TL;DR: Cyber Security Tribe’s 2026 Annual State of the Industry Report, based on 455 cybersecurity practitioners, finds AI governance exists in many organisations but enforcement is inconsistent, autonomous AI systems are already in production, and browser-layer visibility remains a major blind spot, according to the report. Policy without technical enforcement is not governance when AI tools, data handling, and delegated actions happen inside the browser.
At a glance
What this is: This report argues that enterprise AI risk is now being driven by weak enforcement, browser blind spots, and accelerating agentic adoption.
Why it matters: It matters because IAM, data security, and AI governance teams now need controls that can govern interactions at the point of use, not just document intent.
By the numbers:
- Cyber Security Tribe’s 2026 Annual State of the Industry Report surveyed 455 cybersecurity leaders across technology, healthcare, finance, and manufacturing.
- 70% of organizations have AI security policies in place, while 27% are still actively developing them.
- 73% of organizations have autonomous AI agent systems in use or actively in development as part of their cybersecurity strategy.
- 59% of respondents in parallel Omdia research identify browser-based AI use as the attack vector they are least able to monitor.
👉 Read Island’s analysis of the Cyber Security Tribe 2026 State of the Industry Report
Context
AI governance now fails most often at enforcement, not policy design. Organisations may have acceptable-use rules, but if those rules depend on voluntary compliance and cannot be enforced where the work happens, they do not control AI use in any meaningful way. That creates a browser-level governance gap that also affects IAM, data handling, and delegated access patterns across enterprise workflows.
The article’s broader point is that browser activity has become the control plane for shadow AI, sanctioned AI, and agentic automation alike. For identity and security teams, the real issue is whether policy can be converted into technical control at the point of interaction, especially when existing network, endpoint, and perimeter tools cannot reliably observe what users and agents are doing inside live sessions.
Key questions
Q: How should security teams choose between browser-based and network-level AI governance?
A: Security teams should choose based on where AI activity actually happens. Browser-based controls fit managed, browser-first workforces. Network-level governance is better when users rely on native apps, unmanaged devices, or agent workflows that bypass the browser. The decision should follow traffic paths, not vendor feature lists.
Q: Why do agentic AI systems complicate existing IAM and PAM controls?
A: They complicate them because IAM and PAM were built around stable identities, human-paced approvals, and entitlements that are reviewed after use. Agentic systems compress decision-making into runtime, which means access can be consumed, combined, and discarded before a review cycle ever sees it. That makes static privilege models incomplete for autonomous execution.
Q: What breaks when security tooling only sees the browser?
A: Authorisation gaps, hidden endpoints, and machine-to-machine access paths go untested. A browser view can prove that a page loads while missing the endpoint that actually moves data or triggers privileged actions. That creates false confidence and leaves backend logic, token scope, and service access unchecked.
Q: Who is accountable when an AI browser exposes sensitive data or makes a bad decision?
A: The organisation remains accountable for the access path it allowed. Security, IAM, and data-governance teams should jointly define approval boundaries, logging requirements, and content restrictions before deployment. If the browser can act across regulated systems, then its governance must be explicit before use, not after failure.
Technical breakdown
Why browser-layer control matters for AI governance
Most enterprise AI use now happens in the browser, where prompts, file uploads, copy-paste actions, and credential use all occur in-session. That matters because network controls see traffic, not intent, and endpoint tools often miss the exact interaction that creates risk. A browser-native control layer can observe the user action itself, apply policy in real time, and create an audit trail for governance and discovery. Without that layer, organisations are left inferring AI behaviour after the fact from logs that do not capture the decision point.
Practical implication: teams need controls that can govern browser interactions in real time, not just perimeter rules and policy documents.
How agentic AI changes the identity and access model
Agentic AI systems are different from ordinary automation because they can select actions, tools, and timing within a live workflow. That makes them closer to identity-bearing systems than static scripts, since they may interact with SaaS apps, sensitive data, and business processes under delegated authority. Traditional IAM assumes a user or service account has a stable lifecycle and clear approval path. Agentic systems can compress those assumptions, especially when they operate across unmanaged devices or shared browser sessions. Governance now has to account for how an AI system is authorised, what it can reach, and how its activity is bounded.
Practical implication: assign explicit identity and access boundaries to agentic workflows before they are allowed to act on enterprise data.
Why the browser is the least visible security layer
The browser has become the convergence point for SaaS, AI tools, identity sessions, and data movement, but it sits below the visibility of many existing control stacks. SASE may inspect traffic, and EDR may watch the endpoint, yet neither reliably sees local copy, paste, upload, or prompt submission events inside a session. That creates a presentation-layer blind spot where sanctioned and shadow AI can behave identically from the outside. The result is not just weak detection. It is weak governance, because organisations cannot consistently prove which tools were used, what data moved, or which policy was applied.
Practical implication: extend monitoring to the presentation layer if you need defensible evidence of AI use and data handling.
NHI Mgmt Group analysis
Policy-only AI governance is a control illusion. When organisations rely on acceptable-use language without an enforcement layer, they are describing intent rather than governing behaviour. The report shows that compliance depends on employee judgement in the exact place where convenience defeats policy. For IAM and security teams, this is a governance failure because the control objective is not written approval, it is enforced boundary control.
Browser governance gap: is the specific failure mode this report exposes. The browser is where AI tools, data, and delegated access converge, yet most existing controls were built to observe around it, not inside it. That leaves a gap between identity policy and actual data movement. NIST Cybersecurity Framework 2.0 and Zero Trust thinking both point toward continuous verification, but practitioners still need technical enforcement where the session occurs.
Agentic AI is becoming an identity problem before it is a tooling problem. Once AI systems can choose actions and interact with enterprise services, they begin to behave like identities with operational scope, not just features inside applications. That shifts the governance question from whether AI is allowed to what authority it has, how that authority is constrained, and who is accountable for misuse. For practitioners, this means agent governance must be folded into IAM and access review models rather than treated as a separate innovation track.
Security budgets are already revealing the architectural winners. The reported emphasis on IAM, Zero Trust, and risk controls shows that organisations are prioritising governance layers that can follow activity across contexts. That is consistent with a market shift away from isolated detection tools toward controls that can enforce policy at the moment of action. For practitioners, the signal is clear: the next control investment should reduce blind spots, not just add another dashboard.
Shadow AI is now a data-governance and identity-governance issue at the same time. When employees can submit company data to unsanctioned tools from within a browser, the risk spans identity, access, and data handling in one interaction. That is why the most useful response is not simple blocking, but policy enforcement tied to context, session, and data sensitivity. Practitioners should treat AI use as governed work activity, not informal experimentation.
What this signals
The operational signal for practitioners is that AI governance will increasingly be judged by enforcement quality, not policy volume. Controls that cannot observe and act inside the browser will fail to produce defensible evidence for access, data movement, or sanctioned tool use, which makes browser-layer control a prerequisite for mature governance.
Presentation-layer governance: the next control boundary is the browser, because that is where AI, identity sessions, and sensitive data now intersect. Teams that can connect browser telemetry to identity context and data sensitivity will be better positioned to support audit, discovery, and incident response.
For identity programmes, the practical shift is toward treating AI interactions as governed access events. That means aligning IAM, DLP, and audit logging so sanctioned and shadow AI can be distinguished consistently across managed devices, BYOD, and third-party endpoints.
For practitioners
- Enforce AI policy at the session level Move from written acceptable-use rules to technical controls that can approve, block, or log AI interactions inside the browser session where prompts and uploads actually occur.
- Classify agentic systems as access-bearing entities Define which AI systems can act on behalf of users, what tools they can call, and which datasets they can touch, then require ownership and review for each delegated workflow.
- Close browser visibility gaps Correlate browser activity with identity, endpoint, and SaaS logs so copy, paste, file transfer, and prompt submission events can be investigated as part of one access chain.
- Prioritise IAM and Zero Trust controls over point tools Use the budget signal in the report to justify controls that reduce cross-layer blind spots, including policies that work across managed devices, BYOD, and third-party machines.
Key takeaways
- AI policy without in-session enforcement is guidance, not governance, because users can still route around it in the browser.
- The report’s strongest signal is architectural: browser visibility has become a prerequisite for governing AI, identity sessions, and data movement together.
- Practitioners should treat agentic AI and shadow AI as access-bearing behaviours that need explicit boundaries, logging, and ownership.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST AI RMF | GOVERN | The article is about AI governance and accountability gaps. |
| NIST CSF 2.0 | PR.AC-4 | Browser-session enforcement and access boundaries align with identity and access control. |
| NIST Zero Trust (SP 800-207) | The article reflects continuous verification across sessions and devices. | |
| OWASP Agentic AI Top 10 | Agentic AI use introduces tool and delegation risks. |
Assign ownership for AI use, enforcement, and oversight under GOVERN before expanding agentic deployment.
Key terms
- Browser Governance: The policy and control layer that manages how credentials, sessions, extensions, downloads, and authentication challenges behave inside the browser. It turns the browser from an unmanaged endpoint into part of the identity boundary, which is increasingly necessary for SaaS and privileged web access.
- Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions — including calling APIs, writing code, and orchestrating other agents — with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Action Layer: The action layer is the point where an identity moves from asking for access to doing something with that access. For AI agents, this layer matters because tool use can happen faster than human review, and the meaningful risk appears when actions are chained across systems.
What's in the full report
Island's full article covers the operational detail this post intentionally leaves for the source:
- How the browser-native control model enforces AI policy at the point of interaction across managed and unmanaged devices
- The report’s detailed breakdown of how security leaders are prioritising Zero Trust, IAM, and risk controls in 2026
- Specific examples of browser-layer activity that network and endpoint tools miss, including copy, paste, uploads, and prompts
- The article’s discussion of how organisations are handling AI governance, visibility, and auditability under budget pressure
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners translate identity controls into durable operational practice across modern security programmes.
Published by the NHIMG editorial team on August 14, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org