By NHI Mgmt Group Editorial TeamBased on Netwrix: “Browser Agents: What are their security risks?” (March 30, 2026)

TL;DR: Browser agents can inherit user permissions, execute actions in live sessions, and become a shadow AI risk when prompt injection or weak approval boundaries let them act beyond intended scope, according to Netwrix. The real issue is not the browser alone but the governance gap between delegated human access and machine-driven execution.


At a glance

What this is: This article explains how browser agents can become shadow AI when they inherit user permissions and act inside live sessions without tight approval boundaries.

Why it matters: It matters because IAM and security teams need to govern delegated browser execution as a distinct access pattern, not just another extension of human authentication or standard automation.


Context

Browser agents are software that can act inside a browser session on a user's behalf, which makes them different from ordinary automation scripts. The identity question is not whether the browser is secure by itself, but whether the delegated execution path is governed as a non-human identity with real constraints on what it can see, do, and approve.

The risk emerges when those agents inherit existing user permissions and operate in live sessions where prompt injection or weak guardrails can redirect them. That creates a shadow AI problem for identity teams because the organisation may approve the human account while failing to govern the machine-driven actor now using it.


Key questions

Q: What breaks when a browser agent inherits user permissions without separate governance?

A: The main failure is that the approved human account and the actual executor are no longer the same subject. That makes access reviews, approvals, and audit trails misleading because they describe the user, not the delegated runtime actor. The result is a control gap where machine-driven actions can occur inside legitimate sessions without a separate identity boundary.

Q: Why do shadow AI tools create risk for IAM teams?

A: Shadow AI complicates IAM because the real subject is often not just the employee, but the AI service, token, or connector acting on the employee's behalf. That expands the identity surface without formal provisioning, certification, or offboarding, which means access governance becomes incomplete even when human login controls are strong.

Q: What controls should organisations put in place before approving browser agent use?

A: Require a named owner, a defined business case, least-privilege session scope, distinct logging for agent actions, and a clear kill switch. If the agent can make sensitive changes, add step-up approval and block it from operating on untrusted content by default.

Q: How should teams evaluate browser agents versus normal automation?

A: Teams should ask whether the system only follows predefined steps or whether it can interpret live content and choose actions at runtime. If it can make those decisions inside a user session, it behaves more like a delegated non-human actor than fixed automation. That distinction determines whether IAM, AI governance, and session controls must all apply.


Technical breakdown

How browser session delegation changes the identity model

Browser agents often operate inside the same authenticated context as the user, which means they inherit the user's entitlements rather than receiving a separately governed machine identity. That creates an ambiguous control plane: the human account is approved, but the actions are increasingly machine-driven. If the agent can read the page, click controls, and submit transactions in-session, the organisation is treating delegated execution as if it were ordinary user activity, even when the action path is effectively non-human.

Practical implication: Treat browser-agent execution as a distinct identity surface and separate it from the user account that launched it.

Why prompt injection matters for browser agents

Prompt injection is malicious or misleading content that influences an agent's instructions or decision path. In a browser-agent context, the agent may process page content, hidden text, or downloaded instructions as if they were trustworthy cues, which can steer the agent toward unsafe actions. The problem is not only content filtering. It is that the agent may combine untrusted inputs with live permissions and then carry out a command the human never intended.

Practical implication: Constrain what browser agents can interpret as instruction and restrict the actions they can execute from untrusted pages.

Shadow AI appears when approval does not match execution

Shadow AI is not just undiscovered software. In this case, it is an unmanaged decision layer embedded in a browser workflow that can act with human permissions but outside normal governance review. The control failure happens when approvals are granted for the account or application but not for the actual tasks the agent performs. That breaks the assumption that access reviews capture the real actor, because the visible user is no longer the only decision-maker in the session.

Practical implication: Align approvals, logging, and review processes to the actions the browser agent can take, not only to the account it uses.


Threat narrative

Attacker objective: The attacker objective is to manipulate a delegated browser agent into carrying out unsafe actions using legitimate user permissions.

  1. Entry occurs when a browser agent is allowed into a live authenticated session under the user's existing permissions.
  2. Scope escalation follows when untrusted page content or injected instructions redirect the agent to act beyond the human's intended task.
  3. Impact occurs when the agent performs sensitive browser actions, exposing data or triggering transactions that the user did not explicitly authorise.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Browser agents expose an identity delegation gap, not just a browser security problem: The core issue is that approval is often granted to the human account while execution is carried out by a machine-driven actor inside the same session. That breaks the assumption that the authenticated user is the only subject making decisions. Security programmes should therefore treat browser agents as non-human identities with their own governance boundary, not as a simple feature of the browser.

