AI discovery is the continuous identification and inventory of AI assets across an enterprise environment: agents, models, MCP servers, AI-powered applications, browser-based AI tools, and the integrations between them. Effective discovery spans several surfaces, because no single signal source captures the full footprint on its own.
- Continuous inventory of agents, models, MCP servers, and AI applications
- No single signal source sees the whole footprint, so surfaces must combine
- It is the first function in NIST AI RMF, OWASP, and MITRE ATLAS alike
- Partial inventory means posture management on a sample, not a population
Why is AI discovery important?
Discovery matters because every downstream AI control assumes you already know what you are protecting. It is the first function in every major AI security framework – the Map function of the NIST AI RMF, the prerequisite for applying the OWASP Top 10 for LLM Applications, and the starting point for mapping techniques in MITRE ATLAS.
An inventory built on one discovery surface is an inventory with known blind spots. A security program built on partial inventory is doing posture management on a sample rather than a population, and the assets it misses are rarely random – they cluster in the places nobody instrumented, which is also where unreviewed AI use concentrates.
The cost of that gap is measurable. IBM found that a high level of unsanctioned AI use added $670,000 to the average breach cost. Gartner expects 40% of enterprise applications to carry task-specific AI agents by the end of 2026, so the population being inventoried is growing faster than most review cycles.
What is AI discovery?
AI discovery is the process of finding and cataloguing every AI asset operating inside an environment, then keeping that catalogue current as the environment changes. The assets include autonomous agents, hosted and self-hosted models, MCP servers, AI features embedded in approved SaaS applications, browser-based assistants, and the integrations connecting them to enterprise data.
Two properties separate discovery from a one-time audit. It is continuous, because agents are created and retired faster than quarterly review cycles can track. And it is multi-surface, because each signal source sees a different slice – network traffic reveals API calls to model providers, endpoint telemetry reveals locally running tools, identity systems reveal service accounts, and code repositories reveal agents that exist only as configuration.
Discovery is not observability. Discovery establishes that an asset exists and what it connects to. Observability captures what that asset does once it runs. The first is a question about population; the second is a question about behavior.
Types of AI discovery
Discovery approaches are best understood by which surface they read, because coverage is the differentiator rather than technique.
Browser-based discovery sees the AI tools employees reach through a tab, which is where most unsanctioned use begins. Endpoint discovery finds locally installed assistants and coding agents. Network and SASE inspection reveals traffic to model providers, including from systems nobody registered. Cloud and CNAPP integration surfaces the models and agent workloads running in your own accounts. Identity-based discovery finds the service accounts and tokens agents authenticate with, which often exposes agents no other surface sees. AI platform integrations enumerate what has been built inside sanctioned tooling.
By method, agent-based collection runs on the host, API-based collection queries platforms directly, and traffic inspection observes the wire. None is sufficient alone. The practical test for any discovery claim is which surfaces it reads and what it concedes it cannot see.
AI discovery & Onyx
AI Discovery is one of seven canonical capability areas in the Onyx platform, and it reads six surfaces rather than one: browser extension, AI platforms, cloud and CNAPP, network and SASE, endpoint and EDR, and identity. Comprehensive AI inventory is typically available within 24 hours of deployment.
Because discovery shares a data model with posture scoring and policy, an asset found on any surface arrives ready to be tagged, scored, and governed rather than exported to a spreadsheet. That continuity is what makes discovery and shadow AI coverage operational rather than informational, and it is what the rest of the control plane depends on.



