Buying shadow AI discovery is supposed to mean you can list the ChatGPT tabs, the Copilot Studio agents, and the Bedrock apps nobody filed a ticket for. What shows up in the category is often AI-SPM of systems you already know, or a DLP product that found a prompt. Those are not the same buy.
Shadow AI is workforce AI the buyer did not approve: a personal ChatGPT login, an unsanctioned OAuth grant, a browser extension, or an agent someone stood up in Foundry. AI-SPM is posture of known or sanctioned AI. Microsoft’s Copilot admin docs treat third-party generative AI apps as an inventory and control job, not a model-card review. Our AI-SPM list is the known-system job. The method we used is on How we review tools.
We compared seven tools on that split: whether a first-party page names shadow or unsanctioned AI discovery; whether the plane is browser, SaaS, or API; whether any meter is public; and whether the inventory covers AI the buyer did not approve. Nudge Security prints a mailbox rate. Microsoft Purview DSPM sits inside Microsoft 365 E5 or Purview Suite, not a standalone discovery meter. LayerX, Harmonic Explore, Reco, Lasso Discovery & AI-BOM, and Obsidian are quote-only on this job.
Problems and Solutions
Most shadow AI quotes fail for the same few reasons. The fix is operational, not a new acronym.
| Problem | Solution |
|---|---|
| The quote is AI-SPM of known systems, or DLP that found a prompt | Require a first-party page that names shadow AI, unsanctioned AI, or GenAI discovery of workforce AI the buyer did not approve |
| The demo is browser tabs, but the leak is an OAuth grant or a Foundry agent | Write the plane on the PO: browser, SaaS, or API. One plane will miss the other two |
| Finance treats Microsoft 365 E5 $60 as the discovery line | Read whether the printed dollar is a suite, a mailbox rate, or a sales quote, and whether Copilot licenses are extra |
| The nearby vendor name on last year’s brief does not exist | Harmonize was not a living first-party product on 25 August 2026. The living nearby name is Harmonic Explore |
How we evaluated shadow AI discovery tools
The filter was four first-party checks: a page that names shadow AI, unsanctioned AI, or GenAI discovery; a named plane (browser, SaaS, or API); a public meter versus quote-only; and an inventory of workforce AI the buyer did not approve, not only posture of known systems. SSE and DLP products with a shadow-AI tile did not move a ranking. Cyberhaven, Palo Alto AI Access Security, and Nightfall sit in What we left out because they failed a named check. Prisma AIRS Agent Discovery inventories agents on clouds you already onboarded. That is AI-SPM of known accounts, not this page.
TL;DR: The Seven Compared
| Tool | Best For | Pricing Model | Highlights |
|---|---|---|---|
| LayerX | Last-mile Chrome or Edge: personal accounts and AI extensions | Quote-only. Fees on a purchase order. Akamai acquired LayerX | Browser-extension inventory of apps, identities, and AI extensions |
| Harmonic Explore | A browser-extension map of 1,000+ web AI tools | Quote-only. Demo / contact sales | Named Shadow AI Discovery SKU. Desktop AI needs endpoint / OpenTelemetry |
| Reco Shadow AI Discovery | Unsanctioned GenAI tied to OAuth, identity, and data access | Quote-only. Quote on users and integrations | First-party sources: SaaS, IDP, API, network, browser |
| Nudge Security | A printed SaaS/AI discovery price plus email, API, and browser channels | Essential $750/month billed annually (≤150 mailbox users). Growth $5/user/month billed annually (150–1,500). Example: 500 users = $2,500/mo. Enterprise custom | Active user = licensed mailbox. Agent discovery is a research preview |
| Lasso Discovery & AI-BOM | API/CI inventory of agents in Bedrock, Foundry, Copilot Studio, Vertex, Agentforce | Quote-only. Do not use the AWS Marketplace $50k gateway listing | Agentless, read-only. Not a ChatGPT-tab census |
| Microsoft Purview DSPM | Microsoft 365 shops that need Copilot plus a browser view of third-party GenAI sites | Microsoft 365 E5 $60.00 user/month yearly is the suite, not a discovery meter. Needs E5 or Purview Suite | Purview browser extension for third-party sites. Copilot licenses are extra |
| Obsidian Shadow AI | SSPM teams that want one page that splits browser, API, and MCP | Quote-only. Free trial of the browser extension | API-only tools miss the browser. The browser alone misses agent platforms |
LayerX

LayerX Shadow AI Discovery is a named use case on LayerX’s browser security platform. The page H1 is expose and eliminate ‘shadow’ AI tools: discover, audit, and secure all AI usage across the organization. The homepage says most users consume GenAI tools via the browser, and LayerX deploys as a browser extension with visibility and control over AI applications and extensions. The use case also says LayerX is not limited to web channels and covers native desktop AI applications. First-party does not name an API discovery plane on that page.
What it inventories: every AI app in use (sanctioned, unsanctioned, or embedded in SaaS), who is using them, corporate and personal accounts, AI browser extensions across users and devices with permissions and threat level, unsanctioned shadow AI apps and PWA-based native apps, and AI conversations across major platforms (user prompts and LLM responses). There is no first-party dollar rate on layerxsecurity.com. Terms point to fees on a purchase order. LayerX pages say AWS customers can procure LayerX via AWS Security Hub Extended / Marketplace with pay-as-you-go on the AWS bill. Those pages do not print a list rate. Akamai acquired LayerX. A first-party banner on the discovery page says so. The buy path may sit under Akamai, not a standalone LayerX rate card.
Best for: Teams whose shadow AI lives in the last mile of Chrome or Edge: personal ChatGPT accounts, AI extensions, and embedded SaaS AI.
What you get:
- Named Shadow AI Discovery use case, led by a browser-agnostic extension
- Inventory of apps, identities, AI extensions, and conversations
- Quote-only. Akamai acquired LayerX
Why we like it: It is the only shortlist name whose first-party use case is titled AI Discovery / Shadow AI and leads with browser-extension inventory of apps, identities, and AI extensions.
Limits:
- This is an AI interaction / browser security platform, not a SaaS-API inventory of OAuth grants or a cloud-builder AI-BOM
- Desktop AI coverage is claimed on the same page. The deployment model still leads with a browser extension
Price: Quote-only. Fees on a purchase order. layerxsecurity.com/use-cases/shadow-ai-discovery.
Ask before you sign
Ask whether the contract is still LayerX or an Akamai SKU, and whether desktop AI is in the same line as the browser extension.
Harmonic Explore

Harmonic Explore is Harmonic’s AI usage visibility and Shadow AI Discovery product. Deploy the Harmonic browser extension, and within days you have a map of the AI tools the workforce actually uses, including a long tail of 1,000+ web AI tools that the catalogue updates weekly. Prompt-level insights run across over 1,000 applications, including embedded AI features inside SaaS tools already in use. The FAQ names Canva, Grammarly, and Google AI mode. Each tool profile shows who uses it, how often, whether the vendor trains on user inputs, and a risk score.
There is no public list rate on harmonic.security. The path is demo or contact sales. The FAQ surfaces browsers (Chrome, Edge, Firefox, Safari, Arc, Brave, Vivaldi, Island, Genspark, Comet, Dia). Desktop AI is via OpenTelemetry / endpoint (Claude Desktop, ChatGPT Desktop, Cursor, Windsurf). Agents and MCP are a separate surface. First-party does not name a SaaS-API connector plane for Explore. Harmonic is an AI Governance and Control platform. Explore is visibility. Guide and Command add inline SLM DLP. Do not sell Explore as an API-key scanner. The FAQ contrasts itself with SASE: it sits on the device and inside the AI surface.
Best for: Security and AI leaders who want a browser-extension inventory of web GenAI plus embedded SaaS AI, then usage intelligence on why people use each tool.
What you get:
- Named Shadow AI Discovery SKU (Explore)
- 1,000+ web AI tools. Prompt-level insights. Per-tool risk and training-policy profile
- Quote-only. Desktop and MCP need the endpoint / MCP gateway, not the extension alone
Why we like it: Explore is a first-party Shadow AI Discovery SKU, not a CASB category tag, and the page leads with deploy-the-extension.
Limits:
- No first-party dollar. Do not invent a per-seat Explore price
- Coverage of desktop AI and MCP is not the browser extension alone
Price: Quote-only on harmonic.security/products/explore.
Reco Shadow AI Discovery

Reco Shadow AI Discovery is Reco’s named use case for unsanctioned GenAI and agents. The homepage prints full coverage across SaaS, IDP, API, network, and browser, and Unified Discovery discovers every agent and app from those sources. The Shadow AI FAQ lists OAuth connection monitoring, email metadata scanning, network traffic analysis, browser extension detection, and behavioral pattern analysis. Generative AI Discovery FAQ language includes personal ChatGPT or Claude accounts, unauthorized integrations, browser-based usage and extensions, and mobile AI apps accessing corporate data.
There is no public dollar rate card on reco.ai. Reco compare pages say pricing is quote-based on users and the number of integrations, offered directly and through the AWS Marketplace. Do not invent a per-user dollar. Reco is a SaaS and agent security platform (SSPM plus agent security plus ITDR), not a last-mile browser DLP or an endpoint process inventory. Browser and network are named as sources. The product still leads with a SaaS API and identity graph. Homepage copy also says connect any supported SaaS app using Reco’s API, and Reco Factory language sits next to a 260+ SaaS apps figure on some pages. Reco’s other URLs print different app counts. Cite the page you used.
Best for: SaaS security teams who need an inventory of unsanctioned GenAI and agents tied to OAuth, identity, and data access, not only DNS hits on chat.openai.com.
What you get:
- Named Shadow AI Discovery and Generative AI Discovery pages
- Sources printed as SaaS, IDP, API, network, and browser
- Quote-only on users and integrations
Why we like it: Reco publishes a dedicated Shadow AI Discovery use case and first-party-lists five sources, so the PO can say more than “browser extension.”
Limits:
- No first-party list price. Integration count is part of the quote
- Not an endpoint process inventory of Claude Code
Price: Quote-only. Users and integrations. reco.ai/use-cases/shadow-ai-discovery.
Ask before you sign
Ask which sources (SaaS API, browser, network) are in the first year, and whether the quote is Shadow AI Discovery or the broader SSPM+ platform.
Nudge Security

Nudge Security discovers workforce AI from email, then adds API and browser channels for employee-built agents. Day One copy is historical and real-time workforce AI apps and accounts via patented email-based discovery on Microsoft 365 or Google Workspace, including ChatGPT, Claude, DeepSeek, Perplexity, Gemini, and tools not on a static list. The AI Security page also names MCP, API, and webhook SaaS-to-AI integrations, plus API key copy-and-paste detection. Connected-app API discovery refreshes about every 24 hours. The browser extension is near real-time.
The pricing page (25 August 2026) prints Essential at $750/month billed annually, up to 150 users, all features included. Growth is $5/user/month billed annually for 150–1,500 users, all features included. The page example is 500 users = $2,500/mo. Enterprise at 1,500+ users is a custom ELA. An active user is an active licensed user with a mailbox in Google Workspace or Microsoft 365, queried via the Google Workspace API or Microsoft Graph. Archived, deleted, or suspended users, groups, and shared aliases are excluded. Nudge platform admin seats are not a separate meter. First-party says organizations typically have 1.2–1.5 active workspace users per employee, and you generally cannot monitor a subset of mailboxes. AI agent discovery is listed under every plan. The feature page says it is a research preview: live, coverage expanding, request access.
Best for: IT and security teams that want a printed SaaS/AI discovery price, email-based Day One inventory, then API plus browser channels for employee-built agents.
What you get:
- Email, API, and browser discovery of SaaS and AI
- Essential $750/month billed annually (≤150 mailbox users). Growth $5/user/month billed annually (150–1,500)
- AI agent discovery on every plan, as a research preview
Why we like it: It is the only shortlist vendor with a first-party dollar card that also first-party-splits SaaS email discovery, API connected-app agent inventory, and browser-extension agent discovery.
Limits:
- AI agent discovery is a research preview. Existing customers ask product success for access
- The meter is workspace mailboxes, not employees. You generally cannot monitor a subset
Price: Essential $750/month billed annually (≤150 users). Growth $5/user/month billed annually. Example 500 users = $2,500/mo. nudgesecurity.com/pricing.
Ask before you sign
Ask for the mailbox count in the admin console before you estimate Growth, and whether AI agent discovery is enabled for your tenant or still a preview request.
Lasso Discovery & AI-BOM

Lasso Discovery & AI-BOM is the API and CI inventory on the Lasso AI Security Platform. Native integrations cover CI platforms and low-code or no-code agent builder platforms, with Amazon Bedrock, Azure AI Foundry, Microsoft Copilot Studio, Google Vertex AI, and Salesforce Agentforce named on the page. Zero Deployment is agentless, read-only integration into CI pipelines and native integrations with cloud providers and third-party agent builder tools. The inventory consolidates every AI agent and application: owner, LLM, system prompt, policies, tool registry, and guardrails. The AI-BOM lists models, MCP servers, delegated agents, databases, third-party tool connectors, identity boundaries, and authorization policies.
There is no first-party rate card for Discovery & AI-BOM. The CTA is Book a Demo. Do not apply AWS Marketplace dollars for Lasso for Secured Gateway for LLMs ($50,000 annual commit plus $0.01 additional usage) to this SKU. That listing is a gateway product. First-party discovery language is agents and applications you build or stand up on connected platforms. It is not first-party copy for personal ChatGPT tabs or random Chrome extensions. The homepage names Shadow AI as the visibility problem (employees using and creating AI tools and agents). Runtime enforcement is a separate module at the proxy, API, or AI Gateway layer. First-party claim: discovery time for new agents is 7 minutes.
Best for: Security teams that need an API/CI inventory of agents employees and builders stand up in cloud AI platforms, then an AI-BOM for what those agents call.
What you get:
- Agentless Discovery & AI-BOM on Bedrock, Foundry, Copilot Studio, Vertex, and Agentforce
- Dependency graph: sub-agents, LLMs, APIs, MCPs, delegation chains
- Quote-only. Do not quote the marketplace gateway commit
Why we like it: It is the cleanest API-plane discovery SKU on this list: platform and CI integrations, not a CASB hit on chatgpt.com.
Limits:
- Not a workforce browser census
- No public Discovery price
Price: Quote-only on lasso.security/platform/discovery-ai-bom.
Ask before you sign
Ask whether the quote is Discovery & AI-BOM or the gateway listing, and which builder platforms are connected in year one.
Microsoft Purview DSPM

Microsoft Purview Data Security Posture Management is the Copilot-tenant plus browser-extension path for third-party GenAI sites. Current DSPM docs (updated 2026) include a Discover > Apps and agents dashboard, an AI observability inventory of AI apps and agents, and Activity explorer AI activities that include when a user browsed to a generative AI site. Classic DSPM for AI still names the Microsoft Purview browser extension and onboarded devices as prerequisites for third-party AI sites. Other AI apps detected through browser activity are categorized as Generative AI in the Defender for Cloud Apps catalog (ChatGPT, Google Gemini, Microsoft Copilot consumer, DeepSeek). Enterprise AI apps include Entra-registered apps, ChatGPT Enterprise, and Microsoft Foundry. Copilot experiences include Microsoft 365 Copilot, Security Copilot, Copilot in Fabric, and Copilot Studio.
There is no standalone Shadow AI meter. Microsoft 365 E5 lists $60.00 user/month, paid yearly (annual commitment) on the US page (25 August 2026). That is the E5 bundle, not a DSPM-only rate. First-party get-started copy: access DSPM / DSPM for AI with Microsoft 365 E5 or Microsoft Purview Suite (formerly Microsoft 365 E5 Compliance). Copilot activity insights also need Microsoft 365 Copilot licenses. Prompt and response capture for some Copilots needs the matching one-click policy. Classic DSPM for AI is replaced by the current DSPM. New features go to the current version only. Third-party site coverage is a supported-sites list plus the browser extension and device onboarding, not every GPT wrapper on the internet. Do not write $60 as the price of AI discovery.
Best for: Microsoft 365 shops that already pay for E5 or Purview Suite and need Copilot plus a first-party browser-extension view of third-party GenAI sites.
What you get:
- AI apps and agents dashboard, including Copilot experiences and third-party GenAI sites
- Microsoft 365 E5 $60.00 user/month yearly is the suite. Needs E5 or Purview Suite
- Purview browser extension and device onboarding for third-party sites
Why we like it: It is the only shortlist path that first-party-inventories Copilot experiences, ChatGPT Enterprise connectors, and a supported list of third-party GenAI sites from the Purview portal.
Limits:
- Not a multi-IdP SaaS discovery graph and not an endpoint process inventory of Claude Code
- E5 $60 is the suite. Extra Copilot, Copilot Studio, or pay-as-you-go Purview meters are separate
Price: Microsoft 365 E5 $60.00 user/month yearly is the suite, not a discovery meter. Microsoft 365 E5.
Ask before you sign
Ask whether you already have E5 or Purview Suite, whether Copilot licenses are in the tenant, and whether the Purview browser extension is in the deployment plan.
Obsidian Shadow AI

Obsidian Shadow AI is a dedicated product page on the Obsidian SaaS security / AISPM platform. The page says most security tools only scan for AI via API integrations and miss a significant portion of what is actually running. Obsidian combines browser-level discovery, API integration scanning, and agent monitoring. The FAQ: browser-level discovery inventories GenAI apps by tracking login events and user interactions in the browser. The academy page names the browser extension for unsanctioned GenAI and personal accounts, plus native API connections to Salesforce Agentforce, Microsoft Copilot Studio, Amazon Bedrock, Google Vertex AI, ChatGPT Enterprise, n8n, and Azure AI Foundry.
There is no first-party dollar rate on the Shadow AI page. The FAQ prints a free trial that deploys the browser extension and starts discovering GenAI apps. Paid seats are sales-quoted. Do not invent a per-user SSPM rate. What it inventories: every AI tool in use, AI that activates inside enterprise apps, agents (who created them, connectors, OAuth scopes, whether the creator is still active, org-wide or public access), MCP connections, and LLM interactions agents make. Sensitive data typed into prompts is analyzed locally in the browser so content does not leave the device, per first-party copy. Agent-platform depth depends on those native API connections. The browser path is GenAI usage, not OS-level coding agents.
Best for: SaaS security teams that already think in SSPM and want one product page that first-party-splits browser GenAI, API agent platforms, and MCP.
What you get:
- Named Shadow AI page: browser, API, and agent/MCP inventory
- Free trial of the browser extension. Paid seats quote-only
- Local-in-browser analysis of prompt content, per first-party copy
Why we like it: The Shadow AI page is explicit about the three-plane gap: API-only tools miss what the browser sees, and the browser alone misses agent platforms.
Limits:
- Shadow AI is a capability, not a self-serve browser-only SKU with a printed meter
- No public list price
Price: Quote-only. Free trial of the extension. obsidiansecurity.com/shadow-ai-security.
If the next job is posture of AI systems you already know, start with AI-SPM platforms. If the next job is Salesforce or Okta misconfig rather than unsanctioned ChatGPT, use SSPM platforms.
Browser or SaaS API, and whether the meter is public
This grid plots two questions. Across is the lead discovery plane: browser on the left, SaaS or API on the right. Up is how you pay: a printed suite or mailbox rate at the top, a sales quote at the bottom.
Placement is from first-party SKU language: the lead discovery plane printed on the product page, and a printed suite or mailbox rate versus contact-sales. Reco, Nudge, and Obsidian name more than one plane. Each logo sits in the lead-plane square. Placement is a SKU map, not a ranking.
