Frontier models, apps with embedded AI, and MCP servers carry very different risks. Count them as one thing and your inventory ends up bloated and blind.
Ask a CISO how many AI apps are in use at their company and you'll get a number. Ask them to define what counted as an AI app and the number falls apart. Is Salesforce an AI app now? Is anything with a Model Context Protocol (MCP) server? Is Cursor an AI company or a customer of one?
‍
This isn't pedantry. If you're trying to govern AI use in your organization, your inventory is only as good as your definition. And right now there are really three distinct categories getting lumped under one label, each with a different risk profile.
‍
These are the companies actually training and serving foundation models: Anthropic, OpenAI, Google, Mistral, Cohere. Most people meet them through the chat apps everyone already knows, but the chat interface is just the retail storefront. The bigger story is the API business underneath it, where these same models get embedded into other products and power agent runtimes.
‍
That distinction matters for governance. When an employee signs up for ChatGPT, you can see it. When a vendor three layers down in your stack calls the OpenAI API with your data, you probably can't. Same model provider, very different visibility.
‍
This is the largest and fastest-growing category by a wide margin. Most of it is existing SaaS that bolted AI onto its workflows. HubSpot summarizes your calls. Salesforce drafts your emails. Asana suggests your next task. At this point it's harder to name a SaaS app that hasn't added AI than one that has.
‍
Here's the part that gets glossed over: almost none of these companies trained the models doing the work. They're calling frontier models in their supply chain. Your CRM's shiny AI feature is, functionally, your CRM plus a dependency on a model provider you never evaluated, never contracted with, and may not even be able to name.
‍
There's a subset worth calling out: AI-native apps built almost entirely on upstream frontier models for one explicit use case. Cursor, Replit, and Lovable for code development are the obvious examples. These are absolutely AI tools. But the question of which models they're running is not academic, and Cursor demonstrated why.
‍
In March 2026, Cursor launched Composer 2 and positioned it as its own frontier-level coding model. Within a day, a developer poking at Cursor's API found the actual model identifier: a fine-tuned version of Kimi K2.5, an open-weight model from Beijing-based Moonshot AI. Cursor hadn't mentioned it anywhere. The use was licensed and the follow-on training was real, but the disclosure only happened because someone in the community caught it. A co-founder later called the omission a miss.
‍
Set aside how you feel about Chinese open-weight models. The lesson is simpler: one of the most valuable AI startups in the market shipped its flagship product on a foundation its own customers couldn't identify, and the customers found out from a model ID exposed in an API response. If that's true at the top of the market, assume it's true everywhere else in your stack. Model provenance is now a supply chain question, and most vendors aren't volunteering the answer.
‍
MCP servers are the newest source of confusion. There's real overlap with category two, since plenty of apps that added AI features also ship an MCP server. But the two are not the same thing.
‍
An MCP server doesn't make an application an AI tool. It's an interface. It's the plumbing that lets AI agents and chatbots reach into an application's functions and datasets. Your ticketing system exposing an MCP server hasn't become intelligent; it's become reachable. That's a meaningful distinction, because the risk isn't that the app is doing AI things. The risk is that agents you may or may not know about now have a programmatic path into its data. The agents on the other end of that connection are their own inventory problem, and a topic for another post.
‍
Each category demands a different question from a security team:
‍
‍
As Cursor showed, vendors sometimes don't disclose their models until they're caught.
‍
Collapse all three into one "AI apps" bucket and you end up with an inventory that's simultaneously bloated and blind. Bloated because you're counting every SaaS app that shipped a summarize button. Blind because the actual exposure, the models in your supply chain and the agents holding access, never shows up on the list.
‍
So the next time someone asks how many AI apps your organization uses, the honest answer starts with a question back: which kind?
‍
Nudge Security gives you visibility across all three at the Workforce Edge: the AI tools employees sign up for, the AI features hiding inside the SaaS you already use, and the integrations and access grants connecting them. Start a free trial to see what your inventory is missing.