Shadow AI Tools
Home How It Works The Report Coverage Pricing FAQ Contact
Run a Free Audit Sample Report (PDF)
Shadow AI Detection

Find the AI Tools Your Employees Already Use

Upload a DNS, proxy or firewall export. Get back every AI tool reached from your network, with category, risk level, who used it and whether the vendor trains on your data.

No agent. No SSL inspection. First results in minutes, from a log you already have.

20,410AI tools detected
700+Train on your data by default
85.5%Say nothing about training
$99Full audit report
The Visibility Gap

Shadow AI Is a Visibility Problem First

Policy documents and blocking rules come second. The first question is what is actually in use today.

You cannot govern what you cannot see

Staff adopt chatbots, code assistants and file converters long before IT hears about them. Most never show up in procurement.

Your data is the payment

700+ AI tools train on customer input by default, and 85.5% say nothing about training at all. Every paste is a potential disclosure.

Discovery should not cost five figures

Consulting-led shadow AI assessments take weeks and are quoted in the thousands. The same evidence is already in your logs.

How It Works

From Log Export to AI Inventory in Three Steps

The audit runs on files your network equipment already produces. Nothing is installed and nothing is inspected in transit.

1

Export a log

Take a DNS, proxy or firewall export covering a normal week. A CSV, syslog file or plain hostname list all work.

2

Upload it

The tool reads the export once and matches every hostname against 20,410 known AI tool domains. The file itself is then discarded.

3

Read the report

See every AI tool found, by category and risk level, with vendor training terms. Full reports add the per-user breakdown, CSV and PDF evidence pack.

Cisco Umbrella Zscaler Palo Alto Fortinet Cloudflare Gateway DNSFilter NextDNS Pi-hole SonicWall Squid Any CSV or hostname list
The Report

An AI Inventory You Can Hand to Management

Every finding is tied to a hostname seen in your own logs. No survey answers, no estimates.

  • Every AI tool found, with its functional category and AI type, from chatbots to code assistants to face swappers.
  • Risk flags per tool: risk level, data sovereignty and abusive-use categories such as deepfake generators.
  • Training verdicts: whether each vendor trains on your data, opts you in by default or says nothing, with the date the terms were checked.
  • Who used what: the per-user, per-device or per-IP breakdown, when your export carries that column.
  • Sanctioned vs unsanctioned, split against your own approved-tool list.
  • CSV and PDF evidence pack for follow-up, ticketing and audit files.
Open the Sample Report

Inside a full report

Summary tiles: tools found, users involved, high-risk count
Tool-by-tool table with category and risk columns
Training-terms verdict per vendor, dated
Per-user breakdown of AI destinations
Sanctioned vs unsanctioned split
CSV export and shareable PDF
Pricing

Free Preview. Full Reports From $99. No Subscription.

Start free and unlock the complete report only if the preview finds something worth chasing.

1 report

$99
one-time
Buy 1 Report
save 33%

3 reports

$199
$66 each, one-time
Buy 3 Reports
Best value save 40%

5 reports

$299
$60 each, one-time
Buy 5 Reports
Free previewFull report
Totals by category and risk flags
AI tools namedA fifth of those found, at least fiveAll of them
Per-user breakdown×
Sanctioned vs unsanctioned split×
Vendor training verdicts, datedOn named tools
PDF preview PDF evidence pack
CSV export×
Export sizeUp to 5,000 linesUp to 2,000,000 lines or 25 MB
Price$0$99, or less in packs

Running audits monthly? The subscription plans on aitoolsblocklist.com include 1 to 10 full audits a month. Larger exports are handled on request.

Detection Coverage

Backed by a Purpose-Built AI Tools Database

Detection is only as good as the list behind it. Ours is maintained daily as a commercial product, not scraped once.

20,410AI tool domains across 18 functional categories
300,000new domains checked every day from a 120M domain corpus
13,000+vendor terms reviewed for training-on-your-data verdicts
3,900+tools mapped to the model provider behind them

Explore the research behind the audit: the Policy Silence Index, training-terms verdicts and where AI tools send your data.

Who Runs It

Built for the People Who Get Asked "What AI Are We Using?"

The same audit answers a board question, a compliance finding or a client engagement.

CISOs and IT leaders

Turn a suspicion into a dated inventory before the next board or risk meeting. Repeat quarterly to track drift.

Compliance and privacy teams

Get evidence of which vendors receive staff input and what their terms say about training, with the date checked.

MSPs and consultants

Deliver shadow AI assessments under your own engagement. The MSP plan includes 10 audits a month, each labeled with the client name.

Data Handling

Your Logs Are Evidence, Not Our Product

The audit is designed so the sensitive artifact, your raw log, never persists on our side.

Read once, then discarded

The uploaded export is parsed in a single pass and deleted. It is never stored, resold or used for anything else.

Reports expire

Finished reports stay in your account for 90 days, then they are removed. You can delete them earlier yourself.

Private to your account

A report is visible only to the account that produced it. Share it deliberately, as a PDF or CSV, or not at all.

FAQ

Shadow AI Detection, Answered

How do I find out which AI tools my employees are using?

Export a log from the DNS filter, proxy or firewall you already run and upload it. Every hostname is matched against 20,410 known AI tool domains, so the report reflects real traffic from your own network, not a survey.

Which log formats are accepted?

Exports from Cisco Umbrella, Zscaler, Palo Alto, Fortinet, Cloudflare Gateway, DNSFilter, NextDNS, Pi-hole, SonicWall and Squid all parse directly. So does any CSV with a header row, key=value syslog lines, or a plain list with one hostname or URL per line.

Do I need to install anything?

No. There is no agent, no browser extension and no SSL inspection. The audit works entirely from a file you already have.

Is my log stored?

No. The export is read once, matched and discarded. Only the report is kept, for 90 days, inside your account.

What does it cost?

The preview is free: category totals, risk counts and a fifth of the tools found, with the rest shown as withheld rows. Full reports are $99 for one, $199 for three or $299 for five, one-time.

Can MSPs and consultants use it for clients?

Yes. The MSP plan includes 10 full audits a month, and each report carries the client name you enter. One account serves every engagement.

How is this different from CASB or DLP discovery?

Those platforms are excellent but need deployment, licensing and time. This audit needs one log export and gives an AI-specific answer today, including vendor training terms that network tools do not track.

Your Logs Already Know the Answer

Run the free preview on last week's export. If it finds nothing, you have your evidence. If it finds something, you will want the full report.

Run a Free Audit Sample Report (PDF)