Shadow AI: a blind spot versus a read-only inventory with leavers flagged
Before: local AI tools run on the fleet unseen, with no console to query. After: a read-only inventory lists them by device and user and flags leavers who still have shadow AI installed.
Ketan Kamble
BEFORE · A BLIND SPOT
AFTER · SEEN + FLAGGED
STEP 1 · LOOKS QUIET
THE FLEET
sanctioned apps only — you assume
what’s actually running?
STEP 2 · ALREADY RUNNING
HIDDEN LOCAL AI
Ollama · LM Studio · GPT4All — humming, unseen
no console to query
STEP 3 · A BLIND SPOT
?
unknown local installs
no list, no query
you can’t query what you can’t see
▶ Collect-LocalAIAgentInventory.ps1
read-only → inventory → join directory state
INVENTORY · DEVICE · USER · TOOL
LEAVER · STILL INSTALLED
Ollama · LM Studio · GPT4All — by version
departed user · Ollama present
FLAGGED
shadow AI —
and the leavers who kept it
Pause