For the complete documentation index, see llms.txt. This page is also available as Markdown.

Governing AI tools

Use AI tools governance to detect AI tool activity across your organization, assess potential risks, and define governance policies that guide employees toward approved or preferred AI solutions—aligned with your standards and security requirements.


Accessing AI tools governance

Select AI Tools > AI Tools Overview from the navigation panel to open the AI tools governance tab.


Reviewing AI tools in use

Review the top section of the AI tools governance page that maps all AI tools in use, including those not configured for adoption monitoring and without any governance policy:

  • Identify how many detected AI tools are currently Pending review. Also, on the AI governance tab itself, the system displays the number of AI tools pending governance review.

  • Track how many Users interacted with non-recommended AI tools (last 7 days), including trends over time. Colored arrows with percentages indicate the direction of change.

  • Track Users over time across the different governance categories of all AI tools in use.

Nexthink detects all AI tools in use based on connection.events data. The system maps observed domains and automatically displays discovered AI tools under the AI tools governance tab.

Review the All AI tools table to obtain further tool details:

  • Tool description and Country of origin.

  • Current governance Policy: Recommended, Allowed, Prohibited, and Pending review. The system lists the tools pending for governance review at the top of the table. Depending on the assigned governance policy, verify how often the system notifies users to redirect to an alternative AI tool.

  • User count for the specifc AI tool.

  • Link to the AI adoption dashboard, available for those AI tools configured in Nexthink for adoption monitoring. User roles with only AI tools governance permissions—that is, without permissions to view or manage AI adoption monitoring—can only confirm in the table whether adoption monitoring is Active or not. Refer to Monitoring the adoption of a particular AI tool for tool usage interpretation.

  • Status of the built-in campaign: Enabled or Disabled for the particular AI tool. Refer to Built-in campaign content for sentiment tracking for more information.

  • The date the AI tool was Added on to the table—first usage detection in your environment.

The system displays the ✦ sparkles icon to indicate AI-generated content or insights. AI is evolving rapidly and delivering great insights, but it can still make mistakes. Nexthink recommends validating your results to ensure accuracy and support informed decision-making.

Additionally, from the All AI tools table, you can:

  • Assign a policy to define how the system governs a particular AI tool. Refer to Assigning governance policies

  • Ignore a tool to remove it from the applications pending review, without applying any governance policy.


Assessing AI tools for governance

Select a specific tool from the All AI tools table for risk assessment and contextual governance information.

The system does not include risk assessments for custom AI tools, defined as tools added manually by users.

To assess AI tool risk, from the right-side panel of the chosen tool:

  1. Confirm the details of the current governance Policy: Recommended, Allowed, Prohibited, and Pending review. If applicable, this section includes notification configurations and the alternative AI tool suggested to the user.

  2. Identify AI tool Risk, determined by an AI analysis of the privacy policy, terms of service, security/trust page, and compliance documentation of the particular AI tool. Nexthink assesses risk based on data training and retention, compliance posture, enterprise readiness, and incident history.

  3. Review Usage information, including the user interaction visualization over the last 30 days.

  4. Review Adoption monitoring details:

    • Date when the system started monitoring the adoption of the particular tool.

    • Status of the built-in campaign: Enabled or Disabled for the particular AI tool. Refer to Built-in campaign content for sentiment tracking for more information.

    • Link to the AI adoption dashboard, available for those AI tools configured in Nexthink for adoption monitoring. User roles with only AI tools governance permissions—that is, without permissions to view or manage AI adoption monitoring—can only confirm in the table whether adoption monitoring is Active or not. Refer to Monitoring the adoption of a particular AI tool for tool usage interpretation.

Additionally, from the right-side panel of the selected AI tool, you can:

  • Assign/Change policy to define how the system governs a particular AI tool. Refer to Assigning governance policies

  • Open the action menu to Mark the tool as ignored or pending review for governance. The system removes ignored tools from the applications pending review, without applying any governance policy.

If required, you may add custom AI tools (not automatically discovered by the system) for governance policy implementation.

Adding custom AI tools for governance

​To add a new AI tool for governance:

  1. ​Select the New tool button in the All AI tools table.

  2. ​Fill in the tool details, including Domain for policy configuration, for example: www.KanopyAI.com. You can edit domains after saving.

After saving the custom tool, assign it to a governance policy. Refer to the Assigning governance policies section on this page.

The system does not monitor the adoption of tools manually added for governance policy, unless you also configured them for monitoring.

Refer to Configuring AI tools to set up adoption monitoring in Nexthink.


Assigning governance policies

Assign governance policies to define how Nexthink handles AI tools detected in your environment.

Governance policies help organizations guide employees toward approved AI tools, discourage usage of non-recommended tools, and reduce organizational or security risks.

Assigned governance policies apply to all users using the corresponding AI tool.

1

Choose an AI governance policy for the AI tool

From the All AI tools table or the right-side panel of a selected tool:

  • Click Assign/Change policy.

  • Choose the preferred governance policy: Recommended, Allowed, or Prohibited.

2

Optional — Guide users toward approved AI tool alternatives

When implementing Allowed or Prohibited governance policies, you should guide users towards approved AI tools:

  • Inform users of the governance policy when accessing the target AI tool. Define the notification Ocurrence. Select Once per day or Every 7 days.

  • Preview notice to see the warning pop-up displayed to users when accessing the AI tool.

  • Suggest an alternative tool for users. You can only suggest tools already configured in Nexthink for adoption monitoring. Refer to Configuring AI tools for tool settings.

  • Test the redirection link provided to users as an alternative and approved tool.

Last updated

Was this helpful?