TL;DR: The average organisation now has 16 AI apps, 17 AI browser extensions, and 17 AI OAuth integrations in use, showing that Shadow AI is already embedded in everyday browser workflows, according to Push Security. The governance gap is no longer discovery alone; it is controlling how AI apps inherit identity, consent, and browser-session access.
NHIMG editorial — based on content published by Push Security: Shadow AI: how to discover, govern, and secure AI apps
By the numbers:
- Push Security says the average organization has 16 AI apps in use.
- Push Security says the average organization has 17 AI browser extensions in use.
- Push Security says the average organization has 17 AI OAuth integrations in use.
Questions worth separating out
Q: How should security teams govern Shadow AI in everyday browser use?
A: Security teams should govern Shadow AI by enforcing controls where users actually interact with AI tools, not only at the network edge.
Q: Why do AI browser extensions and OAuth integrations create governance risk?
A: They extend enterprise identity into tools that may be added outside normal procurement or review, often with broad delegated scopes.
Q: What breaks when Shadow AI is handled only as a procurement issue?
A: Procurement-only controls miss the fact that employees can adopt new AI tools continuously in the browser, often before IT sees them.
Practitioner guidance
- Map AI usage from the browser outward Correlate browser telemetry, SaaS logs, and identity data to identify AI apps, extensions, and OAuth grants that are active in the workforce.
- Review delegated AI access separately from app inventory Track OAuth consents for AI tools as governed access relationships, with owner, scope, and revocation status.
- Use in-browser guardrails to steer behaviour Apply banners, policy prompts, or blocks at the point of access for high-risk AI use cases such as unapproved data upload or unmanaged SaaS connections.
What's in the full article
Push Security's full blog post covers the operational detail this post intentionally leaves for the source:
- How Push data identifies AI apps, browser extensions, and OAuth integrations in active workforce use
- The browser-level controls used to surface banners, restrict access, and guide users toward approved AI paths
- The specific telemetry signals security teams can use to distinguish sanctioned adoption from Shadow AI
- The product and workflow details behind browser-based visibility for unmanaged AI usage
👉 Read Push Security’s analysis of Shadow AI discovery and browser controls →
Shadow AI in the browser: what IAM teams need to know?
Explore further
Shadow AI is an identity governance problem before it is an AI problem. The moment a user authorises an AI app, extension, or connector, the organisation has created a new identity relationship that must be discovered, governed, and revoked like any other access path. That is why browser-centric discovery matters: it exposes the control plane where consent happens, not just where traffic flows. Practitioners should treat Shadow AI as an unmanaged access estate, not a tooling fad.
A few things that frame the scale:
- The average organisation believes more than 1 in 5 of their non-human identities are insufficiently secured, according to The 2024 ESG Report: Managing Non-Human Identities.
- Enterprise teams that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, according to The 2024 ESG Report: Managing Non-Human Identities.
A question worth separating out:
Q: What should IAM teams change when AI is added to the environment?
A: IAM teams should expand ownership, review, and offboarding processes so they apply to AI services and supporting non-human identities, not only human users. AI introduces assets that can be provisioned quickly, used broadly, and left behind without a clear leaver event. Lifecycle governance has to follow that pattern.
👉 Read our full editorial: Shadow AI telemetry shows AI sprawl is already in the browser