Shadow AI · Visibility & control of unsanctioned generative-AI usage

See, qualify and control the generative-AI usage that leaves your perimeter, at the point of creation.

Your teams use ChatGPT, Claude, Gemini, Copilot, DeepSeek and browser extensions far beyond what your SSPM, LLM gateway or DLP/CASB can see. SentinelleIA operates the missing enforcement point: runtime supervision in the browser, at the endpoint and on the server, before exfiltration.

10 / 10 OWASP LLM Top 10, full technical coverage
Art. 12 & 14 EU AI Act, logging & human oversight
FR Sovereign hosting & operation

Shadow AI, an operational definition

What it is

  • Use of generative-AI models (public LLMs, browser extensions, assistants built into SaaS) outside the tool catalog validated by IT or the CISO.
  • Business data flows (source code, contracts, customer, HR and financial data) leaving in clear text to third-party models via web browsing, ungoverned APIs or AI-enhanced office tools.
  • A surface that keeps expanding: new AI features enabled by default in already-approved SaaS (M365 Copilot, Slack AI, Notion AI, Atlassian Rovo).

What it is not

  • Not only an OAuth inventory problem: most leaks go through the browser in direct access, with no traced application integration.
  • Not a problem solved by an enterprise LLM gateway: by construction, Shadow AI is the perimeter outside the gateway.
  • Not a classic network DLP problem: content is analyzed in memory in the browser, in encrypted HTTPS sessions streamed token by token.

Why your current tools don't see Shadow AI

Four tool families dominate enterprise AI security today. Each addresses a legitimate segment, with a distinct operating mode (passive read or active enforcement). None, taken in isolation, covers the zone where data actually leaves the perimeter.

Approach Mode Operation layer Shadow AI blind spot
SSPM
OAuth mapping, SaaS inventories
Passive read SaaS control plane via admin API A posture tool, blocks nothing. Blind to prompt content. Blind to public models accessed via direct browsing. Blind to browser extensions and local MCP servers.
CASB API-mode
Out-of-band, reads sanctioned SaaS
Passive read SaaS control plane via API Same blind spot as SSPM. Sees the configuration of known SaaS, does not cover off-catalog usage.
LLM Firewall API
Enterprise outbound gateway
Active enforcement Declared enterprise API Blind to any model not going through the gateway, i.e. the dominant Shadow AI perimeter by definition. Handles neither multi-turn exfiltration nor token-by-token streaming.
CASB in-line / DLP / SWG
HTTPS proxy, endpoint DLP, network DLP
Active enforcement Network (HTTPS proxy with TLS MITM) or OS (clipboard, syscalls) A reading grid calibrated for structured data (IBAN, SSN, regex), with no LLM conversational semantics (injection, jailbreak, progressive leakage). Bypassed by desktop apps with certificate pinning. Massively bypassed outside the network perimeter (mobile, BYOD, remote work without SASE/ZTNA). Invisible to browser extensions and local MCP servers that orchestrate the flow in the DOM before emission.
SentinelleIA
In-line control plane, multi-surface
Active enforcement + observation Browser (DOM via Manifest V3 extensions) + Endpoint (processes via Windows agents) + Server (orchestration) The missing enforcement point, complementary to the four above. Active authorization policy per user, per department, per domain, applied at the point of creation. Capture of the content actually exchanged with an LLM-native reading grid (OWASP LLM Top 10).

SSPM and API-mode CASB are posture tools (read-only). In-line CASB, DLP and SWG enforce policies but with a grid calibrated for structured data, not for natural language and the conversational patterns specific to LLMs. SentinelleIA operates an application-layer enforcement at the point of creation, with an LLM-native reading grid: complementary to, not a replacement for, the other tools.

CISO Command Center, in action

Not a mockup. Not a PowerPoint. This is the SentinelleIA CISO console running in production.

Multi-surface runtime supervision Cloud + Localhost interception Multi-Tenant
SentinelleIA security events, Shadow AI detection

Security Events, 32 detections in 24h

Every prompt sent to ChatGPT, Claude, Gemini or DeepSeek is analysed in real time, with the machine, the user and the model that received it.

5 CRITICAL 5 BLOCKED
SentinelleIA security alerts, critical and high alerts

Security Alerts, 133 critical/high alerts

Unauthorised filesystem call blocked by agent-guard, Q4 financial data caught in a ChatGPT prompt, OpenAI API key detected before sending. Every alert is traceable by machine, user and source.

