Last updated:
The technical process of monitoring and inspecting network calls made to external AI service providers.
This is a primary discovery method for shadow AI. By analyzing DNS logs and HTTPS traffic for connections to domains like api.openai.com or anthropic.com, security teams can identify which AI services employees are using, even if they haven't been formally disclosed or sanctioned by IT.
Real world example:
A security team notices a spike in traffic to a new generative AI video site; through API traffic analysis they discover a marketing team is feeding raw customer footage into an unvetted third-party tool.




