11 min read
As employee AI use spreads beyond procurement, specialist firms and security platforms are competing to make it visible and governable.
TL;DRTap to expand the short version
- Employee adoption has created a layer of AI use that procurement and security teams may not be able to see.
- Specialist monitoring firms compete with browser-security companies and established cybersecurity platforms.
- Discovery tools identify services and data flows. Organisations still set policy, ownership and acceptable-use boundaries.
- Monitoring raises questions about employee privacy, false positives, enforcement and evidence of effectiveness.
- NIST and European Commission guidance support risk-based governance built around inventory, accountability, training and review.
Seven months is not long to build a customer base from nothing. In January 2026, Danish startup Velatir had no paying customers. By August, chief executive Michael Blicher Sørensen said it had 80 customers across Denmark, Sweden, Norway, the Netherlands, France and the UK. Named customer sectors include banking, insurance, law, government and utilities.
The early demand points to a governance gap created as generative AI spread through workplaces. It has also helped form a market for software that promises to close that gap. Employers may provide approved copilots while staff continue using free accounts, browser extensions, coding assistants and other services that never appear in procurement records.
Shadow AI monitoring through ordinary work
In companies that were not built around AI, adoption often moved faster than procurement. Employees opened personal ChatGPT accounts, marketing teams connected writing tools to customer systems, and developers pasted production logs into assistants for debugging. Free tools and individual accounts entered daily work without appearing as company purchases.
The scale is difficult to estimate because published figures usually come from providers monitoring their own customers. Harmonic Security analysed roughly 22.5 million prompts and file uploads generated during 2025 across its customer base. It recorded 579,113 instances of sensitive-data exposure across 665 AI tools, with about 17% occurring through personal or free accounts. The sample covers organisations already using Harmonic and is not representative of all European businesses. Its breadth indicates how many tools can sit outside a central inventory.
This is the starting point for the industry. Security teams cannot classify a tool, assess its data handling or apply a policy until they know it is being used. Monitoring providers sell that first layer of visibility, then extend into classification and enforcement.
A monitoring market takes shape
Shadow AI monitoring sits between several established software categories. It overlaps with data-loss prevention, secure enterprise browsers, cloud-access security, identity management and AI governance. Products typically discover AI services, record activity, inspect data moving into them and apply policies set by the customer.
Velatir illustrates the specialist approach. Its technical documentation describes a browser extension for web-based tools and a desktop agent for desktop and command-line applications. The company says automated reviewers can flag, block or escalate activity according to customer policies. Other specialists package similar functions differently, while established security companies add them to products companies may already use.
A standalone product may provide deeper visibility into AI-specific behaviour and faster policy updates. An incumbent platform may offer simpler deployment, fewer integrations and one place to manage security controls. Public comparisons remain difficult because providers disclose product coverage more readily than detection accuracy, false-positive rates, employee adoption or independently verified outcomes.
Identifying an AI service is only the beginning. The product must connect activity to a user or device, classify the information being shared, compare the event with company policy and decide whether to log, warn, block or escalate it. A human reviewer then needs enough context to understand the flag. Broad discovery paired with weak classification creates noise. Accurate classification applied to only part of the workforce leaves blind spots. Similar-looking products can therefore produce very different workloads for security and compliance teams.
Operational bottlenecks remain
Coverage depends on where a product can observe activity. Browser extensions can see browser use, network tools can classify traffic, endpoint agents can cover installed applications, and identity systems can track approved accounts. Personal devices, embedded AI features, application programming interfaces and locally run models may remain outside those views, leaving even a useful inventory incomplete.
Detection also says little about context. A prompt containing a customer name may be routine, sensitive or prohibited depending on the data, purpose, contract and receiving system. Automated classification reduces the review burden while introducing false positives that can interrupt legitimate work and false negatives that can create misplaced confidence. Companies need an exception process and someone accountable for disputed classifications.
The monitoring process creates its own data-governance questions. Products may inspect prompts, files, user identities and application activity in order to protect them. Buyers must assess what is collected, where it is processed, how long it is retained, who can access it and whether the monitoring is proportionate. Velatir says it uses EU-based infrastructure and restricts support access unless a customer grants it temporarily. Those company claims still require review through contracts, technical testing and a processor assessment.
Controls can change employee behaviour as well. Blocking useful tools without providing an adequate alternative may push work toward personal devices or unmonitored channels. A permissive policy can leave sensitive data exposed. Governance depends on the quality and accessibility of approved tools as much as on enforcement software.
Procurement reaches beyond a feature comparison. Buyers need to know how the product is deployed, which operating systems and applications it covers, how it integrates with identity and security tools, and what happens when an employee works from an unmanaged device. They also need a clear account of the monitoring data itself. A security control that stores sensitive prompts or detailed employee activity can create a new concentration of information requiring access controls, retention limits and internal oversight.
Rollout design can determine whether the technology becomes useful or simply creates friction. An observation period gives teams a baseline before blocking begins. Security staff can see which tools employees rely on, which policies generate repeated exceptions and whether approved services meet the same needs. Employees need a route to request access or challenge a decision. Without those feedback loops, enforcement data may measure compliance with the tool instead of the underlying risk.
Questions to ask before buyingOpen the buyer check
- Which browser, network, endpoint and account activity can the product see?
- Which prompts, files and employee identifiers does it collect or retain?
- Who reviews disputed flags, exceptions and blocked work?
- Which approved alternatives will employees receive?
- Which measures will show whether the control reduces risk without obstructing useful work?
European rules add pressure
Once a company can see which tools are in use, it still has to decide which legal and governance duties apply. Existing data-protection obligations may arise before the more specialised provisions of the AI Act. GDPR Article 30 requires controllers and processors, subject to its scope and exceptions, to maintain records of personal-data processing activities. A company needs to know which tools process personal data before it can maintain those records or decide whether a data-protection impact assessment is required.
Article 4 of the EU AI Act requires providers and deployers to support AI literacy among staff and others using AI systems on their behalf. The European Commission’s current guidance recommends considering the organisation’s role, the risks of its systems, users’ knowledge and the context in which AI is used. The guidance does not mandate one training format or a specific governance structure. The UK’s ICO guidance similarly places AI within existing accountability, security, data-minimisation and impact-assessment duties.
The European guidance and the voluntary NIST framework leave organisations to choose an operating model. NIST organises AI risk work around govern, map, measure and manage. For shadow AI, that begins with an inventory of approved and observed tools and a named owner for each decision. Companies can then separate low-risk drafting from work involving personal data or regulated decisions, provide approved alternatives before restricting tools, and review incidents and adoption as the technology changes.
Monitoring software can support inventory and enforcement. Decisions about risk tolerance, lawful processing and the reliability of AI-assisted work remain with the organisation. This division is easy to blur when a dashboard makes governance look like a technical problem. The software can show an event and apply a selected rule; management still owns the rule and its consequences.
Specialists meet larger platforms
Those governance needs have attracted providers from several parts of the security market. Specialists such as Velatir and Harmonic Security sell AI discovery and policy enforcement as standalone products. Browser and network-security companies are extending existing products into the same territory. Akamai acquired LayerX on 2 July 2026 for about $205m. Its earlier deal announcement forecast roughly $10m in LayerX annual recurring revenue by year-end.
Large security platforms offer overlapping functions. Microsoft documents AI-app discovery through Defender and Purview. Netskope markets controls across public, private and agentic AI. Palo Alto Networks describes AI application discovery and data controls, while CrowdStrike launched a shadow-AI visibility service in April 2026.
Customer totals and funding announcements demonstrate interest without revealing retention, contract size, detection quality or changes in security outcomes. Most available evidence still comes from the companies selling the products. Buyers can ask for measures that expose how a product behaves after deployment, including the share of workforce activity covered, false-positive rates, time spent reviewing alerts, repeated policy exceptions and movement from unapproved to approved tools.
Incident counts are difficult to interpret in isolation. More alerts may indicate better visibility, riskier behaviour or overly broad detection. Evidence becomes more useful when it shows how findings changed policy, reduced exposure or improved the use of approved systems over time. Independent benchmarking remains scarce, leaving buyers to test many of these claims during procurement and rollout.
A category with an unsettled future
Shadow AI monitoring is forming around an organisational blind spot that existing security products did not fully cover. Browsers, security platforms and workplace suites are now adding similar controls. Will specialist monitoring remain a distinct software category, or become a standard capability inside tools companies already buy?
Methodology and sources
This analysis draws on company technical documentation, product pages, funding and acquisition announcements, and guidance from the European Commission, the UK Information Commissioner’s Office and NIST. Customer totals, exposure figures and infrastructure claims are identified as company-reported because independent benchmarking remains limited. Product descriptions explain documented capabilities rather than verifying performance in a live customer environment.
FAQ
Shadow AI is the use of AI tools inside a company without formal procurement, security review or IT oversight. Examples include personal ChatGPT accounts, unapproved browser extensions and coding assistants connected to company data without sign-off. It mirrors the earlier problem of shadow IT, while adding tools that can process or retain sensitive prompts and files.
The functions overlap. Traditional data-loss prevention tools monitor sensitive information leaving a network. Shadow AI products add AI-service discovery, prompt and file classification, and policies applied when an employee submits information to an AI service. The practical difference depends on the coverage and integrations of each product.
No. Article 4 requires providers and deployers to support AI literacy among staff. Existing GDPR obligations may require organisations to understand which tools process personal data. Neither rule mandates monitoring software or a particular governance structure. Monitoring is one way companies may build an inventory and apply oversight.
The answer depends on coverage, data handling, integration, false-positive rates and reviewer workload. A specialist may offer deeper AI-specific visibility and faster policy updates. An existing security platform may deploy more easily and consolidate controls. Public evidence on detection quality remains limited for both approaches.
Related stories
- How AI Is Repricing Nordic SaaS
- European ESG Software Was Built on Regulation. Now AI Must Sell It
- The Complete Guide to AI Governance, IP and Brand Risk (2026)
- Why Uber’s Engineers Burned a Year’s AI Budget in Four Months
Spotted an error, have a correction, or want to pitch a story? Contact [email protected].
Spotted an error in this piece? We correct publicly, tell us via the contact page. Read our corrections policy.