How the meter bills, side by side
| Tool | Meter | What to write on the PO |
|---|---|---|
| LayerX | Quote-only. Purchase order. Possible AWS Marketplace path, no list rate | LayerX Shadow AI Discovery. Confirm whether the contract is Akamai |
| Harmonic Explore | Quote-only | Harmonic Explore, not Guide or Command alone |
| Reco Shadow AI Discovery | Quote on users and integrations | Shadow AI Discovery. Cite which sources are in year one |
| Nudge Security | Active licensed mailbox in Google Workspace or Microsoft 365 | Essential $750/month billed annually (≤150) or Growth $5/user/month billed annually. Agent discovery is a research preview |
| Lasso Discovery & AI-BOM | Quote-only. Not the marketplace gateway commit | Discovery & AI-BOM. Not Lasso for Secured Gateway for LLMs |
| Microsoft Purview DSPM | Suite. Microsoft 365 E5 $60.00 user/month yearly, or Purview Suite | E5 or Purview Suite plus DSPM. Not “$60 for AI discovery.” Copilot licenses are extra |
| Obsidian Shadow AI | Quote-only. Free trial of the extension | Obsidian Shadow AI, not only the $0 SSPM Free tile |
What we left out
These are real products. Each one failed a named check, not a popularity contest.
- Cyberhaven AI Security names Shadow AI Discovery across endpoints, browsers, CLIs, and IDEs, plus MCP servers, with Data Lineage. Someone who needs OS-level agents (Claude Code, Copilot, Codex) should look at it. It failed the plane-split check: it is a Unified AI and Data Security / DLP platform with a shadow-AI feature, not a Browser-versus-SaaS-versus-API discovery SKU.
- Palo Alto Networks AI Access Security and Netskope’s GenAI module both name visibility into shadow AI. They failed the standalone-discovery check. They are SSE / SASE-native GenAI CASB. Quote-only. Use them if you already buy that SASE.
- Nightfall Shadow AI discovers AI apps, agents, and MCP servers so security can govern AI. It failed the inventory-product check. Discovery is in service of AI-native DLP. Harmonize was a name on some briefs. No first-party Harmonize product showed up on 25 August 2026. The living nearby vendor is Harmonic Explore, which is on this list.
Questions before you sign a shadow AI discovery tool
If a quote cannot answer these three, you are still buying the wrong SKU.
- Is the lead plane browser, SaaS (OAuth / email / IdP), or API (cloud builders / CI), and which plane is missing?
- Is the printed dollar a mailbox rate, a suite tile, or a sales quote, and are Copilot or agent-preview modules extra?
- Does the inventory cover AI the buyer did not approve, or only posture of systems you already onboarded?
Which shadow AI discovery tool should you pick
If the leak is a personal ChatGPT tab or an AI extension, start with LayerX, Harmonic Explore, or Obsidian’s browser path. If the leak is an OAuth grant or a mailbox you can query on Day One, start with Nudge or Reco. If the leak is an agent someone stood up in Bedrock, Foundry, or Copilot Studio, the quote is Lasso Discovery & AI-BOM. If you already pay for Microsoft 365 E5 or Purview Suite, open DSPM before you add a second console, and do not write $60 as the discovery line. Write the plane, the meter, and whether agent discovery is preview. The logo on the slide is not the purchase.
Frequently asked questions
Is shadow AI discovery the same as AI-SPM?
No. Shadow AI discovery inventories workforce AI the buyer did not approve. AI-SPM is posture of known or sanctioned AI systems: models, agents, and data paths you already onboarded. A quote that only lists Bedrock accounts you connected last quarter is not a ChatGPT-tab buy. Our AI-SPM list is that known-system job.
Is Microsoft 365 E5 $60 the price of Purview AI discovery?
No. $60.00 user/month yearly is Microsoft 365 E5, a suite. First-party DSPM docs say you need Microsoft 365 E5 or Microsoft Purview Suite. Copilot activity insights also need Microsoft 365 Copilot licenses. Write the suite and the extra Copilot line, not “$60 for shadow AI.”
Is Nudge’s AI agent discovery generally available?
It is listed under every Nudge plan. The feature page calls it a research preview: live, coverage expanding, request access. The printed rates (Essential $750/month billed annually up to 150 mailbox users, Growth $5/user/month billed annually) are the platform. Confirm preview access before you treat agent inventory as coverage.









