Netskope introduces AI Discovery on the Netskope Client, a periodic signature-based scanning capability that detects AI agents, locally running Large Language Models (LLMs), local Model Context Protocol (MCP) servers, and AI extensions installed in web browsers and integrated development environments (IDEs).
Previously, administrators had no visibility into shadow AI assets: unauthorized or unmanaged AI applications, agents, and tools running on managed endpoints. This created significant security and governance blind spots, especially as end-users increasingly experiment with AI tools locally on their machines. With AI Discovery enabled, administrators can now automatically inventory AI assets across Windows and macOS endpoints and centrally visualize them in the AI Command Center (AICC)dashboard.
Administrators can enable AI Discovery through Client Configuration > AI Security webUI. When enabled, the Netskope Client periodically scans the endpoint and reports discovered AI assets to the cloud for centralized visibility and governance. Discovery results include AI agents, local LLM processes, local MCP servers, browser AI extensions (Chrome, Edge, Safari), and IDE AI extensions (VS Code, Cursor). Administrators can configure the scan interval (1 to 1,440 minutes; default: 60 minutes).
Prerequisites
-
Supported Operating Systems: Windows, macOS
-
Minimum Netskope Client Version: 137.1.0.0.0 (Beta)
Enable AI Discovery
To activate AI Discovery, navigate to Settings > Security Cloud Platform > Netskope Client > Client Configuration > AI Security and select Enable AI Discovery. To learn more, view AI Security.

Assets Detected During AI Discovery
On each scan, the Netskope Client enumerates and reports the following:
| Asset Type | Detected Assets | Data Collected |
|---|---|---|
| AI Agents | Claude Desktop (Anthropic), ChatGPT Desktop (OpenAI), Microsoft Copilot, Claude Code, OpenClaw, Perplexity Comet AI Browser, Perplexity Desktop | Process name, PID,PPID,binary path, installation path, version (if available), connected MCP servers or LLMs (local connections only) |
| Locally Running Large Language Models (LLMs) | Ollama, LM Studio, Jan AI, GPT4All | Process name, PID, PPID, binary path, installation path, version, loaded models (name, family, size, format, parameter size — if discoverable) |
| IDE AI Extensions — VS Code | GitHub Copilot, Codeium, CodeWhisperer, Tabnine, Claude Code, IntelliCode | IDE name, PID, binary path, version; per extension: name, ID, description, publisher, version |
| IDE AI Extensions — Cursor | GitHub Copilot, Tabnine, Claude Code, Cline | IDE name, PID, binary path, version; per extension: name, ID, description, publisher, version |
| Browser AI Extensions — Chrome (Windows and macOS) | Monica, Sider, Perplexity, ChatGPT, Copilot, Speechify, Merlin, Grammarly | Browser name, PID, binary path, version; per extension: name, ID, description, version, installation path |
| Browser AI Extensions — Edge (Windows) | Monica, Sider, Perplexity, Grammarly | Browser name, PID, binary path, version; per extension: name, ID, description, version, installation path |
| Browser AI Extensions — Safari (macOS) | Monica, Sider, Perplexity, Grammarly, LINER | Browser name, PID, binary path, version; per extension: name, ID, description, version, installation path |
Limitations
-
Windows and macOS only: Netskope supports AI Discovery on Windows (64-bit) and macOS endpoints only.
-
Detection limited to AI signatures file: AI Discovery detects only those AI assets that are enumerated in the AI Signatures file maintained by Netskope. The scanner does not detect assets missing from this file. The AI Signatures file is updated periodically as new AI tools become prevalent. Contact Netskope Support if you require detection of a specific AI asset not currently included.
-
Multi-user environment limitation: In environments where multiple users share a single endpoint (such as shared workstations or terminal servers), AI Discovery is limited to scanning the default browser and IDE profile of the currently active logged-in user. The Client may not detect AI assets installed or configured by other users on the same device.
-
VM and Container AI assets: If AI LLMs or agents are running inside virtual machines or Docker containers deployed separately from the Netskope Client installation, those assets are not detected by the endpoint AI Discovery scanner (If the Netskope Client is installed inside the VM/Container, discovery operates normally within that environment).
-
Browser/IDE extension scanning limited to active user: In multi-user environments, only the default browser and IDE profiles of the currently logged-in user are scanned. Extensions installed by other users on the same device are not enumerated.

