Shadow-AI Discovery

Shadow-AI Discovery A workflow diagram generated by Archify. 01 / Where AI hides 02 / Layer 02 Inventory & Transparency 03 / Registry EX / Frozen 05 / Evidence Scan Match + triage Register + evidence Cloud accounts · running services · Where AI hides › Scan Cloud accounts running services Network egress · external API calls · Where AI hides › Scan Network egress external API calls Identity providers · agent logins · Where AI hides › Scan Identity providers agent logins Code repos · SDK, prompt use · Where AI hides › Scan Code repos SDK, prompt use Discovery scan · finds models, agents · Layer 02 Inventory & Transparency › Scan Discovery scan finds models, agents Match vs registry · known / unknown · Layer 02 Inventory & Transparency › Match + triage Match vs registry known / unknown Triage & claim · assign an owner · Layer 02 Inventory & Transparency › Match + triage Triage & claim assign an owner Registry entry · owner, scope · Registry › Register + evidence Registry entry owner, scope Scope frozen · until claimed · Frozen › Register + evidence Scope frozen until claimed Discovery report · reconciliation · Evidence › Register + evidence Discovery report reconciliation unknown as evidence reconcile unclaimed: freeze open entry, claim Legend Agent logic Policy Context / trace External system

You cannot govern what you cannot see

  • • A registry fed only by voluntary declaration is always behind
  • • Discovery scans identity providers, cloud accounts, network egress and code repos
  • • Run it before you claim your inventory is complete

Unknowns become governed

  • • Findings are reconciled against the registry as known or unknown
  • • Each unknown opens an entry with an owner to claim it
  • • The unclaimed are escalated and their scope frozen

The result is evidence

  • • The reconciliation feeds the registry's drift check
  • • The discovery report is the machine-readable proof the inventory was tested against reality