AI Command Center (AICC) is a Netskope capability that provides comprehensive visibility, governance, and risk management for AI usage across your organization.
As enterprises rapidly adopt AI services, risks such as shadow AI, data leakage, and unmanaged AI assets increase. AI Command Center addresses these challenges by enabling security teams to:
-
Discover AI applications and services in use.
-
Discover MCP Servers in use.
-
Monitor user interactions with AI systems.
Key Concepts
AI Command Center introduces a set of core AI components that form the foundation of visibility and analysis:
AI Applications – Applications that provide AI-driven functionality, such as, chatbots, coding assistants, Image and video generation tools, etc. These applications act as the entry point for users interacting with AI systems.
MCP Servers (Model Context Protocol Servers) – MCP servers act as integration and execution layers for AI systems. They enable communication between models and external tools, retrieval of contextual data and execution of actions.
Agents – AI-enabled extensions that run inside a browser, code editor, or desktop, such as browser extensions, editor extensions, and desktop extensions. AICC groups agents by category so you can see where AI is embedded in everyday tools your users already run.
Models – Large language models running locally on managed endpoints, such as open-source LLMs running in frameworks like Ollama or vLLM. AICC surfaces these through Endpoint AI Discovery in the Netskope Client, giving you visibility into AI activity that never touches the network and would otherwise stay invisible.
Identities – Users and unknown entities that interact with AI applications and MCP servers. Known identities are users authenticated through your Identity Provider (IdP). Unknown identities represent unauthenticated or unrecognized traffic sources, identified by source IP address.
The Overview page gives you a high level of insights on AI usage, while the Inventory page enables detailed analysis and response.
AICC Components
AICC builds its visibility on several Netskope components. Turn on the ones that match what you want to monitor.
| Use Case | Required Component |
|---|---|
| Visibility into Generative AI application usage across traffic steered via Netskope | Next-Gen Secure Web Gateway (NG-SWG) must be enabled and fully operational |
| Visibility into MCP server access across traffic steered via Netskope | Agentic Broker must be available and operationalized |
| Visibility into alerts | Data Loss Prevention or Threat Protection must be configured |
| Visibility to Guardrail alerts | AI Guardrails must be available and functional |
| Visibility into AI models and AI application footprints on managed endpoints | Netskope Client (NS Client) version R137.1 or later must be deployed on managed endpoints, with Endpoint AI Discovery enabled. See NS Client AI Discovery article to learn more. |
Turning on the components you need lets AICC discover AI assets accurately and surface insights you can act on.
To open the AICC dashboard, your role also needs the Security Posture > AI Visibility permission. See Getting Started with AI Command Center to set this up.

