TL;DR: As AI agents move from browser-based use to desktop workflows, enterprises lose visibility into access, data handling, and policy enforcement, according to Lasso Security. That gap turns governance, compliance, and sensitive-data control into network-level identity problems, not just endpoint or browser issues.
Editorial analysis by NHI Mgmt Group, based on content published by Lasso Security: “Securing Desktop AI Agents with Palo Alto Networks Next-Generation Firewall Integration”.
Key questions
Q: What breaks when desktop AI agents are only governed at the browser layer?
A: Browser-only governance misses desktop-originated AI activity, so security teams lose reliable visibility into access, data handling, and policy enforcement.
Q: Why does desktop AI create a governance and compliance risk for IAM teams?
A: Because identity teams need traceability over who used an AI service, what data was sent, and which rule applied.
Q: What are the signs that AI use has become shadow AI in the desktop environment?
A: Common signs include unmanaged traffic to public AI services, unknown departments using local agents heavily, and data leakage reduction that cannot be explained by existing controls.
Practitioner guidance
- Map desktop AI traffic paths Identify which desktop applications, copilots, and agents reach public AI services so governance can follow the actual traffic path rather than the browser path.
- Correlate AI activity to user identity Tie outbound AI requests to user-level identity and policy context so security teams can explain who used which service and under what rule set.
- Define policy actions by data class Set explicit responses for customer data, personal data, code, financial records, and confidential materials, including block, alert, or mask outcomes.
Bottom line: Desktop AI agents are widening the gap between where work happens and where governance can still see it.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Desktop AI governance fails when organisations treat local AI use as a browser problem. Once agents move into desktop workflows, the control surface shifts from web sessions to network paths, endpoint activity, and local policy enforcement. That means browser-centric visibility leaves a blind spot around how AI is actually used, especially when employees adopt copilots or desktop assistants outside sanctioned flows. The practitioner conclusion is simple: the identity model must follow the execution path, not the interface.
A few things that frame the scale:
- 96% of technology professionals identify AI agents as a growing security threat, and 66% believe this risk is immediate, according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
A question worth separating out:
Q: Who is accountable when desktop AI tools transmit sensitive data?
A: Accountability should sit with the owning identity, the policy owner, and the team responsible for the control path that observed or failed to stop the transfer. If logging, masking, or blocking is incomplete, the accountability gap is a governance failure, not just an operational miss.
👉 Read our full editorial: Desktop AI agent governance needs network-level visibility
Desktop AI governance has become a network visibility problem because the control point moved. When AI use leaves the browser and enters desktop workflows, identity teams lose the clean boundary they used to rely on for enforcement. That shifts governance from session-centric oversight to traffic and interaction inspection, which is a different operating model. Practitioners should treat the network as part of the identity perimeter.
A few things that frame the scale:
- 19% of organisations give AI systems dramatically more access than human employees, nearly one in five granting unrestricted privilege, according to the 2026 Infrastructure Identity Survey.
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
A: Security teams should treat AI growth as a data governance and access problem, not only a model risk problem. The core controls are data classification, least privilege, continuous visibility into where sensitive data moves, and evidence that compliance policies are enforced across environments. Leadership needs a shared operating model that ties security, privacy, legal, and platform teams to clear accountability.
👉 Read our full editorial: Desktop AI agent governance needs network-level visibility