Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Browser-based AI agents and unmanaged apps: where identity breaks down


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15374
Topic starter  

TL;DR: Browser-based AI agents are widening an existing identity gap by acting inside unmanaged applications, where federation covers only 20 to 50 percent of enterprise apps according to Unixi. The real problem is delegated execution without task-level authority, attribution, or auditability, which makes browser-level governance essential.

NHIMG editorial — based on content published by Unixi: Browser-based AI agents and the unmanaged application identity gap

Questions worth separating out

Q: How should security teams govern browser-based AI agents in SaaS environments?

A: Security teams should govern browser-based AI agents as runtime actors, not as ordinary users or static integrations.

Q: Why do unmanaged applications create such a hard identity problem for AI agents?

A: Because the enterprise often cannot see the application, the credential, or the session, it also cannot reliably see the agent acting inside that session.

Q: What do security teams get wrong about AI agent identity governance?

A: They often assume human IAM patterns can be reused with minor adjustments.

Practitioner guidance

What's in the full article

Unixi's full article covers the operational detail this post intentionally leaves for the source:

  • How browser-level policy enforcement is applied across managed and unmanaged applications without replacing the identity provider
  • The delegation and attribution model for representing a human principal and an agent actor separately in audit logs
  • The browser-based control points used to bind authority to a task and revoke it without disabling the user account
  • The unmanaged-app workflow patterns that make shadow AI harder to see in standard IAM and SaaS logs

👉 Read Unixi's analysis of browser-based AI agents and unmanaged app identity risk →

Browser-based AI agents and unmanaged apps: where identity breaks down?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14958
 

Browser agents are not just another automation layer, they are a second actor inside the identity boundary. That distinction matters because governance built for human login events cannot reliably explain machine action taken after authentication succeeds. The field needs to stop treating the browser as an endpoint and start treating it as an enforcement surface for delegated execution. For practitioners, the conclusion is clear: identity governance must extend into the session where action actually happens.

A few things that frame the scale:

  • 100% of organisations report AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.

A question worth separating out:

Q: Who should be accountable when a browser agent exposes files or credentials?

A: Accountability should sit with the team that governs the delegated session, the identity permissions behind it, and the systems that allowed secret exposure or recovery changes. If an organisation lets an agent act inside a human session, then access review, PAM, and browser governance all share responsibility for the resulting blast radius.

👉 Read our full editorial: Browser-based AI agents expose the unmanaged app identity gap



   
ReplyQuote
Share: