Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Browser-based AI use: what it means for security teams


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Omdia’s Browser Management and Security report, cited by Island, says 55% of 400 enterprise IT and cybersecurity professionals saw a successful attack or near-miss through employee browser use in the past 12 months, while 59% say browser-based AI use is the least visible attack vector. The pattern shows why browser-native controls are becoming a governance issue for IAM, data protection, and shadow AI oversight.

NHIMG editorial — based on content published by Island: New Report: The Browser Is Now Enterprise Security's Biggest Blind Spot

By the numbers:

Questions worth separating out

Q: How should security teams govern AI browsers that can act on enterprise content?

A: They should govern them as access intermediaries, not just as user interfaces.

Q: Why do traditional tools struggle to secure the browser session?

A: Traditional tools usually govern traffic around the browser rather than actions inside it.

Q: What do security teams get wrong about browser AI risk?

A: Many teams focus on whether AI tools are allowed, but ignore the prompt itself as the exposure event.

Practitioner guidance

  • Map browser activity to governed identity and data flows Identify which browser workflows carry authentication, prompt submission, file transfer, and sensitive data movement, then classify them as governed access paths rather than general web traffic.
  • Control sanctioned and unsanctioned AI destinations Maintain an explicit allowlist for AI platforms that may receive company data, and block or warn on prompt submission to unsanctioned services.
  • Test whether existing tooling sees inside the session Validate whether VPNs, proxies, EDR, or DLP controls can detect copy-paste, downloads, extension use, and browser-based prompt activity before data leaves the session.

What's in the full report

Island's full blog covers the operational detail this post intentionally leaves for the source:

  • The full Omdia benchmark table on browser incident frequency, budget response, and top-five priority ranking
  • The breakdown of browser security spending shifts across IT and security teams, including funding ownership trends
  • The detailed productivity-impact metrics that show where browser security friction is actually appearing
  • The report’s application-access findings on browser-based and Windows workflows, which explain tool sprawl in more depth

👉 Read Island’s analysis of Omdia’s browser security findings and AI risk data →

Browser-based AI use: what it means for security teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Browser security has become an identity governance problem, not just an endpoint problem. The browser is now where authenticated users, sensitive data, AI prompts, and SaaS access converge. That means the main question is not whether a device is managed, but whether session activity is being governed at the point of action. Practitioners should treat browser controls as part of access governance, not as a separate perimeter add-on.

A question worth separating out:

Q: What should organisations do first if browser-based attacks are rising?

A: Start by identifying which browser workflows carry credentials, sensitive data, and AI interactions, then prioritise those paths for policy enforcement and audit logging. The first objective is not to block every browser action, but to control the highest-risk session behaviours where the greatest leakage and credential abuse occurs.

👉 Read our full editorial: Browser-based AI risk is exposing the limits of perimeter security



   
ReplyQuote
Share: