By NHI Mgmt Group Editorial TeamDomain: Agentic AI & NHIsSource: UnixiPublished August 10, 2026

TL;DR: Browser-based AI agents are widening an existing identity gap by acting inside unmanaged applications, where federation covers only 20 to 50 percent of enterprise apps according to Unixi. The real problem is delegated execution without task-level authority, attribution, or auditability, which makes browser-level governance essential.


At a glance

What this is: This article argues that browser-based AI agents amplify the unmanaged application problem by acting inside sessions the identity team cannot fully see.

Why it matters: It matters because IAM, IGA, and PAM programmes now have to govern delegated machine action in browser sessions, not just human logins and federated apps.

By the numbers:

👉 Read Unixi's analysis of browser-based AI agents and unmanaged app identity risk


Context

Primary keyword: browser-based AI agents are exposing a long-standing identity gap in enterprise applications. The issue is not that AI created unmanaged applications. The issue is that many business systems were already outside SAML or OpenID Connect coverage, leaving identity teams without a reliable way to see who or what acted inside them.

That gap has direct consequences for NHI governance and human IAM alike. When an AI agent operates through a human browser session, the enterprise needs to understand not only who authenticated, but what authority was delegated, what the agent did, and how that activity can be attributed and revoked across managed and unmanaged apps.


Key questions

Q: How should security teams govern browser-based AI agents in SaaS environments?

A: Security teams should govern browser-based AI agents as runtime actors, not as ordinary users or static integrations. Give each agent a distinct identity, constrain what it can do in-session, and monitor browser, identity, and SaaS logs together. The key control is not just login validation, but continuous authorization of live actions.

Q: Why do unmanaged applications create such a hard identity problem for AI agents?

A: Because the enterprise often cannot see the application, the credential, or the session, it also cannot reliably see the agent acting inside that session. That makes authentication coverage, lifecycle control, and auditability all weaker at the same time.

Q: What do security teams get wrong about AI agent identity governance?

A: They often assume human IAM patterns can be reused with minor adjustments. That fails because agents can invoke tools dynamically, operate continuously, and combine multiple systems in one session. Governance has to focus on runtime scope, delegated identity, and revocation, not just authentication.

Q: Who should be accountable when a browser agent exposes files or credentials?

A: Accountability should sit with the team that governs the delegated session, the identity permissions behind it, and the systems that allowed secret exposure or recovery changes. If an organisation lets an agent act inside a human session, then access review, PAM, and browser governance all share responsibility for the resulting blast radius.


Technical breakdown

Why browser-based AI agents break the login-only identity model

Traditional federation answers a narrow question: who authenticated to which application. Browser-based agents change the execution model because they can read the page, interpret context, and act inside the same session as the human user. That means the identity event is no longer the end of the control path. Once an agent can operate through the browser, the system needs to govern downstream actions, not just initial access. This creates a gap between authentication and delegated execution that SAML, OpenID Connect, and OAuth were never designed to fully close on their own.

Practical implication: Treat browser session activity as a separate governance layer, not as proof that the underlying action was safe.

How unmanaged applications amplify shadow AI and NHI risk

Unmanaged applications are tools the business depends on but the identity team never onboarded, often because they do not support federation or were acquired outside standard procurement paths. In that environment, the browser becomes the only path in, which means agents can work inside systems that lack central audit, policy enforcement, or lifecycle controls. From an NHI perspective, this is the same structural problem seen with overprivileged service accounts and shared credentials: authority exists outside governance, so attribution and revocation become weak or impossible.

Practical implication: Prioritise discovery of unmanaged SaaS and browser-only workflows before adding more automation into them.

Task-level delegation is the missing control in agentic identity

The key design flaw is broad privilege inheritance. If an agent receives the user’s whole session, it inherits far more authority than the task requires. A safer model separates the human principal from the agent actor, assigns bounded authority for a specific objective, and records on-behalf-of attribution in the audit trail. This is where browser-level governance can enforce task scope, approval gates, and revocation without replacing the identity provider. That pattern is closer to delegated identity than to conventional user login.

Practical implication: Bind each agent action to a task-scoped grant and require revocation paths that work independently of the human account.


Threat narrative

Attacker objective: The objective is to turn legitimate user access into ungoverned delegated action that can alter records, move data, or send messages without clear accountability.

  1. Entry occurs when a browser-based AI agent operates inside a legitimate human session in an unmanaged or partially governed application.
  2. Escalation occurs when the agent inherits broad session authority and performs actions beyond the original task scope.
  3. Impact occurs when those actions are executed without reliable attribution, audit coverage, or a clear revocation path across shadow SaaS and federated apps.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Browser agents are not just another automation layer, they are a second actor inside the identity boundary. That distinction matters because governance built for human login events cannot reliably explain machine action taken after authentication succeeds. The field needs to stop treating the browser as an endpoint and start treating it as an enforcement surface for delegated execution. For practitioners, the conclusion is clear: identity governance must extend into the session where action actually happens.

Unmanaged applications are the real multiplier behind shadow AI risk. Browser-based agents do not create the unmanaged app problem, but they make its blind spots operationally dangerous because work now happens inside systems with no standard identity lifecycle, no central logs, and no uniform policy plane. This is a governance exposure, not a tooling inconvenience. Teams should re-evaluate where they rely on browser-stored access, shared accounts, or department-owned SaaS that never entered the IAM programme.

Task-level delegation is the named control gap that current IAM models still under-specify. Federation proves identity at login, but it does not prove the scope, intent, or downstream accountability of an agent acting on behalf of a human. The browser session becomes the place where identity and authority collapse into one another unless the enterprise separates them explicitly. Practitioners should treat delegated execution as its own control domain, not a side effect of user authentication.

Broad privilege inheritance is the wrong default for both NHIs and browser agents. A session that gives an agent everything the user can do creates the same overreach pattern seen in overprivileged service accounts, only faster and harder to trace. The governance lesson is not that agents are special, but that they amplify existing identity failure modes inside a browser-first environment. Security and compliance leads should assume that any broad-session design will expand blast radius before it improves productivity.

Browser-level policy enforcement is becoming part of identity architecture, not a convenience feature. When apps fall outside federation, the enterprise still needs a place to observe, constrain, and attribute action. That control point has to sit where the browser converts intent into execution. The implication for practitioners is that browser governance, NHI governance, and human IAM are converging into one operational model for delegated access.

From our research:

  • 100% of organisations report AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
  • For a governance baseline, see Ultimate Guide to NHIs , Lifecycle Processes for Managing NHIs for lifecycle controls that need to extend into delegated agent activity.

What this signals

With browser-based AI agents now operating inside sessions that enterprises already struggle to govern, the next maturity step is not broader federation alone but a control plane for delegated action. Organisations that still rely on login logs as their main evidence source will miss the point where authority becomes execution.

Delegated execution debt: this is the gap that appears when a human session carries too much authority for too long, allowing an agent to act without task-level boundaries or attribution. The practical response is to redesign access review, approval, and revocation workflows so they cover actions inside the browser, not just account state.

The governance signal is clear: identity teams need operational visibility into shadow SaaS, browser-stored credentials, and unmanaged workflows before AI adoption scales further. If the browser is where work happens, it also has to become where policy is enforced and evidence is captured.


For practitioners

  • Map unmanaged application exposure Identify the browser-only and non-federated applications where staff already work outside SAML or OpenID Connect, then rank them by data sensitivity and business criticality. Focus first on apps where shared accounts, browser-stored passwords, or shadow AI are already in use.
  • Separate human identity from agent action Require a distinct representation for browser-based agents so the audit trail can distinguish human login from delegated machine execution. Record the task, the target application, and the scope of authority attached to each agent run.
  • Bind authority to a specific task Replace broad session inheritance with task-scoped grants such as read-only, draft-only, or update-only permissions. Expire those grants automatically and make revocation possible without disabling the human’s full account.
  • Put approval gates on high-risk browser actions Require explicit confirmation before exports, deletions, privileged updates, external sharing, or financial actions performed through browser agents. Attach the control to the action itself, not just the login event.
  • Build browser-side evidence capture Log which agent acted, what it touched, and what evidence supported the action so investigation does not depend on a SaaS admin console that may not exist. This is essential in shadow SaaS and other unmanaged workflows.

Key takeaways

  • Browser-based AI agents expose a governance gap that already existed in unmanaged applications and shadow SaaS.
  • Federation proves who authenticated, but not what delegated machine action actually occurred or who is accountable for it.
  • Task-scoped authority, browser-side evidence, and action-level approval gates are now core identity controls, not optional enhancements.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10A1The article focuses on delegated agent action and tool use inside browser sessions.
OWASP Non-Human Identity Top 10NHI-01Overprivileged browser agents mirror classic NHI scope and lifecycle failures.
NIST CSF 2.0PR.AC-4The piece centres on least-privilege access and delegated authority across apps.
NIST SP 800-53 Rev 5AC-6Broad session inheritance and task overreach map directly to least-privilege control failures.
NIST Zero Trust (SP 800-207)The browser is used as a policy enforcement point in a zero trust style model.

Map browser agent workflows to agentic controls for delegation, tool scope, and action-level authorization.


Key terms

  • Browser-based AI usage: Use of AI tools through a web browser where prompts, uploads, and pasted content can move sensitive data outside traditional file and email controls. It is a governance problem because identity, intent, and content all matter at the point of entry, not only after storage.
  • Unmanaged application: An unmanaged application is a business system used by the organisation but not integrated into the identity team’s standard controls, such as SAML, OpenID Connect, or central lifecycle management. These systems often hide credentials, sessions, and actions from normal IAM visibility, making them high-risk for delegated automation.
  • Task-Scoped Authority: Task-scoped authority is access that exists only for the duration and purpose of a specific workflow. It is narrower than standing privilege and more practical for agentic systems, because it ties permission to execution context instead of leaving broad access in place after the job is done.
  • Delegated Execution: Delegated execution is when software is allowed to perform actions on behalf of a user, process, or business function. In NHI governance, the risk is that the delegated actor may chain actions beyond the original intent, so controls must focus on scope, approval, and revocation.

What's in the full article

Unixi's full article covers the operational detail this post intentionally leaves for the source:

  • How browser-level policy enforcement is applied across managed and unmanaged applications without replacing the identity provider
  • The delegation and attribution model for representing a human principal and an agent actor separately in audit logs
  • The browser-based control points used to bind authority to a task and revoke it without disabling the user account
  • The unmanaged-app workflow patterns that make shadow AI harder to see in standard IAM and SaaS logs

👉 The full Unixi article covers browser-level governance, delegated authority, and unmanaged app control points in more detail.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 11, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org