The tools sold to govern employee AI use do five different jobs: discovery (finding out which AI is in use), enforcement (allowing, blocking or redirecting it), sanctioned access (giving staff an approved route to AI), data protection (controlling what data leaves), and licensing visibility (knowing who is paying for what). Most organisations need two of those jobs done well. Most vendors sell platforms that bundle three or four of them, which is why buying in this market so often starts with a feature grid and ends with an unused module.
This guide compares the products UK IT managers actually name, grouped by the job each one does, with published prices where they exist and an honest note where they do not. The most consequential difference between these products appears on no feature grid: whether the tool reads the text of what employees type into a chatbot. That single design choice separates a network report from workplace monitoring under UK GDPR, and it gets its own section below.
The five jobs these tools do
Shadow AI tooling splits into five jobs that vendors tend to blur: discovery, enforcement, sanctioned access, data protection, and licensing visibility. A buyer who names the job first will spend far less than one who starts from a platform demo, because platforms are priced on the assumption you want all five.
Discovery answers "which AI is in use, by whom". Enforcement decides what happens when someone opens a chatbot: allow, block, warn, or redirect. Sanctioned access is the approved route you offer instead, usually an AI gateway that manages keys, spend and logging for the models you have chosen. Data protection watches the content itself, blocking or redacting sensitive data on its way into a model. Licensing visibility, knowing which teams hold which AI subscriptions, is the job of SaaS-management platforms such as Flexera, Zylo and Productiv, plus the admin reporting in Microsoft 365 itself; it matters for cost control but is a procurement discipline rather than a security control, and this article concentrates on the first four.
Two practical consequences follow. First, discovery and data protection are different purchases: a tool can tell you ChatGPT is in heavy use without ever seeing a prompt, and a DLP engine can redact a credit card number without telling you which other AI apps exist in your estate. Second, if you already run Microsoft 365 E5 or a SASE platform, you probably own more of these jobs than you think, and the right first step is an inventory of what your current licences cover. Our guide to AI governance for mid-market organisations covers the policy layer that should drive that inventory.
Discovery tools show which AI is in use
Discovery tools answer the first question any governance effort needs: which AI services are actually in use, by which users, on which devices. Almost every practitioner account of getting control of shadow AI starts here, and the tooling is often already licensed.
Microsoft Defender for Cloud Apps matches network traffic against a catalogue of more than 31,000 cloud apps scored on over 90 risk factors, with a generative AI category, according to Microsoft's documentation. Discovery data can come from the Defender for Endpoint sensor on Windows and macOS devices, on or off the corporate network with no proxy required, or from log collectors fed by existing firewalls and proxies. Tagging an app as unsanctioned pushes blocks out through Defender for Endpoint. It is included in Microsoft 365 E5, or on E3 via the Defender Suite add-on at $12.00 per user per month (Microsoft's US list pricing, December 2025 announcement).
Microsoft Entra Global Secure Access adds a network-based shadow AI discovery view for organisations running Microsoft's SSE service: it identifies traffic to generative AI applications, MCP servers and model provider APIs, matches it against the Defender for Cloud Apps catalogue, and reports users, usage and data volumes, per Microsoft Learn.
Netskope One rates more than 370 generative AI applications among over 82,000 SaaS apps in its Cloud Confidence Index, and its instance awareness distinguishes a personal ChatGPT account from a corporate ChatGPT Enterprise tenant on the same domain, a distinction DNS and URL filtering cannot make (Netskope documentation). Zscaler provides equivalent discovery dashboards from its inline proxy, showing which AI apps are in use and by whom. Both are quote-only platforms.
LayerX takes the browser as its vantage point: an extension inventories web AI tools, AI browser extensions and AI features embedded inside approved SaaS, including use through personal accounts. Akamai announced a definitive agreement to acquire LayerX for approximately US$205 million on 14 May 2026, with closing expected in the third quarter of 2026, and is folding it into Akamai Workforce Protector, per Akamai's press release. CrowdStrike approaches from the endpoint: Falcon discovers AI applications, LLM runtimes, MCP servers and IDE extensions on devices. Darktrace positions its SECURE AI product around visibility of AI use and detection of anomalous data movement rather than content logging. Fortinet's FortiOS 8.0, released in early 2026, adds a FortiView AI attack surface view on the firewall itself; its AI features require a FortiGuard subscription, per Fortinet's release announcement.
