Ask any IT or security leader whether their organization uses AI, and the answer is yes. Ask how many AI tools are running across the enterprise, and the confident answers stop. That gap between adoption and awareness is where the real risk lives.
AI adoption is happening bottom up. Employees are adding AI tools to daily work, faster than IT, security, and finance can track it. Research from Netskope reports that 94% of organizations have gaps in AI activity visibility, and only 6% can see it completely. The tools are powerful, but you cannot govern what you cannot see.
Shadow AI is The New Shadow IT, And It Moves Faster
Shadow AI is any AI tool used inside the organization without IT review or approval. It is not a rare edge case. The average enterprise sees roughly 60 AI apps in use each week, and many of them might never have gone through procurement. A developer installs a local model to speed up coding. A marketer adds a browser extension that rewrites copy. A finance analyst pastes a spreadsheet into a chatbot to summarize it. Each action is reasonable. Together, they create exposure no one approved of, and no one is watching.
The challenge is not that employees are reckless. It is that AI hides in places traditional tools were never built to look.
AI Hides in Three Places Most Tools Miss
In the Browser
Much of today's AI usage happens in a browser tab. ChatGPT, Claude, Gemini, and a long tail of AI browser extensions never appear in an endpoint scan because nothing gets installed. Tools designed only for installed software, and even many SaaS discovery tools, struggle to see browser-based AI activity. That blind spot covers the fastest-growing category of AI use.
On the Endpoint, Below the Registry
Many AI tools install without a standard installer or never touch the operating system registry. Local LLM runtimes store models as files such as .gguf and .safetensors on developer machines. Registry-only inventories walk right past them. So do most software asset management tools that depend on conventional installation signals.
The MCP Connections Nobody Is Tracking
As teams connect AI assistants to internal systems, they configure Model Context Protocol servers inside their IDEs. These connections can read and write to code repositories, collaboration tools, and identity systems. Netskope found AI agents already hold write access to collaboration tools at 53% of organizations, email at 40%, and code repositories at 25%. Very few teams have any inventory of where those connections exist.
The AI Your Inventory Can’t See
When most business software is installed, it leaves an official record that IT systems can check. Many AI tools skip that step entirely. An employee can download an AI model as an ordinary file and run it on their laptop — no installer, no record, nothing in the places IT normally looks.
Inventory tools that depend on those records walk right past this, and that includes most software asset management products on the market today. The result: AI can be running across your organization without ever appearing in a report.
The MCP Connections Nobody Is Tracking
AI assistants are no longer just answering questions. Using connectors called MCP servers, teams now plug them directly into the systems where work happens - code repositories, team conversations, email, documents, even identity and access controls. Some MCP servers sit inside the company; many are run by outside providers, so these connections can also carry company data out to external services. Either way, they don't just let the AI read information - they let it make changes.
And they're usually set up by individual employees inside their own working tools, with no central approval or record. Netskope found AI agents can already make changes in collaboration tools at 53% of organizations, in email at 40%, and in code repositories at 25%. Very few companies have any list of where these connections exist or what they can reach.
What Complete AI Visibility Actually Looks Like
Closing the shadow AI gap takes more than one signal. It takes coverage across the endpoint and the browser at the same time, from a platform that already understands software at enterprise scale. That is the foundation HCL BigFix AI Management, our AI Governance Platform is built on.
- Seven categories of AI tools. Automation agents, browser plugins, local LLM runtimes, desktop assistants, code assistants, productivity add-ins, and AI web browsers, all in one inventory.
- Local model detection. Identifies .gguf and .safetensors model files on developer machines that registry-based tools miss entirely.
- Browser-layer discovery. Detects browser-based AI through extensions, connectors, and firewall logs, so SaaS AI in Chrome or Edge is no longer invisible.
- MCP server reporting. Surfaces the MCP servers configured to your systems and IDEs in the organisation, so you can see exactly where AI connects to your systems.
- Deep endpoint discovery. The Software Recognition Catalog finds AI installed without standard installers, producing one real-time view of sanctioned and shadow AI.
Visibility Is the First Step to Governance
Seeing every AI tool is not the finish line. It is the starting line. Once you have a defensible inventory, you can assess each tool against policy, enforce decisions across thousands of endpoints, and account for what you are spending. None of that is possible while most of your AI footprint is invisible. HCL BigFix AI Management is built on a combined UEM and SAM foundation precisely so that discovery, compliance, and control live in one platform rather than three disconnected tools.
See It Before You Have to Govern It
Your employees are already using AI. The organizations that stay in control will be the ones that can answer, at any time, exactly which AI is running, where, and whether it is safe. That answer starts with visibility you can trust. To know more about how AI tools can be governed, read our other blog : From Shadow AI to Governed AI.
See the AI your enterprise can't see yet. Book a demo of HCL BigFix AI Management.
Start a Conversation with Us
We’re here to help you find the right solutions and support you in achieving your business goals.



