Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Shadow AI in the browser: what IAM teams need to know


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: The average organisation now has 16 AI apps, 17 AI browser extensions, and 17 AI OAuth integrations in use, showing that Shadow AI is already embedded in everyday browser workflows, according to Push Security. The governance gap is no longer discovery alone; it is controlling how AI apps inherit identity, consent, and browser-session access.

NHIMG editorial — based on content published by Push Security: Shadow AI: how to discover, govern, and secure AI apps

By the numbers:

Questions worth separating out

Q: How should security teams govern Shadow AI in everyday browser use?

A: Security teams should govern Shadow AI by enforcing controls where users actually interact with AI tools, not only at the network edge.

Q: Why do AI browser extensions and OAuth integrations create governance risk?

A: They extend enterprise identity into tools that may be added outside normal procurement or review, often with broad delegated scopes.

Q: What breaks when Shadow AI is handled only as a procurement issue?

A: Procurement-only controls miss the fact that employees can adopt new AI tools continuously in the browser, often before IT sees them.

Practitioner guidance

  • Map AI usage from the browser outward Correlate browser telemetry, SaaS logs, and identity data to identify AI apps, extensions, and OAuth grants that are active in the workforce.
  • Review delegated AI access separately from app inventory Track OAuth consents for AI tools as governed access relationships, with owner, scope, and revocation status.
  • Use in-browser guardrails to steer behaviour Apply banners, policy prompts, or blocks at the point of access for high-risk AI use cases such as unapproved data upload or unmanaged SaaS connections.

What's in the full article

Push Security's full blog post covers the operational detail this post intentionally leaves for the source:

  • How Push data identifies AI apps, browser extensions, and OAuth integrations in active workforce use
  • The browser-level controls used to surface banners, restrict access, and guide users toward approved AI paths
  • The specific telemetry signals security teams can use to distinguish sanctioned adoption from Shadow AI
  • The product and workflow details behind browser-based visibility for unmanaged AI usage

👉 Read Push Security’s analysis of Shadow AI discovery and browser controls →

Shadow AI in the browser: what IAM teams need to know?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Shadow AI is an identity governance problem before it is an AI problem. The moment a user authorises an AI app, extension, or connector, the organisation has created a new identity relationship that must be discovered, governed, and revoked like any other access path. That is why browser-centric discovery matters: it exposes the control plane where consent happens, not just where traffic flows. Practitioners should treat Shadow AI as an unmanaged access estate, not a tooling fad.

A few things that frame the scale:

A question worth separating out:

Q: What should IAM teams change when AI is added to the environment?

A: IAM teams should expand ownership, review, and offboarding processes so they apply to AI services and supporting non-human identities, not only human users. AI introduces assets that can be provisioned quickly, used broadly, and left behind without a clear leaver event. Lifecycle governance has to follow that pattern.

👉 Read our full editorial: Shadow AI telemetry shows AI sprawl is already in the browser



   
ReplyQuote
Share: