AI Exposure Check User Guide
How to detect Shadow AI services on your network, assess DLP gaps, and maintain governance over unauthorised AI usage.
1. What Is This Tool?
AI Exposure Check is a free, browser-based assessment tool that discovers which AI services are reachable from your network. It helps IT administrators, security teams, and compliance officers identify Shadow AI — AI tools being used by employees without organisational approval or visibility.
When an employee pastes sensitive data into an unapproved AI tool, that data may be logged, used for model training, or exposed through third-party integrations. DLP policies are only effective against services the organisation knows about. Every unknown AI service is a blind spot.
2. Why It Matters for DLP
Data Loss Prevention (DLP) depends on visibility. If your CASB, firewall, or proxy rules don't include a service, traffic to that service bypasses all inspection. This tool helps you:
- Discover unapproved AI services — find tools employees may be using without IT consent
- Verify CASB coverage — check whether Netskope, Zscaler, or your proxy is actually intercepting AI traffic
- Detect policy gaps — identify services that bypass your firewall or DNS filtering
- Establish a baseline — capture your current exposure state for future comparison
- Track changes over time — detect new accessible services or policy drift between scans
- Support audit readiness — produce evidence for ISO 27001, SOC 2, GDPR, or internal compliance reviews
3. How It Works
3.1 Domain Reachability Scan
The tool checks a list of known AI service domains. For each domain, it attempts a lightweight HTTP request and records:
| Signal | What It Measures | Why It Matters |
|---|---|---|
| Accessible | Domain resolves and responds within timeout | Service is reachable — DLP gap exists |
| Blocked | Connection refused, reset, or returns an error page | Proxy or firewall is intercepting — policy is working |
| Timeout | No response within the timeout window | Ambiguous — could be blocked, rate-limited, or unreachable |
| Restricted | Connection blocked at network level | DNS or firewall block is in place |
3.2 Proxy / CASB Detection
The tool checks two things to determine if a security appliance is in the traffic path:
- CASB-specific headers — Products like Netskope, Zscaler, Palo Alto, and Fortinet inject distinctive HTTP headers (e.g.
x-netskope,x-zscaler). These are a strong signal of interception. - Header passthrough integrity — A custom header is sent via httpbin.org and checked on the response. If a proxy modifies or strips it, TLS interception is likely occurring.
Via or X-Forwarded-For are noted but not flagged as proxy detection — CDNs like Cloudflare add these routinely.
3.3 Network Context
The tool also captures your network context to help correlate findings:
- Local IP address — identifies which network segment the scan ran from (via WebRTC, with graceful fallback if blocked)
- DNS resolver — determines whether queries go to a local resolver, ISP, or public DNS (via DoH latency comparison)
3.4 Before You Scan — Network Activity Awareness
The scan makes lightweight HTTP requests to a list of known AI service domains. This is standard browser traffic — the same kind of request your browser makes when you visit any website. However, because the scan contacts many domains in rapid succession, it may be visible to network monitoring tools.
In most environments, this is a non-event. The scan uses standard HTTPS on port 443 — the same traffic as routine web browsing. No data is sent to the scanned domains beyond the initial connection request.
If your organisation has strict network monitoring policies or a Security Operations Centre (SOC), consider these steps:
- Notify your SOC or IT security team before running the scan. A one-line heads-up ("running an AI exposure assessment from my workstation today") prevents unnecessary alerts and demonstrates good security hygiene.
- Check with your compliance team if your organisation requires pre-approval for network scanning tools — even browser-based ones.
- Run from a representative network segment — the scan should reflect the network your employees actually use, not an isolated test environment.
4. How To Use — Step by Step
Open the tool — Launch ai-exposure-check.html in your browser. On first load, you'll see the Disclaimer modal.
Accept the Disclaimer — Read and accept. This confirms you're authorised to run network reachability checks from your current location.
Review network context — The header shows your detected proxy status, network, and DNS resolver. These help correlate results with specific network segments.
Select categories — Use the Categories panel to toggle which AI service categories to scan. All are enabled by default. Use the select all/none checkbox to quickly toggle.
Load a baseline (optional) — When you click "Run Scan", a dialog offers to load a previous scan for drift comparison. This is optional — you can always compare later.
Run the scan — Click "Run Scan". A progress bar with ETA appears in the Results area. You can click "Abort" at any time to stop mid-scan.
Review results — Results are grouped by status: Accessible (DLP gaps), Blocked (protected), Timeout (ambiguous). Sort by any column.
Export the scan — Click "Export scan" to save as JSON or CSV. Add notes (e.g. "Pre-audit baseline, Q3 2026") for governance records. A nudge suggests your next scan date.
5. Understanding the Results
Accessible Domains (DLP Gaps)
Any AI domain that returns Accessible is reachable from your network without proxy interception. This does not necessarily mean employees are using the service — but it does mean the DLP gap exists. Prioritise these for CASB policy review.
Blocked Domains (Protected)
Blocked domains confirm your proxy, firewall, or DNS filtering is working correctly for those services. These are success stories — your policies are effective.
Timeout Domains (Ambiguous)
Timeout results are inconclusive. The domain may be blocked, rate-limited, temporarily down, or unreachable from your network. Re-scan later or test from a different network segment to clarify.
Drift Comparison
When a baseline is loaded, the Drift panel shows changes between scans: newly accessible domains (risk increase), newly blocked domains (policy improvement), and newly timed-out domains. Click "Inspect changes" for a detailed breakdown.
6. Scan History & Governance
All scans are saved locally in your browser (localStorage). The Scan History panel shows every past scan with timestamp, results summary, network IP, and CASB status.
Export Options
| Action | Format | Contents |
|---|---|---|
| Export scan | JSON or CSV | Single scan with full domain results, network context, proxy info, and optional notes |
| Export history | JSON | Multiple scans with configurable retention (purge records older than N months) |
Governance Nudges
- Import nudge — If your last scan is older than 14 days, a reminder appears suggesting you rescan
- Export nudge — After exporting, a suggested next scan date is shown based on your scan cadence
- History overview — When exporting history, a summary shows total scans, date range, and retention settings
History Management
Each history record has Export and Delete buttons. Use Delete to remove individual scans (with confirmation). Use Export History with the retention slider to bulk-purge old records.
7. Common Use Cases
Pre-Audit Baseline
Run a scan before a compliance audit to document your current AI exposure. Export with notes explaining the context. Use this as evidence of due diligence.
CASB Policy Verification
After updating proxy or firewall rules, scan again and compare against a previous baseline. Newly blocked domains confirm the policy change took effect.
Quarterly Exposure Review
Schedule scans each quarter. Export history with retention set to 12 months. The drift comparison shows whether new AI services have appeared on the network.
New Office / Network Segment
Run from a new office, VPN endpoint, or network segment to verify the same DLP policies apply everywhere. Compare results across locations.
Board / Stakeholder Reporting
Export a scan as CSV and share with non-technical stakeholders. The colour-coded status badges and summary statistics make it accessible to any audience.
8. FAQ
Does this tool exfiltrate data?
No. The tool only tests network reachability with lightweight HTTP requests. It does not send, receive, or store any data from scanned domains. All processing happens in your browser.
Can I run this from outside the corporate network?
Yes, but results will reflect your current network, not the corporate perimeter. To assess corporate DLP coverage, run the scan from inside the corporate network (or via VPN).
Why do some domains show as Timeout?
Timeouts can mean the domain is blocked, rate-limited, temporarily down, or simply slow to respond. They're ambiguous by nature — re-scan later or test from a different network to clarify.
What's the difference between Blocked and Restricted?
Blocked means the server responded with an error or block page (e.g. CASB intercept). Restricted means the connection was refused or reset at the network level (e.g. DNS block, firewall drop).
How often should I scan?
The governance nudge suggests a cadence based on your last scan. For most organisations, quarterly scans are sufficient. Scan more frequently during policy changes, M&A activity, or after security incidents.
Can I customise the domain list?
The tool loads a built-in list of known AI services, plus an extended list from a community-maintained blocklist. You can modify the built-in list in the source code to add domains specific to your organisation.
9. Limitations
- Results reflect reachability from the browser's network, not necessarily from every corporate endpoint
- A reachable domain does not prove active usage — it proves the DLP gap exists
- Some services use CDN-fronted domains that may be reachable even when the AI service itself is blocked
- The tool does not inspect certificate chains, deep-packet content, or application-layer protocols
- For comprehensive DLP coverage, combine these results with CASB logs, proxy logs, and endpoint telemetry