Shadow AI monitoring: see every AI tool your team uses
Shadow AI is any AI tool employees use for work without IT or management approval. VAHTOR finds it with a Chrome and Edge extension that records which AI sites are used, not what people type, and lists them in one company inventory where you approve, restrict or block each tool.
What is shadow AI, and why does it matter for SMBs?
When staff paste customer data into a free chatbot or start using an unvetted AI tool, the company loses track of where its information goes. Most smaller companies have no inventory of AI use at all, which makes it hard to write an AI policy, answer a customer security questionnaire or show EU AI Act literacy measures.
Unapproved AI tools in daily use
Company data in personal AI accounts
No record when a customer or auditor asks
How VAHTOR discovers shadow AI
Each employee installs the VAHTOR extension in Chrome or Edge and joins with a personal device code. As people work, the AI sites they use appear in your inventory with the tool name and time. There is no network proxy, no root certificate and no HTTPS interception, so discovery also works off-VPN and for remote staff.
Personal device code, no heavy agent
Continuous discovery as new AI tools appear
Works on any network
Approve, restrict or block each AI tool
Classify each tool once for the whole company. Devices pick up the decision on their next sync. Publish an AI policy that people accept alongside it, so your written rules and your controls say the same thing.
One registry for the whole company
Decisions apply on the next device sync
Policy acceptance tracked by version
Monitoring without reading prompts
VAHTOR never collects prompts or chat text. The workspace stores the tool, a detection type and a risk level. Reporting is aggregated by default, and names appear only if the owner turns individual identifiers on.
Chat text is never collected
Aggregated reporting by default
Retention set by the owner
What browser-based discovery does not cover
The extension sees AI use in Chrome and Edge on devices where it is installed. Desktop AI apps, mobile devices and other browsers are outside its view, so combine it with your device management and a clear AI policy.
Frequently asked questions
How do I find out which AI tools my employees use?
Discover AI use in the browser, where most of it happens. With VAHTOR, staff add a Chrome or Edge extension using a personal device code, and every AI site they use appears in one company inventory. Surveys and firewall logs miss personal accounts and remote work; browser-level discovery sees use on any network.
Is monitoring employee AI use allowed under GDPR?
It can be, if it is proportionate, transparent and has a lawful basis. Tell staff what is collected and why, and involve your DPO or employee representatives where required. VAHTOR is built for data minimisation: no prompts or chat text, and aggregated reporting by default. This is not legal advice.
Does VAHTOR read what employees type into ChatGPT?
No. VAHTOR does not collect prompts or conversations. Admins see which AI tools were used and whether a rule fired, not the message itself.
Which AI tools can VAHTOR detect?
AI tools used in the browser, including ChatGPT, Microsoft Copilot, Claude, Gemini and Perplexity. New AI sites appear in the inventory as people start using them.
Which VAHTOR plan includes shadow AI discovery?
All plans. Starter (€199/month + VAT, up to 25 employees) includes automated shadow AI discovery and inventory, approve/restrict/block controls, policy acceptance tracking and an audit trail.
Should we just block ChatGPT?
Blanket bans tend to push AI use onto personal phones and accounts. A common approach is to approve one or two tools with clear data rules, block the rest and train staff. VAHTOR supports this with per-tool status, a published policy and an AI literacy course.
Start monitoring shadow AI this week
Create a workspace, invite the team, and connect the browser extension.