Rostec learned to catch "shadow" AI agents on work computers

RT Protect EDR will show which AI tools employees are running without the security service's knowledge

RT-Informatsionnaya Bezopasnost (part of Rostec) has released a solution for detecting "shadow AI" – intelligent agents that employees run on work computers without the knowledge of the information security service. The RT Protect EDR product determines not only the presence of such software but also its activity: command execution, file operations, and other actions. This will help companies control risks associated with AI access to corporate data.

Image source: Official Rostec website // пресс-служба Ростеха

Employees are increasingly using AI agents to work with code directly on their work machines. Such assistants can read and modify files, execute commands, and access external and local models. The use of AI tools in itself does not indicate an information security breach, but an AI agent acts on behalf of the user and inherits their permissions – which means it can potentially access repositories, access keys, and other data available to the account.

RT-IB specialists analyzed common AI tools, including Claude Code, OpenAI Codex, GitHub Copilot CLI, Gemini CLI, Cursor, Cline, and OpenHands, as well as the local Ollama environment. Based on this data, they were able to identify signs by which the system detects the activity of various AI agents.

The study showed that it is impossible to detect such activity solely by network traffic or the presence of an installed program: local models can run directly on the computer without accessing external services, and AI tools themselves are launched in various ways and are not always displayed in the list of corporate software. Based on the research results, RT-IB experts formed two expertise packages for RT Protect EDR. The "AI Agent Control" package records the launch and behavior of the agent on the host and shows what data it accesses. The "Shadow AI" package covers unauthorized clients, local models, and channels for accessing external services.

Read more on the topic: