TL;DR: Shadow AI is expanding faster than many organisations can observe or govern, and Push Security argues that browser-level visibility is becoming the practical control point for discovering AI app use, browser extensions, and OAuth integrations across the workforce. The governance challenge is no longer whether employees use AI, but whether security teams can see, classify, and constrain that use before it becomes shadow SaaS, data loss, or identity sprawl.
At a glance
What this is: This article argues that AI use is already embedded in the browser, making browser visibility the control plane for discovering and governing shadow AI.
Why it matters: It matters to IAM practitioners because AI app use increasingly arrives through browser sessions, OAuth grants, and unmanaged identities that sit outside traditional app inventory and access review processes.
By the numbers:
- Push telemetry shows the average organization has 16 AI apps, 17 AI browser extensions, and 17 AI OAuth integrations in use.
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes and as quickly as 9 minutes in some cases.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities.
👉 Read Push Security's analysis of shadow AI discovery and browser control
Context
Shadow AI is the use of AI tools, extensions, or integrations that security teams have not formally inventoried or governed. In browser-centric work patterns, that problem quickly becomes an identity issue because access is created through OAuth grants, sessions, and managed or unmanaged browser profiles rather than through a clean application onboarding process.
The primary governance gap is visibility, then control. If a team cannot see which AI apps employees use, which extensions they install, or which SaaS tenants receive delegated access, it cannot reliably apply IAM, DLP, or lifecycle controls across the route by which data and credentials move.
For identity programmes, the article’s starting position is now typical, not exceptional: AI adoption is advancing faster than access governance, and the browser has become the place where that mismatch shows up first.
Key questions
Q: How should security teams govern Shadow AI in everyday browser use?
A: Security teams should govern Shadow AI by enforcing controls where users actually interact with AI tools, not only at the network edge. That means browser-level inspection, content classification, and policy enforcement for paste, upload, and prompt actions. If users can move sensitive data into an AI tool without a control decision, the governance model is incomplete.
Q: Why do browser-based AI extensions create identity risk for enterprise users?
A: They create identity risk because they can sit inside the authenticated session and see the same bearer tokens the user relies on. That means an apparently harmless productivity add-on can become a credential interception path, especially when it has access to web application runtime state and connected services.
Q: What do security teams get wrong about blocking AI tools outright?
A: They assume network blocking creates control, but users often shift to personal devices, browser workarounds, or OS-level agents that bypass those restrictions. Blocking can reduce visible risk while increasing shadow AI and making the governance problem harder to measure.
Q: Who is accountable when sensitive data is retained in a third-party AI tool?
A: Accountability sits with the organisation that allowed the data into the tool, even if the provider stores or processes it. Teams need clear ownership for prompt retention, deletion requests, and vendor data processing terms. If the provider cannot prove erasure or lineage, the organisation still carries the compliance and privacy risk.
Technical breakdown
Why the browser becomes the control plane for shadow AI
Browser-based AI use bypasses many traditional discovery points because it appears as normal web traffic, not as a sanctioned enterprise application. Once a user authenticates through OAuth or a federated login, the AI service can inherit data access without ever entering a central approval workflow. That makes the browser a practical observation layer for identity, session, and data-use governance. It also means unmanaged devices and personal profiles can participate in sanctioned workflows, expanding the control gap beyond endpoint agents alone.
Practical implication: discover and classify AI usage from browser telemetry, not only from application inventories or CASB data.
How OAuth sprawl turns AI tools into identity risk
OAuth integrations create delegated access that can persist long after the user stops actively using a tool. In shadow AI scenarios, the risk is not only the AI app itself but the combination of granted scopes, retained refresh tokens, and weak offboarding. If an AI extension or SaaS provider is compromised, the attacker may inherit the permissions originally approved by the user or tenant admin. This is why delegated access has to be treated as part of identity governance, not just SaaS hygiene.
Practical implication: inventory AI-related OAuth grants and review scopes, token lifetime, and revocation paths as part of access governance.
What browser telemetry adds to identity and data protection
Browser telemetry can show which pages, sessions, uploads, and copy actions occur inside AI tools, giving security teams context that endpoint or network logs often miss. That context helps distinguish sanctioned use from shadow use, and it supports data loss prevention where prompts or uploads may contain sensitive content. The same telemetry can also reveal when unmanaged identities are operating from personal browsers or BYOD environments, which is important because those sessions often sit outside normal control baselines.
Practical implication: use browser-layer evidence to connect identity, session behaviour, and data movement in one investigation path.
Threat narrative
Attacker objective: The attacker objective is to exploit unmanaged AI access paths to reach data, credentials, or downstream SaaS tenants with minimal friction.
- Entry begins when employees adopt AI apps, browser extensions, or OAuth-integrated services outside approved procurement and review processes.
- Escalation occurs when those tools inherit delegated access or session privileges that exceed the user’s intended task scope.
- Impact follows through exposed data, widened shadow SaaS exposure, or compromised third-party access paths that can be reused by attackers.
NHI Mgmt Group analysis
Browser-level discovery is now part of identity governance. AI use no longer sits neatly inside application inventories, because employees bring it in through browsers, personal accounts, and delegated integrations. That means IAM and IGA teams need a discovery model that starts with sessions and OAuth grants, not only with approved apps. The practitioner conclusion is simple: if the browser is ungoverned, the AI estate is ungoverned too.
Shadow AI creates a new form of identity sprawl. The issue is not just more tools, but more credentials, more tokens, and more unmanaged authorization paths attached to those tools. That is a classic governance problem in a new wrapper, and it links directly to NHI control gaps such as secret lifecycle, revocation, and owner accountability. The named concept here is browser-mediated identity sprawl: AI-related access that proliferates through browser sessions and OAuth approvals faster than it can be lifecycle-managed. Practitioners should treat that as an identity estate issue, not only a usage-policy issue.
Delegated access is the real security boundary for AI apps. Once an AI tool has OAuth scopes, the practical question becomes what it can see, export, or retain on behalf of the user or tenant. That makes scope review, token revocation, and third-party trust validation more important than simply approving or blocking the tool category. The practitioner conclusion is to govern the delegation chain, not just the front-end application.
Data-loss controls must move closer to the point of interaction. Traditional controls often arrive after data has already been entered into an AI interface or copied into an unmanaged extension. Browser telemetry gives security teams a chance to detect that behaviour in time to classify, block, or investigate it. The practitioner conclusion is to align DLP, identity, and browser policy around the same session context.
The market is converging on control over visibility, not prohibition. The article reflects a broader shift in security operations: organisations are less able to stop AI use outright, and more dependent on seeing where it happens and how it is authorised. That same pattern is now visible in NHI governance, where unmanaged service identities and AI-integrated tools create access that must be discovered before it can be controlled. Practitioners should expect browser-centric governance to become a standard part of identity architecture.
What this signals
Browser-mediated identity sprawl is likely to become a standard control concern as AI use shifts from standalone apps into delegated browser sessions and extensions. IAM teams should expect more pressure to connect SSO logs, browser telemetry, and OAuth consent data into one governance view, with NIST Cybersecurity Framework 2.0 as a useful organising reference.
The practical signal for programmes is that discovery is now an access-control problem, not just a shadow IT issue. Where AI sessions create delegated access, the same lifecycle questions that apply to NHIs apply here too, including ownership, scope, revocation, and offboarding. Teams that already use the NHI Lifecycle Management Guide will have a clearer path to extending those controls into AI-enabled browser workflows.
For practitioners
- Implement browser-based AI discovery Use browser telemetry to identify AI apps, extensions, and SaaS sessions before they enter your approved application catalogue. Tag usage by user, device, and tenant so access reviews can distinguish sanctioned from shadow behaviour.
- Review AI-related OAuth grants Inventory delegated permissions for AI tools, including scope breadth, refresh token lifetime, and revocation status. Fold those grants into access governance so third-party AI access is reviewed alongside other privileged integrations.
- Enforce browser-layer data controls Apply policy to uploads, prompts, copy actions, and downloads inside AI sessions so sensitive data is not handled only by downstream DLP controls. Where possible, combine browser policy with identity context from SSO and device posture.
- Map unmanaged AI use to identity owners Assign accountability for each AI app, extension, and OAuth integration to a named business and technical owner. Require offboarding and token revocation when the owner changes or the use case ends.
Key takeaways
- Shadow AI is an identity governance problem because access now arrives through browsers, OAuth grants, and unmanaged sessions.
- Visibility has to come before control, because organisations cannot govern AI use they cannot see.
- Browser telemetry, delegated access review, and lifecycle ownership are the controls most likely to narrow the shadow AI gap.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 address the attack surface, NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-01 | Browser discovery and access visibility map to identity and authentication oversight. |
| NIST Zero Trust (SP 800-207) | Browser sessions and unmanaged devices fit zero trust access assumptions. | |
| OWASP Agentic AI Top 10 | AI tool use through extensions and integrations raises agentic governance concerns. | |
| NIST AI RMF | GOVERN | AI use governance needs ownership and accountability across business and security teams. |
| ISO/IEC 27001:2022 | A.5.15 | Access control policy is directly relevant to shadow AI authorization paths. |
Review AI-enabled workflows for delegated access, data exposure, and boundary violations.
Key terms
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Browser-mediated identity: Browser-mediated identity is access that is established, maintained, or abused through the web session rather than only through a traditional login boundary. It matters because cookies, tokens, and session state can become attack assets, especially when unmanaged devices and SaaS applications are involved.
- Delegated Access: Delegated access is permission granted to one identity to act on behalf of another user, service, or system. In NHI environments, this usually appears in OAuth-connected apps and automation tooling. It is powerful, but it must be tightly scoped and reviewed because it can persist long after the original business need ends.
- Browser telemetry: Browser telemetry is the event data produced by enterprise browser activity, including logins, profile changes, downloads, session starts, and extension or site interactions. In identity governance, it becomes useful when those events are correlated with account state and privilege context rather than treated as generic activity logs.
What's in the full article
Push Security's full post covers the operational detail this post intentionally leaves for the source:
- How its browser visibility model identifies AI apps, extensions, and SaaS use across real sessions
- Examples of the telemetry signals used to separate sanctioned AI use from shadow use
- The control workflow for turning browser discovery into policy, investigation, and response
- The article's practical framing for teams evaluating browser security as an AI governance control
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps identity and security practitioners build lifecycle controls that scale across modern access paths.
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org