The AI Tools tab in AI Detection and Response (AIDR) lists all AI applications and services detected on your managed endpoints. Use this tab to review AI tool usage, assign governance stances, and configure rules that determine how tools are treated across your policies. For configuring AIDR, see Configure AI Detection & Response.
Governance Stance
The governance stance reflects your organization’s current policy on an AI tool. Each tool is assigned one of three stances:
- Needs Review: The tool has been detected but not yet evaluated. A decision is required before it can be classified.
- Authorized: The tool is approved for use within your organization.
- Unauthorized: The tool is not approved for use. Any detected use is a policy violation and should be investigated.
AI Tools table
The table lists all AI tools detected in your environment for the selected time frame, which defaults to the last 7 days. The following columns are available:
| Column | Description |
|---|---|
| Actions | Select a governance status for this specific AI tool. Each AI tool inherits the default governance setting based on its category. |
| Category | Type of AI tool (e.g., Code, Image & Video, Writing & Translation). New AI tools that haven't been categorized display as Unknown. They should be categorized by ThreatDown within a few days. |
| Domain Requests | Number of domain requests made by this tool in the selected time frame. |
| Endpoints | Number of endpoints where the tool was detected |
| Governance Stance | The approval status of the tool: Needs Review, Authorized, or Unauthorized. See Governance Stance above for definitions. |
| Last Used | Date of the most recent access event |
| Last User | Last user to access the AI tool. |
| Rule Scope | Displays only global if the governance rule applies to all policies. Shows number of policies to indicate how many policies have exceptions to the governance stance. |
| Tool | Name of the AI application or service. Click on the tool name to get more details such as any policy overrides. |
| Trend | The percentage change in AI tool usage over the selected time period. |
| Vendor | Provider of the tool (e.g., OpenAI, Microsoft, Anthropic) |
Viewing tool details
Click any tool name to open a detailed slide-out, which includes:
- Tool details: Vendor, category, last used, and last detected dates.
- Governance Summary: The tool’s governance stance and any policy-level overrides. See Governance Stance above for definitions.
- Tool Information: The number of endpoints running this tool, their authorization status, user count, request volume, and a breakdown of the installed versions of this tool.
- Endpoint Activity: A list of endpoints and their activity for this tool.
Back to AIDR guide.