AI Usage Control: Governing Shadow and Sanctioned AI Where It Actually RunsΒ
The AI Running on Your Endpoints Is Not the AI You Approved
AI usage control is the practice of discovering and governing every AI tool, autonomous agent, and machine identity operating inside an organization, enforced at the point where the AI actually executes. It answers three questions most security teams cannot answer today: which AI is running, whose identity is driving it, and what that AI is allowed to touch.
Today Morphisec announced the general availability of AI Usage Control, or AIUC. It discovers and governs AI tools, agents, and machine identities across Windows, Linux, and macOS endpoints. It runs inside the Morphisec Protector, the agent our customers already have deployed. No proxy. No cloud relay. No second agent.
Here is the gap it closes. Enterprise AI adoption ran ahead of the controls meant to secure it, and most of the governance tooling built to catch up watches network traffic. The AI that carries the most risk never touches the network. It runs locally, under credentials nobody audited, with permissions nobody scoped.
Key Takeaways
- 51% of organizations already run AI agents in production, according to LangChain State of AI Agents research. Governance has not kept pace with deployment.
- Gartner projects that by 2030, more than 40% of enterprises will experience a security or compliance incident tied to unauthorized shadow AI.
- Proxy and API based governance cannot see local AI: local models, command-line agents, and Model Context Protocol servers never cross the wire.
- The identity is the risk surface, not just the tool: a sanctioned agent running under an unapproved identity is invisible to tool-level allow lists.
- Agents act, they do not advise: they execute commands, move files, and chain tools on standing privileges, so governance has to bind at runtime.
What Is Shadow AI, and Why Is It Different From Shadow IT?
Shadow AI is any AI tool, agent, model, or machine identity operating in an environment without security team approval or visibility. It differs from shadow IT in one decisive way: shadow IT stores and moves data, while shadow AI takes action on its own.
A rogue SaaS account is a container. Someone puts data in it and the risk is exposure. An unapproved AI agent is an operator. It reads, decides, executes, and chains one tool into the next, all on credentials it was handed and rarely on a scope anyone reviewed.
The exposure lands in four places:
- Shadow AI: tools, models, and agents nobody sanctioned, running on managed devices.
- Compromised AI: a trusted agent hijacked through a poisoned document, email, or web page, because an agent cannot reliably tell an instruction from the data it is reading.
- Data leakage: confidential material moving off the endpoint through a tool that had no business touching it.
- Compliance risk: privacy and data sovereignty obligations that assume you can produce an inventory and an enforcement log on demand.
There is a fifth problem hiding inside the first four, and it gets missed constantly. The risk is not only unmanaged tools. It is unmanaged identities running managed ones. A sanctioned agent operating under an identity nobody approved. An approved identity driving a tool nobody vetted. Both pass a tool-level allow list without a flag.
Why Traffic-Based AI Governance Misses the AI That Matters
Most AI governance products intercept traffic. They sit in a proxy, a browser extension, or an API gateway and inspect content on the way past. That architecture has three problems, and each one is structural rather than a tuning issue.
- It cannot see what never crosses the wire: local models, command-line agents, and Model Context Protocol servers run directly on the machine. A proxy sees nothing.
- It reads your content to do its job: inspecting prompts and responses creates privacy and data sovereignty questions in exactly the jurisdictions regulators are watching most closely.
- It adds weight to a crowded endpoint: another agent, another relay, another thing to deploy, maintain, and troubleshoot.
The adjacent controls do not close the gap either. EDR looks for malicious code. It is not built to flag a sanctioned agent making a legitimate-looking request for data it should never touch, because nothing about that request looks like malware. Identity platforms authorize a session. They do not evaluate each action the agent takes once that session is live, and an agent takes thousands.
Morphisec takes the opposite approach. We govern the AI itself at the point of execution, by identity, tool, and permission, without reading a single prompt.
What Does AI Usage Control Actually Do?
AI Usage Control gives security teams an inventory of every AI identity in the environment and a policy engine that enforces what each one is permitted to do, at runtime, on the endpoint. Six capabilities ship today.
- AI discovery: inventories every AI tool, account, agent, browser extension, LLM service, and MCP connector, including shadow AI and the identities behind it.
- Identity-aware governance: maps every AI action to a user, identity, and device, so teams enforce which tools run by role and catch sanctioned tools running under unsanctioned identities.
- Tool, skill, and permission control: the same agent is benign with one tool and high risk with another. Read-only access is not file system access. AIUC governs the tools and skills each agent may use, not just the agent itself.
- Data exfiltration control: stops AI from moving confidential data off the endpoint based on what a tool is and where the data goes, with no content inspection.
- Audit-ready compliance: inventories and enforcement logs mapped to the EU AI Act, NIST AI RMF, ISO 42001, and SOC 2.
- Runtime guardrails: least-privilege policies block risky AI actions, such as an agent reaching for stored credentials, before they run.
That last point is the one that matters most. Governing the agent is not enough. Governing what the agent is allowed to pick up is what turns a policy into a control.
How AIUC Maps to the AIUC-1 Standard
AIUC-1 is an independent certification standard for AI agents, published in 2025 and often described as SOC 2 for AI agents. It now sits in the Cloud Security Alliance STAR registry, and it covers attack resistance, operational boundaries, agent identity, and error prevention. Morphisec maps to AIUC-1 controls across all six of its pillars.
That matters for a practical reason. Boards and auditors are starting to ask for evidence of AI governance, not assurances about it. An inventory you can export and an enforcement log you can hand to an assessor is the difference between a policy document and a passed audit.
Prevention Beats Detection, and With Agents the Margin Gets Thinner
Detection assumes you get a second look. Something happens, a signal fires, and a human or a playbook responds. That model was already strained against fast-moving ransomware. Against an autonomous agent it breaks down further, because the agent does not pause between steps. It reads a poisoned page, forms a plan, calls a tool, moves a file, and calls the next tool, and it does all of that as fast as the hardware allows.
By the time a detection pipeline surfaces the first action, the agent is several actions past it. The only control that holds is one that decides before the action runs.
That is the same principle behind everything Morphisec builds. Stop the thing before it executes. We applied it to in-memory exploits and to ransomware, and AI Usage Control extends it to the AI now running on the same endpoints.
Get the Inventory First
You cannot govern what you cannot see, and almost nobody has a real inventory of the AI running inside their environment right now. Start there. Find out which AI tools, agents, and machine identities are live on your endpoints, whose credentials are driving them, and what they are permitted to reach. Then decide what stays.
AI Usage Control is available today as a standalone module and inside the Anti-Ransomware Assurance Complete bundle, backed by the Morphisec Ransomware-Free Guarantee.
Take Action Now
Β See AI Usage Control live at Black Hat USA 2026, August 1 to 6 in Las Vegas. Book a briefing at morphisec.com/events/blackhat-2026, explore the AI Hub at morphisec.com/ai-hub, or request a demo at morphisec.com/demo.Β
Stay up-to-date
Get the latest resources, news, and threat research delivered to your inbox.