YOWIE TECH STUDIOS • AI Exposure Check User Guide

AI Exposure Check User Guide

How to detect Shadow AI services on your network, assess DLP gaps, and maintain governance over unauthorised AI usage.

1. What Is This Tool?

AI Exposure Check is a free, browser-based assessment tool that discovers which AI services are reachable from your network. It helps IT administrators, security teams, and compliance officers identify Shadow AI — AI tools being used by employees without organisational approval or visibility.

Key principle: The tool tests network reachability only. It does not access, store, or exfiltrate any data from scanned domains. Everything runs locally in your browser.

When an employee pastes sensitive data into an unapproved AI tool, that data may be logged, used for model training, or exposed through third-party integrations. DLP policies are only effective against services the organisation knows about. Every unknown AI service is a blind spot.

2. Why It Matters for DLP

Data Loss Prevention (DLP) depends on visibility. If your CASB, firewall, or proxy rules don't include a service, traffic to that service bypasses all inspection. This tool helps you:

Risk example: An employee uses an unapproved AI writing tool to draft a client proposal. The tool's servers are reachable from the corporate network without proxy interception. The proposal content — including confidential client details — is transmitted without DLP inspection, logged by the AI provider, and potentially used for model training.

3. How It Works

3.1 Domain Reachability Scan

The tool checks a list of known AI service domains. For each domain, it attempts a lightweight HTTP request and records:

SignalWhat It MeasuresWhy It Matters
Accessible Domain resolves and responds within timeout Service is reachable — DLP gap exists
Blocked Connection refused, reset, or returns an error page Proxy or firewall is intercepting — policy is working
Timeout No response within the timeout window Ambiguous — could be blocked, rate-limited, or unreachable
Restricted Connection blocked at network level DNS or firewall block is in place

3.2 Proxy / CASB Detection

The tool checks two things to determine if a security appliance is in the traffic path:

Note: Generic headers like Via or X-Forwarded-For are noted but not flagged as proxy detection — CDNs like Cloudflare add these routinely.

3.3 Network Context

The tool also captures your network context to help correlate findings:

3.4 Before You Scan — Network Activity Awareness

The scan makes lightweight HTTP requests to a list of known AI service domains. This is standard browser traffic — the same kind of request your browser makes when you visit any website. However, because the scan contacts many domains in rapid succession, it may be visible to network monitoring tools.

What to expect: Your organisation's SIEM, IDS/IPS, or endpoint detection tool may log the scan as a burst of outbound connections to unfamiliar domains. This is normal and expected — the tool is designed to produce exactly this kind of traffic so you can see what your monitoring infrastructure sees.

In most environments, this is a non-event. The scan uses standard HTTPS on port 443 — the same traffic as routine web browsing. No data is sent to the scanned domains beyond the initial connection request.

If your organisation has strict network monitoring policies or a Security Operations Centre (SOC), consider these steps:

Why this matters: The fact that the scan is visible to your monitoring tools is actually a useful data point. If a burst of connections to AI domains doesn't generate an alert, that gap tells you something about your detection coverage — and is itself a finding worth noting.

4. How To Use — Step by Step

1

Open the tool — Launch ai-exposure-check.html in your browser. On first load, you'll see the Disclaimer modal.

2

Accept the Disclaimer — Read and accept. This confirms you're authorised to run network reachability checks from your current location.

3

Review network context — The header shows your detected proxy status, network, and DNS resolver. These help correlate results with specific network segments.

4

Select categories — Use the Categories panel to toggle which AI service categories to scan. All are enabled by default. Use the select all/none checkbox to quickly toggle.

5

Load a baseline (optional) — When you click "Run Scan", a dialog offers to load a previous scan for drift comparison. This is optional — you can always compare later.

6

Run the scan — Click "Run Scan". A progress bar with ETA appears in the Results area. You can click "Abort" at any time to stop mid-scan.

7

Review results — Results are grouped by status: Accessible (DLP gaps), Blocked (protected), Timeout (ambiguous). Sort by any column.

8

Export the scan — Click "Export scan" to save as JSON or CSV. Add notes (e.g. "Pre-audit baseline, Q3 2026") for governance records. A nudge suggests your next scan date.

5. Understanding the Results

Accessible Domains (DLP Gaps)

Any AI domain that returns Accessible is reachable from your network without proxy interception. This does not necessarily mean employees are using the service — but it does mean the DLP gap exists. Prioritise these for CASB policy review.

Blocked Domains (Protected)

Blocked domains confirm your proxy, firewall, or DNS filtering is working correctly for those services. These are success stories — your policies are effective.

Timeout Domains (Ambiguous)

Timeout results are inconclusive. The domain may be blocked, rate-limited, temporarily down, or unreachable from your network. Re-scan later or test from a different network segment to clarify.

Drift Comparison

When a baseline is loaded, the Drift panel shows changes between scans: newly accessible domains (risk increase), newly blocked domains (policy improvement), and newly timed-out domains. Click "Inspect changes" for a detailed breakdown.

6. Scan History & Governance

All scans are saved locally in your browser (localStorage). The Scan History panel shows every past scan with timestamp, results summary, network IP, and CASB status.

Export Options

ActionFormatContents
Export scan JSON or CSV Single scan with full domain results, network context, proxy info, and optional notes
Export history JSON Multiple scans with configurable retention (purge records older than N months)

Governance Nudges

History Management

Each history record has Export and Delete buttons. Use Delete to remove individual scans (with confirmation). Use Export History with the retention slider to bulk-purge old records.

7. Common Use Cases

Pre-Audit Baseline

Run a scan before a compliance audit to document your current AI exposure. Export with notes explaining the context. Use this as evidence of due diligence.

CASB Policy Verification

After updating proxy or firewall rules, scan again and compare against a previous baseline. Newly blocked domains confirm the policy change took effect.

Quarterly Exposure Review

Schedule scans each quarter. Export history with retention set to 12 months. The drift comparison shows whether new AI services have appeared on the network.

New Office / Network Segment

Run from a new office, VPN endpoint, or network segment to verify the same DLP policies apply everywhere. Compare results across locations.

Board / Stakeholder Reporting

Export a scan as CSV and share with non-technical stakeholders. The colour-coded status badges and summary statistics make it accessible to any audience.

8. FAQ

Does this tool exfiltrate data?

No. The tool only tests network reachability with lightweight HTTP requests. It does not send, receive, or store any data from scanned domains. All processing happens in your browser.

Can I run this from outside the corporate network?

Yes, but results will reflect your current network, not the corporate perimeter. To assess corporate DLP coverage, run the scan from inside the corporate network (or via VPN).

Why do some domains show as Timeout?

Timeouts can mean the domain is blocked, rate-limited, temporarily down, or simply slow to respond. They're ambiguous by nature — re-scan later or test from a different network to clarify.

What's the difference between Blocked and Restricted?

Blocked means the server responded with an error or block page (e.g. CASB intercept). Restricted means the connection was refused or reset at the network level (e.g. DNS block, firewall drop).

How often should I scan?

The governance nudge suggests a cadence based on your last scan. For most organisations, quarterly scans are sufficient. Scan more frequently during policy changes, M&A activity, or after security incidents.

Can I customise the domain list?

The tool loads a built-in list of known AI services, plus an extended list from a community-maintained blocklist. You can modify the built-in list in the source code to add domains specific to your organisation.

9. Limitations