TL;DR: AI browser agents inherit user-level privileges across authenticated SaaS sessions, while indirect prompt injection and runtime blind spots let attackers steer actions inside the browser, according to WitnessAI. Legacy DLP, CASB, firewall, and endpoint controls were built for human-initiated activity, not autonomous decision loops that move data and actions across apps.
At a glance
What this is: AI browser agents inherit user-level privileges across authenticated sessions and create a governance gap because legacy enterprise controls cannot see or steer their runtime actions.
Why it matters: IAM and security teams need to treat browser-based agent activity as delegated identity execution, not just automation, because control boundaries shift from the app layer to the decision loop.
Context
AI browser agents are software systems that act inside a live browser session on behalf of a user. The governance problem is that they inherit authenticated access, then make their own runtime decisions across SaaS apps, internal tools, and cloud services without the visibility assumptions that human-centric IAM controls rely on.
That mismatch matters because the browser becomes a delegated identity execution environment rather than a simple access channel. When an agent can read, synthesize, and act across tabs and applications, the enterprise is no longer supervising a user session in the usual sense, and existing control planes often lose sight of what the actor is doing.
WitnessAI frames the issue as a browser runtime gap in enterprise IAM, not as a narrow browser security bug. The article’s core argument is that governance has to move closer to agent decision time if organisations want to use these systems safely.
Key questions
Q: What breaks when AI browser agents inherit user sessions without runtime controls?
A: The break is that delegated authority becomes broader than any static review process can safely govern. Once the agent can see and act across authenticated SaaS sessions, access decisions happen inside the loop, not before it. That makes post-hoc monitoring insufficient and forces teams to control what the agent can do at runtime, not just what it was allowed to open.
Q: What breaks when indirect prompt injection reaches a browser agent?
A: The trust boundary breaks first. Security teams often assume web content is passive input, but an agentic browser may treat it as operational instruction. Once that happens, untrusted content can drive privileged actions inside enterprise systems, turning a normal page view into an access and data-governance issue.
Q: How can security teams tell whether agentic browser governance is actually working?
A: Look for attributable audit trails, approved access scopes, visible policy enforcement on consequential actions, and discovery of unmanaged installs. If you can only describe a policy but cannot prove which sessions were constrained, the governance model is not operating as intended.
Q: How should security teams handle AI agents that need to log into SaaS applications?
A: Use delegated authorization rather than cloned human sessions. Give the agent a separate identity grant with explicit scopes, short-lived tokens, and revocation. That preserves auditability and lets IAM and PAM teams control what the agent can do without inheriting the user’s full browser session or password material.
Technical breakdown
How AI browser agents turn browser sessions into delegated identity
AI browser agents operate through iterative model calls that inspect the current screen, decide the next step, and then use browser-level tools such as mouse, keyboard, file, or navigation actions. Because they act inside an authenticated session, they inherit whatever cookies, tokens, and access rights are already present. That means the browser runtime becomes the control point, not just the user interface. The technical distinction is important: the agent is not merely automating clicks, it is interpreting context and selecting actions dynamically across multiple applications in one chained workflow.
Practical implication: treat browser sessions as delegated execution environments and scope agent access to the narrowest identity context possible.
Why indirect prompt injection defeats conventional browser security
Indirect prompt injection works by placing malicious instructions in content the agent will later process, such as a web page, document, or email. The agent cannot reliably separate trusted instructions from untrusted text when both arrive as natural language. Invisible Unicode, hidden text, and multimodal payloads widen the attack surface because the content can be unreadable to humans but still actionable to the model. The result is a control failure at the point where the agent converts content into intent, which is why pre-execution and response-time protections matter more than post-event detection alone.
Practical implication: inspect and constrain what enters the agent’s context before it can be turned into an action.
Why legacy DLP, CASB, and endpoint tools miss agent behaviour
DLP, CASB, firewalls, and endpoint tools were built to observe traffic, files, or user activity at layers above or below the agent’s actual decision loop. They can see some outcomes, but not the internal sequence where the agent synthesises data across tabs, generates a command, and executes it with existing authentication. Enterprise browsers also assume the threat is code running inside a page, not an autonomous system operating above the page and moving information between contexts. That is why browser-native safeguards alone do not close the gap.
Practical implication: add runtime policy enforcement at the session layer instead of relying on perimeter or endpoint visibility alone.
Breaches seen in the wild
- CoPhish OAuth phishing via Copilot Studio: Datadog showed Copilot Studio agents on a Microsoft domain can front OAuth consent phishing and forward stolen tokens; no victims reported.
- SalesBleed Salesforce Agentforce 2026: Three fixed Agentforce flaws let poisoned web leads make AI agents leak CRM data with zero clicks and send phishing under the agent's identity.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
AI browser agents create a delegated identity problem, not just a browser problem. Once an agent inherits a user's authenticated session, the relevant security question becomes how authority is bounded during runtime rather than how access was granted initially. That shifts governance from static entitlement review to active execution control, which is a different control model entirely. Practitioners should stop treating browser agents as enhanced automation and start treating them as identity-bearing execution systems.