Shadow AI is the correct governance lens for unmanaged browser agents: If a browser agent can initiate actions, interpret instructions, and operate outside centrally reviewed workflows, it is no longer just automation. It becomes a shadow AI actor whose behaviour may be invisible to access reviews and approval chains. The practical implication is that discovery, inventory, and policy enforcement must extend to browser-based agent execution, not only to sanctioned AI tools.

Prompt injection turns page content into an attack surface for delegated identity: The article points to a failure mode where untrusted content can steer agent behaviour while the agent still holds valid user permissions. That means the security boundary is not only authentication, but also instruction integrity and action containment. For practitioners, the important shift is to govern what the agent may infer and what it may do from that inference, because the browser becomes a control channel.

Access review assumptions collapse when the actor inside the session is not stable: Traditional review processes assume the reviewed identity is the same entity that will later perform the work. Browser agents break that assumption when they inherit permissions but make their own runtime decisions. The governance conclusion is straightforward: teams need controls for delegated execution, not just for the account that authorises it.

Shadow AI discovery must include browser-native execution paths: Unmanaged browser agents can hide in plain sight because they may appear to be normal user activity. That makes browser telemetry, session policy, and agent inventory part of the same governance problem. Practitioners should treat this as a cross-domain issue spanning IAM, AI governance, and browser-side control design.

What this signals

Shadow AI discovery needs to extend into browser-native execution: browser agents may look like ordinary user activity while actually performing delegated machine actions inside authenticated sessions. That means discovery is not limited to standalone AI tools. Security teams need to surface browser extensions, assistants, and agentic workflows wherever they can act on behalf of a user.

The governance challenge is less about whether the browser is trusted and more about whether the delegated actor is constrained. If the organisation can approve the human account but not the action set, it has a blind spot that traditional access reviews will miss. This is where session policy, instruction integrity, and execution logging become part of identity governance.


For practitioners

  • Define browser-agent approval boundaries Specify which browser tasks a delegated agent may perform, which data it may access, and which actions always require human confirmation.
  • Separate human and agent audit trails Log the initiating user, the browser agent's actions, and any instruction changes so reviews can distinguish human intent from machine execution.
  • Block untrusted instruction sources Restrict browser agents from treating page text, hidden fields, or downloaded content as executable guidance unless the content is explicitly trusted.
  • Inventory browser-based AI use cases Discover where browser assistants and agentic extensions are already operating so shadow AI does not enter production workflows unnoticed.

Key takeaways

  • Browser agents blur the line between human access and machine execution, which creates a governance gap if the delegated actor is not controlled separately.
  • Prompt injection and inherited permissions make browser agents a shadow AI problem as much as a browser-security problem.
  • The practical fix is to govern approvals, logging, and action boundaries for the browser agent itself, not only for the user account behind it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI02 — Tool MisuseBrowser agents can be steered into unsafe actions through injected instructions.
ASI03 — Identity & Privilege AbuseThe article centers on delegated execution using inherited user permissions.
Recommendation — Constrain browser agents so untrusted content cannot trigger unsafe tool use. Separate delegated browser execution from the human account that launched it.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationBrowser agents operate inside authenticated sessions and inherit access boundaries.
NHI-10 — Human Use of NHIThe browser agent acts on behalf of a human while extending that user's permissions.
Recommendation — Govern browser-agent access as a distinct non-human identity surface. Restrict human-to-agent delegation so users cannot silently extend their access through browsers.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe issue is whether the right actions are authorised for the delegated actor.
Recommendation — Tie authorisation to delegated browser actions, not just to the user session.

Key terms

  • Browser Agent: A browser agent is software that can navigate websites and complete browser-based tasks on behalf of a person or system. In identity terms, it is an execution identity that may inherit access, session state, and trust boundaries that were previously assumed to belong only to humans.
  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Prompt Injection (Agentic): An attack where malicious instructions are embedded in content that an AI agent reads, causing the agent to execute unintended actions using its own legitimate credentials. A primary vector for agent goal hijacking and identity abuse.
  • Delegated Execution: Delegated execution is when software is allowed to perform actions on behalf of a user, process, or business function. In NHI governance, the risk is that the delegated actor may chain actions beyond the original intent, so controls must focus on scope, approval, and revocation.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org