Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Shadow AI in the browser: what IAM teams need to see


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Telemetry shows the average organisation has 16 AI apps, 17 AI browser extensions, and 17 AI OAuth integrations in use, according to Push Security, while separate analysis argues that blocking AI tools only hides how employees actually use them. The governance gap is visibility, control, and policy enforcement across the browser layer.

NHIMG editorial — based on content published by Push Security: Shadow AI: how to discover, govern, and secure AI apps

By the numbers:

Questions worth separating out

Q: How should security teams govern Shadow AI in everyday browser use?

A: Security teams should govern Shadow AI by enforcing controls where users actually interact with AI tools, not only at the network edge.

Q: Why do AI browser extensions and OAuth integrations create governance risk?

A: They extend enterprise identity into tools that may be added outside normal procurement or review, often with broad delegated scopes.

Q: How do you know if Shadow AI controls are working?

A: Look for a shrinking set of approved AI services, visible logs for prompt and integration activity, clear data-class restrictions, and documented review steps for outputs.

Practitioner guidance

  • Inventory browser-born AI usage Map AI apps, browser extensions, and OAuth integrations observed in browser telemetry to the identities that authorised them.
  • Review OAuth grants as standing access Treat AI-related OAuth authorisations like persistent delegated access, then recertify them on a defined schedule.
  • Link browser telemetry to access revocation Connect discovery findings to identity operations so that suspicious or unsanctioned AI access can be removed through the same offboarding and revocation processes used for other enterprise access.

What's in the full article

Push Security's full post covers the operational detail this post intentionally leaves for the source:

  • Browser telemetry examples showing how AI use is surfaced across apps, extensions, and OAuth connections
  • Practical guidance on how Push positions browser visibility for AI governance and control
  • Examples of the control paths used to restrict shadow AI and unmanaged SaaS in the browser
  • Details on how the browser layer supports incident investigation and data loss prevention

👉 Read Push Security's analysis of shadow AI discovery and browser control →

Shadow AI in the browser: what IAM teams need to see?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Browser-visible AI use is now an identity inventory problem, not just an acceptable-use problem. Once AI apps, browser extensions, and OAuth integrations are in active use, the real question is which identities have already been linked to which services. That moves the issue from policy language into identity governance, because inventory, entitlement, and revocation all depend on seeing the actual access paths. Practitioners should treat browser discovery as a prerequisite for AI governance.

A few things that frame the scale:

  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
  • Enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, a sign that one failure often becomes a repeat pattern.

A question worth separating out:

Q: What should IAM teams do when employees keep using unsanctioned AI tools?

A: Provide a sanctioned alternative, then enforce access policy through identity and browser controls rather than relying on awareness campaigns alone. If users can still connect unmanaged AI services to enterprise data, the control design is failing. IAM teams should align acceptable use, OAuth review, and revocation so policy can be enforced in practice.

👉 Read our full editorial: Shadow AI visibility in the browser is now an IAM problem



   
ReplyQuote
Share: