Most AI use at work runs through personal accounts and tools security never approved. MoorAI inventories the AI on each device — the apps, accounts, agents, and extensions — from redacted, content-free signals, so shadow AI stops being a blind spot. On-device, open source, macOS & Windows.
Signals a network proxy can't see — because they live on the endpoint, not on the wire.
Gateway-based shadow-AI discovery only sees what crosses the corporate egress. A developer off the VPN, an agent calling a model API directly, a locally-configured MCP server, a personal account on a personal network — none of it reaches the proxy, so none of it appears in the inventory. MoorAI reads the device itself, so coverage doesn't depend on the traffic taking a particular path.
Every signal rolls up into a per-device trust score and a per-tenant, board-level AI-readiness number: how many devices report in, how many personal accounts and unapproved MCP servers are in play, how many high-risk AI apps are installed, and what the endpoint posture (antivirus, patch state) looks like. A content-free data-lineage trail shows which data categories left via which agent over time — never the content itself.
Never. MoorAI reads only the account name/identity for reporting, and never the credential.
Yes — set your corporate email domains and any agent account on another domain is flagged as personal.
MoorAI flags MCP servers whose launch config fetches and pipes remote code to a shell — a high-signal proxy for a poisoned tool.
More: on-device AI DLP · OWASP LLM Top 10 tooling · MoorAI vs Netskope
Accounts, apps, MCP, extensions — from content-free signals.