See who is using which AI services, validate AI policy compliance, and surface shadow AI.
See AI usage live, tied to users, groups, roles, and employment type.
Uses your existing identity provider—no deep packet inspection and no endpoint agents.
Validate AI policy against live network data, not post-event logs.
Shadow AI is the use of AI tools and services inside an organization without IT, security, or compliance approval. It usually starts with employees, contractors, or automated agents reaching public assistants such as OpenAI ChatGPT, Anthropic Claude, or Microsoft Copilot using personal or corporate credentials. The risk is that corporate intellectual property and customer personally identifiable information end up ingested by public LLMs, which is difficult to prove or disprove after the fact. Because the traffic is encrypted and leaves as ordinary outbound sessions, it rarely appears in software inventories or expense reports. Kentik makes it visible by tagging traffic against known AI services and attributing it to the users, groups, and departments generating it.
Detection starts with the network, because that is the one place all AI traffic has to pass regardless of who approved it or which device it came from. Historically this meant deep packet inspection, which is expensive and degrades performance, so most teams settled for periodic audits instead. The alternative is to work from flow metadata: identify the destination as an AI service, then attach identity to the source. Kentik does this by combining next-gen firewall flow that already carries user identity with curated AI destination intelligence, producing a continuously updated record of AI activity without adding anything to the traffic path.
Yes. AI traffic is encrypted, but the metadata around it is not, and destination identity is enough to name the service on the other end. Flow records show which AI provider was reached, by which source, how much data moved, and in which direction, without inspecting payloads or decrypting sessions. What metadata cannot show is prompt content, which still requires data loss prevention or an enterprise browser. Kentik works entirely from the flow data next-gen firewalls already export, so there is no inline component to size, tune, or troubleshoot, and no performance penalty.
Three signals, all of which most enterprises already collect, can reveal AI tool use. Flow records from next-gen firewalls are richer than traditional flow: the firewall has already resolved Layer 7 detail, so each record can carry the username, user group, destination DNS name, and application alongside the usual addresses and byte counts. Identity and attribute context from the enterprise identity provider adds group membership, role, and employment type. AI destination intelligence then maps those resolved destinations to named AI vendors and categories. Kentik joins all three as additional dimensions on flow data, so every dashboard, query, and alert policy can group or filter by identity, role, and AI destination across the full data retention window.
Network traffic alone only shows addresses, so this requires joining network data to an identity source. Mapping network flow against identity provider groups and attributes lets AI usage be reported by team, role, and employment type, This makes policy monitoring and enforcement possible. Acceptable AI use policies for an engineering group are rarely the same as for contractors or finance, for example. Kentik supports this by enriching real-time flow with group, role, and employment-type context from an identity provider such as Okta, so AI usage can be broken out by department and by named service rather than by subnet.
Enforcement happens in the controls already deployed: next-gen firewalls, SASE stacks, and identity controls. What most programs lack is verification. Firewall rules drift, exceptions accumulate, and new AI services appear weekly, so a policy that was correct at configuration time quietly stops matching reality. Kentik supports this by using real-time enriched flow to confirm that configured policy is actually holding, and alerting on policy deviations, such as when a restricted group reaches a sanctioned service for an unsanctioned use or when contractor activity diverges from policy.
Compliance and privacy teams generally need to show which external services were reached, by which identities, under which policy, and over what retention window. Regulations including GDPR, HIPAA, and the EU AI Act put the burden of proof on the organization, and periodic manual audits are obsolete the moment they are finished. Flow data is useful here because it is a metadata record of what actually crossed the network, independent of endpoint or application logs that can be bypassed. Kentik supports this by retaining identity-enriched flow across the full retention window, queryable through dashboards, investigation queries, and natural-language questions to Kentik AI Advisor.
Event-log SIEMs can answer these questions, but the economics work against continuous monitoring. Log platforms charge for ingest, retention, and often each detection rule, so teams narrow what they collect and how long they keep it, which is the opposite of what governance reporting needs. Event logs also arrive late and require parsing before they are usable. Kentik works from flow data organizations are already collecting at predictable cost, which makes it practical to run many concurrent detections and to keep the full history available for audit rather than sampling it.
Flow analytics detects exfiltration patterns rather than file contents, which is usually enough to trigger investigation. The signals that matter are outbound volume that departs from an established baseline, byte-ratio asymmetry where a client sends far more than it receives, transfers slow enough to stay under alerting thresholds, and destinations with no business precedent. All four survive encryption because they depend on metadata. Kentik supports this by alerting on bulk data movement to external LLM endpoints before it escalates into a public breach, then handing enriched context to the security workflow where the investigation continues.
New AI services, vendors, and application endpoints appear weekly, which is why point-in-time audits and hand-maintained block lists fall behind almost immediately. A more durable approach watches for destinations that have not been seen before and treats each one as a policy decision rather than waiting for the next review cycle. Kentik supports this by alerting when a new AI vendor appears in traffic and by maintaining curated AI destination lists, so security policy and compliance reporting can move at the same pace as the market.
They should, and employment type is often the more important dimension than the individual user. Contractors, third parties, and automated agents frequently operate under different acceptable-use terms than employees, and agent traffic in particular can reach AI APIs at volumes no person would generate. Reporting that groups only by user or subnet hides both. Kentik supports this by carrying employment-type and group context from the identity provider onto every flow record, so contractor and agent activity can be reported and alerted on separately from employee usage.


