TL;DR: The real question is not how much AI exists in the workforce, but how much of it is reachable through browser-based identity paths, where stolen credentials, compromised tokens, shadow SaaS, and unmanaged access create control blind spots, according to Push Security. That shifts the programme from awareness and inventory toward browser-level visibility, detection, and guardrails.
NHIMG editorial — based on content published by Push Security: AI in the workforce and browser-based identity risk
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities.
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes.
Questions worth separating out
Q: How should security teams handle AI app usage that appears only in browser sessions?
A: Security teams should treat browser-discovered AI usage as a discovery and governance problem, not just an acceptable-use issue.
Q: Why do browser-based attacks bypass many IAM controls?
A: They exploit the point after authentication succeeds.
Q: What breaks when organisations rely on awareness training instead of browser controls?
A: Training can reduce risky behavior, but it cannot stop a live credential from being pasted, a token from being replayed, or a session from being hijacked.
Practitioner guidance
- Instrument browser telemetry as an identity signal Feed browser events into account takeover, SaaS risk, and access governance workflows so token abuse and suspicious login paths are visible in real time.
- Build a shadow AI discovery workflow Inventory AI apps that appear through browser sessions, then classify whether they are sanctioned, unmanaged, or personal-use services that touch corporate data.
- Tie token misuse to immediate containment Automate session revocation, token invalidation, and step-up review when a browser session shows credential reuse, suspicious redirection, or unmanaged device access.
What's in the full article
Push Security's full post covers the operational detail this post intentionally leaves for the source:
- Specific browser telemetry patterns that expose compromised credentials and tokens during real sessions
- Examples of how browser-based controls can interrupt account takeover and data loss paths
- Practical distinctions between sanctioned AI use, shadow AI, and unmanaged SaaS access
- Implementation detail on how browser guardrails fit into detection and response workflows
👉 Read Push Security's analysis of browser-based AI identity risk →
AI in the workforce: what browser security teams need to control?
Explore further
Browser security is now an identity control plane, not a side control. When credentials, sessions, and SaaS access all converge in the browser, the traditional boundary between endpoint security and IAM stops being useful. That means identity teams have to treat browser events as first-class access signals, not just web activity. The practical conclusion is that control ownership must span IAM, SOC, and browser telemetry.
A few things that frame the scale:
- The average organisation believes more than 1 in 5 of their non-human identities are insufficiently secured, according to The 2024 ESG Report: Managing Non-Human Identities.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, which shows the issue is already operational rather than theoretical.
A question worth separating out:
Q: How do security teams decide whether to prioritise browser security or IdP hardening?
A: They should not treat it as an either-or choice. IdP hardening protects the front door, but browser security protects the active session where many modern attacks actually succeed. If the organisation sees shadow SaaS, token theft, or AI app sprawl, browser controls should be prioritised alongside IdP policy.
👉 Read our full editorial: AI in the workforce is a browser security problem, not a headcount metric