Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI sessions and endpoint enforcement: what changes for SWG teams?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Traditional cloud-proxy SWG models fail when AI assistants, autonomous workflows, and encrypted application traffic dominate outbound activity, according to Island, while its endpoint-enforced architecture claims 90% of sessions skip cloud backhaul and 100% visibility into AI sessions and agent workflows. The governance shift is real: identity, data, and session control now have to move closer to the endpoint, where policy can still see the action.

NHIMG editorial — based on content published by Island: Island Secure Web Gateway, SWG for the AI Era

By the numbers:

Questions worth separating out

Q: How should security teams govern AI sessions that generate outbound web traffic?

A: Security teams should treat AI sessions as governed activity, not just application usage.

Q: Why do proxy-only SWG models struggle with modern identity-driven traffic?

A: Proxy-only models struggle because they assume the network sees enough of the interaction to make the right decision.

Q: What breaks when data loss prevention only works at the network layer?

A: It misses actions that never become transit events, such as copying regulated data between apps, pasting into AI tools, or masking information inside the browser.

Practitioner guidance

  • Validate SWG enforcement at the endpoint. Test whether policy still applies when traffic never reaches the cloud proxy, especially for browser actions, SaaS clients, and AI sessions that generate local activity.
  • Map identity to outbound action. Require logs that tie user identity, device, destination, action, and outcome together so SecOps can reconstruct what actually happened during a session.
  • Separate transit inspection from on-device control. Identify which controls need to block copy, paste, upload, or redaction before data becomes network traffic, and which controls can remain at the proxy layer.

What's in the full article

Island's full blog covers the operational detail this post intentionally leaves for the source:

  • Policy mechanics for browser-originated traffic, non-browser traffic, and AI session enforcement across the same console
  • Endpoint enforcement workflow for DLP, URL filtering, malware scanning, and application access control
  • Deployment options across Island Desktop, explicit proxy, and IPsec tunnel for different managed environments
  • Audit and integration detail for SIEM, SOAR, and incident reconstruction use cases

👉 Read Island’s analysis of SWG enforcement for AI sessions and endpoint traffic →

AI sessions and endpoint enforcement: what changes for SWG teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Proxy-only SWG is becoming a governance assumption failure, not just a performance problem. The older model assumes outbound activity is sparse enough, visible enough, and centralized enough to inspect at the network edge. AI sessions and desktop-originated traffic invalidate that assumption because the meaningful control point has moved inside the endpoint. Practitioners should treat this as a structural governance change, not a tuning issue.

A few things that frame the scale:

  • The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
  • 43% of security professionals are concerned about AI systems learning and reproducing sensitive information patterns from codebases, according to The State of Secrets in AppSec.

A question worth separating out:

Q: Who is accountable when endpoint-enforced web controls block a business workflow?

A: Accountability should sit with the team that owns the policy, the identity context, and the audit trail, not only the network team. When enforcement moves closer to the endpoint, governance has to include IAM, SecOps, and data protection ownership in the same decision chain.

👉 Read our full editorial: Island SWG for the AI era shifts control to the endpoint



   
ReplyQuote
Share: