How a Global Sports Betting and iGaming Operator Moved From Shadow AI to Full Governance

Media and Entertainment

How a Global Sports Betting and iGaming Operator Moved From Shadow AI to Full Governance

What’s inside?

Request a Demo

Summary

As AI tools spread across a global sports betting and iGaming operator’s workforce, developer teams, and production systems, the security team needed full visibility into how AI was actually being used — and a way to protect the AI applications and agents the company was building internally. With Cato AI Security in place, the company gained real-time governance across every layer of AI use: employee tools, developer copilots, and internally built AI agents in production.

Key results

  • 34 MCP servers and 4,000+ local agents discovered across 1,500+ users — activity with zero prior visibility
  • Nearly 1 million agentic tool calls monitored in a single 30-day window
  • Nearly 49,000 prompts to third-party AI apps inspected in 7 days
  • Dual-business-unit deployment live with strong role-based access control, meeting compliance requirements from day one

A Regulated Industry Meets a New Kind of Risk

This operator runs one of the largest online sports betting and iGaming businesses in the world, spanning multiple brands and business units across several countries. Operating in a heavily regulated industry, the company had long-established data-protection and compliance obligations — and as generative AI tools spread from employee laptops into developer workflows and production applications, the security team recognized a new category of risk emerging alongside them.

Employees were using AI chat tools. Developers had AI coding assistants built into their IDEs. And the company’s own engineering teams were beginning to build AI-powered applications and agents — including an internal assistant connected to their engineering and project-management systems — running on AWS Bedrock.

None of this activity was invisible by accident. It was invisible because nothing in the company’s existing security stack was built to see it.

The Gap: Shadow AI, Agent Sprawl, and Unprotected AI You Build

The security team’s existing tools — a secure web proxy and an endpoint detection platform — could see traffic and processes, but not what was happening inside an AI conversation, and not what a locally running AI agent was actually doing once installed.

That gap mattered on two fronts. First, employee and developer AI usage was growing without any inventory of which tools were sanctioned, which were shadow AI, and what data was flowing into them. Second, the company’s own internally built AI agents — including a production assistant integrated with core engineering systems — had no dedicated protection against prompt injection or data leakage, and no security review process built for how fast AI features were shipping.

The company needed a platform that could do both: govern the AI tools employees and developers already used, and protect the AI applications and agents the company was building itself — while meeting AI-specific compliance frameworks relevant to its industry.

From Zero Visibility to Full-Stack AI Governance

The company deployed Cato AI Security across its existing security architecture rather than adding a new, separate stack. AI traffic visibility was built on top of its existing secure web proxy, and agent and MCP discovery was layered onto its existing endpoint detection platform — extending investments already in place instead of introducing new agents to manage. Developer-tool coverage extended protection into AI-assisted coding environments, and the company’s internally built AI agent, running on AWS Bedrock, became a protected production workload from day one.

Because the company operates as two distinct business units, the deployment was scoped from the outset with strong access controls to keep each unit’s AI activity properly separated and governed — a requirement built into the rollout plan rather than retrofitted after go-live.

The results were immediate. Within days of deployment, discovery mode alone surfaced dozens of MCP servers, thousands of local AI agents across more than a thousand users, and nearly a million agentic tool calls in a single month — activity the security team had no way to see before. Nearly 49,000 prompts to third-party AI tools were inspected in a single week.

Governance Built to Scale With AI

The engagement wasn’t without friction — a certificate-handling issue between one AI coding assistant and the proxy configuration required joint troubleshooting, and coordinating a dual-business-unit rollout with strict access separation added complexity to the deployment. But those challenges were scoped and solved before go-live, not after, and the company now has a single governance layer covering how its people, its developers, and its own AI-powered products all interact with AI.

As the company continues building more AI-powered applications and agents, that governance layer — covering everything from a single employee prompt to a production agent’s tool calls — is already in place.

More customer stories

Baltimore Aircoil Replaces MPLS with Cato, Improving Voice Quality, Enabling Video Conferencing, and Increasing Agility

Manufacturing

Baltimore Aircoil Replaces MPLS with Cato, Improving Voice Quality, Enabling Video Conferencing, and Increasing Agility
Baltimore Aircoil Replaces MPLS with Cato, Improving Voice Quality, Enabling Video Conferencing, and Increasing Agility Summary As AI tools spread across a global sports betting and iGaming operator's workforce, developer teams, and production systems, the security team needed full visibility into how AI was actually being used — and a way to protect the AI applications and agents the company was building internally. With Cato AI Security in place, the company gained real-time governance across every layer of AI use: employee tools, developer copilots, and internally built AI agents in production. Key results 34 MCP servers and 4,000+ local agents discovered across 1,500+ users — activity with zero prior visibility Nearly 1 million agentic tool calls monitored in a single 30-day window Nearly 49,000 prompts to third-party AI apps inspected in 7 days Dual-business-unit deployment live with strong role-based access control, meeting compliance requirements from day one A Regulated Industry Meets a New Kind of Risk This operator runs one of the largest online sports betting and iGaming businesses in the world, spanning multiple brands and business units across several countries. Operating in a heavily regulated industry, the company had long-established data-protection and compliance obligations — and as generative AI tools spread from employee laptops into developer workflows and production applications, the security team recognized a new category of risk emerging alongside them. Employees were using AI chat tools. Developers had AI coding assistants built into their IDEs. And the company's own engineering teams were beginning to build AI-powered applications and agents — including an internal assistant connected to their engineering and project-management systems — running on AWS Bedrock. None of this activity was invisible by accident. It was invisible because nothing in the company's existing security stack was built to see it. The Gap: Shadow AI, Agent Sprawl, and Unprotected AI You Build The security team's existing tools — a secure web proxy and an endpoint detection platform — could see traffic and processes, but not what was happening inside an AI conversation, and not what a locally running AI agent was actually doing once installed. That gap mattered on two fronts. First, employee and developer AI usage was growing without any inventory of which tools were sanctioned, which were shadow AI, and what data was flowing into them. Second, the company's own internally built AI agents — including a production assistant integrated with core engineering systems — had no dedicated protection against prompt injection or data leakage, and no security review process built for how fast AI features were shipping. The company needed a platform that could do both: govern the AI tools employees and developers already used, and protect the AI applications and agents the company was building itself — while meeting AI-specific compliance frameworks relevant to its industry. From Zero Visibility to Full-Stack AI Governance The company deployed Cato AI Security across its existing security architecture rather than adding a new, separate stack. AI traffic visibility was built on top of its existing secure web proxy, and agent and MCP discovery was layered onto its existing endpoint detection platform — extending investments already in place instead of introducing new agents to manage. Developer-tool coverage extended protection into AI-assisted coding environments, and the company's internally built AI agent, running on AWS Bedrock, became a protected production workload from day one. Because the company operates as two distinct business units, the deployment was scoped from the outset with strong access controls to keep each unit's AI activity properly separated and governed — a requirement built into the rollout plan rather than retrofitted after go-live. The results were immediate. Within days of deployment, discovery mode alone surfaced dozens of MCP servers, thousands of local AI agents across more than a thousand users, and nearly a million agentic tool calls in a single month — activity the security team had no way to see before. Nearly 49,000 prompts to third-party AI tools were inspected in a single week. Governance Built to Scale With AI The engagement wasn't without friction — a certificate-handling issue between one AI coding assistant and the proxy configuration required joint troubleshooting, and coordinating a dual-business-unit rollout with strict access separation added complexity to the deployment. But those challenges were scoped and solved before go-live, not after, and the company now has a single governance layer covering how its people, its developers, and its own AI-powered products all interact with AI. As the company continues building more AI-powered applications and agents, that governance layer — covering everything from a single employee prompt to a production agent's tool calls — is already in place.
Read customer story Search
CIAL Dun & Bradstreet Improves Networking and Security in Latin American with Cato

