Skip to content

Category 11 of 12 · Controls: How employees use AI tools

Workforce AI usage control

Browser, endpoint, and network controls over which AI tools employees use and what data they paste in, including coding agents on developer machines.

Mitigates: ASI05 Unexpected Code Execution, LLM02 Sensitive Information Disclosure

Vendors, by signal score

Ranked within this category only. How the score works.

Also covers this category

Questions to ask a vendor

  1. Can it see and control AI use in the browser without breaking productivity?
  2. Does it cover coding agents and local tools, not only web chat?
  3. Can it coach users in the moment rather than only block?

FAQ

Is blocking public AI tools effective?
Rarely on its own. Employees move to personal devices. Visibility plus approved alternatives plus in-the-moment guidance tends to work better.
Why do coding agents need special attention?
They run with a developer's local access and can execute commands, so they combine data exposure with code execution risk.