TL;DR: AI attacks now cut both ways, with attackers using AI to scale phishing and identity abuse while AI platforms themselves become part of the attack surface, according to Push Security. The practical problem for identity teams is not model performance but browser-level visibility, control, and guardrails across human, NHI, and shadow AI access paths.
At a glance
What this is: This is a Push Security analysis of how AI attacks are reshaping the browser as an identity security boundary, with the key finding that visibility and control need to move closer to runtime access paths.
Why it matters: It matters because IAM, PAM, and NHI programmes increasingly fail where browser sessions, unmanaged identities, and AI usage converge outside traditional control planes.
By the numbers:
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes, and as quickly as 9 minutes in some cases.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, with 46% confirmed and 26% suspected.
👉 Read Push Security's analysis of AI attacks in the browser
Context
AI attacks are no longer limited to model misuse or prompt injection. The larger identity security problem is that attackers are using AI to scale phishing, credential abuse, and browser-based tradecraft, while organisations are also placing AI apps and agents into the same access paths as employees and service accounts.
That makes the browser a control point, not just an endpoint. If security teams cannot see or govern AI usage, shadow SaaS, unmanaged identities, and session-level behaviour in the browser, then IAM and NHI policy can exist on paper while the real access decision happens elsewhere.
Key questions
Q: How should security teams govern employee use of public AI tools in the browser?
A: They should treat browser AI use as an identity and data-control problem, not just an acceptable-use issue. The team needs visibility into what was pasted, which account was active, whether the content was sensitive, and whether policy enforcement occurred before the data left the organisation. Controls that only inspect network events will miss the real decision point.
Q: Why do AI browsers create new identity and access risk?
A: Because they turn the browser from a passive display layer into a system that can interpret content and execute actions. That collapses the distance between authentication, privilege use, and data movement. Existing IAM models assume a user or workload is behind the action. AI browsers weaken that assumption.
Q: What do security teams get wrong about shadow AI governance?
A: They often treat shadow AI as a banned-app problem when it is usually an identity and accountability problem. Employees can use approved tools, personal accounts, or embedded AI features in ways that bypass policy even when the app itself is not explicitly blocked. Governance has to follow the interaction, not just the endpoint.
Q: When should organisations block an AI app instead of approving it?
A: Block an AI app when its access scope, data handling, or downstream integrations exceed the organisation's risk tolerance and cannot be constrained with policy. If the app touches sensitive systems, lacks credible security posture, or can widen access dynamically, approval should wait until controls can be enforced at runtime.
Technical breakdown
Browser-level control is now part of identity security
The browser has become the execution layer where authentication, session continuation, SaaS access, and AI usage converge. That matters because many identity controls stop at the IdP or CASB boundary, while the actual abuse happens after login, inside the session, and across unmanaged devices or shadow SaaS. Browser telemetry can reveal credential use, token abuse, and suspicious in-session behaviour that traditional identity tools never see. In this model, the browser is not a user interface detail. It is where identity governance becomes operational.
Practical implication: build browser visibility into your identity control stack before relying on downstream detection alone.
AI attacks work in both directions
AI increases attack scale in two distinct ways. First, attackers use AI to accelerate phishing, lure generation, and identity theft. Second, AI platforms themselves become targets, because they can expose credentials, sessions, data, or delegated access to tools and content. Push Security’s framing is useful because it separates attacker use of AI from AI as an attack surface. That distinction matters for governance, since the response differs depending on whether the risk sits in the user workflow, the application, or the identity path connecting them.
Practical implication: classify each AI-related risk by whether AI is the attacker, the target, or the access path.
Shadow AI creates unmanaged identity and data paths
Shadow AI is the same governance problem as shadow SaaS, but with faster adoption and weaker oversight. Employees can connect AI tools to corporate data, browser sessions, and browser-stored credentials without formal onboarding, review, or offboarding. That creates a policy gap between approved access and actual usage. The result is not just data leakage. It is identity sprawl, because each unmanaged AI session can become a new access path with its own trust assumptions and persistence.
Practical implication: inventory AI usage from the browser outward, then decide which tools require governance, restriction, or replacement.
Threat narrative
Attacker objective: The attacker wants to turn browser access into scalable identity compromise, then use that access to reach data, SaaS workflows, or AI-driven abuse paths.
- Entry occurs through browser-delivered lures, credential theft, or abused AI workflows that bring the attacker into the session context.
- Escalation follows when stolen credentials, tokens, or delegated SaaS access are reused to move from one account or app to another.
- Impact is delivered through account takeover, data exposure, malware delivery, or misuse of AI and SaaS access paths at session level.
Breaches seen in the wild
- Meta AI Instagram Account Takeover — 20,225 Instagram accounts hijacked via compromised Meta AI support chatbot with overprivileged access.
- Replit AI Tool Database Deletion — Replit vibe coding AI assistant deletes live production database and creates 4,000 fake user records.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Browser visibility is now an identity control requirement, not a telemetry luxury. When authentication, session activity, and AI usage all happen inside the browser, controls that only observe the IdP or endpoint miss the moment abuse becomes real. The governance gap is that identity policy now needs runtime context from the browser to remain enforceable. Practitioners should treat browser telemetry as part of access governance, not as a separate security discipline.
Shadow AI is a non-human identity problem disguised as user behaviour. An unmanaged AI app often carries delegated access, stored tokens, or session continuity that outlives the approval decision that should have governed it. That makes it structurally similar to unmanaged SaaS and other NHIs, even when users believe they are just using a productivity tool. The implication is that AI inventory and NHI inventory are converging faster than most programmes recognise.
Browser-based identity abuse collapses the distance between phishing and privilege. If a credential or token can be captured, replayed, and used inside the same browser session, then traditional perimeter-style detection arrives too late. This is the identity blast radius problem in practice: one session becomes the bridge to many apps, many tokens, and many downstream actions. Practitioners should stop treating browser abuse as an edge case and start treating it as the normal path of compromise.
Machine access and human access are now governed through the same session layer. AI apps, service accounts, and human users increasingly rely on the browser to reach cloud services, collaboration tools, and data. That convergence means access policy has to account for actor type, session continuity, and unmanaged devices at the same time. The practical conclusion is that IAM, NHI governance, and browser security need a shared operating model.
From our research:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, with 46% confirmed and 26% suspected, according to The 2024 ESG Report: Managing Non-Human Identities.
- Our research also found that enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months.
- For practitioners, the forward pivot is lifecycle governance, as outlined in the NHI Lifecycle Management Guide, because unmanaged access paths rarely fail once.
What this signals
Shadow AI will increasingly be managed as an NHI governance problem. The practical issue is not whether a tool uses AI, but whether it carries delegated access, session continuity, or corporate data outside approved identity controls. Teams that already struggle with shadow SaaS should expect the same discovery and offboarding problems to surface faster in AI workflows, especially where browser-based access is the default.
The next control gap is not detection alone, but governance handoff. Browser telemetry can expose activity, yet security teams still need a clean way to decide when an AI tool is approved, conditional, or prohibited. That makes lifecycle, policy, and browser control converge into one operating model rather than three separate programmes.
For practitioners
- Instrument the browser as an identity control plane Collect browser telemetry for authentication events, session changes, token use, and AI app access so identity teams can see what happens after login. Tie that data back into IAM and SIEM workflows so suspicious browser activity is not isolated from access governance.
- Inventory shadow AI as part of NHI governance Map which AI tools employees use through the browser, which accounts or tokens they connect, and whether those sessions can access corporate data. Treat unmanaged AI usage as an identity inventory problem, not just an acceptable-use issue.
- Separate managed AI access from unmanaged browser usage Define which AI tools require approved access paths, which can be blocked, and which need conditional controls such as device trust, session binding, or data loss prevention. Apply the same discipline you use for shadow SaaS.
Key takeaways
- AI attacks now operate through the browser as much as through the model, which makes session-level identity control central to defence.
- Shadow AI creates unmanaged access paths that look like user behaviour but behave like NHI sprawl, especially when tokens and delegated sessions are involved.
- Security teams need browser telemetry, identity governance, and lifecycle control in the same operating model if they want to reduce AI-driven account takeover risk.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Browser-delivered AI access paths still depend on non-human identities and delegated credentials. |
| NIST CSF 2.0 | PR.AC-1 | The article centers on controlling access and session behaviour across browser-based identity paths. |
| NIST Zero Trust (SP 800-207) | Browser-mediated AI usage reinforces continuous verification and session-aware trust decisions. | |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is directly challenged by unmanaged browser access and delegated AI workflows. |
| MITRE ATT&CK | TA0006 , Credential Access; TA0008 , Lateral Movement | The threat pattern relies on credential theft, token reuse, and movement across browser-accessible services. |
Map browser-visible identity events to access control outcomes and tighten conditional access rules.
Key terms
- Browser-mediated identity: Browser-mediated identity is access that is established, maintained, or abused through the web session rather than only through a traditional login boundary. It matters because cookies, tokens, and session state can become attack assets, especially when unmanaged devices and SaaS applications are involved.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
What's in the full article
Push Security's full blog post covers the operational detail this post intentionally leaves for the source:
- Specific examples of how browser security controls detect AI-related identity abuse in real sessions
- Threat-research detail on the poisoned tenant technique and how it was used against Push employees
- Practical distinctions between browser visibility, shadow AI discovery, and response workflows
- Examples of how attackers use computer-using agents to automate identity attacks
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org