AI adoption often begins before security has approved it. Marketing pastes customer lists into a free chatbot while engineering wires an API key into a build script. A vendor quietly adds an AI feature to software that is already in your environment. None of these actions is malicious, but each can create an AI route that is invisible until an incident brings it to light.
Shadow AI sprawl begins with an inventory gap. Security cannot govern routes it cannot see. First Recon AI makes every route observable so your team can approve each one under policy, constrain the information it carries, or move the activity into a workspace your policies already cover.
Fig S1 · From unknown routes to three forward paths.
The first week
Inventory
Every AI route in the building gets a name and an owner. Your team works from a live register, not a best guess.
Identity
Routes are tied to real people through your identity provider, so you know who is using what instead of staring at IP addresses.
Posture
Every route starts in observe mode. You see the full picture first, and nothing breaks while you watch.
Fig S2Full route map: signals to evidenceGo deeperClose