Financial Services

CIAL Dun & Bradstreet Improves Networking and Security in Latin American with Cato
CIAL Dun & Bradstreet Improves Networking and Security in Latin American with Cato Summary As AI tools spread across a global sports betting and iGaming operator's workforce, developer teams, and production systems, the security team needed full visibility into how AI was actually being used — and a way to protect the AI applications and agents the company was building internally. With Cato AI Security in place, the company gained real-time governance across every layer of AI use: employee tools, developer copilots, and internally built AI agents in production. Key results 34 MCP servers and 4,000+ local agents discovered across 1,500+ users — activity with zero prior visibility Nearly 1 million agentic tool calls monitored in a single 30-day window Nearly 49,000 prompts to third-party AI apps inspected in 7 days Dual-business-unit deployment live with strong role-based access control, meeting compliance requirements from day one A Regulated Industry Meets a New Kind of Risk This operator runs one of the largest online sports betting and iGaming businesses in the world, spanning multiple brands and business units across several countries. Operating in a heavily regulated industry, the company had long-established data-protection and compliance obligations — and as generative AI tools spread from employee laptops into developer workflows and production applications, the security team recognized a new category of risk emerging alongside them. Employees were using AI chat tools. Developers had AI coding assistants built into their IDEs. And the company's own engineering teams were beginning to build AI-powered applications and agents — including an internal assistant connected to their engineering and project-management systems — running on AWS Bedrock. None of this activity was invisible by accident. It was invisible because nothing in the company's existing security stack was built to see it. The Gap: Shadow AI, Agent Sprawl, and Unprotected AI You Build The security team's existing tools — a secure web proxy and an endpoint detection platform — could see traffic and processes, but not what was happening inside an AI conversation, and not what a locally running AI agent was actually doing once installed. That gap mattered on two fronts. First, employee and developer AI usage was growing without any inventory of which tools were sanctioned, which were shadow AI, and what data was flowing into them. Second, the company's own internally built AI agents — including a production assistant integrated with core engineering systems — had no dedicated protection against prompt injection or data leakage, and no security review process built for how fast AI features were shipping. The company needed a platform that could do both: govern the AI tools employees and developers already used, and protect the AI applications and agents the company was building itself — while meeting AI-specific compliance frameworks relevant to its industry. From Zero Visibility to Full-Stack AI Governance The company deployed Cato AI Security across its existing security architecture rather than adding a new, separate stack. AI traffic visibility was built on top of its existing secure web proxy, and agent and MCP discovery was layered onto its existing endpoint detection platform — extending investments already in place instead of introducing new agents to manage. Developer-tool coverage extended protection into AI-assisted coding environments, and the company's internally built AI agent, running on AWS Bedrock, became a protected production workload from day one. Because the company operates as two distinct business units, the deployment was scoped from the outset with strong access controls to keep each unit's AI activity properly separated and governed — a requirement built into the rollout plan rather than retrofitted after go-live. The results were immediate. Within days of deployment, discovery mode alone surfaced dozens of MCP servers, thousands of local AI agents across more than a thousand users, and nearly a million agentic tool calls in a single month — activity the security team had no way to see before. Nearly 49,000 prompts to third-party AI tools were inspected in a single week. Governance Built to Scale With AI The engagement wasn't without friction — a certificate-handling issue between one AI coding assistant and the proxy configuration required joint troubleshooting, and coordinating a dual-business-unit rollout with strict access separation added complexity to the deployment. But those challenges were scoped and solved before go-live, not after, and the company now has a single governance layer covering how its people, its developers, and its own AI-powered products all interact with AI. As the company continues building more AI-powered applications and agents, that governance layer — covering everything from a single employee prompt to a production agent's tool calls — is already in place.
Read customer story Search
Diamond Braces Uses Cato to Boost WAN Security, Performance, and Reliability

