TL;DR: Telemetry shows the average organisation has 16 AI apps, 17 AI browser extensions, and 17 AI OAuth integrations in use, according to Push Security, while separate analysis argues that blocking AI tools only hides how employees actually use them. The governance gap is visibility, control, and policy enforcement across the browser layer.
At a glance
What this is: This is an analysis of shadow AI governance in the browser, with the key finding that organisations are using more AI apps, extensions, and OAuth integrations than their control plane typically sees.
Why it matters: It matters because IAM, IGA, and security teams need visibility into AI usage patterns before they can govern access, approvals, and revocation across human, NHI, and emerging agentic workflows.
By the numbers:
- Push telemetry shows the average organisation has 16 AI apps, 17 AI browser extensions, and 17 AI OAuth integrations in use.
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes, and as quickly as 9 minutes in some cases.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities.
👉 Read Push Security's analysis of shadow AI discovery and browser control
Context
Shadow AI is not just an application usage problem. It becomes an identity governance problem as soon as employees connect AI tools, browser extensions, and OAuth integrations to enterprise accounts without central visibility or lifecycle control. In that state, the browser becomes the control gap between sanctioned identity policy and actual AI usage.
Push Security's browser-focused analysis frames the issue around visibility and enforcement in the browser, where most AI usage now occurs. For IAM and security teams, the practical question is no longer whether AI is present, but whether the organisation can see which identities, tokens, and integrations are already in play.
This is typical of modern AI adoption: the workforce moves faster than the governance layer, and the browser is where the mismatch shows up first. That makes browser telemetry, access review, and OAuth governance part of the same operational conversation.
Key questions
Q: How should security teams govern Shadow AI in everyday browser use?
A: Security teams should govern Shadow AI by enforcing controls where users actually interact with AI tools, not only at the network edge. That means browser-level inspection, content classification, and policy enforcement for paste, upload, and prompt actions. If users can move sensitive data into an AI tool without a control decision, the governance model is incomplete.
Q: Why do AI browser extensions and OAuth integrations create governance risk?
A: They extend enterprise identity into tools that may be added outside normal procurement or review, often with broad delegated scopes. That can leave persistent access in place after the user forgets it, changes role, or leaves the organisation. The risk is less about the tool label and more about unmanaged authorisation lifecycle.
Q: How do you know if Shadow AI controls are working?
A: Look for a shrinking set of approved AI services, visible logs for prompt and integration activity, clear data-class restrictions, and documented review steps for outputs. If employees still rely on unofficial tools for core work, the programme is not yet governing behaviour, only issuing guidance.
Q: What should IAM teams do when employees keep using unsanctioned AI tools?
A: Provide a sanctioned alternative, then enforce access policy through identity and browser controls rather than relying on awareness campaigns alone. If users can still connect unmanaged AI services to enterprise data, the control design is failing. IAM teams should align acceptable use, OAuth review, and revocation so policy can be enforced in practice.
Technical breakdown
Why browser telemetry matters for shadow AI discovery
Browser telemetry is the data generated by user activity in the browser, including visited apps, extensions in use, and auth flows that touch enterprise identity. For shadow AI, it matters because many AI interactions never pass through a central procurement or security workflow. The browser can reveal which tools are actually being used, which accounts are being connected, and whether access is happening through personal or corporate identities. Without that signal, teams are governing a partial inventory, not the real one.
Practical implication: treat browser telemetry as a discovery control for AI apps and linked identities, not just a detection feed.
OAuth integrations and the hidden identity surface
OAuth integrations create delegated access that can persist after the initial login moment. In AI workflows, that means a user can authorise a tool once, then continue using it with broad access to mail, files, or SaaS data long after the original context has been forgotten. The governance challenge is not only consent at grant time, but lifecycle oversight after grant. That is an identity problem because the risk sits in the token, the scope, and the offboarding gap, not just the application label.
Practical implication: inventory AI-related OAuth grants and review them as standing access, not one-time approvals.
Why blocking AI tools often fails as a control strategy
Blocking AI apps at the network or policy layer does not remove demand. It shifts usage into unmanaged paths, such as personal accounts, browser extensions, shadow SaaS, or unsanctioned workflow bridges. That creates a visibility deficit, not a real reduction in exposure. A control strategy that only prohibits usage can also weaken the organisation's ability to understand adoption, enforce acceptable use, or revoke access cleanly when employees leave or roles change.
Practical implication: pair policy restriction with governed access paths, otherwise you create blind spots rather than control.
NHI Mgmt Group analysis
Browser-visible AI use is now an identity inventory problem, not just an acceptable-use problem. Once AI apps, browser extensions, and OAuth integrations are in active use, the real question is which identities have already been linked to which services. That moves the issue from policy language into identity governance, because inventory, entitlement, and revocation all depend on seeing the actual access paths. Practitioners should treat browser discovery as a prerequisite for AI governance.
Shadow AI exposes the limits of consent-based control models. A one-time approval is a weak foundation when users can connect multiple tools, reauthorise access, or shift between corporate and personal identities in the browser. The security model assumes a stable approval event, but AI usage is often iterative and distributed across sessions. The implication is that governance must follow the lifecycle of the token and the identity, not the moment of initial grant.
Browser control has become part of NHI governance because many AI integrations behave like delegated machine access. AI tools commonly operate through OAuth scopes, API keys, and connected services that function as non-human access paths even when a person initiated them. That makes the browser a front door to NHI sprawl, especially where employees can create integrations outside central review. Teams should stop separating browser security from identity governance.
Shadow AI creates an offboarding and recertification problem that traditional SaaS inventories miss. If the organisation cannot see which AI tools and extensions are connected to employee identities, it cannot reliably remove access when the user changes role or leaves. That gap is especially dangerous where AI tools touch email, documents, or internal knowledge systems. The governance implication is straightforward: access review must include browser-born AI connections, not just core IAM systems.
Visibility without enforcement is only half a control. Discovery shows what is already happening, but governance fails if teams cannot convert that discovery into scoped approvals, exceptions, and revocation workflows. The most useful AI browser controls are the ones that connect telemetry to identity policy, so security teams can decide what is sanctioned, what is tolerated, and what must be removed. Practitioners should measure whether discovery data changes access outcomes.
From our research:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
- Enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, a sign that one failure often becomes a repeat pattern.
- For a broader governance lens, NHI Lifecycle Management Guide shows why discovery alone is not enough without provisioning, rotation, and offboarding controls.
What this signals
Browser-discovered AI use should now be treated as governed identity inventory. The control challenge is no longer only detection, because once an AI tool is linked to a corporate identity or delegated via OAuth, it enters the same lifecycle risk surface as other non-human access. The broader governance signal is that browser visibility, recertification, and revocation are converging into one workflow for modern IAM teams.
With 17 AI browser extensions in the average organisation, per the 2026 Infrastructure Identity Survey, the scale of unmanaged access is already large enough to distort access reviews. Teams that still anchor review processes only on sanctioned SaaS will miss the browser-layer connections where AI usage actually happens. That gap is where shadow AI becomes persistent identity risk.
The practical next step is to align browser telemetry with identity policy and lifecycle controls, then use that signal to decide what gets sanctioned, what gets restricted, and what gets removed. NHI Lifecycle Management Guide is the right starting point for the lifecycle mechanics, while browser-focused discovery tells you where to apply them first.
For practitioners
- Inventory browser-born AI usage Map AI apps, browser extensions, and OAuth integrations observed in browser telemetry to the identities that authorised them. Use that inventory to identify unmanaged access paths and personal-account workarounds before setting policy.
- Review OAuth grants as standing access Treat AI-related OAuth authorisations like persistent delegated access, then recertify them on a defined schedule. Prioritise scopes that reach email, file storage, chat, or other high-value SaaS data.
- Link browser telemetry to access revocation Connect discovery findings to identity operations so that suspicious or unsanctioned AI access can be removed through the same offboarding and revocation processes used for other enterprise access.
- Create sanctioned paths for approved AI use Allow approved AI tools through governed identities, scopes, and policy checks so employees are less likely to route around controls with shadow SaaS or unmanaged extensions.
Key takeaways
- Shadow AI is fundamentally an identity governance problem because browser-based AI use creates unmanaged access paths, delegated tokens, and hidden integrations.
- The scale is already material, with the average organisation using 16 AI apps, 17 AI browser extensions, and 17 AI OAuth integrations.
- Security teams need discovery, recertification, and revocation to work together, or browser visibility will expose risk without reducing it.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-07 | Shadow AI maps to unmanaged non-human access and secret exposure. |
| NIST CSF 2.0 | PR.AC-1 | The topic is fundamentally about controlling and monitoring access paths. |
| NIST SP 800-53 Rev 5 | IA-5 | OAuth tokens and API keys are credentials requiring lifecycle oversight. |
| NIST Zero Trust (SP 800-207) | Browser-layer AI use fits zero trust assumptions about continuous verification. | |
| MITRE ATT&CK | TA0006 , Credential Access; TA0010 , Exfiltration | Compromised tokens and delegated access are the main threat paths. |
Inventory browser-born AI connections and enforce lifecycle controls on the identities behind them.
Key terms
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Delegated Access: Delegated access is permission granted to one identity to act on behalf of another user, service, or system. In NHI environments, this usually appears in OAuth-connected apps and automation tooling. It is powerful, but it must be tightly scoped and reviewed because it can persist long after the original business need ends.
- Browser telemetry: Browser telemetry is the event data produced by enterprise browser activity, including logins, profile changes, downloads, session starts, and extension or site interactions. In identity governance, it becomes useful when those events are correlated with account state and privilege context rather than treated as generic activity logs.
- OAuth Integration: An OAuth integration is a delegated trust relationship between applications that allows one service to access another on behalf of a user or workload. These connections can carry broad permissions, so compromise of one token can extend access across multiple systems and increase the blast radius.
What's in the full article
Push Security's full post covers the operational detail this post intentionally leaves for the source:
- Browser telemetry examples showing how AI use is surfaced across apps, extensions, and OAuth connections
- Practical guidance on how Push positions browser visibility for AI governance and control
- Examples of the control paths used to restrict shadow AI and unmanaged SaaS in the browser
- Details on how the browser layer supports incident investigation and data loss prevention
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org