The honest limit of every discovery tool is the same one practitioners keep reporting: none of them sees a personal phone on a mobile network, and AI features arriving inside already-approved SaaS blur the category the tools are trying to count.
Enforcement tools decide what happens next
Enforcement tools act on what discovery finds: allow, block, warn, isolate or redirect. The design question is not which tool blocks best but how graduated the response can be, because a hard block with no sanctioned alternative reliably moves the activity somewhere less visible.
The bluntest control is DNS. Cisco Umbrella can block AI domains at its DNS tiers, but Cisco's own documentation is clear about the ceiling: content-level control needs the SIG tier with HTTPS inspection, and DNS filtering cannot tell a personal ChatGPT login from a corporate one because both resolve the same domain. Cisco has expanded Umbrella's real-time DLP to cover the 70 AI tools in its generative AI application category, inbound responses included, but only where full proxying is on (Cisco documentation).
URL and category filtering sit a level up. Microsoft Entra Conditional Access on its own cannot block third-party AI websites, because it governs sign-ins to applications, not browsing destinations. Blocking ChatGPT, Claude or Gemini by category in the Microsoft stack requires Entra Internet Access, whose web content filtering and AI category ship as part of the Microsoft Entra Suite at $12.00 per user per month (Microsoft's Entra pricing page, accessed 6 August 2026). Conditional Access itself requires at least Entra ID P1, which rises from $6.00 to $7.00 per user per month on Microsoft's July 2026 price list.
The SASE platforms offer the most graduated enforcement. Netskope can coach rather than block, showing a real-time message that steers the user towards the corporate-approved AI tool, and its policies can allow a corporate instance while restricting the personal instance of the same app. Zscaler offers block, caution and browser-isolation modes, and can allow prompts while preventing bulk file uploads. Check Point Browser Security enforces at the browser, blocking the copy-and-paste of sensitive data patterns into AI chat interfaces in its Advanced tier. These graduated modes exist because vendors have learned what IT managers report from full blocks: the behaviour does not stop, it just leaves your network. The zero trust principles NCSC publishes apply directly here: policy should follow identity and data, not network location.
AI gateways provide the sanctioned route
An AI gateway is how an organisation offers staff an approved path to AI rather than only a wall: one endpoint through which applications and users reach many models, with the organisation holding the keys, the logs and the spend controls. Gateways govern the sanctioned route only. A gateway sees nothing of an employee's personal ChatGPT tab; that is discovery and enforcement's job.
Cloudflare AI Gateway's core features (analytics, caching, rate limiting) are free on every plan, and its DLP scanning is also free, per Cloudflare's pricing page (updated 19 May 2026). Optional Guardrails, which evaluate prompts and responses using Meta's Llama Guard model, are billed as Workers AI inference, and buying provider credits through its Unified Billing carries a 5 per cent fee. OpenRouter aggregates more than 400 models behind one API, charges a platform fee on credit purchases rather than a per-user licence, and offers routing controls that exclude providers which store or train on inputs, with zero-data-retention options and, for enterprise accounts, an EU in-region endpoint, per OpenRouter's published pricing and documentation.
LiteLLM is the self-hosted option: an MIT-licensed open source gateway that is free to run forever, with an Enterprise tier (SSO, SCIM, audit logs, air-gapped deployment) priced to annual request capacity on a quote basis, "never per token", per LiteLLM's pricing page. Because it runs entirely in your own infrastructure, prompt data never touches a vendor, which makes it the natural pairing for organisations already exploring self-hosted alternatives to SaaS.
The network security vendors now sell gateways too. Palo Alto Networks' Prisma AIRS AI Gateway reached general availability in July 2026 and inspects prompts and responses inline, licensed through the company's credit-based model on a quote basis. Fortinet's FortiAIGate is a separate product from FortiOS, a dedicated reverse proxy between applications and LLM providers with its own guardrails and DLP, also quote-only. Netskope includes an AI gateway for app-to-LLM traffic within its platform. The distinction that matters for a buyer: the free and open gateways govern developer and application access economically, while the security-vendor gateways add inline threat and data inspection at platform prices.
Data protection tools inspect what leaves
Data protection tools examine the content of AI interactions and block, redact or log sensitive data before it reaches a model. This is the job most buyers actually mean when they say they need to "control AI", and it is where capability, cost and legal obligation all concentrate.
Microsoft Purview is the incumbent for Microsoft estates. Its Data Security Posture Management (DSPM) for AI creates one-click policies that detect sensitive information pasted into AI sites in Edge, Chrome and Firefox, detect visits to AI sites, and capture Copilot interactions. Prompts and responses are recorded in the unified audit log and stored in the user's mailbox, where retention policies and eDiscovery apply, and the Activity Explorer's AI activities tab shows "the prompts and responses and if they contained sensitive information", per Microsoft Learn. For what Copilot itself can leak inside a tenant, see our guide to stopping Copilot surfacing confidential data to the wrong people.
The SASE platforms do the same job inline. Zscaler applies DLP across more than 100 dictionaries (source code, PII, payment card data, health data) to AI traffic and offers "prompt/response extraction and classification", per Zscaler's product pages. Netskope says its DLP and AI Guardrails "inspect every prompt and response in real time", using semantic inspection that evaluates intent and context rather than pattern matching alone, with over 3,000 data classifiers (Netskope documentation).
CrowdStrike Falcon AIDR, generally available since December 2025, collects telemetry that includes "original prompts and AI responses" across a browser extension, the endpoint sensor, SDKs and an MCP proxy, and enforces policies of log, redact or block, per CrowdStrike's documentation. Check Point GenAI Protect treats all prompts as potentially sensitive, categorises usage into use cases and severity levels, and gates the viewing of actual prompt text behind a specific administrator permission, per Check Point's administration guide; Check Point also acquired the AI runtime security firm Lakera (announced 16 September 2025) for guardrails against prompt injection and jailbreaks. Fortinet's FortiOS 8.0 adds DLP with keyword and FQDN matching for AI traffic plus OCR to catch sensitive data inside screenshots and images, FortiGuard subscription required.
Which tools read employee prompts
Thirteen of the products in this comparison can inspect the actual text of employee prompts; a handful, by design, cannot. This is the dividing line a buyer should establish before any demo, because it determines both what the tool can do and what deploying it obliges you to do.
| Product | Reads prompt text? | Where inspection happens |
|---|---|---|
| Microsoft Purview DSPM for AI | Yes | Endpoint DLP, Edge integration, browser extension; audit log |
| Microsoft Entra Internet Access prompt policies (preview) | Yes | TLS inspection in Microsoft's SSE network |
| Microsoft Defender for Cloud Apps | No | App and domain level only |
| Microsoft Entra Conditional Access (alone) | No | Identity sign-in layer |
| Zscaler AI Access Security / AI Guard | Yes | Inline cloud proxy with TLS decryption |
| Netskope One | Yes | Inline proxy, semantic DLP |
| Palo Alto Prisma AIRS | Yes | Runtime API and inline gateway |
| Check Point GenAI Protect / Browser Security Advanced | Yes | Network inspection / browser extension |
| CrowdStrike Falcon AIDR | Yes | Browser extension, endpoint sensor, SDK, MCP proxy |
| LayerX (Akamai Workforce Protector) | Yes | Browser extension |
| Cloudflare AI Gateway (Guardrails or DLP enabled) | Yes | API proxy |
| LiteLLM (guardrails enabled) | Yes | Self-hosted proxy, your infrastructure |
| OpenRouter | No | Routes requests; stores metadata, not content |
| Cisco Umbrella | SIG tier only | Cloud proxy with HTTPS inspection; DNS tiers cannot |
| Darktrace | Behavioural | Volume and pattern anomalies rather than content logging; confirm scope with the vendor |
| Fortinet FortiOS 8.0 / FortiAIGate | Yes | Network DLP with HTTPS inspection / LLM reverse proxy |
Two readings of this table are worth making explicit. If your requirement is knowing which AI is in use and steering people to a sanctioned tool, several capable options never touch prompt content, and choosing one of them keeps you out of content monitoring entirely. If your requirement genuinely is content-level DLP, then every option that meets it puts you in the territory the next section describes, and vendor privacy features (Check Point's permission gating, Zscaler's no-storage default, Purview's pseudonymised reviews in Communication Compliance) mitigate but do not remove the obligations.
