← Tech blog

Blocking is half the answer: AI usage control, and what comes after it

· Prabhu Eshwarla

Your people are already using AI at work. Some of it is the tool the company bought. A lot of it is whatever was open in the next browser tab. Security teams have a name for the second kind, shadow AI, and in the last year a whole category of software has grown up to deal with it.

This post explains what that category does, why it matters, and why we think stopping unapproved AI is only half of the answer.

What AI usage control is

In August 2026 Gartner published its first overview of a category it calls AI usage control. Its definition is short: technology that discovers the use of third-party AI and enforces an organisation's security policies on it. In practice these tools do four things:

  1. Discover which AI tools employees actually use, in the browser, on the desktop and through company systems.
  2. Assess the risk of each tool, such as where it stores data and whether it trains on what you send it.
  3. Enforce policy, by warning, masking or blocking when sensitive material is about to go somewhere it should not.
  4. Protect at runtime, by watching for misuse while AI is being used.

The category is young and moving fast. Gartner counts more than 50 vendors, and about 80% of them are early-stage startups. The established names include Microsoft, Cisco, Zscaler, Palo Alto Networks and Check Point, and specialists such as Harmonic Security, Lasso and Prompt Security focus on it directly. Gartner forecasts it as the fastest-growing part of the market for securing AI, with spending rising 73% to about $749 million in 2027.

That growth makes sense. Most companies cannot say which AI tools their staff use, or what has been pasted into them. These tools answer that question, and they answer it well.

The half that blocking does not solve

Picture what happens after a usage control tool does its job. An analyst pastes a client's financial model into a public chatbot, and the tool stops it. The data is safe.

But the analyst still has the work to do. They were using AI because it made the job faster, and that need has not gone away. If the company offers nowhere approved to do the work, one of three things happens. They do it slowly by hand, they find a tool the blocker does not catch, or they use their phone. Blocking without an alternative does not remove the demand. It moves it somewhere you cannot see.

Gartner's research points at the same gap. It names understanding why people use AI, and steering them towards approved use rather than only stopping them, as the next way vendors in this category will set themselves apart. Most still have it on their roadmaps.

So the full answer to shadow AI has two halves. One half is a control that recognises when confidential material is heading to an unapproved tool. The other half is an approved place where people can do the same work properly. Usage control tools are built for the first half. Forge is built for the second.

Where Forge fits

Forge is the company-approved AI workspace, where your teams work with confidential documents, build workflows that act on them, and run agents under your organisation's policies.

The point is not to stop people using AI. It is to give them somewhere they are allowed to use it, for the work that matters most. Inside the workspace that means:

Do you need both?

Possibly. If your main worry is visibility across every AI tool your staff touch, a usage control tool is the right first purchase, and Forge does not replace it. If your main worry is that confidential work has nowhere safe to happen, start with the approved workspace.

The two fit together. A usage control tool tells staff where they cannot go. An approved workspace gives them somewhere to go. Most organisations will end up needing both halves, because the goal was never to stop people using AI. It was to let them use it on work that matters, without wondering where the material went.

If that second half is the gap in your organisation, book a demo and we will show you what working with confidential documents in Forge looks like.

← More from the Forge tech blog