Healthcare

Diamond Braces Uses Cato to Boost WAN Security, Performance, and Reliability
Diamond Braces Uses Cato to Boost WAN Security, Performance, and Reliability Summary As AI tools spread across a global sports betting and iGaming operator's workforce, developer teams, and production systems, the security team needed full visibility into how AI was actually being used — and a way to protect the AI applications and agents the company was building internally. With Cato AI Security in place, the company gained real-time governance across every layer of AI use: employee tools, developer copilots, and internally built AI agents in production. Key results 34 MCP servers and 4,000+ local agents discovered across 1,500+ users — activity with zero prior visibility Nearly 1 million agentic tool calls monitored in a single 30-day window Nearly 49,000 prompts to third-party AI apps inspected in 7 days Dual-business-unit deployment live with strong role-based access control, meeting compliance requirements from day one A Regulated Industry Meets a New Kind of Risk This operator runs one of the largest online sports betting and iGaming businesses in the world, spanning multiple brands and business units across several countries. Operating in a heavily regulated industry, the company had long-established data-protection and compliance obligations — and as generative AI tools spread from employee laptops into developer workflows and production applications, the security team recognized a new category of risk emerging alongside them. Employees were using AI chat tools. Developers had AI coding assistants built into their IDEs. And the company's own engineering teams were beginning to build AI-powered applications and agents — including an internal assistant connected to their engineering and project-management systems — running on AWS Bedrock. None of this activity was invisible by accident. It was invisible because nothing in the company's existing security stack was built to see it. The Gap: Shadow AI, Agent Sprawl, and Unprotected AI You Build The security team's existing tools — a secure web proxy and an endpoint detection platform — could see traffic and processes, but not what was happening inside an AI conversation, and not what a locally running AI agent was actually doing once installed. That gap mattered on two fronts. First, employee and developer AI usage was growing without any inventory of which tools were sanctioned, which were shadow AI, and what data was flowing into them. Second, the company's own internally built AI agents — including a production assistant integrated with core engineering systems — had no dedicated protection against prompt injection or data leakage, and no security review process built for how fast AI features were shipping. The company needed a platform that could do both: govern the AI tools employees and developers already used, and protect the AI applications and agents the company was building itself — while meeting AI-specific compliance frameworks relevant to its industry. From Zero Visibility to Full-Stack AI Governance The company deployed Cato AI Security across its existing security architecture rather than adding a new, separate stack. AI traffic visibility was built on top of its existing secure web proxy, and agent and MCP discovery was layered onto its existing endpoint detection platform — extending investments already in place instead of introducing new agents to manage. Developer-tool coverage extended protection into AI-assisted coding environments, and the company's internally built AI agent, running on AWS Bedrock, became a protected production workload from day one. Because the company operates as two distinct business units, the deployment was scoped from the outset with strong access controls to keep each unit's AI activity properly separated and governed — a requirement built into the rollout plan rather than retrofitted after go-live. The results were immediate. Within days of deployment, discovery mode alone surfaced dozens of MCP servers, thousands of local AI agents across more than a thousand users, and nearly a million agentic tool calls in a single month — activity the security team had no way to see before. Nearly 49,000 prompts to third-party AI tools were inspected in a single week. Governance Built to Scale With AI The engagement wasn't without friction — a certificate-handling issue between one AI coding assistant and the proxy configuration required joint troubleshooting, and coordinating a dual-business-unit rollout with strict access separation added complexity to the deployment. But those challenges were scoped and solved before go-live, not after, and the company now has a single governance layer covering how its people, its developers, and its own AI-powered products all interact with AI. As the company continues building more AI-powered applications and agents, that governance layer — covering everything from a single employee prompt to a production agent's tool calls — is already in place.
Read customer story Search