Overview
The Syteca AI Usage policy establishes controls for detecting and governing employee interactions with Artificial Intelligence (AI) tools, including browser-based AI services, browser extensions, standalone applications, and AI-enabled development environments. The policy helps ensure AI usage aligns with organizational security, privacy, and governance requirements, while supporting compliance with frameworks such as the EU AI Act and the NIST AI Risk Management Framework (AI RMF).Controls
Data Processing Integrity
Data Processing Integrity ensures that organizational data is processed accurately, securely, and only through authorized technologies and workflows. In the context of AI usage, this control validates whether employees are accessing AI systems through approved channels, helping prevent unauthorized processing of business information and reducing the risk of unmanaged AI adoption. By monitoring AI access points rather than the content being processed, the organization can:- Identify unauthorized or unapproved AI usage.
- Reduce the risk of sensitive data exposure.
- Improve visibility into AI adoption across the environment.
- Support regulatory and governance requirements.
- Promote responsible and secure use of AI technologies.
Risk Factors
AI Access via Browsers (URLs)
Detection of access to web-based AI platforms through internet browsers. This is an event based risk factor that validates monitored URLs against the pre-defined blacklist.URL monitoring must be enabled on the endpoint to check this risk.
- Shadow AI usage
- Unauthorized data processing
- Compliance violations
AI Access via Browser Extensions and Add-ons
Detection of AI-enabled browser extensions and plugins. This is a state-based risk factor. Risks:- Data leakage
- Unmanaged third-party integrations
- Lack of governance
AI Access via Applications
Detection of standalone AI applications installed or executed on endpoints. This is an event based risk factor that validates monitored applications against the pre-defined blacklist.Only applications detected in monitored sessions are checked.
- Unauthorized AI software usage
- Sensitive data exposure
- Reduced visibility into AI activities
AI Access via IDEs
Detection of AI-assisted coding tools and IDE integrations, including Microsoft Copilot for Visual Studio, Claude Code, and similar solutions. This is an event based risk factor triggered by each user prompt in the AI IDE. Risks:- Source code exposure
- Intellectual property leakage
- AI-generated code security concerns
Business Value
This policy provides visibility into AI adoption across the organization and helps ensure AI technologies are used in a secure, compliant, and governed manner. By identifying AI access channels and enforcing approved usage practices, organizations can reduce AI-related risks while enabling responsible innovation.Related
How to manage and mitigate AI-related risks
Monitor AI-related activities across endpoints, investigate detected AI usage, and implement appropriate technical, administrative, or user-awareness controls to reduce AI-related risks.
About policies
Explore security and compliance policies, understand how risk factors, controls, and severity ratings contribute to policy health scores.