# Best shadow AI discovery tools in 2026: Nudge Security, Harmonic Security, Netskope and Lutril

> Four shadow AI discovery tools compared on the signals they read (OAuth, email, browser, network, endpoint, code), local models, agents, DLP and EU hosting. Sourced.

Source: https://www.lutril.com/compare/shadow-ai-discovery-tools
Last reviewed: 2026-09-26

---

## Short answer

The best shadow AI discovery tool is the one whose signals match where your AI use happens, because each signal type misses something. Nudge Security reads email metadata, OAuth grants and a browser extension, installs nothing on endpoints, and publishes its pricing. Harmonic Security and Netskope add an endpoint agent that sees desktop AI apps, MCP servers and models running locally through Ollama, and Netskope also inspects web traffic through its secure web gateway. Lutril reads OAuth grants, sign-up emails, a Chrome extension and GitHub and GitLab repositories, then carries each finding into access governance: a decision per tool, an owner per agent, OAuth revocation at offboarding and EU hosting; it has no endpoint agent and does not detect local models.

## Where each one starts

**Nudge Security.** A SaaS and AI security platform: your workforce uses three times more AI and SaaS apps than you think. Discovery from machine-generated email metadata and OAuth grants in Google Workspace and Microsoft 365, plus a browser extension for Chromium browsers, Edge, Firefox and Safari; nothing touches the corporate network or endpoints. An AI agent inventory with approval status and owner, risk scores per vendor, and remediation through nudges to employees. Published pricing, all features on every tier.

**Harmonic Security.** An AI governance and control platform: understand, control, enable. Explore discovers the AI tools in use and scores each one; Guide warns or blocks in the browser and on the desktop, with small language models judging the data in each interaction; Command extends governance to agents. A browser extension for Chrome, Edge, Firefox, Safari and AI browsers, an endpoint agent, and a locally installed MCP gateway for Windows, macOS and Linux. EU hosting on request.

**Netskope.** Modern security and networking for the cloud and AI era. NASDAQ-listed (NTSK) and named a Leader in Gartner's Magic Quadrant for SASE Platforms for the third year in 2026. The Netskope One platform sees AI use in web traffic through its secure web gateway, on Windows and macOS endpoints through the Netskope Client, and across MCP through its Agentic Broker; AI Command Center inventories AI apps, MCP servers, agents and locally running models. The Cloud Confidence Index rates apps from 0 to 100.

**Lutril.** Access governance for employees and AI agents. Shadow AI discovery reads OAuth grants from Google Workspace and Microsoft 365, sign-up emails, a Chrome extension and GitHub and GitLab repositories, and merges them into one inventory per vendor. Each tool is marked managed, unmanaged or blocked, OAuth access can be revoked, and agents found in code are promoted into the registry with an owner and governed through the MCP proxy. No endpoint agent. Hosted in France.

