By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: Push SecurityPublished August 13, 2026

TL;DR: Browser visibility is now central to seeing how employees use AI apps, while shadow AI and shadow SaaS create governance gaps that network controls miss, according to Push Security. The underlying problem is not just detection but the loss of control over unmanaged access paths and session-level activity.


At a glance

What this is: This is Push Security’s browser-security analysis of shadow AI, shadow SaaS, and browser-based identity risk, with the key finding that web-path controls miss the session layer where modern abuse happens.

Why it matters: It matters because IAM, NHI, and security teams need visibility into how identities actually use AI apps and SaaS in the browser, not just whether traffic passed through a proxy.

👉 Read Push Security’s analysis of shadow AI and browser-based identity risk


Context

Browser security matters because the browser is where users, sessions, tokens, and SaaS access now converge. When organisations rely only on network-path inspection, they see traffic but not the identity behaviour inside the session, which leaves shadow AI and shadow SaaS effectively unmanaged.

For IAM and security teams, that creates a governance gap across human identities and the unmanaged access paths they create. Push Security’s article frames the issue as one of visibility and control in the browser, where modern business use of AI tools can bypass the sanctioned access model.

That starting position is typical of enterprises that have invested in proxy-based controls but not in session-level identity telemetry. The risk is not that the browser replaces IAM, but that it becomes the place where IAM enforcement is either confirmed or silently evaded.


Key questions

Q: How should security teams govern Shadow AI in everyday browser use?

A: Security teams should govern Shadow AI by enforcing controls where users actually interact with AI tools, not only at the network edge. That means browser-level inspection, content classification, and policy enforcement for paste, upload, and prompt actions. If users can move sensitive data into an AI tool without a control decision, the governance model is incomplete.

Q: Why do proxies miss so much browser-based identity risk?

A: Proxies inspect traffic in transit, but they do not reliably show the full session context after authentication. That means token use, SaaS switching, copy-and-paste behaviour, and in-browser AI activity can escape the control point that the organisation thinks is watching.

Q: Why do browser security decisions matter for IAM teams?

A: Because the browser is where users enter credentials, approve OAuth grants, and reuse sessions, so it has become an identity control surface. IAM teams need visibility into that layer to reduce credential theft, session abuse, and unauthorized access that bypasses traditional perimeter controls.

Q: What should organisations do when browser telemetry reveals unsanctioned AI use?

A: Classify the session, identify the identity behind it, and determine whether the behaviour represents policy violation, training need, or data exposure. Then feed the finding into access review, offboarding, and incident response processes so the same pattern does not recur.


Technical breakdown

Why web proxies miss browser-based identity behaviour

A secure web gateway inspects traffic in transit, which is useful for blocking known destinations and malicious content. It does not reliably show what happens once a session is established in the browser, where users can authenticate, paste secrets, approve sessions, and move between SaaS apps or AI tools. That gap matters because the browser increasingly acts as the control plane for identity use, not just the endpoint for web requests. Browser telemetry can reveal session context, unmanaged identities, and suspicious use patterns that packet inspection cannot reconstruct.

Practical implication: treat browser visibility as a control layer for identity activity, not just a web filtering add-on.

Shadow AI and shadow SaaS as governance problems

Shadow AI is not only an application discovery issue. It is an identity governance problem because users can create new access paths, authenticate through personal accounts, and move data into unmanaged tools outside approved control frameworks. Shadow SaaS follows the same pattern. The issue is not simply that the tool exists, but that the organisation cannot reliably see who used it, what data was shared, and which identity was responsible for the session. That breaks auditability across both human and non-human workflows that depend on SaaS backends.

Practical implication: map browser-discovered app usage back to identity ownership and governance controls, including offboarding and review processes.

Why browser telemetry changes detection and response

Browser telemetry adds session-level evidence that can support investigation when identity attacks or data loss originate in the user’s browser rather than at the network edge. It can help distinguish sanctioned use from workaround behaviour, show where credentials were entered, and surface the sequence of actions taken inside SaaS and AI tools. That is materially different from post-event log review, because it preserves the behavioural trail closest to the user action. For browser-based attacks, that improves both triage and containment.

Practical implication: make browser telemetry part of incident response workflows for account takeover, AI tool misuse, and session-based exfiltration.


NHI Mgmt Group analysis

Browser visibility is now an identity control problem, not a network monitoring problem. When users authenticate, reuse sessions, and move data inside the browser, the enforcement point shifts away from the proxy and toward the session itself. That means identity teams need to think in terms of governed access paths, not just authenticated traffic. The implication is that browser telemetry belongs in the same conversation as IAM, IGA, and session governance.

Shadow AI creates unmanaged identity sprawl before it creates data risk. The first failure is often not exfiltration, but ungoverned access through personal logins, unsanctioned tools, and untracked browser sessions. Once that behaviour becomes normal, access review and offboarding processes lose completeness because the organisation never had a full inventory of the access path. The implication is that discovery must be tied to identity ownership, not app inventory alone.

Session-level control is the missing layer between proxy security and endpoint security. Proxies can block destinations and endpoints can detect compromise, but neither fully explains how identities actually use SaaS and AI apps in the browser. That gap is where credential misuse, token abuse, and data movement can hide in plain sight. The implication is that modern identity governance has to include the browser as an evidentiary source.

The browser is becoming the practical boundary for governing AI use at work. As employees adopt AI tools through web sessions, the distinction between approved and shadow AI depends on whether the organisation can see, classify, and respond to those sessions. That is a governance question, not a content-filtering question. The implication is that security leaders should evaluate whether their current controls can explain who used which AI service, from which identity, and under what policy.

From our research:

  • 72% of breach incidents involve a human element, showing how identity and session misuse remain central to real-world compromise, according to 52 NHI Breaches Analysis.
  • 2.7 separate incidents was the average for organisations that experienced a compromised non-human identity in the 2024 ESG report, reinforcing how repeat exposure becomes a governance pattern.
  • Browser session visibility belongs alongside lifecycle control, which is why the NHI Lifecycle Management Guide is the right next resource for provisioning, rotation, and offboarding discipline.

What this signals

Shadow AI will keep expanding until organisations can classify browser sessions by identity, not just by application. The practical gap is not discovery alone. It is the lack of a governed path from browser activity to ownership, review, and remediation, which means unmanaged use can persist even when the app catalog looks complete.

With 72% of breach incidents involving a human element, the browser has become a high-value evidence source for identity governance. Teams that pair browser telemetry with lifecycle controls will detect more workaround behaviour, especially where personal accounts and sanctioned SaaS overlap.

Browser session governance: This is the point where discovery, access control, and response start to converge. Organisations that cannot explain browser-based AI use will struggle to enforce policy consistently across human, unmanaged, and delegated access paths.


For practitioners

  • Implement browser-level identity telemetry Collect session evidence for SaaS and AI app use so security teams can see which identities authenticated, which apps were accessed, and what actions occurred inside the browser.
  • Tie shadow AI discovery to identity ownership Do not stop at app discovery. Assign each discovered browser-based AI tool to a business identity, a risk owner, and an offboarding path so usage can be reviewed and revoked.
  • Extend incident response to browser sessions Add browser telemetry to triage for account takeover, suspected data loss, and AI session abuse so responders can reconstruct user activity without relying only on network logs.
  • Review unmanaged access paths after offboarding Check whether former employees, contractors, and guests still have live browser-based access to AI apps and shadow SaaS through personal accounts or residual sessions.

Key takeaways

  • Browser security is increasingly an identity governance issue because the session, not the packet, is where modern SaaS and AI use happens.
  • Shadow AI and shadow SaaS create unmanaged access paths that break ownership, review, and offboarding even when the application catalogue looks complete.
  • Security teams should treat browser telemetry as evidence for IAM, IGA, and incident response, not as a standalone web filtering feature.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Browser-based identity governance depends on controlled access paths and accountability.
NIST Zero Trust (SP 800-207)The article's session-level control problem aligns with zero trust access verification.
NIST SP 800-53 Rev 5AC-6Least privilege is directly challenged by unmanaged browser access to SaaS and AI tools.
OWASP Non-Human Identity Top 10NHI-01Unmanaged browser access paths and identity sprawl fit NHI governance risk patterns.

Map browser-discovered AI and SaaS use to PR.AC-4 and ensure access is owned, reviewed, and revocable.


Key terms

  • Browser telemetry: Browser telemetry is the event data produced by enterprise browser activity, including logins, profile changes, downloads, session starts, and extension or site interactions. In identity governance, it becomes useful when those events are correlated with account state and privilege context rather than treated as generic activity logs.
  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Shadow SaaS: Shadow SaaS is the set of unauthorised or unreviewed software-as-a-service tools used outside central security governance. These applications often bypass normal identity controls, making them difficult to inventory, monitor, and harden against credential-based abuse.
  • Session Governance: The practice of binding access to a specific task, time window, and execution context, then revoking it when the work is done. For non-human identities, session governance matters because tokens and delegated permissions often persist longer than the action they were created to support.

What's in the full article

Push Security's full blog post covers the operational detail this post intentionally leaves for the source:

  • Browser security product positioning for detecting account takeover, shadow SaaS, and AI app usage in-session
  • Examples of the browser telemetry used to investigate identity abuse and browser-related incidents
  • How the vendor frames secure browsing across managed devices, BYOD, and Chromebooks
  • The specific browser-based use cases the product is designed to observe and control

👉 The full Push Security post covers browser telemetry, shadow SaaS visibility, and the practical controls behind session-level detection.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org