Indirect prompt injection is the most important trust-break in browser-agent design. The attack works because the agent consumes untrusted content as if it were task context, then turns that content into action using the user’s access. This collapses the assumption that natural-language inputs can be safely separated into instructions and data once they enter the agent loop. The practical implication is that content provenance and action provenance must be governed together.
Legacy enterprise controls miss the governing layer because they were built for human-paced activity. CASB, DLP, firewalls, and endpoint tooling are useful only when the actor’s intent is externally visible before action. AI browser agents compress observation, decision, and execution into one loop, so the old boundary between monitoring and control no longer holds. That means browser-runtime governance becomes part of enterprise IAM, not an adjacent security concern.
Browser-agent security is becoming the front edge of a broader agentic governance model. The same control gap will appear wherever an autonomous system acts through authenticated enterprise surfaces, including copilots, MCP-connected tools, and other agentic workflows. The named concept here is browser runtime governance gap: a control failure where runtime actions outrun the visibility and policy model that IAM inherited from human users. Practitioners should design for that gap as a category issue, not a point product issue.
Human attribution must become a first-class control for agent actions. If an enterprise cannot tie prompts, tool invocations, and resulting actions back to the initiating human, incident response and accountability both degrade. This is especially important where agents cross SaaS boundaries using pre-existing sessions and leave little evidence inside any single application. The governance requirement is to preserve traceability across the full agent loop.
From our research library:
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security, according to the 2026 Infrastructure Identity Survey.
- 53% of security leaders expect AI to run major portions of their infrastructure autonomously within the next three years, according to the 2026 Infrastructure Identity Survey.
- Read next: Agentic AI Identity Guide
What this signals
Browser runtime governance gap: AI browser agents expose a control layer that most IAM programmes have never had to manage, because the agent decides and acts inside the same authenticated session. That shifts the security boundary from application access to action governance, and static entitlements alone no longer describe actual risk.
The programme implication is that teams need a traceable policy layer for delegated sessions, especially where agents can cross SaaS boundaries and combine data from multiple contexts. Without that, the organisation may know which apps were reachable but still not know what the agent was authorised to do inside them.
For practitioners
- Define browser-agent authority boundaries Map which SaaS sessions, repositories, and internal tools an AI browser agent may touch, then restrict it to the smallest delegated identity context that still completes the task.
- Block untrusted content before agent execution Add pre-execution inspection for documents, pages, and emails that may carry indirect prompt injection or hidden instructions, and prevent those inputs from reaching the agent context unchanged.
- Separate human and agent decision paths Require explicit policy checks for high-risk actions such as data movement, account changes, or external sharing, so the agent cannot chain those steps without review.
- Build immutable agent audit trails Capture prompts, responses, tool invocations, and resulting actions in a record that lets investigators reconstruct what the agent did and which human initiated it.
Key takeaways
- AI browser agents inherit broad delegated access across authenticated sessions, which makes the browser runtime a governance boundary rather than a simple access channel.
- Indirect prompt injection is the central attack pattern because malicious content can become executable intent inside the agent loop.
- Enterprises need runtime policy, content provenance, and immutable action tracing to keep browser agents inside governable limits.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | Browser agents inherit user sessions and exercise delegated privilege inside the runtime. |
| ASI02 — Tool Misuse | The article centres on agents choosing and chaining browser tools against enterprise systems. | |
| Recommendation — Restrict agent authority so runtime actions cannot exceed the delegated identity boundary. Constrain tool access and block high-risk tool chains before execution begins. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | AI browser agents operate through authenticated sessions that the runtime cannot adequately govern. |
| NHI-10 — Human Use of NHI | The article shows a user delegating human authority to a non-human browser agent. | |
| Recommendation — Treat session inheritance as a governance boundary and validate every delegated authentication path. Track which human initiated each agent action and preserve that linkage in audit records. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The core problem is ungoverned runtime authorization across SaaS sessions. |
| Recommendation — Review whether delegated entitlements still match actual agent actions at runtime. | ||
Key terms
- AI Browser Agent: An AI browser agent is software that performs multi-step tasks inside a logged-in browser session by reading screen context and choosing actions at runtime. It differs from scripted automation because the sequence is not fixed in advance, which makes governance depend on delegated access, session visibility, and action attribution.
- Indirect Prompt Injection: Indirect prompt injection is an attack where malicious instructions are hidden inside content that an AI system reads later. The model may treat that content as context rather than as hostile input, which can influence tool use, data access, or workflow actions if controls are weak.
- Browser Runtime: The live execution environment inside a web browser where scripts, tags, and application code interact with data and user actions. It is the place where client-side privileges are exercised, which makes it a critical enforcement boundary for privacy and identity governance.
- Delegated Identity: Delegated identity is when one actor acts on behalf of another with explicit permission and bounded authority. In AI-assisted commerce, it requires clear consent, limited scope, and traceable records so the retailer can distinguish authorised delegation from unauthorised automation.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org