Best shadow AI discovery tools in 2026: Nudge Security, Harmonic Security, Netskope and Lutril
Four shadow AI discovery tools compared on the signals they read (OAuth, email, browser, network, endpoint, code), local models, agents, DLP and EU hosting. Sourced.
Short answer
The best shadow AI discovery tool is the one whose signals match where your AI use happens, because each signal type misses something. Nudge Security reads email metadata, OAuth grants and a browser extension, installs nothing on endpoints, and publishes its pricing. Harmonic Security and Netskope add an endpoint agent that sees desktop AI apps, MCP servers and models running locally through Ollama, and Netskope also inspects web traffic through its secure web gateway. Lutril reads OAuth grants, sign-up emails, a Chrome extension and GitHub and GitLab repositories, then carries each finding into access governance: a decision per tool, an owner per agent, OAuth revocation at offboarding and EU hosting; it has no endpoint agent and does not detect local models.
Where each one starts
Nudge Security
A SaaS and AI security platform: your workforce uses three times more AI and SaaS apps than you think. Discovery from machine-generated email metadata and OAuth grants in Google Workspace and Microsoft 365, plus a browser extension for Chromium browsers, Edge, Firefox and Safari; nothing touches the corporate network or endpoints. An AI agent inventory with approval status and owner, risk scores per vendor, and remediation through nudges to employees. Published pricing, all features on every tier.
Harmonic Security
An AI governance and control platform: understand, control, enable. Explore discovers the AI tools in use and scores each one; Guide warns or blocks in the browser and on the desktop, with small language models judging the data in each interaction; Command extends governance to agents. A browser extension for Chrome, Edge, Firefox, Safari and AI browsers, an endpoint agent, and a locally installed MCP gateway for Windows, macOS and Linux. EU hosting on request.
Netskope
Modern security and networking for the cloud and AI era. NASDAQ-listed (NTSK) and named a Leader in Gartner's Magic Quadrant for SASE Platforms for the third year in 2026. The Netskope One platform sees AI use in web traffic through its secure web gateway, on Windows and macOS endpoints through the Netskope Client, and across MCP through its Agentic Broker; AI Command Center inventories AI apps, MCP servers, agents and locally running models. The Cloud Confidence Index rates apps from 0 to 100.
Lutril
Access governance for employees and AI agents. Shadow AI discovery reads OAuth grants from Google Workspace and Microsoft 365, sign-up emails, a Chrome extension and GitHub and GitLab repositories, and merges them into one inventory per vendor. Each tool is marked managed, unmanaged or blocked, OAuth access can be revoked, and agents found in code are promoted into the registry with an owner and governed through the MCP proxy. No endpoint agent. Hosted in France.
Capability by capability
| Capability | Nudge Security | Harmonic Security | Netskope | Lutril |
|---|---|---|---|---|
| OAuth grants and IdP sign-in data (Google Workspace, Microsoft 365) | YesOAuth connection to Google Workspace or Microsoft 365; OAuth grant inventorySource 3 | Not documented | PartialThird-party OAuth apps for Entra ID, Google Workspace and Salesforce; requires API-enabled protection with SSPMSource 21 | YesOAuth grants with scopes, users, first authorizer and first-seen date |
| Mailbox scanning for sign-up emails | YesMachine-generated emails only; metadata stored, analysed in memorySource 3 | Not documented | Not documented | YesOpt-in; sender and subject of sign-up emails, bodies never fetched |
| Browser extension | YesChromium browsers, Edge, Firefox and SafariSource 4 | YesChrome, Edge, Firefox, Safari, Arc, Brave, Island, Comet, DiaSource 16 | Not documentedBrowser traffic is steered to the secure web gateway by the Netskope Client | YesChrome, force-installed by MDM; reports catalogued hostnames only |
| Network or secure web gateway inspection | Not offeredVendor states it does not touch the corporate networkSource 3 | Not documented | YesNext-Gen SWG feeds AI apps and identities into AI Command CenterSource 18 | Not offeredNo proxy on employee web traffic; the MCP proxy covers agent tool calls |
| Endpoint agent: desktop AI apps, CLI tools, IDE extensions | Not offeredVendor states it does not touch endpoints and needs no agent roll-outSource 3 | YesClaude Desktop, ChatGPT Desktop, Cursor, Claude Code, GitHub CopilotSource 14 | YesNetskope Client scans for desktop agents, MCP servers, browser and IDE AI extensionsSource 19 | Not offeredNo endpoint agent |
| Detects models running locally on laptops (Ollama, LM Studio) | Not documentedNo endpoint component by design; local inference not addressed | YesEndpoint coverage lists Ollama and locally hosted modelsSource 14 | YesSignature-based: Ollama, LM Studio, Jan AI, GPT4All; Windows and macOS onlySource 19 | Not offeredLocal inference leaves no OAuth grant, email or browser visit for Lutril to read |
| Discovers AI agents, not only chat apps | YesAPI discovery (Agentforce, Copilot Studio, n8n) plus browser discovery (Cursor, Zapier Agents)Source 5 | YesMCP gateway discovers MCP clients and servers and who uses themSource 15 | YesAI Command Center lists agents, MCP servers and local modelsSource 18 | YesCode scanning of GitHub and GitLab for agent frameworks and tool-calling loops |
