published by Salesforce’s engineering team, generates a fingerprint from the negotiation details of an encrypted connection’s opening handshake, details that reveal the client software making the connection without needing to decrypt anything. The same fingerprinting logic used for years to spot malware command-and-control traffic works just as well to spot the distinctive signature of an AI SDK or agent framework talking to its API, even when the payload itself is fully encrypted and the destination domain has never been seen before.
This will not name the specific employee or the specific tool with certainty on its own. What it does is turn “we have no idea if AI traffic exists on this network” into a specific, investigable list of connections worth a closer look, tied back to information security risk management‘s own basic premise: you triage what you can actually see.
An asset inventory is a claim about what exists. A network scan is a measurement of what actually does. The gap between the two is where shadow AI, along with almost everything else unmanaged, actually lives.
Attack surface research consistently finds a meaningful share of an organization’s real assets missing at least one baseline security control or invisible to its own vulnerability management tooling entirely, and that gap is not a one-time cleanup problem. It reopens continuously as teams provision new SaaS tools, employees connect new integrations, and vendors add AI features to platforms that were audited before those features existed.
Treat the mismatch itself as the signal. A scheduled reconciliation, comparing the CMDB or system of record against a fresh scan on a fixed cadence, and investigating every discrepancy rather than filing it away, does more to surface shadow AI than any single tool aimed specifically at AI detection, the same lesson that has already justified the cost of taking this seriously for the human side of the risk.
Some of the highest-risk shadow AI never generates network traffic worth fingerprinting, because it operates through a legitimate login rather than a new connection: an AI tool an employee authorized through their Google Workspace or Microsoft 365 account, using their real credentials, with standing access that persists until someone revokes it.
This is an identity problem, not a network one, which is exactly why it survives every layer above. Catching it means pulling the list of third-party applications authorized against corporate accounts and checking which of them touch mail, calendar, or documents, on a recurring schedule rather than once, the same discipline good DNS security practice already applies to a narrower, network-side problem. It is the one layer here that has nothing to do with the network at all, and skipping it because the other three layers feel more familiar is how an otherwise thorough discovery program still misses the riskiest cases.
Discovery programs fail less often from a bad method than from a good method nobody repeats. A minimum cadence:
None of this replaces continuous behavioral detection built around people, since the employee who connected the tool is still the fastest route to understanding why it is there and whether it should stay, the same premise behind an outbound email security policy that assumes the person, not just the system, is part of the control. A reporting culture that treats disclosure as routine, rather than something to hide from IT, will surface a meaningful share of this before any scan does.
Unknown assets caused the majority of the incidents Trend Micro’s research measured well before AI entered the picture, and shadow AI has not solved that problem. It has added a category that hides in places the old discovery methods were never built to check: encrypted traffic, SaaS features nobody requested, and access grants that live entirely outside the network. Finding it takes running all four layers on a schedule, not picking the one that feels most familiar, under the same people security management umbrella that already treats the human and the technical sides of a risk as one program rather than two.
Because AI services rotate infrastructure and sit behind shared cloud providers and CDNs faster than any blocklist can track, and new services launch constantly. A blocklist approach is structurally always behind the thing it is trying to catch.
TLS fingerprinting, sometimes called JA3 fingerprinting after the specific technique, identifies what software is making a network connection by examining the technical details of how the connection’s encryption is negotiated, not the encrypted content itself. It can flag a distinctive AI client or SDK talking to its API even when the destination is unfamiliar and everything sent is fully encrypted.
Quarterly is a reasonable baseline for most organizations, with every discrepancy between the documented inventory and an actual scan assigned to a specific owner rather than logged and left. The reconciliation itself, not just the scan, is what catches drift before it becomes an incident.
No. A meaningful share of the highest-risk shadow AI operates through a legitimate account login rather than new network traffic, which means it never appears in network or TLS-based monitoring at all. Finding it requires an identity-side audit of authorized third-party applications as a separate, recurring layer.
Both own pieces of it, but neither owns it alone. IT typically holds the asset inventory and identity systems where the clearest signals live, while security typically owns the judgment calls about what a discovered tool’s risk actually is, which is why a workable program needs both at the table on a fixed schedule, not just after an incident.
Shikha Mishra is responsible for driving the growth and adoption of TDMARC, a flagship product of Threatcop, across India, the Middle East, APAC, and the UK region. With her expertise, she helps organizations safeguard their domains so that no hacker can misuse them to send fraudulent emails, thereby protecting both their brand and reputation. She is passionate about enabling businesses to simplify the complexities of outbound email security through TDMARC’s comprehensive solution, allowing them to stay focused on what matters most to their success.
Shikha Mishra is responsible for driving the growth and adoption of TDMARC, a flagship product of Threatcop, across India, the Middle East, APAC, and the UK region. With her expertise, she helps organizations safeguard their domains so that no hacker can misuse them to send fraudulent emails, thereby protecting both their brand and reputation. She is passionate about enabling businesses to simplify the complexities of outbound email security through TDMARC’s comprehensive solution, allowing them to stay focused on what matters most to their success.
Runtime AI governance is not free. See the real compute cost, why tiered monitoring cuts it 24-fold, and what...
AI agents need their own security model. See the real risks, why agent identity is the hardest part, and...
Shadow IT was a data location problem. Shadow AI hands out standing authority to act. See why detection has...
Table of Contents
×