129 UNREAD
SentinelleIA control policies, BLOCK and WARN per domain

Control Policies, BLOCK / WARN per domain

Rules created per target AI domain: block chat.openai.com, warn on *.deepseek.*, whitelist the rest. Three levels: BLOCK (access cut), WARN (warning), ALLOW (no log).

GRANULAR
SentinelleIA machine fleet, multi-agent supervision

Machine Fleet, multi-agent supervision

5 supervised machines, 3 agents online. Each workstation runs endpoint + prompt-guard agents. Visibility by department, OS, IP and status.

3 AGENTS ONLINE

OWASP LLM Top 10 coverage, 10 items out of 10

SentinelleIA covers the entire OWASP LLM Top 10 matrix (2025 edition). Each item is handled by one or more of the platform server-side agents.

OWASP LLM item Agents in charge
LLM01 — Prompt Injection AI Firewall Prompt Guard
LLM02 — Sensitive Information Disclosure Prompt Guard (input)   LLM Security (output)
LLM03 — Supply Chain Supply Chain Visibility
LLM04 — Data & Model Poisoning Supply Chain Visibility
LLM05 — Improper Output Handling LLM Security (classify_output)
LLM06 — Excessive Agency Tool Protection Governance (politiques tools)
LLM07 — System Prompt Leakage Prompt Guard LLM Security (analyze_response)
LLM08 — Vector & Embedding Weaknesses Resilience (vector_integrity_check)
LLM09 — Misinformation Resilience (check_hallucination embeddings)
LLM10 — Unbounded Consumption Visibility Governance AI Firewall Gateway

Technical coverage of EU AI Act requirements

SentinelleIA is designed to address the technical requirements applicable to high-risk AI systems defined by Regulation (EU) 2024/1689, in particular the articles that structure a controlled enterprise deployment.

Article Requirement Technical coverage
Art. 9 Risk management system Governance Visibility Resilience
Art. 10 Data governance Supply Chain Visibility
Art. 12 Record-keeping, automatic logging Supervisor (audit chain SHA-256)
Art. 13 Transparency and user information Governance Visibility (SBOM IA)
Art. 14 Human oversight Tool Protection (tool actuation policies)
Art. 15 Accuracy, robustness, cybersecurity Resilience AI Firewall LLM Security

The coverage shown here is a technical and operational capability. Certified legal conformity in the sense of Annex IV / Art. 17 is a matter for an independent assessment (CSPN, ANSSI, notified body) and for the analysis of the using organization and its DPO.

What Shadow AI does to your company

Massive data leakage

Every prompt sent to ChatGPT potentially contains source code, customer data, trade secrets. This data is stored on foreign servers beyond your control.

39.7% of data movements into AI tools involve sensitive data (Cyberhaven Labs, 2026)

GDPR & AI Act non-compliance

Sending personal data to public LLMs breaches the GDPR. The EU AI Act requires a full inventory of every AI system in use, including the ones you are not aware of.

Fines up to 3% of global revenue (EU AI Act, art. 99)

Decisions based on hallucinations

Your employees make business decisions based on unverified LLM answers. Buggy code shipped to production, contracts drafted by AI with invented clauses.

20% of AI answers contain major accuracy issues (EBU/BBC, 2025)

Zero visibility, zero control

You do not know who uses what, with which data, for what purpose. Employees bypass VPNs, use personal accounts and unapproved AI browser extensions.

Only 34% of organisations with an AI governance policy audit for unsanctioned AI (IBM, 2025)

Expanded attack surface

Every unlisted AI tool is an entry point for attackers: malicious plugins, compromised APIs, exfiltration via indirect prompt injection.

97% of organisations breached through an AI model or application had no AI access controls (IBM, 2025)

Uncontrolled hidden costs

Personal ChatGPT Plus subscriptions, APIs paid on corporate credit cards without approval... Shadow AI generates invisible, unbudgeted costs.

How Shadow AI takes hold (without you knowing)

1

Monday 9am, the sales rep discovers ChatGPT

A sales rep copy-pastes a commercial proposal with pricing, client names and special terms into ChatGPT to "rephrase the email".

2

Tuesday 2pm, the developer uses Copilot

A dev installs an AI extension on their IDE. Their code (with hard-coded API keys) is sent to a third-party server for autocompletion.

3

Wednesday 10am, HR generates job descriptions

HR uses a free AI tool to analyze resumes. Candidates personal data (name, address, degrees) is sent to a foreign server.

4

Thursday 4pm, legal translates a contract

A lawyer uses DeepL Pro to translate a confidential M&A agreement. The full document transits through external servers.

