An internal inference server doesn't stop an employee from pasting a client contract into a public chat app. The gap isn't the infrastructure — it's the doorway from any one person's actual work to it.
of AI users bring their own AI tools to work — Microsoft & LinkedIn's 2024 Work Trend Index calls this BYOAI.
of employees using unapproved AI tools admit to feeding them sensitive data — customer records, employee data, internal documents.
added to the average breach cost when shadow AI is a factor — shadow AI played a role in 1 in 5 breaches, per IBM's research.
Plenty of companies already run an internal inference endpoint — a token farm behind gpustack, Ollama, or an OpenAI-compatible gateway, bought precisely so employee AI use stays on infrastructure the company controls. And employees still reach for the public chat app in another tab.
Not because the internal server is worse. Because nobody individually feels it. A shared endpoint is infrastructure, not a tool on anyone's desktop — someone still has to wire it into their actual folder of documents, their actual recurring task, before it's faster than the tab they already have open. Most employees never get that wiring done, so the sanctioned infrastructure sits idle while the same work happens somewhere it can't be governed.
That's the infrastructure-utilization gap: the distance between an inference endpoint existing and any one person's real work actually reaching it. Shadow AI is what fills that distance by default — not because people are careless, but because nothing else was standing there first.
Filer gives every folder its own AI agent, running locally, that talks to whatever inference endpoint is already configured — Local AI, a Frontier AI API key, or the company's own gpustack /Ollama/OpenAI-compatible server. The security boundary is the one already visible in File Explorer: the agent only sees the folder it's pointed at, the same boundary an employee already reasons about every day.
No new subscription for the employee to justify, no data leaving a boundary the company doesn't already control, and no separate workspace to learn — it's the same folder they already work in, now with an agent that watches it, searches it, and acts in it. The sanctioned infrastructure stops being something an employee has to seek out, and becomes the thing already running where their files already are.
Every one of these already has an internal inference endpoint available — what's missing is a doorway from the specific person's folder to it: