How to move from AI discovery to AI enforcement
Discovery found the AI. Enforcement has to stop it.
by https://www.techradar.com/author/brad-laporte · TechRadarOpinion By Brad LaPorte Published 18 September 2026
Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter
Most enterprise shadow AI programs have completed step one. They ran discovery, found more AI in the building than expected, and built a spreadsheet. Then the program stalled.
This pattern is nearly universal. Discovery is genuinely useful, and it's also where the easy work ends. Knowing that 37 agents are running, roughly the enterprise average per Microsoft's February 2026 Cyber Pulse research, doesn't change the fact that more than half operate with no security oversight or logging.
An inventory tells you what happened. Enforcement decides what happens.
Latest Videos FromTechRadarWatch full video here: Brad LaPorte
CMO of Morphisec.
What enforcement means for AI
Enforcement is the ability to change the outcome of an AI action while it's occurring, not report on it afterward. For an agent, that means one of four interventions: block the tool from running, scope down what it can reach, gate a specific action behind approval, or terminate the process mid-execution.
These aren't interchangeable: choosing between them is most of the work. Blocking is blunt and generates the most complaints. Scoping is the most durable and hardest to configure. Gating works until the approval queue becomes a formality people click through. Termination is the last resort; it needs to land before the action completes.
Why network blocking keeps failing
Blocking AI domains at the network edge was the first control most organizations reached for. It's easy to deploy and explain to a board, and it stops a shrinking share of the actual risk. AI stopped being a website.
Local models make no outbound call to inspect. Embedded copilots run inside licensed applications, so their traffic looks like the vendor you approved. IDE and command-line agents, and MCP servers on localhost, never cross a network boundary you control. Personal devices remain the oldest gap, worse now that AI tools are free and everywhere.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsors