TL;DR: Browser-based AI visibility is emerging as an identity control problem, not just a usage reporting issue, because workers are now interacting with AI apps, shadow SaaS, and unmanaged identities inside the browser where traditional endpoint and network tools have limited coverage, according to Push Security. The governance gap is that existing IAM, SaaS, and browser controls rarely give teams a complete view of who or what is using AI and with what authority.
At a glance
What this is: This is a browser-security analysis arguing that AI use in the workforce becomes an identity governance issue when activity, access, and data movement happen inside the browser.
Why it matters: It matters because IAM, NHI, and human identity teams need visibility into AI access paths, browser-based session activity, and unmanaged identities before those pathways become routine control blind spots.
By the numbers:
- 118 posts make Push Security’s browser attacks hub a large reference point for tracking identity-based attack techniques.
- The 2024 ESG Report found that 72% of organisations have experienced or suspect a breach of non-human identities.
- Enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months.
👉 Read Push Security's analysis of browser-based AI visibility and identity control
Context
AI use in the workforce is no longer just a procurement or productivity question. Once employees, contractors, or unmanaged devices interact with AI apps through the browser, the security problem becomes one of identity, session control, and data handling in a place where endpoint and network controls often have reduced visibility.
Push Security’s framing reflects a broader shift: browser activity now sits on the path between human users, shadow SaaS, and AI services. That makes browser telemetry and identity governance relevant to both human access programmes and non-human identity oversight, especially when organisations need to distinguish legitimate AI use from unmanaged or shadow use.
For identity teams, the key issue is not whether AI exists in the environment. It is whether the organisation can see who is invoking it, what data is flowing through it, and whether the access path is governed as part of IAM, SaaS security, and lifecycle control.
Key questions
Q: How should security teams govern employee use of public AI tools in the browser?
A: They should treat browser AI use as an identity and data-control problem, not just an acceptable-use issue. The team needs visibility into what was pasted, which account was active, whether the content was sensitive, and whether policy enforcement occurred before the data left the organisation. Controls that only inspect network events will miss the real decision point.
Q: Why do browser-based AI extensions create identity risk for enterprise users?
A: They create identity risk because they can sit inside the authenticated session and see the same bearer tokens the user relies on. That means an apparently harmless productivity add-on can become a credential interception path, especially when it has access to web application runtime state and connected services.
Q: What signals show that AI access is outpacing governance?
A: The clearest signals are broad inherited permissions, large volumes of stale guest access, and inconsistent file classification across teams. If remediation is happening only after AI rollout, the programme is reacting to exposure rather than controlling it.
Q: What should IAM teams do when browser telemetry reveals shadow AI usage?
A: Reconcile the service to an owner, decide whether it belongs in approved access pathways, and ensure offboarding and review rules apply to every linked account and session. If the service cannot be governed, the issue is not visibility alone but an access path that should not remain open.
Technical breakdown
Browser-level AI visibility and control
Browser-based AI controls sit where the user session actually occurs, which is why they matter when AI tools are accessed through web apps rather than managed desktop clients. The browser can expose identity signals, page context, session activity, and copy-paste behaviour that endpoint tools may not observe. In practice, this makes the browser a control point for detecting shadow AI use, unmanaged SaaS access, and risky data movement between sessions and AI services.
Practical implication: treat the browser as an identity enforcement layer when AI usage is mediated through web sessions.
Shadow SaaS and unmanaged identities
Shadow SaaS appears when users adopt cloud services outside approved procurement, identity, or security workflows, and unmanaged identities are the accounts that support that usage without lifecycle oversight. In an AI context, the same pattern applies to browser-accessed AI apps that may never enter central IAM records. The risk is not only unsanctioned access, but also credential sprawl, weak offboarding, and incomplete visibility into who can reach what.
Practical implication: map browser-observed AI services back to IAM ownership, approval status, and offboarding responsibility.
Stolen credentials, tokens, and browser telemetry
Browser attacks increasingly target credentials, tokens, consent flows, and session state rather than only passwords. That matters for AI-enabled workflows because a compromised browser session can expose AI tools, connected SaaS, and downstream data paths without triggering classic perimeter detections. Browser telemetry helps close that gap by surfacing suspicious authentication behaviour and session-level indicators that are otherwise invisible to EDR or network security alone.
Practical implication: add browser telemetry to detection workflows for account takeover and token abuse involving AI services.
Threat narrative
Attacker objective: The attacker wants to move from browser access to identity-controlled SaaS and AI services, then use that position to steal data or broaden account control.
- Entry occurs through browser-mediated interaction with AI apps, shadow SaaS, or consent flows that appear legitimate to the user session.
- Escalation follows when attackers abuse stolen credentials, tokens, or session state to expand access across connected cloud services and AI tools.
- Impact is achieved when the compromised browser session enables data loss, account takeover, or wider exposure of identity-linked SaaS environments.
Breaches seen in the wild
- Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.
- Coupang Signing Key Breach — Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Browser AI visibility is now an IAM problem as much as a browser-security problem. When AI services are used through the browser, the identity layer is where approval, session state, and data movement converge. That means security teams cannot treat AI usage as separate from access governance, because the browser is often the actual control surface. The practical conclusion is that AI governance must sit inside identity operations, not beside them.
Shadow AI is best understood as shadow SaaS with higher identity risk. The article’s browser-centric framing points to a familiar governance failure: if a service is only visible when someone opens a tab, it can also evade lifecycle oversight, recertification, and offboarding. That creates unmanaged identity debt across users, tokens, and connected apps. The conclusion for practitioners is to inventory AI services as part of SaaS and identity governance, not only as application risk.
Browser telemetry creates a missing evidence layer for human and non-human identity programmes. Traditional IAM records show entitlements, but they often miss the session behaviour that reveals misuse, credential replay, or suspicious AI access paths. That gap matters because identity assurance now depends on what happens after authentication as much as on the login itself. The conclusion is that browser-derived evidence should be treated as governance-grade identity telemetry.
Identity blast radius is the right concept for AI use in the browser. Once a user session links AI apps, work apps, and data-bearing services, a single compromised browser context can expand across multiple identity domains. That is not a single app problem, but a chained-access problem. The conclusion is that teams should assess how far one browser session can move before containment becomes difficult.
Access review processes were built to certify stable entitlements, not fast-moving browser sessions. That assumption holds for fixed permissions, but it weakens when AI use is discovered in the browser after the fact or appears and disappears through shadow adoption. The implication is that recertification alone will not reveal live browser-layer AI usage unless it is paired with runtime visibility and session-level control.
From our research:
- The 2024 ESG Report found that 72% of organisations have experienced or suspect a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
- Enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, which shows how quickly unmanaged identity exposure can repeat.
- Browser-visible AI usage should be assessed alongside 52 NHI Breaches Analysis because repeated access-path weakness is a lifecycle problem, not a one-off event.
What this signals
Shadow AI will increasingly be managed as shadow SaaS with identity consequences. That means security teams should expect browser-discovered AI tools to be folded into application governance, access review, and offboarding processes rather than handled as isolated productivity exceptions. The browser is becoming the place where identity policy either reaches the user or fails to.
Identity programmes need browser-derived evidence to prove control effectiveness. A login record alone will not show whether AI tools were used, what was copied, or whether a session crossed from approved software into unmanaged services. Teams that connect browser telemetry to IAM, SaaS, and PAM workflows will have a clearer view of actual risk.
As a practical next step, teams should align browser observability with the NHI Lifecycle Management Guide. That matters because AI services and their linked credentials still need ownership, review, rotation, and offboarding even when they first appear in user browsers. The lifecycle problem does not disappear just because the entry point is a tab.
For practitioners
- Instrument browser visibility for AI services Capture browser-level activity for AI apps, SaaS sessions, and unmanaged access paths so that security teams can see usage that never passes through central approval workflows.
- Classify AI apps in identity governance records Treat browser-discovered AI services as governed applications with owners, access rules, and offboarding responsibility rather than as informal user tools.
- Correlate browser telemetry with account takeover signals Use browser telemetry alongside identity alerts to identify consent abuse, token theft, and suspicious session behaviour that can lead to AI and SaaS compromise.
- Review offboarding for browser-accessed services Make sure leavers, contractors, and third-party users lose access to browser-based AI services and connected SaaS at the same time as other identity assets.
Key takeaways
- Browser-based AI usage turns workforce AI adoption into an identity governance problem because the real control point is the session, not the logo on the app.
- Shadow AI behaves like shadow SaaS with higher risk, because the service can exist outside IAM records while still handling credentials and data.
- Teams that combine browser telemetry, access governance, and lifecycle controls will be better positioned to manage AI exposure without losing visibility.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | Browser-accessed AI and unmanaged identities create the visibility and lifecycle gaps covered by OWASP NHI. |
| NIST CSF 2.0 | PR.AC-4 | Browser-based AI access depends on managing entitlements and access paths continuously. |
| NIST Zero Trust (SP 800-207) | The article centers on continuous verification at the browser session boundary. | |
| NIST SP 800-53 Rev 5 | IA-5 | Session-held credentials and tokens are part of the identity risk described here. |
| MITRE ATT&CK | TA0006 , Credential Access; TA0009 , Collection | Browser-based AI abuse often depends on credential theft and data collection from active sessions. |
Inventory browser-accessed AI services, then tie each one to ownership, lifecycle, and offboarding controls.
Key terms
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Browser telemetry: Browser telemetry is the event data produced by enterprise browser activity, including logins, profile changes, downloads, session starts, and extension or site interactions. In identity governance, it becomes useful when those events are correlated with account state and privilege context rather than treated as generic activity logs.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
What's in the full article
Push Security's full blog post covers the operational detail this post intentionally leaves for the source:
- Browser attack techniques and detection examples that show how AI usage appears in real session telemetry.
- Product-specific browser visibility workflows for investigating AI, shadow SaaS, and unmanaged identity activity.
- Implementation details for turning browser observations into response and governance actions.
- Examples of the exact telemetry patterns Push uses to identify risky browser-based identity behaviour.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org