> For the complete documentation index, see [llms.txt](https://docs.ox.security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.ox.security/ox-cloud/cloud-security/cloud-ai-governance.md).

# Cloud AI Governance

You can use Cloud AI governance to discover AI services and agents in your cloud environment and identify security risks associated with their use.

OX provides visibility into AI activity across your cloud environment, helping you identify which AI services are running, how they interact with cloud resources and data, and activity that might require investigation.

Cloud AI governance findings are generated according to the AI policies configured for your organization.

### What OX identifies

| Risk                  | Description                                                                                                                                   |
| --------------------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
| Shadow AI services    | Identifies AI services or agents that are not approved according to your organization's AI policy.                                            |
| Abnormal AI usage     | Identifies unusual changes in AI service usage that can indicate compromised or unauthorized activity and result in unexpected service costs. |
| AI privileges         | Identifies AI services or agents with permissions that can introduce security risks in your cloud environment.                                |
| Sensitive data access | Identifies AI services or agents that can access sensitive data or data stores.                                                               |
| Data leakage          | Identifies conditions in which AI services or agents can expose sensitive data outside the intended environment.                              |
| Encrypted DNS bypass  | Identifies AI-related communication that bypasses expected controls by using encrypted DNS.                                                   |

### Configure Cloud AI governance policies

Cloud AI governance detections are controlled by policies. [You can enable and configure these policies according to your organization's AI security requirements.](/ox-policies/cloud-ai-governance-policies.md)

For example, you can configure the Shadow AI policy to define which AI services are approved for use in your organization.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.ox.security/ox-cloud/cloud-security/cloud-ai-governance.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
