Cortex
CortexSecurity · Shadow AI Discovery

Detect and Prevent
Shadow AI

ObservedPolicyAction

Human-initiated Shadow AI

Human-initiated Shadow AI.

Employees use unsanctioned models through the browser, desktop apps, computer-use sessions, and cowork tools. They paste, screenshot, or upload prohibited or sensitive material. Cortex detects that activity and can block it.

  • Computer use
  • Browser
  • Humans
  • Desktop apps
  • Co-work

Policy library

  • POL-14ChromeChatGPT

    Minimize SSN and tax identifiers

    Catches: SSN pasted into a personal ChatGPT tab.

  • POL-31ChatGPTGitHub

    No production secrets to external models

    Catches: .env or wire key dropped on the composer.

  • POL-22ChromeChatGPT

    Tax records stay off unsanctioned models

    Catches: A W-9 scan dropped or screenshotted into ChatGPT.

  • POL-04CursorChatGPT

    Client book stays on the approved MCP

    Catches: Positions leave through a personal tab after MCP deny.

On her desktop

  • W-9 Elena Cho.pdfTax record
  • client-book.xlsxPositions
  • IMG_0941.pngScreenshot
  • .envSecret

ChatGPT

Maya VossSupport

Elena Cho's onboarding is blocked on a missing W-9.

I can extract name, TIN, and address if you share the form.

Compliance wants it on the file today. The scan is on my desktop.

A clear scan is enough. I will type the fields and flag anything unreadable.

Need this W-9 cleaned for her onboarding file.

Attach the form and I will extract the fields.

+

Clean this W-9 for onboarding

Observed

Agent-initiated Shadow AI

Agent-initiated Shadow AI.

At runtime or through assigned tasks, agents access prohibited or sensitive data and either read it or run inference over it: Claude Code, Codex, Grok, and similar tools. Cortex detects these accesses and can block them.

  • Claude Code
  • Codex
  • Grok

Policy library

  • POL-04Claude CodeCursor

    Client book stays on the approved MCP

    Catches: Claude Code reads Elena Cho's book after MCP deny.

  • POL-31CodexGitHub

    No production secrets to external models

    Catches: Codex cats .env to debug a Fedwire batch.

  • POL-19GrokSlack

    Restricted work product stays off third-party models

    Catches: A Grok agent sends the Northshore CIM from Slack.

claudepriya@releases ~/book

$ claude

> Pull Elena Cho's full book and give me the position weights, custody account IDs, and anything marked client-confidential.

ReadRESTRICTEDclient-book.xlsx

Restricted file

client-book.xlsx

  • Elena Cho · client book
  • AAPL 12.4 · MSFT 8.1 · munis 15
  • Custody 4821-0193 · JPM Prime

POL-04 blocked

Policy denied the MCP read. The agent does not receive the client book.

$

Human-initiated and agent-initiated Shadow AI are evaluated against the same policy library. Cortex detects both. When the request is on a controlled path, it can block the read or the inference.

Inventory

Who used unsanctioned AI, and what data left.

Cortex inventories people, agents, and surfaces from capture. Each row is a session: who initiated it, which model it reached, and the sensitive data that went with it.

  • Human and agent sessions on the same inventory
  • Observed on the capture path; blocked on a controlled path
  • Sensitive data classified against the policy library
Shadow AI inventory
4 sessionsMar 14

Priya NairReleases

Cursor · MCP · client book

client_book.positions
BlockedAgent

Maya VossSupport

Chrome · chatgpt.com

pii.ssn
ObservedHuman

Ravi KapoorRisk

Slack · #deal-room

deal.ma
ObservedAgent

Kavya DesaiSupport lead

Chrome · chatgpt.com

tax.w9
ObservedHuman
Residual disclosure

A blocked request is not a contained disclosure.

Policy can deny an MCP connection or a managed tool call. The same client book can be pasted or screenshotted into ChatGPT. Cortex observes that second channel on the capture path.

  • Managed-path policy applies only where Cortex can enforce it
  • Paste and screenshot to consumer models are a separate channel
  • The session is attributed to a person, a surface, and a data class
Managed vs unsanctioned

Priya NairReleases

client_book.positions

01 · Managed path

Blocked

Cursor · FactSet MCP

POL-04 denied the client-book read.

02 · Unsanctioned path

Observed

Chrome · ChatGPT

The same positions were pasted into a prompt.

Data class

Classify what entered the model.

Each captured session is tagged with a data class. A review can start from personal data, tax records, restricted work product, or secrets, instead of a raw usage count.

  • Sessions tagged by data class and tripwire
  • PII, tax records, restricted work product, and secrets
  • The same classes appear on the inventory
Classification
4 data classes

Personal data

pii.ssn

Name, SSN, date of birth

POL-14 · GDPR · GLBA NPI

Tax and account identifiers

tax.w9

W-9 scan, TIN, custody account

POL-22 · IRS · PCI

Restricted work product

deal.ma

CIM, client book, non-public research

POL-19 · confidentiality · MNPI

Secrets and credentials

secret

API keys, tokens, .env values

POL-31 · credential exposure

Deployment, lineage & assurance

Trace every AI session from origin to outcome.

Reconstruct Shadow AI activity across human-operated tools, cloud agents, and self-hosted workloads, then carry the same evidence into risk and compliance review.

  • Who initiated the session, person or agent
  • What data class left, and which destination it reached
  • Whether the session was observed or blocked
Deploy where the session runs
  • Human-operated AI

    Browser and desktop tools people already use. ChatGPT, Claude, Grok, Cursor, and the rest of the consumer surface.

    ChatGPTClaudeGrokCursor

    On-device sensor

  • Cloud workloads

    Hosted agents, provider APIs, and MCP paths: Slack agents, OpenAI, Gemini, GitHub.

    OpenAIGeminiSlackGitHub

    Your cloud

  • Self-hosted

    Run capture in your VPC or on-prem. Same inventory, same data classes, inside your boundary.

    CloudData planeHosted

    Your VPC or on-prem

Assurance carried with the evidence

Review your AI exposure.

We will map one supported surface and compare approved versus unauthorized egress.