What You Can Monitor, Technically
The mechanisms available, in order of intrusiveness, so the choice is deliberate rather than whatever the product does.
Monitoring · Reference
Several techniques can detect AI tool use. They differ enormously in what they reveal, and the difference should be a decision rather than a default.
Applying the boundary described in “What You Can Monitor, Technically” requires a clear operational purpose and a record that can be reviewed without reading private content. Teams considering the productivity guide can use workload and time evidence to understand how approved processes are actually used, while keeping AI discovery, security telemetry and employee monitoring separate and proportionate.
For an independent benchmark, compare the local approach with ICO guidance on AI and data protection; the useful test is whether ownership, access and recovery remain proportionate and explainable when the usual expert is absent.
Least intrusive: destination
DNS and network logs showing which services are reached.
Reveals: that a service was contacted.
Does not reveal: content, or whether anything was sent.
Sufficient for discovery and for most ongoing visibility.
Inventory
Installed applications, browser extensions, enabled features.
Reveals: what is available on the device.
Does not reveal: use or content.
The most useful source per unit of intrusion, particularly for extensions.
Volume and metadata
How much data moved, when, to where.
Reveals: that a large upload occurred.
Does not reveal: what it was.
Useful as a flag for investigation, poor as evidence on its own.
Content inspection at the boundary
Proxies that examine what is being sent, typically looking for classified data patterns.
Reveals: content, including anything the person typed.
This is a substantial step and it is where the collection's note on prompt content applies.
Endpoint content capture
Agents reading what is typed, pasted or displayed.
Reveals: everything.
This is surveillance by any reasonable definition, carries consultation obligations in several jurisdictions, and should be an explicit decision taken at the top rather than a product configuration.
Choosing
Most programmes need the first two and benefit from the third.
The fourth is justifiable for specific high-risk data flows with narrow scope and stated rules.
The fifth needs a reason that would survive being explained to the people subject to it, which is a useful test and one that most proposals fail.
The scope creep pattern
A tool bought for destination visibility includes content inspection.
It gets enabled because it is there.
Nobody decided to inspect content; a default did.
Check what your tooling is configured to collect, as opposed to what it was bought for.
The proportionality test
Several data protection regimes require considering whether a less intrusive method would achieve the purpose.
For discovery and ordinary visibility, it would.
Which means the written justification for content inspection has to explain why destination and inventory were insufficient — and if it cannot, that is the answer.
What to check
Which of the five is your tooling actually doing?
Was that decided, or defaulted?
Could a less intrusive level answer your question?
And would you be comfortable explaining the current level to everybody subject to it?
The point
Five levels of monitoring exist, from destination logs to endpoint content capture.
Most programmes need the first two and benefit from the third.
Underlying all of this
Everything in this collection reduces to four habits: find out what people are doing and why before deciding anything, provide something good enough that the approved route is the easy one, write rules about information rather than about tools, and monitor the destination rather than the content. None requires a product, and a programme doing all four controls more than one built on prohibition.
The recurring pattern
The recurring pattern across every section here is the same: the response that feels like control reduces it. A ban removes visibility rather than use. Content inspection drives activity to personal devices. A discovery exercise with consequences produces quiet answers. In each case the organisation ends up knowing less about a risk it believes it has handled.