TL;DR: AI regulations across the US, EU, and UK are converging on obligations that most organisations cannot meet without browser visibility into AI tool use, according to Push Security. That makes browser-level control a governance issue for NHI, human access, and emerging agentic workflows rather than a point product decision.
At a glance
What this is: This analysis argues that browser visibility is now a governance control point for AI use because policy requirements are converging on activity that happens in the browser.
Why it matters: It matters because IAM, NHI and AI governance teams need visibility into where users, service identities and emerging agentic workflows actually interact with external AI tools.
Context
Browser activity has become the place where identity, data access and AI tool use intersect, which makes it a governance boundary rather than just an endpoint surface. Traditional controls often stop at the network, the IdP or the managed device, but AI usage can now happen inside the browser with little to no durable evidence in the systems teams normally review.
Push Security's article frames this as a compliance problem as much as a detection problem: organisations are being asked to prove control over AI usage, but the control plane is shifting into the browser. That creates a gap for IAM, security architecture and policy enforcement programmes that still assume control can be established before or after the session instead of during it.
Key questions
Q: How should security teams govern employee use of public AI tools in the browser?
A: They should treat browser AI use as an identity and data-control problem, not just an acceptable-use issue. The team needs visibility into what was pasted, which account was active, whether the content was sensitive, and whether policy enforcement occurred before the data left the organisation. Controls that only inspect network events will miss the real decision point.
Q: Why do IdP and EDR controls miss some AI activity?
A: IdP confirms authentication and EDR observes the endpoint, but neither always captures what a user does inside a browser-based AI session. Sensitive prompts, uploads and delegated actions can occur after login and remain invisible unless browser telemetry is included in the governance model.
Q: What breaks when organisations rely on login-based identity controls for autonomous AI agents?
A: Login-based controls assume a person is present to authenticate, approve, and exit the session. Autonomous agents do not fit that model because they may act continuously, across systems, and without human timing. When identity governance stays tied to the old login pattern, teams lose visibility into agent actions, cannot scope access cleanly, and struggle to investigate incidents.
Q: What is the difference between browser visibility and endpoint monitoring for AI risk?
A: Endpoint monitoring focuses on device behaviour, while browser visibility shows the session-level actions where AI interaction often happens. For AI governance, that distinction matters because the control question is frequently about prompts, uploads and tool use inside the browser, not just activity on the host.
Background and context
Why the browser has become the AI control plane
The browser now sits between the user, the enterprise identity layer and the external AI service. That makes it the last common point where organisations can observe prompts, uploads, session context and tool use before data leaves controlled infrastructure. In practice, the browser is becoming the enforcement surface for policy because it can see the actual activity that IdP logs, EDR and CASB-style controls may miss once a session is established. For AI governance, the control question is no longer only who authenticated, but what was done inside the session and where the data went.
Practical implication: treat browser telemetry as a core governance input for AI usage monitoring and policy enforcement.
Why conventional EDR and IdP controls miss browser-native AI activity
EDR is designed to observe endpoints and suspicious process behaviour, while IdP controls authentication and access assertions. Neither model fully describes what happens when a user pastes sensitive material into a browser-based AI tool or when a browser session becomes the true place of AI interaction. That creates a blind spot between successful login and visible downstream action. If the policy question is whether an AI tool was used with controlled data, the answer may only exist in browser-layer events rather than in identity logs or endpoint alerts.
Practical implication: correlate browser events with identity signals before assuming access logs tell the whole story.
Browser visibility and agentic workflows: where governance starts to blur
As organisations adopt more AI-assisted workflows, browser-mediated actions can become the handoff point between human intent and machine execution. Even when a system is not fully autonomous, browser sessions can initiate tool use, data sharing and delegated actions that blur the line between ordinary user activity and early agentic behaviour. That matters because governance models built for static user sessions do not capture runtime tool chaining, prompt reuse or context leakage. The browser becomes not only a visibility layer but also a place where policy must account for behaviour that changes during the session.
Practical implication: classify browser-driven AI interactions separately from ordinary SaaS use when designing governance and logging controls.
NHI Mgmt Group analysis
Browser visibility is becoming the practical enforcement layer for AI governance. Policies about AI use are only meaningful if organisations can observe the action where it happens, and that is increasingly the browser. Identity systems can confirm who authenticated, but they often do not show what was typed, pasted, uploaded or delegated inside the session. The implication is that governance teams need to treat browser-layer evidence as part of the control plane, not as supplemental telemetry.
The control gap is between authentication and in-session behaviour. Most identity programmes are still built around access decisions made before the session starts, yet AI risk is emerging inside the browser after authentication. That means the old assumption that identity logs and device controls are enough no longer holds for AI tool use. The practitioner conclusion is that control design must follow the session boundary, not stop at login.
Browser visibility exposes the overlap between human IAM, NHI governance and emerging autonomous workflows. Users are increasingly acting through browser-based AI services that may later be backed by tokens, connectors or delegated permissions. This is where identity governance starts to span multiple actor types in one interaction chain. The implication is that teams need a shared governance model for browser-mediated activity, rather than separate policies that never meet.
AI governance now depends on where organisations draw the line around data movement and tool use. The browser has become the point at which policy, data handling and access control converge, especially when AI tools sit outside enterprise-managed infrastructure. A named concept emerges here: browser control plane: the session layer where identity, data and AI activity become governable together. Practitioners should anchor policy, logging and review around that plane rather than around the application alone.
What this signals
Browser visibility is now a governance primitive for AI use. Organisations that treat browser telemetry as optional will struggle to enforce policy over the actual session where prompts, uploads and delegated actions occur. The operational shift is simple: if the browser is where AI work happens, it is also where control has to start.
The more AI moves into ordinary user workflows, the less useful it becomes to separate identity governance from browser-layer enforcement. Security teams should expect policy, logging and compliance evidence to converge around session activity rather than around static access grants.
For practitioners
- Define the browser as a governance boundary Map which AI use cases are only visible inside the browser and document which policy decisions depend on that visibility.
- Correlate identity and browser telemetry Pair IdP authentication logs with browser-layer events so AI tool usage can be evaluated in the context of the authenticated session.
- Classify browser-based AI activity separately Create a distinct policy category for browser-mediated AI interactions, including uploads, prompts and delegated tool use.
- Review where controls stop at login Identify AI workflows where access approval exists but in-session behaviour is not monitored, then close that gap in the logging model.
Key takeaways
- Browser visibility has moved from a tactical control to a governance requirement because much of AI use now happens inside the session.
- Identity and endpoint controls can confirm access, but they often do not explain what happened once the browser session began.
- Teams should align policy, logging and compliance evidence to browser-layer activity if they want AI governance to be auditable.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 addresses the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | Browser-mediated AI use can obscure how identity and privilege are exercised during a session. |
| Recommendation — Map browser-mediated AI activity to ASI03 and log in-session privilege use separately from login events. | ||
| NIST AI RMF | GOVERN — AI Governance and Accountability | The article is fundamentally about AI governance obligations and accountability for in-browser use. |
| Recommendation — Use GOVERN to define ownership, policy enforcement and evidence requirements for browser-based AI activity. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Browser control is being used to govern what authenticated users can actually do with AI tools. |
| Recommendation — Apply PR.AA-05 to align browser-layer AI controls with authorizations and session evidence. | ||
| NIST Zero Trust (SP 800-207) | Continuous Verification — Continuous Verification | Browser visibility supports continuous verification of in-session behaviour instead of one-time trust. |
| Recommendation — Extend continuous verification to browser-layer AI actions rather than stopping at initial authentication. | ||
Key terms
- Browser-layer visibility: Browser-layer visibility is the ability to observe user activity where it actually happens in the web session, including app use, input, consent, and extensions. For AI governance, it becomes the evidence layer that shows what employees used, what data they exposed, and what access they granted.
- Action-Level Governance: Action-Level Governance is the practice of controlling what an agent, user, or system can do at each discrete step of execution. It applies policy to individual actions, not just to the identity itself. In AI and automation, it limits tool use, data access, approvals, and side effects in real time.
- Identity Governance Control Plane: The identity governance control plane is the central layer that defines, coordinates, and enforces identity policies across systems. It manages access approvals, role assignments, certifications, segregation of duties, and lifecycle events for human and non-human identities, while maintaining auditability, policy consistency, and operational oversight across connected environments.
- Browser-Mediated AI Risk: Browser-mediated AI risk is exposure created when employees use public AI tools through a web browser instead of governed enterprise platforms. The risk comes from uncontrolled prompts, mixed account contexts, and limited visibility into what content is being submitted.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org