| Risk score per discovered app | YesInherent and residual risk per SaaS and AI vendor, in open betaSource 7 | YesRisk score per application: data policies, training practices, HQSource 11 | YesCloud Confidence Index score from 0 to 100 in five levelsSource 22 | PartialRisk tier from granted OAuth scopes; apps seen only by extension or email carry no scope data; 0 to 100 score per agent |
| Owner and approval decision per tool or agent | YesAgents carry approval status (Approved, Allowed, In Review, Not Permitted) and a technical ownerSource 5 | PartialApproved and monitored groups; owner assignment not documentedSource 13 | PartialSanctioned and unsanctioned apps; owner assignment not documentedSource 20 | PartialApps marked managed, unmanaged or blocked; owners on agents, suggested from commit authors |
| Prompt-level DLP or redaction | PartialDetects secrets, PII and PHI in prompts; alert, mask or store; blocking not documentedSource 6 | YesSmall language models judge each interaction; block, warn or logSource 12 | YesInline DLP profiles block sensitive posts to ChatGPTSource 25 | PartialChatGPT, Claude and Gemini only; detection on the device, redaction on the user's click |
| Coaches or blocks users in the browser | YesBrowser nudges steer users to sanctioned tools and capture exception requests; blocking is not the modelSource 4 | YesBlock in real time or warn with context, browser and desktopSource 12 | YesBlock or User Alert with coaching notification templatesSource 23 | PartialWarning banner on sensitive prompts; AI sites are not blocked |
| Ties into access reviews and offboarding | YesOffboarding revokes OAuth grants and resets passwords on unmanaged accounts; reviews route changes to app ownersSource 8 | Not documented | Not documented | YesOffboarding revokes the leaver's OAuth grants; reviews and lifecycle in the same product |
| EU hosting | Not documented | YesEU hosting on requestSource 10 | YesManagement planes in Amsterdam and FrankfurtSource 26 | YesOVHcloud, France |
| Published pricing | Yes$750 per month up to 150 users; $5 per user per month from 150 to 1,500Source 2 | Not offeredPricing page lists three plans without figuresSource 17 | Not documentedNo public price list found | Not offeredOn request |
Choose Nudge Security if
- You want a full SaaS and AI inventory within hours, with nothing installed on endpoints or in the network path, and a price you can see.
- Your remediation model is people-driven: nudges in the browser, owners confirming accounts, grants revoked at offboarding.
- SaaS security posture and vendor risk matter as much as AI discovery.
Choose Harmonic Security if
- Your main risk is sensitive data in prompts, and you want context-aware detection that warns or blocks in the browser and on the desktop.
- Developers use desktop AI apps, Claude Code, Cursor and local MCP servers, and you can deploy an endpoint agent through your MDM.
Choose Netskope if
- You already steer web traffic through a secure web gateway, or are planning a SASE rollout, and want AI discovery in the same platform.
- You need an inventory of locally running models and desktop agents on Windows and macOS, alongside inline DLP and user coaching.
Choose Lutril if
- Discovery has to end in a decision: each tool marked managed, unmanaged or blocked, OAuth access revoked, agents registered with an owner.
- Agents built in code, wired to API keys in GitHub or GitLab, are part of your shadow AI problem, not only chat apps in the browser.
- Shadow AI access should close at offboarding, in the same product that runs your access reviews and governs agent tool calls through an MCP proxy.
- Nothing should sit in the network path, and your data has to stay in the EU. If local models are a concern, pair Lutril with your EDR or MDM inventory.
Questions buyers ask
What are the best shadow AI discovery tools in 2026?
Four with public documentation of how they find AI use: Nudge Security (email metadata, OAuth grants and a browser extension, nothing on endpoints), Harmonic Security (browser extension, endpoint agent and a local MCP gateway), Netskope (secure web gateway, the Netskope Client on endpoints and Cloud Confidence Index ratings) and Lutril (OAuth grants, sign-up emails, a Chrome extension and code scanning, tied to access governance). LayerX, now sold as Akamai Workforce Protector, is another browser-based option. Choose first on which signals match where your AI use happens, then on what the tool lets you do once it has found something.
How do you discover shadow AI?
By combining signals, because each one misses something. OAuth grants show AI apps authorized with a Google or Microsoft account, with their scopes. Sign-up emails show tools adopted with an email and a password. A browser extension shows AI used in the browser, including with personal accounts. A secure web gateway shows traffic from steered networks and devices. An endpoint agent shows desktop apps, CLI tools and local models. Code scanning shows agents built in your repositories. None of the four tools on this page documents all six.
How can I detect shadow AI when employees run models directly on their laptops?
Only with something on the laptop. A model run through Ollama or LM Studio does its inference locally: no OAuth grant, often no sign-up email, and once the model is downloaded, no traffic to an AI provider for a gateway to inspect. Netskope's Client scans Windows and macOS endpoints against a signature list that includes Ollama, LM Studio, Jan AI and GPT4All, and Harmonic's endpoint coverage lists Ollama and locally hosted models. Lutril has no endpoint agent and does not detect local inference; it sees the traces around it, such as a visit to Hugging Face, a vendor sign-up email or agent code committed to GitHub or GitLab. Your MDM software inventory or EDR is the other place to look, since both list installed applications and running processes.
I'm a CISO looking for AI governance tools that help with shadow AI discovery. What are my options?
Three families. SaaS security platforms such as Nudge Security discover from email and OAuth with nothing to install and remediate through nudges. AI data security and secure access platforms such as Harmonic Security and Netskope sit in the browser, on the endpoint or in the network path, see prompts and enforce DLP in real time. Access governance platforms such as Lutril discover from OAuth, email, the browser and code, then govern what they find: a decision per tool, an owner per agent, policy on each agent tool call through an MCP proxy, and OAuth revocation at offboarding. The families are not exclusive: an inline control for prompts and a governance layer for owners and access can run side by side.
What are the most effective AI governance tools to prevent shadow AI and enforce policies?
Prevention works when the approved path is easier than the shadow one, and enforcement needs a control point. For prompts, inline tools act before data leaves: Harmonic warns or blocks in the browser and on the desktop, Netskope blocks or coaches through real-time policies, Nudge Security steers users toward sanctioned tools, and Lutril's extension warns on sensitive data in ChatGPT, Claude and Gemini and redacts on the user's click. For agents, enforcement means an owner, scoped access and a policy decision on each tool call, which Lutril applies through its agent registry and MCP proxy. Blocking alone tends to move usage to devices and accounts you do not manage.
What is the difference between shadow AI discovery and AI governance?
Discovery answers which AI tools and agents are in use and by whom. Governance answers what happens next: who owns each one, what it may reach, who approved it, when access ends and what evidence an auditor gets. The tools on this page differ in how far they go past the inventory: Nudge Security routes changes to owners and revokes grants at offboarding, Harmonic Security and Netskope enforce inline on prompts and traffic, and Lutril registers agents with owners, governs their tool calls through its MCP proxy and revokes OAuth access when someone leaves.
Sources
- 1Nudge Security homepageread on September 26, 2026
- 2Nudge Security pricingread on September 26, 2026
- 3Nudge Security FAQsread on September 26, 2026
- 4Nudge Security, browser extensionread on September 26, 2026
- 5Nudge Security, AI agent discoveryread on September 26, 2026
- 6Nudge Security, AI conversation monitoringread on September 26, 2026
- 7Nudge Security changelog, inherent and residual risk scores in open betaread on September 26, 2026
- 8Nudge Security, IT offboardingread on September 26, 2026
- 9Nudge Security, user access reviewsread on September 26, 2026
- 10Harmonic Security homepageread on September 26, 2026
- 11Harmonic Security, Exploreread on September 26, 2026
- 12Harmonic Security, Guideread on September 26, 2026
- 13Harmonic Security, shadow AI detectionread on September 26, 2026
- 14Harmonic Security, endpoint AI securityread on September 26, 2026
- 15Harmonic Security, AI agent security and MCP gatewayread on September 26, 2026
- 16Harmonic Security docs, browser extensionread on September 26, 2026
- 17Harmonic Security pricingread on September 26, 2026
- 18Netskope docs, AI Command Centerread on September 26, 2026
- 19Netskope docs, Netskope Client AI Discoveryread on September 26, 2026
- 20Netskope docs, AI asset overviewread on September 26, 2026
- 21Netskope docs, viewing and analyzing 3rd party appsread on September 26, 2026
- 22Netskope docs, Cloud Confidence Indexread on September 26, 2026
- 23Netskope docs, AI Guardrails policy for real-time protectionread on September 26, 2026
- 24Netskope docs, configuring real-time protection policiesread on September 26, 2026
- 25Netskope Community, DLP use cases for ChatGPTread on September 26, 2026
- 26Netskope blog, NewEdge expansion in the UK (management plane locations)read on September 26, 2026
- 27Netskope press release, Leader in the Gartner Magic Quadrant for SASE Platforms, 3rd yearread on September 26, 2026
Lutril wrote this page. Facts about Nudge Security, Harmonic Security, Netskope come from their public documentation as of September 26, 2026; states marked "Not documented" mean we found nothing public that confirms or denies the capability. Spotted an error? Write to hello@lutril.com and we will correct it.
Related reading
- Shadow AI: 80% of Your Employees Use It. You Approved 23%.
- OAuth Finds the SaaS Employees Sign Into. Our Chrome Extension Finds the Rest.
- Shadow AI: See every AI tool and agent your team really uses.
- AI DLP for LLMs: Stop PII from leaking into prompts.
- Lutril vs Nudge Security
- Best access management tools for SaaS apps in 2026: Lumos, Zluri, Torii, BetterCloud, AccessOwl and Lutril