By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: Bishop FoxPublished October 17, 2025

TL;DR: Human behaviour, not exotic exploits, is becoming a repeatable enterprise data-loss path, according to Bishop Fox’s Enterprise AI and SaaS Data Security Report. The report found that 45% of employees use generative AI tools, 77% paste data into them, and 82% of those pastes come from personal, unmanaged accounts, while nearly 40% of uploaded files contain sensitive data.


At a glance

What this is: This report shows that everyday employee behaviour in browsers, SaaS apps, and generative AI tools is now a measurable source of enterprise data exposure.

Why it matters: It matters because IAM, DLP, and governance programmes must now account for unmanaged accounts, browser activity, and identity-linked SaaS usage, not just endpoint or file-based controls.

By the numbers:

👉 Read Bishop Fox's Enterprise AI and SaaS Data Security Report


Context

Enterprise AI and SaaS data exposure is increasingly a governance problem, not just a user-training problem. When employees copy, paste, upload, and prompt sensitive information in unmanaged environments, traditional controls built around endpoints, file shares, and static policy boundaries lose visibility. That is especially relevant to identity programmes because the risk often originates in personal accounts, unmanaged browser sessions, and shadow SaaS access rather than a conventional system breach.

The primary identity challenge is that access is now expressed through behaviour. Who is signed in, which account is personal or corporate, and whether that session is governed all determine whether sensitive data can leave the enterprise without detection. For IAM and NHI practitioners, this looks like an expanding trust boundary around human identity, SaaS identity, and the identity signals embedded in browser-based workflows.

Bishop Fox’s framing is typical of what offensive security teams now observe in real environments: small, routine actions create persistent leakage paths that are easy to miss in policy-only programmes. The lesson is not that AI tools are uniquely dangerous, but that unmanaged identity context makes them easier to misuse.


Key questions

Q: How should security teams govern browser-based AI agents in SaaS environments?

A: Security teams should govern browser-based AI agents as runtime actors, not as ordinary users or static integrations. Give each agent a distinct identity, constrain what it can do in-session, and monitor browser, identity, and SaaS logs together. The key control is not just login validation, but continuous authorization of live actions.

Q: Why do personal accounts create more data exposure risk than corporate sessions?

A: Personal accounts usually sit outside enterprise lifecycle control, so the organisation cannot reliably enforce conditional access, retention, offboarding, or auditability. Once sensitive data moves into that account, visibility drops sharply and the enterprise loses practical control over where the data is stored, shared, or reused.

Q: What breaks when DLP is still built around endpoints and email gateways?

A: It misses the way data now moves through SaaS, cloud, and AI workflows that do not pass through a small set of inspection points. Modern DLP has to understand the data itself, its context, and the identities that can reach it. Without that, enforcement becomes reactive and incomplete.

Q: How should organisations govern AI usage when employees use unapproved tools?

A: Organisations should start with visibility, not enforcement. If teams cannot see which apps, agents, or workflows are being used, they cannot assess data exposure or apply meaningful controls. Once usage is mapped, policy can shift from blanket bans to context-based decisions that reflect sensitivity, role, and business purpose.


Technical breakdown

How browser-based SaaS activity bypasses traditional DLP

Classic DLP was built to inspect files, email, and endpoint transfers, not the live interaction layer where modern work happens. Browser-based SaaS use changes the data path: users paste text into prompts, upload files directly to cloud services, and move data through authenticated sessions that may never touch a controlled file share. That reduces the effectiveness of perimeter inspection and makes policy enforcement dependent on browser telemetry, identity context, and SaaS governance. If the enterprise cannot see the account type, device trust, and application destination in real time, it cannot reliably distinguish routine work from policy-breaking data movement.

Practical implication: extend inspection and logging into browser sessions and sanctioned SaaS pathways, not just endpoint and email controls.

Why unmanaged accounts create identity blind spots

Unmanaged accounts break the chain between identity governance and data governance. Once a user copies enterprise data into a personal AI or SaaS account, the enterprise loses lifecycle control, visibility into retention, and the ability to enforce conditional access or offboarding. This is not only a human identity problem. It also affects NHI and service access patterns when integrations, bots, or shared accounts move data into third-party platforms without clear ownership. The result is a governance gap where authentication happened, but control did not follow the session or the data.

Practical implication: classify personal, unmanaged, and corporate accounts differently in access policy and monitoring logic.

How prompt and upload behaviour become an exfiltration channel

Generative AI tools and SaaS platforms turn ordinary user interactions into a high-volume data egress channel. A prompt can contain confidential text, and an upload can contain PII, PCI, credentials, or internal documents. Because the action looks like productivity, it is often permitted by default unless the programme has explicit controls for allowed applications, content inspection, and behavioural telemetry. This is where governance matters as much as technology: without ownership, policy, and enforcement aligned, the organisation sees individual events but misses the pattern of data drift across everyday workflows.

Practical implication: treat prompt and upload activity as monitored data movement, with controls matched to content sensitivity and account trust.


NHI Mgmt Group analysis

Human-speed data loss is now a governance failure, not a tooling edge case. The report shows that employees are routinely using generative AI and SaaS platforms in ways that bypass standard control assumptions. When 82% of pasted data originates from personal, unmanaged accounts, the enterprise is not dealing with isolated misuse. It is dealing with a repeatable governance model that has not caught up to where work happens. Practitioners should treat browser-based workflows as a primary control surface, not a secondary exception.

Identity context has become the deciding factor in data protection. Traditional DLP can only do so much if it does not know whether the session is corporate, personal, managed, or tied to an approved SaaS workflow. That creates a direct intersection with IAM and NHI governance because the session, the account, and the application identity all influence whether data leaves the organisation under control. Browser identity drift: the gap between authenticated access and governed access is where most leakage now occurs. Security teams should measure that gap explicitly.

Policy without enforcement produces a false sense of control. The report is clear that many AI and SaaS platforms operate outside corporate governance, and that convenience often wins over compliance. That pattern matches what security programmes see when application allowlisting, telemetry, and conditional access are not aligned with actual user behaviour. The relevant question is no longer whether policy exists, but whether it is technically enforceable across the full path from identity to prompt to upload. Practitioners should anchor governance to enforceable controls, not document-only standards.

Offensive testing should now model user behaviour as an attack path. Bishop Fox’s own red-team perspective reinforces a broader industry shift: exfiltration opportunities increasingly arise from routine interactions rather than exploitation of a technical vulnerability. That means testing needs to simulate prompt leakage, unmanaged SaaS use, and sensitive upload paths, then feed the findings into identity and access policy. The control problem is no longer just detection after loss. It is reducing the number of unmanaged paths a user can take with trusted data.

What this signals

The practical signal for security teams is that browser activity is becoming part of the identity perimeter. If your programme cannot distinguish managed from unmanaged accounts at the point of copy, paste, upload, and prompt, then AI governance, SaaS governance, and data protection will continue to fragment across separate tools and teams.

Browser identity drift: the enterprise now has to govern the space between authenticated access and controlled access. That means extending policy, telemetry, and approval logic into the actual work surface while using identity standards such as NIST Cybersecurity Framework 2.0 to organise governance, detection, and response expectations.

For identity leaders, the forward-looking issue is not whether AI tools exist in the environment, but whether they are attached to a clear ownership model and monitored account context. Teams that close the unmanaged-account gap now will be better positioned to absorb shadow AI, browser-based SaaS sprawl, and future agent-driven workflows without losing control.


For practitioners

  • Map AI and SaaS ownership to business accountability Assign a named owner for each approved AI tool, SaaS application, and integration path from procurement through monitoring. Tie policy decisions to that owner so that exceptions, review cycles, and enforcement actions have a clear decision-maker.
  • Extend visibility into browser-based work Capture copy, paste, upload, and prompt telemetry where users actually interact with data. Use that telemetry to distinguish corporate sessions from personal accounts and to identify where unmanaged workflows are moving sensitive information.
  • Enforce application boundaries for unapproved AI use Use application allowlisting, enterprise-hosted AI pathways, and conditional access to reduce unsanctioned exposure. Pair those controls with content-sensitive alerts so that high-risk data types trigger review when they appear in prompts or uploads.
  • Test user workflows like an attacker would Include prompt leakage, SaaS misuse, and data drift scenarios in red-team and penetration test plans. Validate whether your current controls can detect or block sensitive information when it is moved through the browser rather than through email or file transfer.

Key takeaways

  • Employee behaviour, especially in browsers and generative AI tools, is now a repeatable data exposure path that traditional controls often miss.
  • The biggest governance gap is unmanaged identity context, because personal accounts and shadow SaaS usage sever enterprise visibility and lifecycle control.
  • Security teams need enforceable browser telemetry, account classification, and workflow testing if they want to reduce data loss without blocking productive work.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the technical controls, while GDPR define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Identity-driven access control is central to unmanaged browser and SaaS data exposure.
NIST SP 800-53 Rev 5AC-6Least privilege is directly implicated when users move data into unmanaged AI and SaaS services.
NIST Zero Trust (SP 800-207)Continuous verification aligns with unmanaged browser and account trust decisions.
GDPRArt.32Sensitive data uploads and prompts can involve personal data protection obligations.

Use Art.32 to justify controls that protect personal data when users move it into AI and SaaS tools.


Key terms

  • Browser identity drift: The gap between who is authenticated and what the enterprise can actually govern inside a browser session. It matters because users often move between managed and unmanaged accounts, making access control, logging, and policy enforcement inconsistent across the same workflow.
  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Managed account: An account that sits under enterprise governance, including policy enforcement, monitoring, lifecycle control, and offboarding. Managed status does not eliminate risk, but it gives security teams a way to apply conditional access and accountability when data is handled.

What's in the full article

Bishop Fox's full report covers the operational detail this post intentionally leaves for the source:

  • The underlying enterprise browser activity analysis behind the 45%, 77%, 82%, and 40% findings
  • The offensive security examples showing how customer records, credentials, and confidential documents were recovered in assessments
  • The six recommended operating moves in full, including ownership, browser telemetry, and policy enforcement steps
  • The practical framing for translating behavioural risk into measurable governance and board-level reporting

👉 Bishop Fox's full report covers the browser activity findings, offensive security observations, and recommended governance moves.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, secrets management, and identity lifecycle controls that help teams manage modern access risk. It is designed for practitioners who need a stronger governance foundation across identity, access, and operational control.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 11, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org