## Capability by capability

| Capability | Nudge Security | Harmonic Security | Netskope | Lutril |
| --- | --- | --- | --- | --- |
| OAuth grants and IdP sign-in data (Google Workspace, Microsoft 365) | Yes: OAuth connection to Google Workspace or Microsoft 365; OAuth grant inventory [3] | Not documented | Partial: Third-party OAuth apps for Entra ID, Google Workspace and Salesforce; requires API-enabled protection with SSPM [21] | Yes: OAuth grants with scopes, users, first authorizer and first-seen date |
| Mailbox scanning for sign-up emails | Yes: Machine-generated emails only; metadata stored, analysed in memory [3] | Not documented | Not documented | Yes: Opt-in; sender and subject of sign-up emails, bodies never fetched |
| Browser extension | Yes: Chromium browsers, Edge, Firefox and Safari [4] | Yes: Chrome, Edge, Firefox, Safari, Arc, Brave, Island, Comet, Dia [16] | Not documented: Browser traffic is steered to the secure web gateway by the Netskope Client | Yes: Chrome, force-installed by MDM; reports catalogued hostnames only |
| Network or secure web gateway inspection | Not offered: Vendor states it does not touch the corporate network [3] | Not documented | Yes: Next-Gen SWG feeds AI apps and identities into AI Command Center [18] | Not offered: No proxy on employee web traffic; the MCP proxy covers agent tool calls |
| Endpoint agent: desktop AI apps, CLI tools, IDE extensions | Not offered: Vendor states it does not touch endpoints and needs no agent roll-out [3] | Yes: Claude Desktop, ChatGPT Desktop, Cursor, Claude Code, GitHub Copilot [14] | Yes: Netskope Client scans for desktop agents, MCP servers, browser and IDE AI extensions [19] | Not offered: No endpoint agent |
| Detects models running locally on laptops (Ollama, LM Studio) | Not documented: No endpoint component by design; local inference not addressed | Yes: Endpoint coverage lists Ollama and locally hosted models [14] | Yes: Signature-based: Ollama, LM Studio, Jan AI, GPT4All; Windows and macOS only [19] | Not offered: Local inference leaves no OAuth grant, email or browser visit for Lutril to read |
| Discovers AI agents, not only chat apps | Yes: API discovery (Agentforce, Copilot Studio, n8n) plus browser discovery (Cursor, Zapier Agents) [5] | Yes: MCP gateway discovers MCP clients and servers and who uses them [15] | Yes: AI Command Center lists agents, MCP servers and local models [18] | Yes: Code scanning of GitHub and GitLab for agent frameworks and tool-calling loops |
| Risk score per discovered app | Yes: Inherent and residual risk per SaaS and AI vendor, in open beta [7] | Yes: Risk score per application: data policies, training practices, HQ [11] | Yes: Cloud Confidence Index score from 0 to 100 in five levels [22] | Partial: Risk tier from granted OAuth scopes; apps seen only by extension or email carry no scope data; 0 to 100 score per agent |
| Owner and approval decision per tool or agent | Yes: Agents carry approval status (Approved, Allowed, In Review, Not Permitted) and a technical owner [5] | Partial: Approved and monitored groups; owner assignment not documented [13] | Partial: Sanctioned and unsanctioned apps; owner assignment not documented [20] | Partial: Apps marked managed, unmanaged or blocked; owners on agents, suggested from commit authors |
| Prompt-level DLP or redaction | Partial: Detects secrets, PII and PHI in prompts; alert, mask or store; blocking not documented [6] | Yes: Small language models judge each interaction; block, warn or log [12] | Yes: Inline DLP profiles block sensitive posts to ChatGPT [25] | Partial: ChatGPT, Claude and Gemini only; detection on the device, redaction on the user's click |
| Coaches or blocks users in the browser | Yes: Browser nudges steer users to sanctioned tools and capture exception requests; blocking is not the model [4] | Yes: Block in real time or warn with context, browser and desktop [12] | Yes: Block or User Alert with coaching notification templates [23] | Partial: Warning banner on sensitive prompts; AI sites are not blocked |
| Ties into access reviews and offboarding | Yes: Offboarding revokes OAuth grants and resets passwords on unmanaged accounts; reviews route changes to app owners [8] | Not documented | Not documented | Yes: Offboarding revokes the leaver's OAuth grants; reviews and lifecycle in the same product |
| EU hosting | Not documented | Yes: EU hosting on request [10] | Yes: Management planes in Amsterdam and Frankfurt [26] | Yes: OVHcloud, France |
| Published pricing | Yes: $750 per month up to 150 users; $5 per user per month from 150 to 1,500 [2] | Not offered: Pricing page lists three plans without figures [17] | Not documented: No public price list found | Not offered: On request |

## Choose Nudge Security if

- You want a full SaaS and AI inventory within hours, with nothing installed on endpoints or in the network path, and a price you can see.
- Your remediation model is people-driven: nudges in the browser, owners confirming accounts, grants revoked at offboarding.
- SaaS security posture and vendor risk matter as much as AI discovery.

## Choose Harmonic Security if

- Your main risk is sensitive data in prompts, and you want context-aware detection that warns or blocks in the browser and on the desktop.
- Developers use desktop AI apps, Claude Code, Cursor and local MCP servers, and you can deploy an endpoint agent through your MDM.

## Choose Netskope if

- You already steer web traffic through a secure web gateway, or are planning a SASE rollout, and want AI discovery in the same platform.
- You need an inventory of locally running models and desktop agents on Windows and macOS, alongside inline DLP and user coaching.

## Choose Lutril if

- Discovery has to end in a decision: each tool marked managed, unmanaged or blocked, OAuth access revoked, agents registered with an owner.
- Agents built in code, wired to API keys in GitHub or GitLab, are part of your shadow AI problem, not only chat apps in the browser.
- Shadow AI access should close at offboarding, in the same product that runs your access reviews and governs agent tool calls through an MCP proxy.
- Nothing should sit in the network path, and your data has to stay in the EU. If local models are a concern, pair Lutril with your EDR or MDM inventory.

## Frequently asked questions

### What are the best shadow AI discovery tools in 2026?

Four with public documentation of how they find AI use: Nudge Security (email metadata, OAuth grants and a browser extension, nothing on endpoints), Harmonic Security (browser extension, endpoint agent and a local MCP gateway), Netskope (secure web gateway, the Netskope Client on endpoints and Cloud Confidence Index ratings) and Lutril (OAuth grants, sign-up emails, a Chrome extension and code scanning, tied to access governance). LayerX, now sold as Akamai Workforce Protector, is another browser-based option. Choose first on which signals match where your AI use happens, then on what the tool lets you do once it has found something.

### How do you discover shadow AI?

By combining signals, because each one misses something. OAuth grants show AI apps authorized with a Google or Microsoft account, with their scopes. Sign-up emails show tools adopted with an email and a password. A browser extension shows AI used in the browser, including with personal accounts. A secure web gateway shows traffic from steered networks and devices. An endpoint agent shows desktop apps, CLI tools and local models. Code scanning shows agents built in your repositories. None of the four tools on this page documents all six.

### How can I detect shadow AI when employees run models directly on their laptops?

Only with something on the laptop. A model run through Ollama or LM Studio does its inference locally: no OAuth grant, often no sign-up email, and once the model is downloaded, no traffic to an AI provider for a gateway to inspect. Netskope's Client scans Windows and macOS endpoints against a signature list that includes Ollama, LM Studio, Jan AI and GPT4All, and Harmonic's endpoint coverage lists Ollama and locally hosted models. Lutril has no endpoint agent and does not detect local inference; it sees the traces around it, such as a visit to Hugging Face, a vendor sign-up email or agent code committed to GitHub or GitLab. Your MDM software inventory or EDR is the other place to look, since both list installed applications and running processes.

### I'm a CISO looking for AI governance tools that help with shadow AI discovery. What are my options?

Three families. SaaS security platforms such as Nudge Security discover from email and OAuth with nothing to install and remediate through nudges. AI data security and secure access platforms such as Harmonic Security and Netskope sit in the browser, on the endpoint or in the network path, see prompts and enforce DLP in real time. Access governance platforms such as Lutril discover from OAuth, email, the browser and code, then govern what they find: a decision per tool, an owner per agent, policy on each agent tool call through an MCP proxy, and OAuth revocation at offboarding. The families are not exclusive: an inline control for prompts and a governance layer for owners and access can run side by side.

### What are the most effective AI governance tools to prevent shadow AI and enforce policies?

Prevention works when the approved path is easier than the shadow one, and enforcement needs a control point. For prompts, inline tools act before data leaves: Harmonic warns or blocks in the browser and on the desktop, Netskope blocks or coaches through real-time policies, Nudge Security steers users toward sanctioned tools, and Lutril's extension warns on sensitive data in ChatGPT, Claude and Gemini and redacts on the user's click. For agents, enforcement means an owner, scoped access and a policy decision on each tool call, which Lutril applies through its agent registry and MCP proxy. Blocking alone tends to move usage to devices and accounts you do not manage.

### What is the difference between shadow AI discovery and AI governance?

Discovery answers which AI tools and agents are in use and by whom. Governance answers what happens next: who owns each one, what it may reach, who approved it, when access ends and what evidence an auditor gets. The tools on this page differ in how far they go past the inventory: Nudge Security routes changes to owners and revokes grants at offboarding, Harmonic Security and Netskope enforce inline on prompts and traffic, and Lutril registers agents with owners, governs their tool calls through its MCP proxy and revokes OAuth access when someone leaves.

## Sources

1. [Nudge Security homepage](https://www.nudgesecurity.com/) (accessed 2026-09-26)
2. [Nudge Security pricing](https://www.nudgesecurity.com/pricing) (accessed 2026-09-26)
3. [Nudge Security FAQs](https://www.nudgesecurity.com/faqs) (accessed 2026-09-26)
4. [Nudge Security, browser extension](https://www.nudgesecurity.com/features/browser-extension) (accessed 2026-09-26)
5. [Nudge Security, AI agent discovery](https://www.nudgesecurity.com/features/ai-agent-discovery) (accessed 2026-09-26)
6. [Nudge Security, AI conversation monitoring](https://www.nudgesecurity.com/features/ai-conversation-monitoring) (accessed 2026-09-26)
7. [Nudge Security changelog, inherent and residual risk scores in open beta](https://www.nudgesecurity.com/changelog/know-your-real-vendor-risk-with-inherent-and-residual-risk-scores-now-in-open-beta) (accessed 2026-09-26)
8. [Nudge Security, IT offboarding](https://www.nudgesecurity.com/use-cases/it-offboarding) (accessed 2026-09-26)
9. [Nudge Security, user access reviews](https://www.nudgesecurity.com/use-cases/user-access-reviews) (accessed 2026-09-26)
10. [Harmonic Security homepage](https://www.harmonic.security/) (accessed 2026-09-26)
11. [Harmonic Security, Explore](https://www.harmonic.security/products/explore) (accessed 2026-09-26)
12. [Harmonic Security, Guide](https://www.harmonic.security/products/guide) (accessed 2026-09-26)
13. [Harmonic Security, shadow AI detection](https://www.harmonic.security/solutions/shadow-ai-detection) (accessed 2026-09-26)
14. [Harmonic Security, endpoint AI security](https://www.harmonic.security/solutions/endpoint-ai-security) (accessed 2026-09-26)
15. [Harmonic Security, AI agent security and MCP gateway](https://www.harmonic.security/solutions/ai-agent-security-mcp-gateway) (accessed 2026-09-26)
16. [Harmonic Security docs, browser extension](https://docs.harmonicsecurity.app/browser-extension) (accessed 2026-09-26)
17. [Harmonic Security pricing](https://www.harmonic.security/pricing) (accessed 2026-09-26)
18. [Netskope docs, AI Command Center](https://docs.netskope.com/en/ai-command-center) (accessed 2026-09-26)
19. [Netskope docs, Netskope Client AI Discovery](https://docs.netskope.com/en/netskope-client-ai-discovery) (accessed 2026-09-26)
20. [Netskope docs, AI asset overview](https://docs.netskope.com/en/ai-asset-overview) (accessed 2026-09-26)
21. [Netskope docs, viewing and analyzing 3rd party apps](https://docs.netskope.com/en/view-3rd-party-apps) (accessed 2026-09-26)
22. [Netskope docs, Cloud Confidence Index](https://docs.netskope.com/en/cloud-confidence-index) (accessed 2026-09-26)
23. [Netskope docs, AI Guardrails policy for real-time protection](https://docs.netskope.com/en/creating-an-ai-security-guardrails-policy-for-real-time-protection) (accessed 2026-09-26)
24. [Netskope docs, configuring real-time protection policies](https://docs.netskope.com/en/configuring-real-time-protection-policies) (accessed 2026-09-26)
25. [Netskope Community, DLP use cases for ChatGPT](https://community.netskope.com/inside-netskope-22/netskope-dlp-use-cases-for-chatgpt-602) (accessed 2026-09-26)
26. [Netskope blog, NewEdge expansion in the UK (management plane locations)](https://www.netskope.com/blog/explaining-the-importance-of-netskopes-recent-expansion-of-newedge-in-the-uk) (accessed 2026-09-26)
27. [Netskope press release, Leader in the Gartner Magic Quadrant for SASE Platforms, 3rd year](https://www.globenewswire.com/news-release/2026/07/31/3336918/0/en/netskope-named-a-leader-in-the-gartner-magic-quadrant-for-secure-access-service-edge-platforms-for-3rd-year-in-a-row.html) (accessed 2026-09-26)

Lutril wrote this page. Facts about Nudge Security, Harmonic Security, Netskope come from their public documentation as of 2026-09-26. Spotted an error? Write to hello@lutril.com.