5

Friday 11am, the CISO has no visibility

Without an observation layer at the point of creation, the CISO has neither the logs, nor the alerts, nor the policies applicable to these usages. The data is already gone. And it starts again on Monday.

Shadow AI in numbers

55% of workers have used unapproved AI tools at work Source: Salesforce / YouGov, Oct 2023 (14,000 employees, 14 countries)
39.7% of data movements into AI tools involve sensitive data Source: Cyberhaven Labs, 2026 AI Adoption & Risk Report
20% of organisations reported a breach involving shadow AI Source: IBM, Cost of a Data Breach 2025
32% of ChatGPT usage at work goes through personal accounts, not corporate ones Source: Cyberhaven Labs, 2026 AI Adoption & Risk Report

Before and after SentinelleIA

Without SentinelleIA

  • Zero visibility into the AI tools in use
  • Customer data sent to ChatGPT every day
  • No inventory for the EU AI Act
  • Unapproved AI extensions on every workstation
  • Impossible to prove GDPR compliance
  • CISO blind, CIO worried, DPO powerless

With SentinelleIA

  • Real-time CISO dashboard: alerts, flows, blocks
  • ChatGPT, Copilot, DeepSeek detected and blocked at the point of creation
  • Automated EU AI Act inventory and logging (Art. 12 and 14 coverage)
  • Granular BLOCK/WARN policies per AI domain
  • Full audit trail per user and per LLM model
  • Native Go agents, Cloud + Localhost (Ollama)

5 protection functions against Shadow AI

Five front-line protection functions, operated by nine server-side agents (detailed architecture on the agents page). Each function targets a facet of Shadow AI; together they deliver full visibility and control.

Agent Firewall IA

Blocks outbound flows to unauthorized LLMs. No data leaves your perimeter without your consent.

Learn more →

Agent Visibility

Scans your network and detects all hidden AI usage: APIs, extensions, plugins, personal accounts.

Learn more →

Agent Gateway

Zero-Trust gateway: every AI request is authenticated, logged and rate-limited. Full control of flows.

Learn more →

Agent Garde-Prompts

Detects and masks sensitive data (PII, secrets, code) before it is sent to LLMs.

Learn more →

Agent Gouvernance

Automatically generates the AI systems inventory, DPIAs and EU AI Act documentation.

Learn more →

Most frequent questions from CISOs

Does SentinelleIA replace my EDR / SSE / DLP?

No. SentinelleIA is a complementary in-line AI control plane. It sits alongside an existing EDR and adds visibility those tools do not provide by design: analysis of LLM flows in browser and process memory, multi-turn exfiltration detection, real-time injection scoring.

What footprint on the workstation?

Components deployed on the workstation: Chrome / Firefox browser extension (Manifest V3) and Windows endpoint agent. Memory and CPU footprint shared under NDA during the pilot phase.

What happens to intercepted data?

Local analysis on the workstation for detection functions. Metadata and security events sent to the SentinelleIA supervisor hosted at your site (on-premises deployment or sovereign French cloud). No data sent to a non-European third-party service.

How to prevent a user from disabling the agent or extension?

Standard GPO / MDM deployment with browser-extension lockdown via Chrome / Edge / Firefox enterprise policies. The endpoint agent registers as a protected Windows service. Emergency bypass procedure documented for CISO operations.

Multi-tenant or dedicated deployment?

Dedicated deployment recommended for OIV / OES environments and any regulated sector. Multi-tenant mode available for mid-market companies under a logically isolated architecture.

What real latency does the user feel?

Browser interception latency is designed to stay transparent to the user in supervision mode, independent of the remote model network latency. Precise measurements shared under NDA during the pilot phase.

How does a POC / diagnostic work?

Scope limited to 5-20 workstations for 48 hours. Deliverables: inventory of detected AI tools, qualification of outbound data flows, technical coverage of EU AI Act requirements on the scope, prioritized recommendations.

How does the agent itself handle the GDPR?

The agent processes personal data (user identifiers, prompt content that may contain PII) for security purposes. Legal basis: legitimate interest of the employing organization, documented in the PIA provided with the deployment. Employee information required via the internal rules or an amendment.

Is your company exposed to Shadow AI?

You submit your environment, we return a Shadow AI exposure report: detected AI tools, exposed data, measured attack rate and EU AI Act coverage.

Request your Shadow AI diagnostic

Fill in the form below. An expert will get back to you within 24h to schedule your free diagnostic.

Request sent!

A SentinelleIA expert will get back to you within 24h to schedule your Shadow AI diagnostic.