Prompt inspection is a workplace monitoring decision
A tool that records what an employee typed into a chatbot is processing that employee's personal data, and under UK GDPR that makes deployment a data protection decision, not a procurement checkbox. The Information Commissioner's Office guidance on monitoring workers, published in October 2023, was not written about AI controls, but its rules on monitoring emails and messages apply squarely, and the ICO defines messages to include chat functions in collaboration tools.
Three of its requirements bite hardest. First, transparency: apart from exceptional covert circumstances, the ICO says you must inform workers about any monitoring before it begins, and a generic clause in an employment contract does not do that job. Second, a mandatory impact assessment: "If you are considering monitoring emails and messages, you must complete a DPIA," because such monitoring "poses a high risk to workers' data protection rights and freedoms and is likely to capture special category data" (ICO, monitoring workers guidance). A prompt log will sooner or later capture a health question, a grievance draft or a message to a union rep, and incidental capture of special category data requires an Article 9 condition on top of your lawful basis. Third, proportionality: "It would be difficult to justify monitoring the content of emails and messages if monitoring network data traffic would meet your purpose." Translated to this market: if discovery-level data answers your question, the ICO expects you to document why you bought content inspection anyway. Consent is not the answer either; the ICO is explicit that the imbalance of power in employment means workers rarely give it freely, which points employers to legitimate interests and a documented assessment instead.
None of this makes prompt inspection unlawful. Regulated firms with a genuine data-loss requirement deploy it, lawfully, with a DPIA completed before switch-on, a clear policy stating when content may be reviewed, scoped access to the logs, and retention limits. The point is sequencing: the DPIA is a pre-deployment gate, not paperwork to backfill, and it belongs alongside your Article 30 records of processing. Where monitoring output feeds automated decisions about individuals, the ICO's guidance on solely automated monitoring tools adds further safeguards. For the wider regulatory backdrop, see UK AI regulation compared with the EU AI Act.
What Microsoft licensing actually requires
"We already have Microsoft" is the most common opening position, and it is half true: the discovery layer is broadly included, but Purview's AI capabilities concentrate in the top licence tier plus consumption meters that surprise people at the first Azure bill. The figures below are Microsoft's published US list prices; UK prices vary with currency and agreement.
Microsoft 365 E5 rises from $57.00 to $60.00 per user per month on 1 July 2026, announced 4 December 2025, and E3 rises from $36.00 to $39.00 (Microsoft licensing news). E3 carries core Purview DLP for Exchange, SharePoint and OneDrive, information protection, audit and eDiscovery. The capabilities DSPM for AI leans on, Insider Risk Management for detecting AI site visits and risky usage, Communication Compliance for reviewing AI interactions, and automatic labelling, sit in the E5 tier, or reach E3 through the Purview Suite add-on (formerly E5 Compliance) at $12.00 per user per month, which requires an E3 base (Microsoft's Purview Suite pricing page).
Even at E5, two further costs apply, per Microsoft Learn. Monitoring Microsoft 365 Copilot interactions requires each monitored user to hold a Microsoft 365 Copilot licence. And monitoring third-party AI apps (ChatGPT, Gemini and the rest) runs on pay-as-you-go Azure meters: audit records processed, Communication Compliance text records scanned, and Insider Risk processing units are all consumption-billed for non-Microsoft AI interactions, against an Azure subscription you must link to the tenant. Microsoft 365 Copilot interactions are exempt from those meters. Operationally, third-party coverage also needs the Purview browser extension rolled out to Chrome and Firefox users and devices onboarded to endpoint DLP.
On the Entra side: Conditional Access needs Entra ID P1 ($7.00 from 1 July 2026); blocking AI sites by web category needs Entra Internet Access, included in the Entra Suite at $12.00 per user per month; and the preview prompt policies that inspect and block malicious prompts at the network level require an Entra Internet Access licence with TLS inspection configured, per Microsoft Learn.
| You want | You need |
|---|---|
| Discover which AI apps staff use | E5, or E3 plus Defender Suite ($12.00), or standalone Defender for Cloud Apps |
| Warn or block when staff paste sensitive data into a chatbot | E5, or E3 plus Purview Suite ($12.00); browser extension for Chrome/Firefox; onboarded devices |
| Review prompt and response text | E5 or Purview Suite tier; plus a Copilot licence per user for Copilot monitoring |
| Monitor third-party AI interactions at scale | The above plus pay-as-you-go Azure meters (audit records, text records, processing units) |
| Block AI websites by category | Entra Internet Access (in the $12.00 Entra Suite) |
| Inspect prompts in the network (preview) | Entra Internet Access plus TLS inspection |
What the tools cost
Published list prices exist for a minority of this market; the platform vendors are quote-only, and the honest comparison states which is which. All figures below are vendor-published list prices in US dollars, accessed 6 August 2026 unless dated otherwise.
| Product | Published price | Notes |
|---|---|---|
| Microsoft 365 E5 | $60.00/user/month | From 1 July 2026; includes Purview Suite features, Defender for Cloud Apps, Entra ID P2 |
| Microsoft Purview Suite add-on | $12.00/user/month | Requires M365 E3 base |
| Microsoft Entra Suite | $12.00/user/month | Includes Entra Internet Access |
| CrowdStrike Falcon | $59.99 to $184.99/device/year | Go, Pro and Enterprise tiers on CrowdStrike's pricing page; AIDR itself is not separately list-priced and is metered by I/O volume per CrowdStrike's licensing terms |
| Check Point Browser Security | $27.82 base, $54.57 Advanced/user/12 months | AWS Marketplace listing; Advanced tier carries the browser DLP and GenAI security |
| Cloudflare AI Gateway | Core free; 5 per cent Unified Billing fee | Guardrails billed as Workers AI inference |
| LiteLLM | Open source $0; Enterprise quote-only | Priced to request capacity, not per token |
| OpenRouter | Platform fee on credit purchases | Current rates on openrouter.ai/pricing; enterprise quote for EU routing |
| Zscaler | Quote-only | Its UK G-Cloud 14 price book (effective 15 February 2024) lists Zscaler for Users editions from $375 (Business Prime) to $675 (ELA) per user per year |
| Netskope | Quote-only | Its UK G-Cloud 14 pricing document lists Next Gen SWG Professional at $169.61 and the SSE Professional package at $213.16 per user per year |
| Palo Alto Prisma AIRS | Quote-only | Licensed via software firewall credits and token-metered API |
| Check Point GenAI Protect | Quote-only | Separate add-on to the Infinity platform |
| Darktrace, Cisco Umbrella, Fortinet, LayerX | Quote-only | Cisco sells Umbrella through tiered per-user subscriptions; Fortinet AI features require FortiGuard subscriptions |
Quote-only is not a criticism; it reflects platform bundling and channel pricing. For UK buyers the G-Cloud framework documents on the Digital Marketplace are the most useful public reference points, because suppliers file real price books there.
Where the prompt data lives
If a tool inspects prompts, its logs are among the most sensitive data you hold, so where the vendor processes and stores them is part of the buying decision, not an afterthought. The postures differ widely.
Netskope has the most explicit UK story: three data planes (two in London, one in Manchester) carrying UK customer traffic inside UK jurisdiction, plus a UK management plane in London hosting the admin console, logs and metadata, per Netskope's own account of its NewEdge expansion; in May 2026 it announced data sovereignty support across 24 countries including the UK. Microsoft stores UK tenant data at rest in its UK regions, while its EU Data Boundary (completed February 2025) covers EU and EFTA customers, not the UK; Microsoft has said in-country processing for Microsoft 365 Copilot will reach the UK by the end of 2026 (Microsoft blog, November 2025). Zscaler operates in-region inspection across its European data centres and offers options to keep inspected prompt data in customer-controlled storage. CrowdStrike offers an EU-1 cloud region for AIDR alongside its US regions, per its documentation. LiteLLM, being self-hosted, puts residency entirely in your hands. Darktrace is UK-headquartered, and its on-premises appliances keep data on site.
Two cautions. Cloudflare's Data Localization Suite documentation did not list AI Gateway among the products with regional processing controls when we checked on 6 August 2026, so ask Cloudflare directly where gateway logs and inspection occur before routing prompt traffic through it; and for any US-headquartered processor, the US CLOUD Act (18 U.S.C. § 2713) requires production of data under lawful US orders wherever that data is stored, which belongs in your transfer risk assessment. Neither point is unique to AI tooling, and both echo the questions we set out for GDPR-compliant cloud storage generally. Where residency is not documented at all, as we found for several products here, treat it as a question for the vendor rather than an assumption either way.
Questions to put to any vendor
A buyer who asks these ten questions will surface the differences this article has mapped, and will find out quickly which job a product actually does.
- Which of the five jobs (discovery, enforcement, sanctioned access, data protection, licensing visibility) does this SKU do, and which does it not attempt?
- Does it inspect prompt content? Can that be disabled, or scoped to named data types and user groups?
- Where is prompt text processed and stored, for how long, and can you commit to UK or EU processing in writing?
- Which licence tier or add-on carries the AI capability, and what consumption meters apply on top?
- What do we already licence that overlaps with this? (Ask your Microsoft partner the same question the same week.)
- Can it distinguish personal from corporate instances of the same AI service?
- What does it see on unmanaged devices and personal phones, honestly?
- Can it coach and redirect users to our sanctioned tool rather than block outright?
- What does the vendor itself do with the inspection data: sub-processors, retention, and whether anything trains its models?
- What happens to this product through your acquisition pipeline? Lakera is now Check Point, LayerX is becoming Akamai Workforce Protector, and Protect AI's technology sits inside Palo Alto's Prisma AIRS; the tool you evaluate may not be the tool you renew.
Discovery first, decision recorded, sanctioned route chosen on whether people will use it, and content inspection only with the DPIA done: that sequence, which practitioners keep arriving at independently, is also the one the tooling market and the regulator both reward. For what the NCSC actually says about staff using chatbots with business data, see our debunking of the myths around its guidance.
Sources
Vendor documentation and published pricing: Microsoft's licensing news pages and Microsoft Learn documentation for Purview, DSPM for AI, Defender for Cloud Apps and Entra Global Secure Access (accessed 6 August 2026); the Microsoft Purview Suite and Entra pricing pages; CrowdStrike's pricing and licensing pages and Falcon AIDR documentation; Cloudflare's AI Gateway pricing documentation (updated 19 May 2026); LiteLLM's pricing page; OpenRouter's pricing and data residency documentation; Zscaler and Netskope product pages and their G-Cloud 14 pricing documents on the UK Digital Marketplace; Check Point's Browser Security listing on AWS Marketplace and its administration guides; Cisco's Umbrella generative AI documentation; Fortinet's FortiOS 8.0 and FortiAIGate materials. Corporate announcements: Akamai's 14 May 2026 press release on the LayerX acquisition, Check Point's 16 September 2025 press release on Lakera, Palo Alto Networks' Prisma AIRS AI Gateway availability announcement, and Microsoft's November 2025 post on in-country Copilot processing. Regulatory sources: the Information Commissioner's Office guidance on monitoring workers (October 2023), including its pages on data protection and monitoring, methods of monitoring, and solely automated monitoring tools, all verified against ico.org.uk on 6 August 2026.