By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: SeraphicPublished September 17, 2025

TL;DR: Browser-level policy enforcement paired with Akamai ZTNA can reduce proxy-heavy SSE complexity while improving visibility into web and AI-tool access patterns, according to Seraphic. The identity implication is straightforward: when the browser becomes the control point, access governance must extend beyond network policy to session context, data handling, and risky prompt behaviour.


At a glance

What this is: This is Seraphic's analysis of why browser-level enforcement and ZTNA are being positioned as a replacement for proxy-heavy SSE in AI-driven work.

Why it matters: It matters because identity, access, and data controls increasingly fail when users, apps, and AI tools meet in unmanaged browser sessions rather than governed application boundaries.

👉 Read Seraphic's solution brief on browser-level SSE and ZTNA integration


Context

Enterprise access control is weakening at the point where work actually happens: inside the browser, across SaaS, private applications, and AI tools. Traditional secure access models often stop at the network edge, but that leaves browser behaviour, prompt content, and data movement outside the policy boundary. For identity and access teams, the question is no longer just who can reach an app, but what they can do once the session is live.

That shift has a direct identity security angle because browser sessions now carry human identity, device context, and increasingly AI-assisted actions in the same workflow. When unmanaged browsers bypass controls, organisations lose visibility into access decisions, risky sharing, and tool-to-tool interaction. For practitioners, this is a classic governance gap: policy exists, but enforcement no longer sits where the risk is created.


Key questions

Q: How should security teams govern browser sessions used by AI agents?

A: Security teams should treat browser sessions used by AI agents as shared execution environments, not simple user logins. That means stronger logging, action-level attribution, tighter approval flows for high-risk operations, and explicit policy for what an agent may do inside an authenticated session. If the audit trail cannot separate human from agent activity, the control model is incomplete.

Q: Why do unmanaged browsers create access governance gaps?

A: Unmanaged browsers can bypass the controls that organisations rely on for inspection, policy enforcement, and auditability. When users access SaaS, private apps, or AI tools through those browsers, the organisation may still authenticate the user but lose visibility into what happens inside the session. That weakens both access control and accountability.

Q: What do organisations get wrong about AI safety and access control?

A: Organisations often focus on model outputs while ignoring the privileges behind the model. If an agent can read sensitive data or invoke tools, the real risk is what it can cause the environment to do. Effective control starts with scope, policy, and monitoring around actions, not just moderation of generated text.

Q: What should teams do when browser policy and ZTNA overlap?

A: Teams should separate the functions but align the decisions. ZTNA should govern whether a user reaches the application, while browser policy should govern what they can do after access is granted. If those controls are not coordinated, users can pass the gate and still create data exposure or policy violations inside the session.


Technical breakdown

Why browser-level enforcement changes the control plane

Secure Enterprise Browser approaches move policy enforcement into the browser itself rather than depending on proxies, endpoint agents, or TLS interception. That matters because the browser is where authentication, session continuity, SaaS interaction, and AI prompting increasingly converge. A browser-level control plane can inspect intent, session context, and content flows closer to the user action than perimeter tooling can. It does not replace identity governance, but it changes where governance can be applied and what can be observed.

Practical implication: treat browser policy as part of the access architecture, not as a point product layered on top.

Why AI tools create a new SSE visibility problem

AI tools introduce prompt injection, accidental data disclosure, and malicious tool use into ordinary browsing and collaboration flows. Traditional SSE architectures are often strong at destination control but weak at understanding what content a user submits or what an AI service may infer from that content. Browser-level inspection can add context around prompts, uploads, and user actions, which is essential when a session can leak sensitive material without a conventional malware event. The core issue is not just transport security, but behaviour-aware enforcement.

Practical implication: extend controls to prompt content, data sharing actions, and AI-tool access paths rather than relying on URL or category filtering alone.

How ZTNA and browser policy fit together

ZTNA governs reachability to private applications, while browser controls govern how users interact once access is granted. Used together, they can reduce the gap between authentication and actual use by tying access decisions to session context and policy state. This is especially relevant in hybrid work and BYOD scenarios, where endpoint trust is inconsistent and application risk is often created after login. The technical challenge is ensuring consistent policy without stacking multiple interception layers that slow users down.

Practical implication: align ZTNA policy with browser-enforced session controls so authentication, authorization, and in-session behaviour are governed together.


Threat narrative

Attacker objective: The attacker aims to extract sensitive information or manipulate user actions through the browser session without triggering conventional edge-based controls.

  1. Entry occurs through unmanaged or lightly governed browser sessions that bypass traditional IT control points and reach private applications or AI tools.
  2. Escalation happens when users submit sensitive prompts, paste data into third-party services, or interact with malicious web content that the legacy SSE stack does not observe well.
  3. Impact is data leakage, policy evasion, or malicious tool use inside otherwise legitimate enterprise sessions.

NHI Mgmt Group analysis

Browser governance is becoming an identity problem, not just a network problem. When access decisions are enforced at the browser layer, the control point moves closer to the human identity, device context, and application session. That is relevant to IAM because the browser now acts as the execution environment where authorised access can still become unsafe. Practitioners should treat browser policy as part of the access lifecycle, not an adjacent security feature.

AI-driven work creates a data-sharing boundary that legacy SSE stacks do not consistently see. Prompt injection, accidental disclosure, and tool misuse are not classic perimeter failures. They are session-level failures that happen after authentication, which means the governance model must understand content and context, not just destination. The result is a need for policy enforcement that can interpret browser behaviour as part of access control.

Session-level control is the named concept this market is moving toward. The browser is no longer a passive client; it is a policy enforcement point where identity, data handling, and application access converge. That changes how teams think about least privilege because privilege is now expressed in what a user can do inside a live session. The practical conclusion is that governance must follow the session, not stop at login.

AI adoption is widening the gap between access approval and safe use. The old assumption was that if the user reached the application, the access problem was solved. In AI-heavy workflows that assumption fails because the risky act is often the prompt, paste, or share event inside the session. Practitioners should re-evaluate whether their current controls can observe and constrain those actions before they become governance blind spots.

This kind of architecture signals consolidation around access-layer enforcement. Enterprises are trying to simplify proxy-heavy stacks without losing policy depth, which suggests the market is favouring controls that combine access, browser, and data enforcement. For identity programmes, that means future SSE decisions will be judged less by perimeter coverage and more by whether they preserve governable sessions across SaaS, private apps, and AI tools.

What this signals

Browser enforcement will increasingly shape identity programme design. Once access control moves into the session, IAM teams need stronger ties between authentication, device trust, and in-browser policy. That pushes programmes toward controls that can observe behaviour after login, especially for SaaS and AI-heavy workflows. The practical signal is that identity governance will be judged on runtime visibility, not only on initial access approval.

Session control will become a governance requirement for AI adoption. AI tools expose a pattern that traditional SSE often misses: the risky act happens inside the live workflow, not at the perimeter. Teams that cannot inspect or constrain prompts, paste actions, and data sharing will struggle to prove control over AI-enabled access. The programme implication is clear: identity and data governance have to converge at the browser layer.


For practitioners

  • Map browser sessions to access-policy boundaries Identify which applications, SaaS tools, and AI services are now governed only after login and where browser-level enforcement is missing. Use that map to define where policy must shift from perimeter controls to in-session controls, especially for unmanaged device access.
  • Classify AI prompt and paste risks by data sensitivity Review which user workflows allow sensitive text, files, or credentials to move into third-party AI tools. Define controls for prompt inspection, copy-paste suppression, and data-loss prevention at the browser layer where those actions occur.
  • Align ZTNA policy with session behaviour controls Make sure ZTNA decisions are not treated as the end of governance. Tie application reachability to browser session rules so access remains constrained after authentication, particularly for distributed work and BYOD users.
  • Retire overlapping proxy layers where they add no policy value Catalogue proxy, TLS interception, URL rewriting, and endpoint-agent dependencies that duplicate controls without improving visibility. Consolidate only where the new architecture preserves auditability and access enforcement across SaaS, private apps, and AI tools.

Key takeaways

  • The core issue is not only network access, but where policy enforcement sits when users interact with SaaS and AI tools in the browser.
  • Browser-level control changes the governance model by making session behaviour, prompt handling, and data sharing observable and enforceable.
  • Enterprises that keep SSE focused on the perimeter will continue to miss the in-session actions where modern access risk is created.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207), NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Browser-layer access control directly affects how privileges are enforced during sessions.
NIST Zero Trust (SP 800-207)The article centers on Zero Trust access and continuous verification across sessions.
NIST SP 800-53 Rev 5AC-6Least privilege is central to browser-enforced access and session control.
CIS Controls v8CIS-6 , Access Control ManagementBrowser-mediated access depends on strong control over who can reach which resources.
OWASP Agentic AI Top 10AI tools in the browser introduce prompt and tool-use risks that map to agentic security concerns.

Use Zero Trust principles to tie application access to context, session state, and ongoing verification.


Key terms

  • Browser-layer enforcement: Browser-layer enforcement is the ability to apply a security control directly inside the browser session where the risky behaviour occurs. It can block credential entry, interrupt suspicious consent flows, or contain the session before abuse spreads into downstream identity systems.
  • Secure Access Service Edge: SASE is a converged architecture that combines network connectivity with security controls such as zero trust access, secure web gateway, and firewall services. It is useful for consistent enforcement across distributed environments, but it does not replace identity governance or entitlement ownership.
  • Zero Trust: A security model that assumes no identity — human or non-human — should be trusted by default, even inside a network perimeter. Every access request must be verified, authorised, and continuously validated.
  • Session-Level Data Movement Control: Session-level data movement control is the practice of constraining how information can be copied, uploaded, printed, shared, or exported during an active browser session. It matters because many breaches begin with ordinary user actions, not malware or exploit chains.

What's in the full article

Seraphic's full solution brief covers the operational detail this post intentionally leaves for the source:

  • How the Secure Enterprise Browser and ZTNA policy are integrated across private apps, SaaS, and AI tools
  • The specific enforcement model used to avoid proxies, endpoint agents, and TLS interception
  • The vendor's operational framing for reducing infrastructure complexity and policy overlap
  • The access-layer and browser-layer deployment scenarios the brief uses to justify the architecture

👉 The full Seraphic solution brief covers architecture details, policy flow, and AI-aware access scenarios.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners connect identity controls to the broader access and runtime risks their programmes now face.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 18, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org