Portnox Detects & Removes Unauthorized AI Apps from Managed Devices
Portnox introduces advanced features to identify and eliminate unapproved artificial intelligence applications on managed endpoints, enabling automated policy enforcement to limit, isolate, or eliminate non-compliant software upon detection.
Introduction
Understanding Shadow AI
This functionality targets shadow AI: autonomous generative AI systems that access local files, remote resources, and organizational data with the same privileges as the active user. As these tools proliferate beyond traditional oversight, Portnox provides IT and security teams with real-time visibility and automated controls to mitigate risks.
How Portnox Works
Organizations can now establish policies defining permissible or prohibited generative AI tools, allowing Portnox to evaluate device risk levels based on installed applications. The platform supports detection of major generative AI platforms such as ChatGPT, Microsoft Copilot, Claude, Google Gemini, Perplexity, DeepSeek, Cursor, Codex, and Ollama, alongside numerous coding agents, local models, and image-generation utilities. Coverage expands continuously as new AI tools emerge.
Automated Responses
When policy violations occur, Portnox triggers automated responses aligned with existing access controls. This includes network isolation, restricted resource access, or complete application removal across macOS and Windows environments.
Quote from Denny LeCompte
Addressing Unregulated AI
Employees often install AI assistants, coding tools, and local models without centralized approval, creating blind spots for security teams. Portnox eliminates the need for separate processes by applying policy-based controls to these applications, ensuring consistent enforcement.
Detection and Response
Detection alone is ineffective without actionable measures. Portnox automatically responds to policy breaches, whether applications are explicitly forbidden or unapproved, without requiring manual intervention. This includes network-level restrictions or application removals. Once policies are configured, Portnox maintains continuous enforcement.
Complementary Features
This capability complements Portnox’s earlier AI agent security features, which provide a network-level mechanism to revoke access when AI entities pose risks. Together, these tools address AI threats at different stages: endpoint application control and ongoing evaluation of active AI agents.
LeCompte’s Note on AI Integration
LeCompte noted that as AI tools become more integrated into enterprises, maintaining strict access boundaries and automated intervention capabilities is essential. The platform enables organizations to define clear policy parameters, ensuring enforcement aligns with security objectives. Without automated mechanisms, policy implementation remains ineffective.
Recent Developments
Recent related developments include attacks on Check Point Management Servers and F5 BIG-IP APM systems, disruption of the EvilTokens phishing service, and discovery of AI-driven malware.
Additional Resources
Additional resources highlight tools like CIS SecureSuite Platform and analysis of the DarkMe RAT.
