By NHI Mgmt Group Editorial TeamBased on Push Security: “Meet with Push Security at Black Hat Europe” (June 2, 2026)

TL;DR: AI regulations in the US, EU, and UK are converging on obligations that many organisations cannot meet without browser visibility into AI tool use, according to Push Security. The hard part is not the regulation itself, but the fact that existing controls often miss what happens inside the browser.


At a glance

What this is: This is Push Security’s argument that browser visibility has become a core control point for AI governance and compliance because many AI interactions happen where traditional controls cannot see them.

Why it matters: It matters because IAM, security, and compliance teams need evidence and enforcement at the browser layer, not just in network, endpoint, or SaaS control planes, if they want to govern AI tool use effectively.


Context

Browser visibility is the ability to observe and control activity inside the web browser rather than only at the network, endpoint, or SaaS boundary. For AI governance, that matters because many employee AI interactions now happen in the browser, where prompts, uploads, extensions, and session behaviour can escape traditional monitoring.

Push Security’s article frames the problem as a compliance gap, not just a technical visibility gap. If organisations cannot see how AI tools are actually being used in the browser, they cannot reliably evidence policy enforcement, data handling, or acceptable-use controls across modern work patterns.


Key questions

Q: How should organisations govern browser-accessible AI development tools?

A: They should classify them as identity-sensitive runtime services and apply the same scrutiny used for privileged admin tools. That means validating who can connect, what each channel can do, and whether command-bearing paths are isolated from read-only telemetry. If the browser can reach it, the interface is part of the security boundary.

Q: Why do traditional IAM controls miss browser-based AI risk?

A: Traditional IAM controls miss browser-based AI risk because they are strongest at authentication and access grant, not at observing in-session behaviour. A user can log in legitimately and still expose data, use an unsanctioned AI service, or create compliance exposure inside the browser without generating a meaningful IAM violation.

Q: How do teams know whether AI governance is actually working?

A: Look for evidence that every AI interaction can be traced end to end, from identity and intent to output and enforcement. If auditors can ask for a transaction and receive a complete record in hours, not weeks, the programme is producing usable control evidence rather than just documentation.

Q: What is the difference between controlling AI apps and controlling AI use in the browser?

A: Controlling AI apps focuses on the service itself, such as access or tenant settings. Controlling AI use in the browser focuses on the user session, including prompts, copy-paste, uploads, extensions, and unmanaged access paths that may never appear as distinct application events.


Background and context

Browser-layer control is where AI policy becomes enforceable

Browser security sits at the point where users interact with web-based AI tools, browser extensions, and embedded AI features. That makes it different from endpoint telemetry or SaaS audit logs, which often record outcomes after the action has already happened. In practice, browser visibility can reveal the context around tool use, such as the source of a prompt, the destination of copied data, and whether an extension or unmanaged session is mediating the interaction. For AI governance, the browser becomes the control plane where policy can be observed and applied close to the actual user action.

Practical implication: treat browser telemetry as a governance input for AI use cases, not just a security logging source.

Why traditional controls miss AI tool use

Traditional controls often assume the important event is authentication into an application or traffic leaving the network. AI usage breaks that assumption because a user can interact with a consumer or embedded AI service entirely inside the browser, sometimes without a distinct enterprise app boundary. That means DLP, CASB-style visibility, and endpoint tooling may miss the precise moment when sensitive data is pasted, generated, or transformed. The gap is not that the controls are absent, but that they are positioned one layer too far away from the interaction that matters.

Practical implication: map where AI interactions actually occur and test whether your current stack can see the browser session itself.

Governance and compliance need evidence, not assumptions

AI governance obligations increasingly require organisations to demonstrate how AI tools are approved, constrained, and monitored. If the evidence only exists in scattered application logs or user policy statements, compliance becomes speculative. Browser visibility can provide the operational evidence trail needed to show which tools were used, in what context, and with what user behaviour surrounding them. That makes browser telemetry relevant to acceptable-use enforcement, data protection oversight, and policy verification, especially where shadow AI or unmanaged browser-based access exists.

Practical implication: define which browser events create auditable evidence for AI policy, then align compliance reporting to those events.


NHI Mgmt Group analysis

Browser visibility is becoming the enforcement layer for AI governance: The governance problem is no longer only whether a policy exists, but whether organisations can observe the actual AI interaction point. Browser-based use of AI tools creates a control gap between policy intent and user behaviour. The implication is that AI governance programmes must treat the browser as an operational boundary, not a secondary monitoring surface.

Existing compliance models assume controls sit around the application, not inside the session: That assumption was designed for software and SaaS boundaries where authentication, logging, and data controls were visible at the service edge. It fails when AI use is mediated through browser sessions that can mix approved and unapproved tools, copy data across contexts, and bypass higher-level monitoring. The implication is that governance teams must rethink where evidence is collected.

Browser visibility exposes the difference between policy coverage and policy effectiveness: Many organisations can write acceptable-use rules for AI, but far fewer can prove those rules are being followed in real usage. Browser telemetry turns policy from a document into an observable control pattern. Practitioners should treat that gap as a governance maturity issue, not just a technical deployment decision.

AI governance and compliance are converging on the same operational question: what can you actually see? The article’s core signal is that regulation is pushing accountability closer to the user interaction layer. When AI use moves into browsers, security, IAM, and compliance teams need shared observability rather than separate control assumptions. The practical conclusion is that visibility strategy now belongs in the identity governance conversation.

Browser visibility creates a new named concept: browser-governed AI use: This is the idea that AI policy, monitoring, and evidence collection must be anchored at the browser session where work happens. It matters because unmanaged browser interactions are where shadow AI, data leakage, and weak enforcement converge. Practitioners should evaluate AI governance through that browser-governed lens, not through application inventory alone.

What this signals

Browser-governed AI use: The control problem is shifting from whether an AI service is approved to whether the browser session can be observed and constrained. That changes how teams think about evidence, because governance now has to follow the interaction path rather than the application inventory.

Regulatory pressure is exposing a familiar identity lesson: if you cannot observe the action point, you cannot prove control. For AI programmes, that means browser visibility belongs alongside policy, monitoring, and access governance as a core operating requirement.


For practitioners

  • Define the browser as a governance boundary Map AI use cases to the browser session where prompts, uploads, and copy-paste actions occur, then decide which events must be observable for policy enforcement.
  • Inventory AI tool usage at the session level Identify which approved, embedded, and unmanaged AI tools are reachable in browsers used by employees, contractors, and administrators.
  • Align AI policy evidence to observable browser events Specify which browser events demonstrate acceptable use, data handling, and control effectiveness so compliance reviews do not depend on assumptions.
  • Test whether existing controls see the real interaction Validate whether endpoint, network, and SaaS tools can detect the exact browser actions where sensitive data enters or leaves AI workflows.

Key takeaways

  • AI governance now depends on visibility at the browser session, where much of real-world tool use happens.
  • Existing endpoint, network, and SaaS controls can miss the decisive AI interaction point inside the browser.
  • Practitioners should treat browser telemetry as evidence for policy enforcement, compliance, and acceptable-use control.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI09 — Human-Agent Trust ExploitationBrowser-based AI use often depends on user trust and invisible interaction patterns.
Recommendation — Audit browser-mediated AI workflows for trust gaps that let users over-rely on ungoverned AI outputs.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe article is fundamentally about governance and accountability for AI use.
Recommendation — Define oversight, evidence, and accountability for browser-based AI use under GOVERN.
NIST CSF 2.0GV.OC-01 — Organizational ContextBrowser-based AI use changes the organisation's operating context for security and compliance.
PR.AA-05 — Access Permissions, Entitlements and AuthorizationsVisibility into browser-mediated AI use supports control over who can use which tools.
Recommendation — Document browser-based AI use as part of the organisation's security and compliance operating context. Align browser-level AI use controls with PR.AA-05 authorization decisions and approvals.
OWASP Non-Human Identity Top 10NHI-10 — Human Use of NHIEmployees using browser-based AI tools often interact with non-human services through human sessions.
Recommendation — Control human interaction paths to AI services so browser sessions do not bypass NHI governance.

Key terms

  • Browser-layer visibility: Browser-layer visibility is the ability to observe user activity where it actually happens in the web session, including app use, input, consent, and extensions. For AI governance, it becomes the evidence layer that shows what employees used, what data they exposed, and what access they granted.
  • AI Governance: AI governance is the set of controls used to discover, classify, approve, restrict, monitor, and revoke AI-enabled access. It connects identity, data, and policy so organisations can manage what AI can reach, what it can share, and when it should be stopped.
  • Browser-based AI usage: Use of AI tools through a web browser where prompts, uploads, and pasted content can move sensitive data outside traditional file and email controls. It is a governance problem because identity, intent, and content all matter at the point of entry, not only after storage.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org