Shadow AI Discovery and Governance Tools Compared for UK Buyers

Shadow AI Discovery and Governance Tools Compared for UK Buyers

22 min read

The tools sold to govern employee AI use do five different jobs that vendors blur: discovery, enforcement, sanctioned access, data protection and licensing visibility. This comparison groups Microsoft Purview and Defender for Cloud Apps, the SASE platforms, browser and endpoint tools, and the AI gateways by the job each does, states which prices are published and which are quote-only, and sets out the Microsoft licence tiers and consumption meters Purview's AI capabilities require. It then examines the dividing line that matters most: which tools read employee prompt text, and why ICO guidance makes that a workplace monitoring decision needing a DPIA, transparency and a lawful basis before deployment.

Daniel Thomas
Written by Daniel Thomas

The tools sold to govern employee AI use do five different jobs: discovery (finding out which AI is in use), enforcement (allowing, blocking or redirecting it), sanctioned access (giving staff an approved route to AI), data protection (controlling what data leaves), and licensing visibility (knowing who is paying for what). Most organisations need two of those jobs done well. Most vendors sell platforms that bundle three or four of them, which is why buying in this market so often starts with a feature grid and ends with an unused module.

This guide compares the products UK IT managers actually name, grouped by the job each one does, with published prices where they exist and an honest note where they do not. The most consequential difference between these products appears on no feature grid: whether the tool reads the text of what employees type into a chatbot. That single design choice separates a network report from workplace monitoring under UK GDPR, and it gets its own section below.

The five jobs these tools do

Shadow AI tooling splits into five jobs that vendors tend to blur: discovery, enforcement, sanctioned access, data protection, and licensing visibility. A buyer who names the job first will spend far less than one who starts from a platform demo, because platforms are priced on the assumption you want all five.

Discovery answers "which AI is in use, by whom". Enforcement decides what happens when someone opens a chatbot: allow, block, warn, or redirect. Sanctioned access is the approved route you offer instead, usually an AI gateway that manages keys, spend and logging for the models you have chosen. Data protection watches the content itself, blocking or redacting sensitive data on its way into a model. Licensing visibility, knowing which teams hold which AI subscriptions, is the job of SaaS-management platforms such as Flexera, Zylo and Productiv, plus the admin reporting in Microsoft 365 itself; it matters for cost control but is a procurement discipline rather than a security control, and this article concentrates on the first four.

Two practical consequences follow. First, discovery and data protection are different purchases: a tool can tell you ChatGPT is in heavy use without ever seeing a prompt, and a DLP engine can redact a credit card number without telling you which other AI apps exist in your estate. Second, if you already run Microsoft 365 E5 or a SASE platform, you probably own more of these jobs than you think, and the right first step is an inventory of what your current licences cover. Our guide to AI governance for mid-market organisations covers the policy layer that should drive that inventory.

Discovery tools show which AI is in use

Discovery tools answer the first question any governance effort needs: which AI services are actually in use, by which users, on which devices. Almost every practitioner account of getting control of shadow AI starts here, and the tooling is often already licensed.

Microsoft Defender for Cloud Apps matches network traffic against a catalogue of more than 31,000 cloud apps scored on over 90 risk factors, with a generative AI category, according to Microsoft's documentation. Discovery data can come from the Defender for Endpoint sensor on Windows and macOS devices, on or off the corporate network with no proxy required, or from log collectors fed by existing firewalls and proxies. Tagging an app as unsanctioned pushes blocks out through Defender for Endpoint. It is included in Microsoft 365 E5, or on E3 via the Defender Suite add-on at $12.00 per user per month (Microsoft's US list pricing, December 2025 announcement).

Microsoft Entra Global Secure Access adds a network-based shadow AI discovery view for organisations running Microsoft's SSE service: it identifies traffic to generative AI applications, MCP servers and model provider APIs, matches it against the Defender for Cloud Apps catalogue, and reports users, usage and data volumes, per Microsoft Learn.

Netskope One rates more than 370 generative AI applications among over 82,000 SaaS apps in its Cloud Confidence Index, and its instance awareness distinguishes a personal ChatGPT account from a corporate ChatGPT Enterprise tenant on the same domain, a distinction DNS and URL filtering cannot make (Netskope documentation). Zscaler provides equivalent discovery dashboards from its inline proxy, showing which AI apps are in use and by whom. Both are quote-only platforms.

