What is AIDR?
AI Detection & Response (AIDR) is a ThreatDown feature that gives IT admins visibility into which AI tools are in use across managed endpoints. It detects installed AI applications and outbound AI domain traffic, then surfaces that data in a centralized dashboard within the console.
Do I need to install anything new?
No. AIDR uses the ThreatDown Endpoint Agent already running on your endpoints. No additional software is required to start monitoring AI tool activity. Only the Web Protection and Software Inventory policy settings need to be enabled.
Is AIDR included in my current plan?
Phase 1 (Visibility & Discovery) is included at no additional cost for all Nebula customers. Future phases, including enforcement and tool blocking, will require Elite or Ultimate bundle subscriptions.
What operating systems are supported?
Phase 1 supports Windows and macOS endpoints. Linux and mobile devices (iOS and Android) are not supported.
What AI tools does it detect?
AIDR detects AI tools in two ways:
- Installed AI applications (e.g., GitHub Copilot) via Software Inventory.
- Browser-based and API-accessed AI services (e.g., ChatGPT, Claude, Midjourney, Gemini) via outbound domain traffic monitoring. Browser extensions are not detected in this phase.
Will AIDR block AI tools?
This first phase of AIDR focuses on visibility, showing what's being used. You can't block AI tools yet, but you can mark them as unauthorized to help monitor unapproved usage. Blocking and enforcement arrive in Phase 2 with the Elite and Ultimate bundles.
Can AIDR detect local Large Language Models (LLMs)?
No. Local LLMs are not currently detected with AIDR. Support for that is coming in a later phase.
Can I set different policies per group?
Yes. Governance decisions can be made at the policy level.
What happens if I exclude an AI domain?
Excluding a domain on the Configure > Exclusions page stops its AI activity from appearing on the AIDR pages. To restore visibility, narrow the scope of the exclusion or remove it.
Back to AIDR guide.