Media and Entertainment
How a Global Sports Betting and iGaming Operator Moved From Shadow AI to Full Governance
Summary
As AI tools spread across a global sports betting and iGaming operator’s workforce, developer teams, and production systems, the security team needed full visibility into how AI was actually being used — and a way to protect the AI applications and agents the company was building internally. With Cato AI Security in place, the company gained real-time governance across every layer of AI use: employee tools, developer copilots, and internally built AI agents in production.
Key results
- 34 MCP servers and 4,000+ local agents discovered across 1,500+ users — activity with zero prior visibility
- Nearly 1 million agentic tool calls monitored in a single 30-day window
- Nearly 49,000 prompts to third-party AI apps inspected in 7 days
- Dual-business-unit deployment live with strong role-based access control, meeting compliance requirements from day one
A Regulated Industry Meets a New Kind of Risk
This operator runs one of the largest online sports betting and iGaming businesses in the world, spanning multiple brands and business units across several countries. Operating in a heavily regulated industry, the company had long-established data-protection and compliance obligations — and as generative AI tools spread from employee laptops into developer workflows and production applications, the security team recognized a new category of risk emerging alongside them.
Employees were using AI chat tools. Developers had AI coding assistants built into their IDEs. And the company’s own engineering teams were beginning to build AI-powered applications and agents — including an internal assistant connected to their engineering and project-management systems — running on AWS Bedrock.
None of this activity was invisible by accident. It was invisible because nothing in the company’s existing security stack was built to see it.
The Gap: Shadow AI, Agent Sprawl, and Unprotected AI You Build
The security team’s existing tools — a secure web proxy and an endpoint detection platform — could see traffic and processes, but not what was happening inside an AI conversation, and not what a locally running AI agent was actually doing once installed.
That gap mattered on two fronts. First, employee and developer AI usage was growing without any inventory of which tools were sanctioned, which were shadow AI, and what data was flowing into them. Second, the company’s own internally built AI agents — including a production assistant integrated with core engineering systems — had no dedicated protection against prompt injection or data leakage, and no security review process built for how fast AI features were shipping.
The company needed a platform that could do both: govern the AI tools employees and developers already used, and protect the AI applications and agents the company was building itself — while meeting AI-specific compliance frameworks relevant to its industry.
From Zero Visibility to Full-Stack AI Governance
The company deployed Cato AI Security across its existing security architecture rather than adding a new, separate stack. AI traffic visibility was built on top of its existing secure web proxy, and agent and MCP discovery was layered onto its existing endpoint detection platform — extending investments already in place instead of introducing new agents to manage. Developer-tool coverage extended protection into AI-assisted coding environments, and the company’s internally built AI agent, running on AWS Bedrock, became a protected production workload from day one.
Because the company operates as two distinct business units, the deployment was scoped from the outset with strong access controls to keep each unit’s AI activity properly separated and governed — a requirement built into the rollout plan rather than retrofitted after go-live.
The results were immediate. Within days of deployment, discovery mode alone surfaced dozens of MCP servers, thousands of local AI agents across more than a thousand users, and nearly a million agentic tool calls in a single month — activity the security team had no way to see before. Nearly 49,000 prompts to third-party AI tools were inspected in a single week.
Governance Built to Scale With AI
The engagement wasn’t without friction — a certificate-handling issue between one AI coding assistant and the proxy configuration required joint troubleshooting, and coordinating a dual-business-unit rollout with strict access separation added complexity to the deployment. But those challenges were scoped and solved before go-live, not after, and the company now has a single governance layer covering how its people, its developers, and its own AI-powered products all interact with AI.
As the company continues building more AI-powered applications and agents, that governance layer — covering everything from a single employee prompt to a production agent’s tool calls — is already in place.