LayerX takes the browser as its vantage point: an extension inventories web AI tools, AI browser extensions and AI features embedded inside approved SaaS, including use through personal accounts. Akamai announced a definitive agreement to acquire LayerX for approximately US$205 million on 14 May 2026, with closing expected in the third quarter of 2026, and is folding it into Akamai Workforce Protector, per Akamai's press release. CrowdStrike approaches from the endpoint: Falcon discovers AI applications, LLM runtimes, MCP servers and IDE extensions on devices. Darktrace positions its SECURE AI product around visibility of AI use and detection of anomalous data movement rather than content logging. Fortinet's FortiOS 8.0, released in early 2026, adds a FortiView AI attack surface view on the firewall itself; its AI features require a FortiGuard subscription, per Fortinet's release announcement.

The honest limit of every discovery tool is the same one practitioners keep reporting: none of them sees a personal phone on a mobile network, and AI features arriving inside already-approved SaaS blur the category the tools are trying to count.

Enforcement tools decide what happens next

Enforcement tools act on what discovery finds: allow, block, warn, isolate or redirect. The design question is not which tool blocks best but how graduated the response can be, because a hard block with no sanctioned alternative reliably moves the activity somewhere less visible.

The bluntest control is DNS. Cisco Umbrella can block AI domains at its DNS tiers, but Cisco's own documentation is clear about the ceiling: content-level control needs the SIG tier with HTTPS inspection, and DNS filtering cannot tell a personal ChatGPT login from a corporate one because both resolve the same domain. Cisco has expanded Umbrella's real-time DLP to cover the 70 AI tools in its generative AI application category, inbound responses included, but only where full proxying is on (Cisco documentation).

URL and category filtering sit a level up. Microsoft Entra Conditional Access on its own cannot block third-party AI websites, because it governs sign-ins to applications, not browsing destinations. Blocking ChatGPT, Claude or Gemini by category in the Microsoft stack requires Entra Internet Access, whose web content filtering and AI category ship as part of the Microsoft Entra Suite at $12.00 per user per month (Microsoft's Entra pricing page, accessed 6 August 2026). Conditional Access itself requires at least Entra ID P1, which rises from $6.00 to $7.00 per user per month on Microsoft's July 2026 price list.

The SASE platforms offer the most graduated enforcement. Netskope can coach rather than block, showing a real-time message that steers the user towards the corporate-approved AI tool, and its policies can allow a corporate instance while restricting the personal instance of the same app. Zscaler offers block, caution and browser-isolation modes, and can allow prompts while preventing bulk file uploads. Check Point Browser Security enforces at the browser, blocking the copy-and-paste of sensitive data patterns into AI chat interfaces in its Advanced tier. These graduated modes exist because vendors have learned what IT managers report from full blocks: the behaviour does not stop, it just leaves your network. The zero trust principles NCSC publishes apply directly here: policy should follow identity and data, not network location.

AI gateways provide the sanctioned route

An AI gateway is how an organisation offers staff an approved path to AI rather than only a wall: one endpoint through which applications and users reach many models, with the organisation holding the keys, the logs and the spend controls. Gateways govern the sanctioned route only. A gateway sees nothing of an employee's personal ChatGPT tab; that is discovery and enforcement's job.

Cloudflare AI Gateway's core features (analytics, caching, rate limiting) are free on every plan, and its DLP scanning is also free, per Cloudflare's pricing page (updated 19 May 2026). Optional Guardrails, which evaluate prompts and responses using Meta's Llama Guard model, are billed as Workers AI inference, and buying provider credits through its Unified Billing carries a 5 per cent fee. OpenRouter aggregates more than 400 models behind one API, charges a platform fee on credit purchases rather than a per-user licence, and offers routing controls that exclude providers which store or train on inputs, with zero-data-retention options and, for enterprise accounts, an EU in-region endpoint, per OpenRouter's published pricing and documentation.

LiteLLM is the self-hosted option: an MIT-licensed open source gateway that is free to run forever, with an Enterprise tier (SSO, SCIM, audit logs, air-gapped deployment) priced to annual request capacity on a quote basis, "never per token", per LiteLLM's pricing page. Because it runs entirely in your own infrastructure, prompt data never touches a vendor, which makes it the natural pairing for organisations already exploring self-hosted alternatives to SaaS.

The network security vendors now sell gateways too. Palo Alto Networks' Prisma AIRS AI Gateway reached general availability in July 2026 and inspects prompts and responses inline, licensed through the company's credit-based model on a quote basis. Fortinet's FortiAIGate is a separate product from FortiOS, a dedicated reverse proxy between applications and LLM providers with its own guardrails and DLP, also quote-only. Netskope includes an AI gateway for app-to-LLM traffic within its platform. The distinction that matters for a buyer: the free and open gateways govern developer and application access economically, while the security-vendor gateways add inline threat and data inspection at platform prices.

Data protection tools inspect what leaves

Data protection tools examine the content of AI interactions and block, redact or log sensitive data before it reaches a model. This is the job most buyers actually mean when they say they need to "control AI", and it is where capability, cost and legal obligation all concentrate.

Microsoft Purview is the incumbent for Microsoft estates. Its Data Security Posture Management (DSPM) for AI creates one-click policies that detect sensitive information pasted into AI sites in Edge, Chrome and Firefox, detect visits to AI sites, and capture Copilot interactions. Prompts and responses are recorded in the unified audit log and stored in the user's mailbox, where retention policies and eDiscovery apply, and the Activity Explorer's AI activities tab shows "the prompts and responses and if they contained sensitive information", per Microsoft Learn. For what Copilot itself can leak inside a tenant, see our guide to stopping Copilot surfacing confidential data to the wrong people.

The SASE platforms do the same job inline. Zscaler applies DLP across more than 100 dictionaries (source code, PII, payment card data, health data) to AI traffic and offers "prompt/response extraction and classification", per Zscaler's product pages. Netskope says its DLP and AI Guardrails "inspect every prompt and response in real time", using semantic inspection that evaluates intent and context rather than pattern matching alone, with over 3,000 data classifiers (Netskope documentation).

CrowdStrike Falcon AIDR, generally available since December 2025, collects telemetry that includes "original prompts and AI responses" across a browser extension, the endpoint sensor, SDKs and an MCP proxy, and enforces policies of log, redact or block, per CrowdStrike's documentation. Check Point GenAI Protect treats all prompts as potentially sensitive, categorises usage into use cases and severity levels, and gates the viewing of actual prompt text behind a specific administrator permission, per Check Point's administration guide; Check Point also acquired the AI runtime security firm Lakera (announced 16 September 2025) for guardrails against prompt injection and jailbreaks. Fortinet's FortiOS 8.0 adds DLP with keyword and FQDN matching for AI traffic plus OCR to catch sensitive data inside screenshots and images, FortiGuard subscription required.

Which tools read employee prompts

Thirteen of the products in this comparison can inspect the actual text of employee prompts; a handful, by design, cannot. This is the dividing line a buyer should establish before any demo, because it determines both what the tool can do and what deploying it obliges you to do.

ProductReads prompt text?Where inspection happens
Microsoft Purview DSPM for AIYesEndpoint DLP, Edge integration, browser extension; audit log
Microsoft Entra Internet Access prompt policies (preview)YesTLS inspection in Microsoft's SSE network
Microsoft Defender for Cloud AppsNoApp and domain level only
Microsoft Entra Conditional Access (alone)NoIdentity sign-in layer
Zscaler AI Access Security / AI GuardYesInline cloud proxy with TLS decryption
Netskope OneYesInline proxy, semantic DLP
Palo Alto Prisma AIRSYesRuntime API and inline gateway
Check Point GenAI Protect / Browser Security AdvancedYesNetwork inspection / browser extension
CrowdStrike Falcon AIDRYesBrowser extension, endpoint sensor, SDK, MCP proxy
LayerX (Akamai Workforce Protector)YesBrowser extension
Cloudflare AI Gateway (Guardrails or DLP enabled)YesAPI proxy
LiteLLM (guardrails enabled)YesSelf-hosted proxy, your infrastructure
OpenRouterNoRoutes requests; stores metadata, not content
Cisco UmbrellaSIG tier onlyCloud proxy with HTTPS inspection; DNS tiers cannot
DarktraceBehaviouralVolume and pattern anomalies rather than content logging; confirm scope with the vendor
Fortinet FortiOS 8.0 / FortiAIGateYesNetwork DLP with HTTPS inspection / LLM reverse proxy

Two readings of this table are worth making explicit. If your requirement is knowing which AI is in use and steering people to a sanctioned tool, several capable options never touch prompt content, and choosing one of them keeps you out of content monitoring entirely. If your requirement genuinely is content-level DLP, then every option that meets it puts you in the territory the next section describes, and vendor privacy features (Check Point's permission gating, Zscaler's no-storage default, Purview's pseudonymised reviews in Communication Compliance) mitigate but do not remove the obligations.

Prompt inspection is a workplace monitoring decision

A tool that records what an employee typed into a chatbot is processing that employee's personal data, and under UK GDPR that makes deployment a data protection decision, not a procurement checkbox. The Information Commissioner's Office guidance on monitoring workers, published in October 2023, was not written about AI controls, but its rules on monitoring emails and messages apply squarely, and the ICO defines messages to include chat functions in collaboration tools.

Three of its requirements bite hardest. First, transparency: apart from exceptional covert circumstances, the ICO says you must inform workers about any monitoring before it begins, and a generic clause in an employment contract does not do that job. Second, a mandatory impact assessment: "If you are considering monitoring emails and messages, you must complete a DPIA," because such monitoring "poses a high risk to workers' data protection rights and freedoms and is likely to capture special category data" (ICO, monitoring workers guidance). A prompt log will sooner or later capture a health question, a grievance draft or a message to a union rep, and incidental capture of special category data requires an Article 9 condition on top of your lawful basis. Third, proportionality: "It would be difficult to justify monitoring the content of emails and messages if monitoring network data traffic would meet your purpose." Translated to this market: if discovery-level data answers your question, the ICO expects you to document why you bought content inspection anyway. Consent is not the answer either; the ICO is explicit that the imbalance of power in employment means workers rarely give it freely, which points employers to legitimate interests and a documented assessment instead.

None of this makes prompt inspection unlawful. Regulated firms with a genuine data-loss requirement deploy it, lawfully, with a DPIA completed before switch-on, a clear policy stating when content may be reviewed, scoped access to the logs, and retention limits. The point is sequencing: the DPIA is a pre-deployment gate, not paperwork to backfill, and it belongs alongside your Article 30 records of processing. Where monitoring output feeds automated decisions about individuals, the ICO's guidance on solely automated monitoring tools adds further safeguards. For the wider regulatory backdrop, see UK AI regulation compared with the EU AI Act.

What Microsoft licensing actually requires

"We already have Microsoft" is the most common opening position, and it is half true: the discovery layer is broadly included, but Purview's AI capabilities concentrate in the top licence tier plus consumption meters that surprise people at the first Azure bill. The figures below are Microsoft's published US list prices; UK prices vary with currency and agreement.

Microsoft 365 E5 rises from $57.00 to $60.00 per user per month on 1 July 2026, announced 4 December 2025, and E3 rises from $36.00 to $39.00 (Microsoft licensing news). E3 carries core Purview DLP for Exchange, SharePoint and OneDrive, information protection, audit and eDiscovery. The capabilities DSPM for AI leans on, Insider Risk Management for detecting AI site visits and risky usage, Communication Compliance for reviewing AI interactions, and automatic labelling, sit in the E5 tier, or reach E3 through the Purview Suite add-on (formerly E5 Compliance) at $12.00 per user per month, which requires an E3 base (Microsoft's Purview Suite pricing page).

Even at E5, two further costs apply, per Microsoft Learn. Monitoring Microsoft 365 Copilot interactions requires each monitored user to hold a Microsoft 365 Copilot licence. And monitoring third-party AI apps (ChatGPT, Gemini and the rest) runs on pay-as-you-go Azure meters: audit records processed, Communication Compliance text records scanned, and Insider Risk processing units are all consumption-billed for non-Microsoft AI interactions, against an Azure subscription you must link to the tenant. Microsoft 365 Copilot interactions are exempt from those meters. Operationally, third-party coverage also needs the Purview browser extension rolled out to Chrome and Firefox users and devices onboarded to endpoint DLP.

On the Entra side: Conditional Access needs Entra ID P1 ($7.00 from 1 July 2026); blocking AI sites by web category needs Entra Internet Access, included in the Entra Suite at $12.00 per user per month; and the preview prompt policies that inspect and block malicious prompts at the network level require an Entra Internet Access licence with TLS inspection configured, per Microsoft Learn.

You wantYou need
Discover which AI apps staff useE5, or E3 plus Defender Suite ($12.00), or standalone Defender for Cloud Apps
Warn or block when staff paste sensitive data into a chatbotE5, or E3 plus Purview Suite ($12.00); browser extension for Chrome/Firefox; onboarded devices
Review prompt and response textE5 or Purview Suite tier; plus a Copilot licence per user for Copilot monitoring
Monitor third-party AI interactions at scaleThe above plus pay-as-you-go Azure meters (audit records, text records, processing units)
Block AI websites by categoryEntra Internet Access (in the $12.00 Entra Suite)
Inspect prompts in the network (preview)Entra Internet Access plus TLS inspection

What the tools cost

Published list prices exist for a minority of this market; the platform vendors are quote-only, and the honest comparison states which is which. All figures below are vendor-published list prices in US dollars, accessed 6 August 2026 unless dated otherwise.

ProductPublished priceNotes
Microsoft 365 E5$60.00/user/monthFrom 1 July 2026; includes Purview Suite features, Defender for Cloud Apps, Entra ID P2
Microsoft Purview Suite add-on$12.00/user/monthRequires M365 E3 base
Microsoft Entra Suite$12.00/user/monthIncludes Entra Internet Access
CrowdStrike Falcon$59.99 to $184.99/device/yearGo, Pro and Enterprise tiers on CrowdStrike's pricing page; AIDR itself is not separately list-priced and is metered by I/O volume per CrowdStrike's licensing terms
Check Point Browser Security$27.82 base, $54.57 Advanced/user/12 monthsAWS Marketplace listing; Advanced tier carries the browser DLP and GenAI security
Cloudflare AI GatewayCore free; 5 per cent Unified Billing feeGuardrails billed as Workers AI inference
LiteLLMOpen source $0; Enterprise quote-onlyPriced to request capacity, not per token
OpenRouterPlatform fee on credit purchasesCurrent rates on openrouter.ai/pricing; enterprise quote for EU routing
ZscalerQuote-onlyIts UK G-Cloud 14 price book (effective 15 February 2024) lists Zscaler for Users editions from $375 (Business Prime) to $675 (ELA) per user per year
NetskopeQuote-onlyIts UK G-Cloud 14 pricing document lists Next Gen SWG Professional at $169.61 and the SSE Professional package at $213.16 per user per year
Palo Alto Prisma AIRSQuote-onlyLicensed via software firewall credits and token-metered API
Check Point GenAI ProtectQuote-onlySeparate add-on to the Infinity platform
Darktrace, Cisco Umbrella, Fortinet, LayerXQuote-onlyCisco sells Umbrella through tiered per-user subscriptions; Fortinet AI features require FortiGuard subscriptions

Quote-only is not a criticism; it reflects platform bundling and channel pricing. For UK buyers the G-Cloud framework documents on the Digital Marketplace are the most useful public reference points, because suppliers file real price books there.

Where the prompt data lives

If a tool inspects prompts, its logs are among the most sensitive data you hold, so where the vendor processes and stores them is part of the buying decision, not an afterthought. The postures differ widely.

Netskope has the most explicit UK story: three data planes (two in London, one in Manchester) carrying UK customer traffic inside UK jurisdiction, plus a UK management plane in London hosting the admin console, logs and metadata, per Netskope's own account of its NewEdge expansion; in May 2026 it announced data sovereignty support across 24 countries including the UK. Microsoft stores UK tenant data at rest in its UK regions, while its EU Data Boundary (completed February 2025) covers EU and EFTA customers, not the UK; Microsoft has said in-country processing for Microsoft 365 Copilot will reach the UK by the end of 2026 (Microsoft blog, November 2025). Zscaler operates in-region inspection across its European data centres and offers options to keep inspected prompt data in customer-controlled storage. CrowdStrike offers an EU-1 cloud region for AIDR alongside its US regions, per its documentation. LiteLLM, being self-hosted, puts residency entirely in your hands. Darktrace is UK-headquartered, and its on-premises appliances keep data on site.

Two cautions. Cloudflare's Data Localization Suite documentation did not list AI Gateway among the products with regional processing controls when we checked on 6 August 2026, so ask Cloudflare directly where gateway logs and inspection occur before routing prompt traffic through it; and for any US-headquartered processor, the US CLOUD Act (18 U.S.C. § 2713) requires production of data under lawful US orders wherever that data is stored, which belongs in your transfer risk assessment. Neither point is unique to AI tooling, and both echo the questions we set out for GDPR-compliant cloud storage generally. Where residency is not documented at all, as we found for several products here, treat it as a question for the vendor rather than an assumption either way.

Questions to put to any vendor

A buyer who asks these ten questions will surface the differences this article has mapped, and will find out quickly which job a product actually does.

  1. Which of the five jobs (discovery, enforcement, sanctioned access, data protection, licensing visibility) does this SKU do, and which does it not attempt?
  2. Does it inspect prompt content? Can that be disabled, or scoped to named data types and user groups?
  3. Where is prompt text processed and stored, for how long, and can you commit to UK or EU processing in writing?
  4. Which licence tier or add-on carries the AI capability, and what consumption meters apply on top?
  5. What do we already licence that overlaps with this? (Ask your Microsoft partner the same question the same week.)
  6. Can it distinguish personal from corporate instances of the same AI service?
  7. What does it see on unmanaged devices and personal phones, honestly?
  8. Can it coach and redirect users to our sanctioned tool rather than block outright?
  9. What does the vendor itself do with the inspection data: sub-processors, retention, and whether anything trains its models?
  10. What happens to this product through your acquisition pipeline? Lakera is now Check Point, LayerX is becoming Akamai Workforce Protector, and Protect AI's technology sits inside Palo Alto's Prisma AIRS; the tool you evaluate may not be the tool you renew.

Discovery first, decision recorded, sanctioned route chosen on whether people will use it, and content inspection only with the DPIA done: that sequence, which practitioners keep arriving at independently, is also the one the tooling market and the regulator both reward. For what the NCSC actually says about staff using chatbots with business data, see our debunking of the myths around its guidance.

Sources

Vendor documentation and published pricing: Microsoft's licensing news pages and Microsoft Learn documentation for Purview, DSPM for AI, Defender for Cloud Apps and Entra Global Secure Access (accessed 6 August 2026); the Microsoft Purview Suite and Entra pricing pages; CrowdStrike's pricing and licensing pages and Falcon AIDR documentation; Cloudflare's AI Gateway pricing documentation (updated 19 May 2026); LiteLLM's pricing page; OpenRouter's pricing and data residency documentation; Zscaler and Netskope product pages and their G-Cloud 14 pricing documents on the UK Digital Marketplace; Check Point's Browser Security listing on AWS Marketplace and its administration guides; Cisco's Umbrella generative AI documentation; Fortinet's FortiOS 8.0 and FortiAIGate materials. Corporate announcements: Akamai's 14 May 2026 press release on the LayerX acquisition, Check Point's 16 September 2025 press release on Lakera, Palo Alto Networks' Prisma AIRS AI Gateway availability announcement, and Microsoft's November 2025 post on in-country Copilot processing. Regulatory sources: the Information Commissioner's Office guidance on monitoring workers (October 2023), including its pages on data protection and monitoring, methods of monitoring, and solely automated monitoring tools, all verified against ico.org.uk on 6 August 2026.

Frequently Asked Questions

What is shadow AI discovery and which tools do it?

Shadow AI discovery is finding out which AI services employees actually use, before deciding what to do about it. Microsoft Defender for Cloud Apps does it by matching traffic against a catalogue of more than 31,000 apps, Entra Global Secure Access adds a network view, Netskope and Zscaler report it from their proxies, LayerX inventories it from a browser extension, and CrowdStrike finds AI tools on the endpoint. Discovery does not require reading prompt content, which keeps it outside the heavier monitoring obligations.

Do I need Microsoft 365 E5 to monitor AI use with Purview?

For the full capability, yes, or E3 plus the $12.00 Purview Suite add-on. E3 alone carries core DLP, audit and eDiscovery, but the features DSPM for AI relies on, Insider Risk Management and Communication Compliance among them, sit in the E5 tier. Monitoring Microsoft 365 Copilot additionally requires a Copilot licence per monitored user, and monitoring third-party AI apps such as ChatGPT is billed on pay-as-you-go Azure meters on top of the per-user licence.

Does Defender for Cloud Apps read employees' ChatGPT prompts?

No. Defender for Cloud Apps works at application and domain level: it discovers which AI services are in use, scores their risk, and can block unsanctioned ones through Defender for Endpoint. Prompt content visibility in the Microsoft stack comes from Purview DSPM for AI, which records prompts and responses in the audit log, or from the preview prompt policies in Entra Internet Access, which use TLS inspection in the network.

Is it legal for a UK employer to inspect employee AI prompts?

It can be, with the right groundwork done first. ICO guidance on monitoring workers requires informing staff before monitoring begins, a lawful basis (usually legitimate interests with a documented assessment, since consent is rarely valid in employment), and a data protection impact assessment completed before deployment. The ICO also expects employers to justify why less intrusive network-level data would not achieve the same purpose before monitoring content.

Do we need a DPIA before deploying prompt inspection?

Yes, in almost all cases. The ICO states that monitoring emails and messages requires a DPIA because it poses a high risk to workers' rights and is likely to capture special category data, and its definition of messages includes chat functions. A prompt log will eventually capture health questions or union correspondence, which engages Article 9 conditions on top of the lawful basis. The DPIA is a pre-deployment gate, not paperwork to complete afterwards.

What is an AI gateway and when do we need one?

An AI gateway is a single managed endpoint through which applications and users reach approved AI models, with the organisation holding the keys, logs and spend controls. You need one when you provide sanctioned AI access rather than only restricting it: it is how usage becomes visible, billable and governable. Cloudflare AI Gateway's core is free, OpenRouter charges a fee on credits, LiteLLM is open source and self-hosted, and Palo Alto and Fortinet sell inspection-grade gateways at platform prices.

Can Entra Conditional Access block ChatGPT?

Not on its own. Conditional Access governs sign-ins to applications, not browsing destinations, so it cannot stop an employee opening a consumer chatbot in a browser. Blocking AI sites by category in the Microsoft stack requires Entra Internet Access, part of the $12.00 per user per month Entra Suite, which adds web content filtering and, in preview, prompt policies that inspect traffic to AI services under TLS inspection.

Which shadow AI governance tools publish pricing?

A minority. Microsoft publishes list prices ($60.00 E5, $12.00 Purview Suite and Entra Suite), CrowdStrike publishes Falcon device tiers ($59.99 to $184.99 per year), Check Point's Browser Security is listed on AWS Marketplace ($27.82 to $54.57 per user), Cloudflare's AI Gateway core is free, and LiteLLM's open source gateway costs nothing. Zscaler, Netskope, Palo Alto, Fortinet, Darktrace, Cisco Umbrella and LayerX are quote-only, with UK G-Cloud framework documents the best public reference for indicative rates.

Which tools can tell a personal ChatGPT account from a corporate one?

Instance-aware proxies and browser tools can; DNS filtering cannot. Netskope distinguishes personal from corporate instances of the same application and can apply different policies to each. LayerX identifies the account in use from the browser. DNS-layer controls such as Cisco Umbrella's lower tiers see only the domain, which is identical for both, one reason Cisco reserves content-level AI controls for its SIG tier with HTTPS inspection.

Where do these tools store prompt data?

It varies more than any other attribute. Netskope documents UK data planes in London and Manchester plus a UK management plane; Microsoft stores UK tenant data in UK regions with Copilot in-country processing expected by end of 2026; CrowdStrike offers an EU-1 region; LiteLLM is self-hosted so residency is yours; Cloudflare's regional controls documentation did not list AI Gateway when checked in August 2026. Ask every vendor for the processing and storage location of prompt text in writing.