TL;DR: Traditional cloud-proxy SWG models fail when AI assistants, autonomous workflows, and encrypted application traffic dominate outbound activity, according to Island, while its endpoint-enforced architecture claims 90% of sessions skip cloud backhaul and 100% visibility into AI sessions and agent workflows. The governance shift is real: identity, data, and session control now have to move closer to the endpoint, where policy can still see the action.
At a glance
What this is: This is Island’s case that secure web gateway controls must move from cloud proxy centric inspection to endpoint enforcement for AI sessions, SaaS traffic, and non-browser outbound activity.
Why it matters: It matters because identity and access teams now have to govern AI-driven and human-driven outbound actions in the same control plane, with visibility into data movement and session behavior that proxy-only models often miss.
By the numbers:
- 100 to 1 in the enterprise.
- 90% of sessions skip the cloud backhaul
- 10x faster application access
- 100% visibility into AI sessions, agent workflows, and data interactions
👉 Read Island’s analysis of SWG enforcement for AI sessions and endpoint traffic
Context
Secure web gateway architecture was built around a human browsing model, where outbound traffic was relatively sparse, inspectable, and easy to anchor to a user session. That assumption is now under pressure from AI prompts, agent workflows, desktop SaaS clients, browser extensions, and background services generating continuous outbound activity.
For identity teams, the real issue is not just web filtering. It is where policy is enforced, how data loss prevention sees the action, and whether the organisation can attribute and control non-browser activity when the network layer no longer has full context.
Key questions
Q: How should security teams govern AI sessions that generate outbound web traffic?
A: Security teams should treat AI sessions as governed activity, not just application usage. The control model needs to bind identity, destination, action, and data handling together so that prompts, tool calls, and file movement are enforced as one session rather than separate events.
Q: Why do proxy-only SWG models struggle with modern identity-driven traffic?
A: Proxy-only models struggle because they assume the network sees enough of the interaction to make the right decision. In reality, encrypted sessions, desktop clients, and endpoint actions often hide the most important part of the event, which is how data is handled on the device.
Q: What breaks when data loss prevention only works at the network layer?
A: It misses actions that never become transit events, such as copying regulated data between apps, pasting into AI tools, or masking information inside the browser. That leaves the organisation with partial control and weak auditability for the most sensitive user actions.
Q: Who is accountable when endpoint-enforced web controls block a business workflow?
A: Accountability should sit with the team that owns the policy, the identity context, and the audit trail, not only the network team. When enforcement moves closer to the endpoint, governance has to include IAM, SecOps, and data protection ownership in the same decision chain.
Technical breakdown
Why cloud-proxy SWG inspection breaks down for AI and SaaS traffic
Traditional SWG models depend on routing traffic to the cloud, decrypting it, inspecting it, then sending it on. That works poorly when traffic is encrypted, pinned, or produced in parallel by AI workflows and desktop applications. The proxy can see the connection, but not always the meaningful action inside the session. The architectural gap is not just latency. It is that the control point sits too far from the interaction to govern data movement, application behaviour, and user intent in real time.
Practical implication: teams should test whether their SWG can still enforce policy when inspection is blocked, deferred, or blind to on-device activity.
Endpoint enforcement and DOM-layer control in the AI era
Endpoint-enforced SWG pushes policy closer to the actual interaction, including browser events and on-device data actions. DOM-layer control matters because copying, pasting, masking, blocking uploads, and redacting sensitive content can occur before anything becomes a network transaction. That changes the control boundary from packet inspection to activity inspection. In practice, this is where DLP, URL filtering, application controls, and session logging become identity-aware enforcement rather than simple transit filtering.
Practical implication: security teams need to map which controls must operate before the network sees the event and which can still be enforced in transit.
Why one policy framework and one audit log matter for identity governance
When browser traffic, desktop applications, AI tools, and background services are governed under separate consoles, teams lose consistency and cannot reconstruct behaviour cleanly. A single policy framework and a single audit log reduce that fragmentation by tying destination, action, user identity, and outcome together. That is especially useful for IAM, DLP, and SecOps because session-level accountability becomes searchable across traffic types instead of trapped in disconnected tools.
Practical implication: identity governance teams should demand unified logs that preserve user, device, destination, and enforcement outcome across browser and non-browser channels.
NHI Mgmt Group analysis
Proxy-only SWG is becoming a governance assumption failure, not just a performance problem. The older model assumes outbound activity is sparse enough, visible enough, and centralized enough to inspect at the network edge. AI sessions and desktop-originated traffic invalidate that assumption because the meaningful control point has moved inside the endpoint. Practitioners should treat this as a structural governance change, not a tuning issue.
Endpoint-enforced web control creates an identity blast radius model for outbound activity. Once browser, SaaS, AI, and background processes are all governed through one enforcement plane, the question becomes which actions are allowed to leave the device at all. That is a different identity problem from classic proxy filtering because it binds session context, user identity, and data action into the same decision surface. The implication is that policy scope now has to follow the session, not just the URL.
Identity governance for AI-era browsing now extends beyond authentication into action attribution. Knowing who authenticated is not enough if an agent, extension, or background service generates the actual outbound event. This is where SWG and IAM overlap: the organisation needs to know which identity initiated, which process executed, and what data moved. Teams should treat outbound action attribution as part of access governance, not only threat detection.
The named concept here is endpoint-visible session governance. It describes the shift from inspecting network traffic after the fact to governing the interaction where it occurs, on the device, with the full session context intact. That matters because encrypted, pinned, and AI-mediated sessions erase much of the proxy’s visibility. Practitioners should see endpoint visibility as a prerequisite for enforceable policy, not as a supplemental telemetry source.
Agent-scale traffic changes the economics of web security architecture. A world where agents outnumber humans forces controls to handle volume, parallelism, and machine-driven repetition that were not central to legacy SWG design. The control plane must be able to keep up with runtime activity rather than only with user browsing habits. That pushes programmes toward policy models that are endpoint-aware, identity-aware, and session-aware at the same time.
From our research:
- The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
- 43% of security professionals are concerned about AI systems learning and reproducing sensitive information patterns from codebases, according to The State of Secrets in AppSec.
- For a broader identity lens, see Ultimate Guide to NHIs , Lifecycle Processes for Managing NHIs for lifecycle controls that now need to extend beyond human sessions.
What this signals
With 43% of security professionals already worried about AI systems reproducing sensitive information patterns from codebases, the governance problem is no longer limited to browser control. Endpoint-visible session governance becomes the practical requirement when data can move through prompts, desktop clients, and background processes outside the proxy’s field of view.
Endpoint-visible session governance: this is the shift from network-centric inspection to device-level enforcement that can see the action before it becomes a packet. That matters because AI-era browsing blends human, machine, and agent activity into one workflow, and the policy boundary has to follow the session rather than the destination.
For practitioners
- Validate SWG enforcement at the endpoint. Test whether policy still applies when traffic never reaches the cloud proxy, especially for browser actions, SaaS clients, and AI sessions that generate local activity.
- Map identity to outbound action. Require logs that tie user identity, device, destination, action, and outcome together so SecOps can reconstruct what actually happened during a session.
- Separate transit inspection from on-device control. Identify which controls need to block copy, paste, upload, or redaction before data becomes network traffic, and which controls can remain at the proxy layer.
- Reassess visibility for encrypted sessions. Check whether SSL pinning, modern protocols, or desktop-originated workflows are creating blind spots that your current cloud proxy cannot inspect.
- Unify policy and audit trails across traffic types. Avoid separate rule systems for browser, desktop, AI, and non-browser activity when the organisation needs one enforcement model and one incident timeline.
Key takeaways
- Legacy SWG assumptions are weakening because AI sessions, encrypted traffic, and endpoint actions now carry more of the risk than the network edge can see.
- Island’s numbers point to a material architectural shift, with 90% of sessions skipping cloud backhaul and 100% visibility claimed for AI sessions and agent workflows.
- Identity teams should treat outbound control as a session governance problem, not just a web filtering problem, and require logs that preserve user, device, action, and outcome.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | AI sessions and agent workflows are explicitly in scope for agentic application risk. | |
| OWASP Non-Human Identity Top 10 | NHI-07 | Desktop services and AI workflows behave like non-human identities at the control layer. |
| NIST CSF 2.0 | PR.AC-4 | The post centres on access enforcement and session-level control. |
| NIST Zero Trust (SP 800-207) | 5.2 | The article argues for continuous verification beyond the network perimeter. |
Shift enforcement closer to the endpoint and verify session context continuously instead of trusting the network path.
Key terms
- Secure Web Gateway: A Secure Web Gateway is a control point for outbound web and application traffic that enforces policy, blocks threats, and reduces data leakage. In modern environments, the key question is not only what leaves the network, but where the decision to allow or block is made and how much session context is visible.
- Endpoint enforcement: Endpoint enforcement is the use of device-layer controls such as MFA, encryption, policy restrictions, and remote access rules to shape how a device can connect and operate. It is a control layer, not a full identity governance model, because it does not on its own manage entitlements or revocation.
- Data Loss Prevention: Data loss prevention is the set of controls used to detect, block, and report sensitive data moving in ways the organisation does not allow. In practice, DLP must account for endpoints, email, cloud apps, APIs, and user behaviour, or it will miss the paths where real exposure happens.
- Session Governance: The practice of binding access to a specific task, time window, and execution context, then revoking it when the work is done. For non-human identities, session governance matters because tokens and delegated permissions often persist longer than the action they were created to support.
What's in the full article
Island's full blog covers the operational detail this post intentionally leaves for the source:
- Policy mechanics for browser-originated traffic, non-browser traffic, and AI session enforcement across the same console
- Endpoint enforcement workflow for DLP, URL filtering, malware scanning, and application access control
- Deployment options across Island Desktop, explicit proxy, and IPsec tunnel for different managed environments
- Audit and integration detail for SIEM, SOAR, and incident reconstruction use cases
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building identity governance capability across human and non-human systems, it is worth exploring.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org