AIEGIS EYE
AI is already flowing through your business's browsers, desktop apps, and terminals on company devices. Employees are using tools like ChatGPT, Claude, and Copilot to work faster, often with the best of intentions. The challenge is that most organizations have little or no visibility into where company data is going, which AI services are being used, or how to demonstrate responsible oversight when asked.
As the EU AI Act and related regulations take effect, that lack of visibility becomes more than an operational blind spot. It becomes a business risk. When regulators, auditors, customers, or your board ask how AI is being governed, you need answers backed by evidence, not assumptions.
How it works
AIEGIS EYE was built to give you those answers. With a lightweight sensor on each macOS device (Windows and Linux support coming soon) and a single Command Centre for your entire fleet, you gain a live view of AI activity across your organization: which tools are in use, on which machines, by whom, and how often. In seconds, you can switch a device from monitoring to blocking. On macOS, blocking covers browsers, desktop apps, and terminals, helping ensure sensitive information never leaves the device unintentionally. Windows and Linux sensor support is coming soon.
Trust matters in a space this new. AIEGIS is an OWASP AIVSS co-author, helping shape the standards used to assess AI vulnerabilities. The platform is self-hosted by default, protected with end-to-end encryption, and designed from day one to support EU AI Act Article 26 evidence generation, GDPR transparency obligations, and DORA and NIS2 reporting.
Download AIEGIS EYE and see what's happening across your AI estate, before someone else asks you to prove that you know.
How to start
Getting started is simple. Install the Command Centre, activate your first device with the included license, and begin seeing your organization's real AI exposure within minutes. The sooner you gain visibility, the sooner you can move from uncertainty to confident, evidence-based AI governance.
macOS only. Windows & Linux coming soon.
EU AI Act (Regulation (EU) 2024/1689) · Article 26: Human Oversight & Deployer Obligations
Eye creates technical records that can form part of an organisation's AI governance and compliance evidence. Eye provides an append-only audit trail and reporting features that may support selected monitoring, oversight and log-retention activities where applicable.
Under the current EU implementation timeline, relevant Annex III high-risk obligations apply from 2 December 2027 and product-integrated high-risk obligations from 2 August 2028.
Eye generates the agent activity records that support Article 26(6), including the AI vendor, operating context, user attribution and timestamps. Relevant monitoring fields (vendor, device or process context, user attribution and timestamp) are mapped into a report that can support selected monitoring and record-keeping activities.
Audit records are retained for a customer-configurable period. Where Article 26(6) applies, customers must separately ensure that logs automatically generated by the relevant high-risk AI system are retained for the legally required period.
GDPR Articles 13 & 14 · Employer Transparency
Monitoring AI activity on company devices brings GDPR transparency obligations. Eye includes configurable tools and templates that can support a customer's GDPR transparency and governance process. Customers must determine their lawful basis and meet applicable employment and data-protection requirements.
Eye generates a clear employee notice covering what data is collected, the lawful basis for processing, retention periods, and the data controller, ready to provide directly to staff. Where AI activity is linked to employee identity, the data source is logged and traceable.
Subject access requests are supported through a built-in export, where an administrator can produce a complete record of an individual's activity on demand. Eye also includes jurisdiction-specific works council templates for Germany, France, the Netherlands, and Ireland, supporting compliance in employment contexts across member states.
DORA, NIS2, and AI Governance
AIEGIS Eye is designed to align with the broader regulatory landscape, including DORA and NIS2, where visibility into third-party technology is essential.
Eye can help identify AI services in use and provide an input to third-party technology inventories and supply-chain risk reviews. It does not replace DORA registers, contractual records, due diligence, risk assessment or NIS2 controls.
Built With OWASP AIVSS
AIEGIS is not just aligned with emerging AI security standards. It helps define them.
We contributed directly to the OWASP AIVSS enforcement-effectiveness framework, including the audit-pack signing test used to measure how quickly and reliably AI controls are applied. This work is publicly verifiable on GitHub.
For procurement teams, this means your audit trail isn't just a claim. It is built against the same standards used to define what 'defensible' looks like.
Command Centre · Look up a device or tenant
Open the Command Centre to view any single machine, or activity across your whole organisation.
The view updates automatically every 30 seconds.
Command Centre · Alerts
Each lookup retrieves alerts and displays them as clear banners above the events table:
- High: sensor inactive for more than 30 minutes.
- Warn: sensor inactive for more than 5 minutes, or an unsanctioned AI vendor is detected.
Alerts appear directly in the Command Centre and surface on screen in real time.
Command Centre · Reports
Generate clean, locked reports directly from the tenant view. Each report captures activity for the selected scope and time period in a fixed-layout, print-ready format, designed for audit, sharing, and record-keeping.
Reports are structured for clarity, easy to read, and designed to support audit and regulatory review.
Frequently asked questions
What does AIEGIS EYE do?
AIEGIS Eye is an endpoint sensor that detects when employees connect to AI tools, covering 20+ tools via the browser extension (ChatGPT, Claude, Copilot, Gemini, Mistral, Perplexity, Grok, DeepSeek and more), plus Cursor and VSCode Copilot via native app monitoring, directly on the device.
Detection is metadata only: vendor, user, and timestamp. If a prompt is flagged or blocked, the full prompt text is captured and remains on your own systems. This design is intended to reduce data exposure and support legal, security and works-council review. Customer approval and lawful deployment remain required.
Is AIEGIS EYE live in production today?
AIEGIS Eye is currently deployed in live pilot environments. The macOS sensor, backend ingest, Command Centre, alerts, and reports are fully operational; Windows and Linux sensors are coming soon.
How does Eye help with EU AI Act Article 26 compliance?
For organisations deploying high-risk AI systems, Article 26 includes duties concerning use, monitoring, human oversight and retention of automatically generated logs. Eye can provide supplementary endpoint visibility and evidence.
What data does Eye send back to AIEGIS?
Prompt content and customer audit records are not sent to AIEGIS. Limited licensing, update or service-health data may be processed as described in the Privacy Policy and DPA.
What about AIVSS scoring?
AIEGIS contributed to the OWASP AIVSS framework, including work on runtime enforcement effectiveness. Eye events can be used to support AIVSS-based assessment and scoring.
Detection layers
AIEGIS Eye identifies AI vendor connections without decrypting payloads, combining multiple on-device signals to build a clear, reliable view of activity.
- TLS socket scan: monitors active connections and links them to the originating process.
- Process enumeration: matches running applications against known AI vendor processes.
- Connection name matching: reads the destination site name directly from the connection, allowing accurate vendor identification even when services are fronted by providers like Cloudflare.
These signals work together to identify AI usage at the network and process level, without inspecting content.
Shadow AI detection patterns
Shadow AI is the use of generative AI tools outside approved procurement and governance processes. It's one of the fastest-growing enterprise risks, not because employees act maliciously, but because AI tools are now embedded in everyday workflows.
Eye helps you detect and understand that activity in real time.
- Sanctioned vs. shadow: every connection is checked against your approved vendor list. Anything outside it is flagged as a shadow event.
All activity is recorded within your own environment. AIEGIS does not aggregate or use customer data.
Browser extension & native host
The browser extension runs on Chrome, Edge and Brave. It is designed to stay lightweight, capturing activity in the browser and passing it securely to a local helper process.
Because browser extensions are limited by security design, Eye uses a native host on the device to handle signing and secure communication.
How it works:
- Capture: prompts are observed at the point of submission.
- Decision: prompts are allowed, warned, or blocked in real time.
- Audit record: each decision is signed and recorded on your infrastructure.
All processing happens on-device. Data remains within your environment at all times.
How Eye differs from traditional DLP
Traditional DLP tools were built for email and file sharing. They focus on inspecting stored content and controlling data at the network perimeter. Modern AI usage happens inside encrypted browser sessions: a different problem entirely.
- DLP inspects content. Eye inspects context. Eye captures who is using which AI tool, when, and from where, giving you visibility DLP cannot provide.
- No TLS interception required. Eye operates without breaking encryption or requiring certificate installs on devices.
- Designed for AI usage. Instead of managing content rules, Eye tracks AI vendor interactions directly.
- Built for audit, not incident review. Eye creates structured, tamper-evident records aligned with regulatory requirements.
Eye doesn't replace DLP. It extends your coverage to the part of the workflow DLP was never designed to handle: AI usage inside the browser.
Manual · Getting started (Mac)
The Command Centre is a native Mac app. After downloading, drag it into your Applications folder before opening it: opening it straight from Downloads lets it launch, but macOS silently blocks the permissions it needs to monitor anything, with no error shown. Once it's in Applications, open it from there and a guided setup walks you through everything macOS needs to grant it before it can watch AI activity on this machine.
1. The permission wizard. Five steps, all the same pattern: Approve, flip the named switch ON in System Settings, then Done. The five: Accessibility (reads prompts typed into apps), Input Monitoring (sees keystrokes into AI tools to capture prompts), Full Disk Access (reads local audit and policy files), Network Filter (inspects outbound AI traffic; macOS will ask you to allow a system extension), and Browser Coverage (adds the browser extension for Chrome, Edge and Brave). You can skip a step, but the sensor won't run until all five are done. There's no way to fake past it.
2. Company details. After signing in, a short second step asks for your company name, DPO contact, works council contact, and the named human-oversight officer. These feed straight into every compliance report, so it's worth filling in accurately.
3. Monitor by default. Once set up, the whole fleet starts in Monitor mode: everything is watched and logged, nothing is blocked. Flip the Monitor ⇄ Protect switch (bottom-right of the main window) to start actively blocking unsafe prompts across every enrolled machine. This one switch is the only place enforcement is controlled. An individual employee's machine has no local on/off of its own.
Manual · Monitoring & visibility
The main screen (Recent) is a live people roster, not a raw event feed. Each live person shows their longest-open AI tool by full name with a running clock; idle people show when they were last active. Search finds people by vendor, tool, name or machine. Tap anyone to open their full profile inside the same screen: everything they've used, machines, networks, and a day-by-day log of every captured prompt, with a one-click "Full report" export.
A report for every person is also written automatically at midnight, filed under a tidy company-named folder in your Documents so nothing depends on remembering to export.
Other read-only pages round out the picture: Health (which machines are reporting), Rate (how fast events are arriving, busiest hour of day), Uptime (is the whole system live), Top Hosts (busiest machines), By OS (drill from operating system to person), and Overview (a 5-second summary). LAN/Network scans your local network to find devices and assign or release a licence seat to each.
Manual · Protection & threat detection
Incidents lists every prompt actually blocked, with the exact text, why it was stopped, who sent it, and from where, kept in your tenant, never shared with the AI vendor. Protection is where you manage your own custom block words (built-in protections against jailbreaks and data leaks are always on); enforcing vs monitor-only is the master switch described in Getting Started, not this page.
Shadow AI surfaces AI tools your staff are using that you haven't approved, as a share of total traffic. Tap one to see who's using it, and approve it onto your allowlist if it's fine. Detection Proof shows measured block rates and latency against a fixed benchmark, so you can show real evidence the detection works, not just a vendor claim. Alerts flags operational issues (like a machine gone quiet) with one-click fixes. Vendors lists every AI vendor seen with a block/unblock toggle per vendor.
Manual · Deployment & sensors
The Mac Sensor is a small background agent bundled with the Command Centre app. Install it, and it keeps watching in the background, auto-starting on login. A separate Terminal capture toggle extends coverage to AI command-line tools (Claude Code, and others) so prompts typed at a terminal are checked too, the same as anywhere else.
Browser Guard is the browser extension that checks prompts typed into ChatGPT, Claude, Copilot, Gemini and Perplexity, supported on Chrome, Edge and Brave. It pairs with a small native component (the Bridge) that signs and ships the audit trail for every decision the extension makes.
For a whole company at once, Fleet Rollout gives you ready-made deployment payloads for major MDM tools, or can install directly over SSH to every machine it discovers, no MDM required. Endpoints is the roster of every enrolled machine, each with its own drill-down report.
The supported platform today is macOS; Windows and Linux sensor support is coming soon.
Manual · Account, licences & reports
Buying more capacity is simple: pick a quantity and hit buy. Checkout happens on aiegis.ie in your browser, and no card is ever taken inside the app. The Command Centre itself is a one-off website purchase; sensor licence keys for additional machines are bought the same way, one key per machine.
To get a new machine set up quickly, use "Hand out a sensor": it drafts an email with the sensor download link and a freshly-issued licence key, ready to send to whoever needs it. It installs and links back to your Command Centre automatically.
Reports is your evidence and compliance centre: per-machine and company-wide reports, a print-ready EU AI Act Article 26 report, daily/weekly exports, a full audit pack, a DPIA, an employee monitoring notice, a subject-access-request export, and a retention setting. By default nothing is ever auto-deleted. You choose a fixed retention window only if you want one.
Manual · The AIEGIS Engineer
A built-in AI assistant lives in the panel on the left of the main window, not a separate tab. Type to it, or tap the microphone and just talk; it answers out loud once you stop speaking, entirely on-device. It answers questions about your own system, opens the right page for you, and helps guide setup, but it never flips a setting itself. When something needs changing, it takes you to the right control and explains what to do, so the decision always stays with you.
It only ever helps with AIEGIS EYE, and it's built to refuse being steered off that regardless of how it's asked.