Zscaler and AI: What It Sees, and What It Misses

Zscaler and AI: What It Sees, and What It Misses

Zscaler and AI: What It Sees, and What It Misses

Category:

AI Governance

AI Visibility

Published date:

Zscaler logo above a split illustration: a lit dashboard of visible AI usage on the left, the same app tiles fading into shadow on the right

The short answer

Zscaler sees AI traffic. It does not see AI economics. As a proxy on the network path, it identifies which AI apps users reach, classifies prompts, blocks sensitive data and now extends to endpoints. What no proxy produces is a licence count, a token bill, a cost per active user or an ROI number. Those live in procurement and on the device.

Key takeaways

  • Zscaler sees a large volume of AI traffic and it's great for traffic inspection and usage classification. But it provides no visibility on the dollar value side of the equation.

  • The structural gap is not detection. A traffic log has no concept of a seat, a licence renewal or a token price. If you need full suite AI usage tracking and management, that comes with different DNA.

  • Guickly, the AI measurement layer for enterprises, supplies the missing number: what each AI tool costs and whether anyone is using it.

Zscaler's own report says the interesting part out loud. In January 2026 ThreatLabz warned that many organisations still lack a basic inventory of active AI models and embedded features. That warning came from a company that inspects AI traffic inline at scale. When the vendor with that vantage point reports that inventory is still missing, the gap is not something a bigger traffic dataset closes. It is a different measurement problem.

Here is what the network path shows, and what it cannot.

Does Zscaler detect shadow AI?

Yes, on the traffic it inspects. Zscaler Internet Access inspects AI traffic inline with application level granularity. The AI Access Security solution detects and classifies thousands of AI apps, scores them for risk and reports usage by user, department and application trend. ZIA also ships a Gen AI Security Report and an AI visibility dashboard, so a security team can answer "who used which AI app" without building anything.

Zscaler AI Protect, launched January 2026, organises this under three use cases: AI Asset Management, Secure Access to AI and Secure AI Infrastructure and Apps. In June 2026 at Zenith Live, Zscaler extended AI Asset Management to discover embedded AI in SaaS traffic, identify AI agents and MCP servers in public cloud and extend visibility to endpoint AI activity.

The boundary is the path. Shadow AI that crosses an inspected path gets found. Shadow AI that never crosses one does not, and the categories below explain how much of it there is.

Can Zscaler track AI costs?

No. This is the cleanest line in the comparison, and it is structural rather than a gap in the roadmap.

A proxy log records a transaction. It does not record a price. There is no field in a traffic record for the model tier that served the request, the token count billed, the seat the user occupies or the annual value of the contract that seat sits inside. Those facts exist in three other places: the vendor invoice, the licence directory and the device.

Consider the three shapes AI spend actually takes.Seats. Someone in IT bought 4,000 Copilot licences. Traffic tells you how many people generated Copilot requests last month. It cannot tell you how many of those requests came from a licensed seat, because the licence is a billing object and not a network object. Cost per active user is a division problem where the proxy only holds the denominator.

Tokens. Engineering runs agents against OpenAI, Anthropic or Bedrock. That spend arrives as a monthly platform invoice attributed to an organisation key. It is a procurement artifact. Even perfect inspection of the API calls would not reconstruct the bill, because pricing depends on model, cache state and tier.

Bundles. Embedded AI inside sanctioned SaaS is often priced into the platform contract or sold as an add on. Traffic to that SaaS domain looks the same whether the AI feature is on or off, and whether you paid for it or not.

What AI usage does a proxy miss?

Five categories.

1. Device local AI. Models running on the machine produce no outbound inference traffic at all. A developer running a local model through Ollama or an on device assistant generates zero proxy events by design. Endpoint AI Security extends coverage to local AI tools. Security telemetry answers whether something is risky. It is not built to answer what it cost to run.

2. API and platform spend. See above. Token cost is an invoice, not a session.

3. Embedded AI in sanctioned SaaS. ThreatLabz flagged this itself, noting that embedded AI features are often active by default and escape detection by legacy filters. Zscaler named Atlassian as a leading source of embedded AI activity. The point generalises. Copilot inside Microsoft 365 and Einstein inside Salesforce ride the same TLS session as the ordinary product. Classifying that traffic as AI is possible. Pricing it is not.

4. Licences and utilisation. No proxy has ever seen a renewal date. This is the number a CFO asks for first.

5. Usage outside the corporate path. Personal devices, personal accounts, home networks with no forwarding profile. Anything reached from a device that never joined the managed path is invisible to it. For a security team that is an accepted limit. For a budget it is a hole.

Zscaler and AI measurement, side by side

Dimension

What Zscaler sees

What it misses

Who covers it

Browser based GenAI apps on managed devices

App identity, user, department, risk score, allow or block

Nothing material

Zscaler

Prompt and response content

Inline classification, DLP across 100 plus dictionaries, content moderation

Nothing material

Zscaler

Local models and desktop AI apps

Endpoint AI Security covers browsers, extensions, plugins and local AI tools for threat purposes

Which model ran, how often, at what cost

Measurement layer

API and platform token spend

That a call left the network

Tokens billed, model tier, run rate by team

Measurement layer plus finance

Embedded AI in sanctioned SaaS

Discovery of embedded AI in SaaS traffic since June 2026

Whether the feature is licensed and what it adds to the contract

Measurement layer

Licences and seats

Nothing. There is no licence in a packet

Seats bought against seats used, cost per active user

Measurement layer

Agents and MCP servers

Agent Registry and AI Broker govern what an agent may access

What each agent consumes and what it returns

Measurement layer

Usage outside the managed path

Nothing on unenrolled devices

The whole tail

Measurement layer

Return on AI spend

Not in scope

Whether any of it worked

Measurement layer

Read the last column. It splits cleanly on one question: is this a risk fact or a money fact.

Do you need a separate AI measurement layer?

That depends on how much AI matters to your company.

If AI is a handful of sanctioned tools and a small line item, the AI reporting inside your security stack is probably enough. You get app names, user counts and a risk view. The questions you are asking do not go deeper than that.If AI is central to how the company runs, the answer changes. Spend rising every quarter. Agents in production. Engineering building on model APIs. Dozens of tools, most of them bought outside procurement. A CFO asking what came back. At that point AI measurement stops being a feature inside something else and becomes its own discipline, with its own instrument.

Cloud spend took exactly this path. Nobody manages a large cloud bill from the provider console alone. Once the number got big enough it earned dedicated tooling, dedicated owners and its own vocabulary. Enterprise AI is on the same curve, moving faster.

The real distinction is priority. On a security platform, AI is one risk category among many and it competes for roadmap with everything else a CISO owns. On a measurement layer, AI economics is the entire product. Depth follows priority.

One boundary worth stating plainly: a measurement layer does not enforce. No inline choke point, no DLP dictionary, no blocking. Enforcement stays where it already lives. The argument is not about replacing a gateway. It is that if AI is a priority for your business, the AI numbers deserve a specialist rather than a tab.

A CISO asks whether AI usage is safe. A CFO asks what it costs. A CIO asks whether it works. The first question already has good answers. The other two are the ones still going unanswered, and they are why this category exists at all.

FAQ

Does Zscaler show all AI apps employees use?

It shows AI apps reached over paths Zscaler inspects, with application level detail, user attribution and risk scores. Usage on unenrolled personal devices and models running locally on a machine sit outside that view. Zscaler Endpoint AI Security, announced June 2026, extends coverage to local AI tools and browser extensions for security purposes.

Can Zscaler tell me how much we spend on AI?

No. Zscaler reports transactions, prompts, data volume and policy actions. Cost data lives in vendor invoices, licence records and platform billing. No proxy product publishes a cost per active user, because a network log has no licence and no token price in it.

Does Zscaler cover Microsoft Copilot and other embedded AI?

Partly. In June 2026 AI Asset Management added discovery of embedded AI in SaaS traffic. Zscaler also publishes DLP guidance for Copilot. What remains outside scope is whether the embedded feature is licensed and what it adds to the contract.

Is a measurement layer a replacement for a secure web gateway?

They do different jobs. A gateway enforces policy inline. A measurement layer builds the inventory and the economics: every AI tool, model and agent, who uses it, what it costs and whether it earns the spend. If AI is a priority for the business, the second job needs an owner and a tool of its own.

What should a Zscaler customer add to close the gap?

Start with the three facts a proxy cannot hold. Seats bought against seats active. Token and platform spend by team. Local and desktop AI that never crosses the wire. Those three close most of the distance between an AI traffic report and an AI budget.

A proxy will tell you whether your AI usage is safe. If AI is where your budget and your bets now sit, that is not the question you are being asked. Guickly, the AI measurement layer for enterprises, answers the one you are: one view of every AI tool, model and agent in the company, what each one costs and whether it works.

Your AI transformation

starts with visibility.

See every AI tool. Track every dollar. Control every budget. Optimize every call. One platform, live in under an hour.

GUICKLY

The AI Transformation Platform

Guickly gives enterprises complete visibility and control over their AI transformation from adoption through optimization. Trusted by teams that are AI-first.

©2026 Guickly. All rights reserved.

Your AI transformation

starts with visibility.

See every AI tool. Track every dollar. Control every budget. Optimize every call. One platform, live in under an hour.

GUICKLY

The AI Transformation Platform

Guickly gives enterprises complete visibility and control over their AI transformation from adoption through optimization. Trusted by teams that are AI-first.

©2026 Guickly. All rights reserved.

Your AI transformation

starts with visibility.

See every AI tool. Track every dollar. Control every budget. Optimize every call. One platform, live in under an hour.

GUICKLY

The AI Transformation Platform

Guickly gives enterprises complete visibility and control over their AI transformation from adoption through optimization. Trusted by teams that are AI-first.

©2026 Guickly. All rights reserved.