{
  "id": 8218901,
  "title": "How to move from AI discovery to AI enforcement",
  "url": "https://urgent.news/2026/09/18/how-to-move-from-ai-discovery-to-ai-enforcement",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-18T09:08:19.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/how-to-move-from-ai-discovery-to-ai-enforcement"
  },
  "original_language": "en",
  "account": "Enterprise shadow AI programs have discovered more AI than expected, but the programs stall due to a lack of enforcement. Discovery alone doesn't change the fact that many agents operate without security oversight or logging. Enforcement, however, is crucial to changing the outcome of AI actions in real-time. There are four interventions for AI: block the tool, scope down its reach, gate an action behind approval, or terminate the process mid-execution. Blocking is the most blunt but generates the most complaints, while scoping is the most durable but hardest to configure. Gating works until the approval queue becomes a formality. Termination is the last resort and needs to happen before the action completes. Network blocking fails because AI models no longer communicate as websites; they run locally, inside licensed applications, or as command-line agents. The permissions problem makes AI enforcement harder, as existing identity controls only check if a principal is allowed to perform an operation, not if the human would have sanctioned the action. Enforcement must happen at the point where an action executes, where the decision is deterministic. Controls at the instruction layer reduce volume but are probabilistic and fail to solve the problem of separated instructions from data inside a language model. Building enforcement at the endpoint and runtime provides a consistent outcome regardless of the instruction's nature. Organizations should start with one category of prohibited tools and run in monitor mode for two weeks to identify legitimate workflows. Assign an owner to every agent, turn on blocking for the smallest viable scope, and measure the complaint rate before expanding. Leadership should lead with the count of AI agents running without proper control and commit to a second number: enforcement actions taken in the first quarter, broken out into blocks and approvals.",
  "summary": "Shifting shadow AI programs from inventory to real-time action.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}