Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI governance policy gaps: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15737
Topic starter  

TL;DR: Cyber Security Tribe’s 2026 Annual State of the Industry Report, based on 455 cybersecurity practitioners, finds AI governance exists in many organisations but enforcement is inconsistent, autonomous AI systems are already in production, and browser-layer visibility remains a major blind spot, according to the report. Policy without technical enforcement is not governance when AI tools, data handling, and delegated actions happen inside the browser.

NHIMG editorial — based on content published by Island: Where AI Security Breaks Down

By the numbers:

Questions worth separating out

Q: How should security teams choose between browser-based and network-level AI governance?

A: Security teams should choose based on where AI activity actually happens.

Q: Why do agentic AI systems complicate existing IAM and PAM controls?

A: They complicate them because IAM and PAM were built around stable identities, human-paced approvals, and entitlements that are reviewed after use.

Q: What breaks when security tooling only sees the browser?

A: Authorisation gaps, hidden endpoints, and machine-to-machine access paths go untested.

Practitioner guidance

  • Enforce AI policy at the session level Move from written acceptable-use rules to technical controls that can approve, block, or log AI interactions inside the browser session where prompts and uploads actually occur.
  • Classify agentic systems as access-bearing entities Define which AI systems can act on behalf of users, what tools they can call, and which datasets they can touch, then require ownership and review for each delegated workflow.
  • Close browser visibility gaps Correlate browser activity with identity, endpoint, and SaaS logs so copy, paste, file transfer, and prompt submission events can be investigated as part of one access chain.

What's in the full report

Island's full article covers the operational detail this post intentionally leaves for the source:

  • How the browser-native control model enforces AI policy at the point of interaction across managed and unmanaged devices
  • The report’s detailed breakdown of how security leaders are prioritising Zero Trust, IAM, and risk controls in 2026
  • Specific examples of browser-layer activity that network and endpoint tools miss, including copy, paste, uploads, and prompts
  • The article’s discussion of how organisations are handling AI governance, visibility, and auditability under budget pressure

👉 Read Island’s analysis of the Cyber Security Tribe 2026 State of the Industry Report →

AI governance policy gaps: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15322
 

Policy-only AI governance is a control illusion. When organisations rely on acceptable-use language without an enforcement layer, they are describing intent rather than governing behaviour. The report shows that compliance depends on employee judgement in the exact place where convenience defeats policy. For IAM and security teams, this is a governance failure because the control objective is not written approval, it is enforced boundary control.

A question worth separating out:

Q: Who is accountable when an AI browser exposes sensitive data or makes a bad decision?

A: The organisation remains accountable for the access path it allowed. Security, IAM, and data-governance teams should jointly define approval boundaries, logging requirements, and content restrictions before deployment. If the browser can act across regulated systems, then its governance must be explicit before use, not after failure.

👉 Read our full editorial: AI governance fails when enforcement stops at policy alone



   
ReplyQuote
Share: