TL;DR: The real question is not how much AI exists in the workforce, but how much of it is reachable through browser-based identity paths, where stolen credentials, compromised tokens, shadow SaaS, and unmanaged access create control blind spots, according to Push Security. That shifts the programme from awareness and inventory toward browser-level visibility, detection, and guardrails.
At a glance
What this is: This is Push Security’s social engineering and browser-security framing of AI exposure, and its key claim is that AI access risk is now concentrated in browser-mediated identity flows.
Why it matters: It matters because IAM, PAM, and NHI programmes increasingly fail when identity events are happening inside the browser, where token theft, unmanaged identities, and shadow AI are easiest to miss.
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities.
- 17 minutes.
👉 Read Push Security's analysis of browser-based AI identity risk
Context
AI in the workforce becomes an identity problem as soon as people, apps, and machine accounts meet in the browser. Browser sessions now carry the credentials, tokens, invitations, and SaaS links that attackers can abuse without needing a traditional exploit.
Push Security’s framing is that visibility and control must move closer to the browser because that is where account takeover, shadow SaaS, unmanaged identities, and AI app usage collide. For IAM teams, the issue is not AI adoption alone, but where access is granted, observed, and revoked.
This is a governance problem for human identity, NHI, and emerging AI-enabled workflows at the same time. The organisations that still treat browser activity as a user-experience layer are leaving the most actionable identity telemetry outside the control plane.
Key questions
Q: How should security teams handle AI app usage that appears only in browser sessions?
A: Security teams should treat browser-discovered AI usage as a discovery and governance problem, not just an acceptable-use issue. First identify which AI tools are being accessed, then classify whether they are sanctioned, personal, or unmanaged. Finally, connect that inventory to data controls, session monitoring, and access review so the browser does not become an ungoverned entry point.
Q: Why do browser-based attacks bypass many IAM controls?
A: They exploit the point after authentication succeeds. If the attacker steals a session, abuses consent, or rides a trusted extension, the IAM control that only validated the login has already done its job while the real compromise continues elsewhere.
Q: What breaks when organisations rely on awareness training instead of browser controls?
A: Training can reduce risky behavior, but it cannot stop a live credential from being pasted, a token from being replayed, or a session from being hijacked. Without browser enforcement, the attacker still gets a usable identity foothold. That means training is necessary but insufficient when the browser is the attack surface.
Q: How do security teams decide whether to prioritise browser security or IdP hardening?
A: They should not treat it as an either-or choice. IdP hardening protects the front door, but browser security protects the active session where many modern attacks actually succeed. If the organisation sees shadow SaaS, token theft, or AI app sprawl, browser controls should be prioritised alongside IdP policy.
Technical breakdown
Browser-mediated identity paths and stolen token abuse
Modern account takeover rarely requires a full infrastructure breach. Attackers increasingly work through the browser, where session cookies, OAuth grants, SSO tokens, and pasted credentials can be captured or replayed. Browser-based attacks also bypass assumptions that endpoint controls or email security will see the whole flow, because the decisive moment is often a legitimate web session being redirected, mirrored, or coerced into exposing access. For identity teams, the architecture matters: the browser is not just a client, it is an access broker that sits between the user, the IdP, SaaS apps, and many AI tools.
Practical implication: Treat browser telemetry as identity telemetry and connect it to account takeover detection, token revocation, and session containment.
Unmanaged identities and shadow AI in SaaS workflows
Shadow AI is not simply unsanctioned software use. It is undiscovered or unmanaged AI access that appears through browser sessions, personal accounts, third-party prompts, or copied credentials, often outside normal procurement and onboarding flows. The security gap is that AI tools can inherit trust from the user’s browser state without ever being registered as formal services. That creates a governance blind spot across access reviews, data loss prevention, and SaaS approval processes, because the identity subject may be human while the actual data movement happens through an ungoverned AI service.
Practical implication: Map AI app usage to approved identity flows and require discovery of browser-accessed AI services before they reach sensitive data.
Compromised tokens, guardrails, and real-time containment
The article’s core control argument is that browser security can provide live guardrails where awareness training cannot. Detection of pasted credentials, suspicious login flows, unmanaged device use, or risky SaaS access can interrupt the attacker path before a token becomes a durable foothold. In identity terms, this is about shortening the blast radius of credential theft and controlling the session layer where modern attacks actually persist. The browser becomes the enforcement point for high-risk identity behaviors that traditional IAM tools only see after the fact.
Practical implication: Use real-time browser controls to block credential reuse, surface suspicious sessions, and force containment before compromise spreads.
Threat narrative
Attacker objective: The attacker aims to turn a browser interaction into durable identity access that can be reused across SaaS and AI workflows.
- Entry begins in the browser, where a user is lured into a phishing, token theft, or poisoned tenant flow that looks like a normal web interaction.
- Escalation happens when the attacker captures an SSO session, OAuth grant, or other compromised token that extends beyond the initial page visit.
- Impact follows when the attacker reuses that access to move through SaaS apps, AI tools, or shadow identities without triggering conventional perimeter controls.
Breaches seen in the wild
- Salesloft OAuth token breach — hackers stole OAuth tokens to access Salesforce data via Salesloft.
- New York Times breach — New York Times source code and credentials exposed via GitHub.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Browser security is now an identity control plane, not a side control. When credentials, sessions, and SaaS access all converge in the browser, the traditional boundary between endpoint security and IAM stops being useful. That means identity teams have to treat browser events as first-class access signals, not just web activity. The practical conclusion is that control ownership must span IAM, SOC, and browser telemetry.
Shadow AI is a discovery problem before it is a governance problem. Most organisations cannot govern what they have not discovered, and browser-visible AI usage often enters through personal accounts, copied links, or unmanaged sessions. That makes shadow AI structurally similar to shadow SaaS, except the data flow can be faster and harder to see. Practitioners need discovery before policy can mean anything.
Compromised tokens collapse the value of training budgets when enforcement is absent. Awareness can reduce clicks, but it cannot revoke a live token, stop pasted secrets, or block a malicious browser session in real time. The control gap is not user ignorance alone, it is the lack of immediate enforcement at the point of identity interaction. Security teams should therefore align browser controls with account takeover response.
Identity governance has to expand from who can log in to what can be done inside the session. The article points to a broader shift: an identity programme that stops at authentication misses the browser behaviors where modern abuse happens. Access reviews, PAM, and conditional access only work when paired with runtime visibility into sessions, devices, and AI app usage. The practitioner conclusion is to govern the session, not just the login.
From our research:
- The average organisation believes more than 1 in 5 of their non-human identities are insufficiently secured, according to The 2024 ESG Report: Managing Non-Human Identities.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, which shows the issue is already operational rather than theoretical.
- That broader lifecycle exposure is why teams should pair discovery with governance, as shown in NHI Lifecycle Management Guide and the 52 NHI Breaches Analysis.
What this signals
Browser-first identity governance is becoming the practical path to controlling AI sprawl. As AI usage moves into everyday web sessions, teams need one view that spans SSO, SaaS, unmanaged devices, and session telemetry. The organisations that can correlate those signals will be able to distinguish sanctioned use from shadow AI much earlier than teams that only watch the IdP.
More than 1 in 5 non-human identities are already considered insufficiently secured, according to our 2024 ESG research. That figure is a warning that identity programmes still have unresolved visibility gaps, and browser-mediated AI usage only widens them. The next step is not another policy document, but a tighter connection between discovery, containment, and lifecycle governance.
For practitioners, the control question is shifting from login assurance to session assurance. If the browser is where users, tokens, and AI tools converge, then that is also where governance has to prove itself. Teams should expect browser-level controls to become part of the standard operating model for IAM, PAM, and NHI oversight.
For practitioners
- Instrument browser telemetry as an identity signal Feed browser events into account takeover, SaaS risk, and access governance workflows so token abuse and suspicious login paths are visible in real time.
- Build a shadow AI discovery workflow Inventory AI apps that appear through browser sessions, then classify whether they are sanctioned, unmanaged, or personal-use services that touch corporate data.
- Tie token misuse to immediate containment Automate session revocation, token invalidation, and step-up review when a browser session shows credential reuse, suspicious redirection, or unmanaged device access.
- Extend access reviews beyond the IdP Review which SaaS and AI services can be reached through approved browser sessions, and close the gap between authenticated users and ungoverned downstream tools.
Key takeaways
- Browser activity now carries identity risk for both human users and machine-accessed AI workflows, so the control surface has moved closer to the session.
- Token theft, shadow SaaS, and unmanaged AI usage are difficult to govern with awareness alone because the decisive abuse happens after authentication.
- Practitioners should align browser telemetry, session containment, and lifecycle governance so identity controls can act before access becomes durable.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Browser-captured tokens and unmanaged AI access map to NHI visibility and credential risk. |
| NIST CSF 2.0 | PR.AC-1 | Browser-mediated access requires stronger identity and access management visibility. |
| NIST Zero Trust (SP 800-207) | The post fits zero trust because trust must be verified at the session layer. | |
| NIST SP 800-53 Rev 5 | AC-2 | Account management and revocation are central to browser-led identity abuse. |
| MITRE ATT&CK | TA0006 , Credential Access; TA0009 , Collection | The article describes credential and token abuse through browser-based collection paths. |
Inventory browser-accessed identities and reduce exposed credentials with lifecycle controls.
Key terms
- Browser-mediated identity: Browser-mediated identity is access that is established, maintained, or abused through the web session rather than only through a traditional login boundary. It matters because cookies, tokens, and session state can become attack assets, especially when unmanaged devices and SaaS applications are involved.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Session Assurance: Session assurance is the practice of continuously evaluating whether an active digital session still matches the expected identity, device, and behaviour profile. It goes beyond login verification and asks whether the current interaction still deserves to remain trusted before a payment or privilege change is completed.
- Unmanaged identity: Any identity that can authenticate or act without being fully controlled by the organisation’s standard identity stack. That includes service accounts, API keys, tokens, and some AI agents. The risk is not just visibility loss. It is loss of ownership, lifecycle control, and reliable revocation.
What's in the full article
Push Security's full post covers the operational detail this post intentionally leaves for the source:
- Specific browser telemetry patterns that expose compromised credentials and tokens during real sessions
- Examples of how browser-based controls can interrupt account takeover and data loss paths
- Practical distinctions between sanctioned AI use, shadow AI, and unmanaged SaaS access
- Implementation detail on how browser guardrails fit into detection and response workflows
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org