TL;DR: Enterprise security stacks built around access control cannot see what happens inside browser sessions, where 59% of cybersecurity practitioners say browser-based AI use is the attack vector they monitor least, according to Island. The governance gap is no longer theoretical: control must move from the gate to the point of use if organisations want to reduce data exposure and shadow AI risk.
NHIMG editorial — based on content published by Island: What CISOs expect from an enterprise browser
By the numbers:
- 59% of cybersecurity practitioners identify browser-based AI use as the attack vector they are least able to monitor.
- 82% of respondents said security risk reduction is the leading expectation for an enterprise browser.
- 73% of organizations already have autonomous AI agent systems in use or in active development.
Questions worth separating out
Q: How should security teams control AI use in browsers without blocking productivity?
A: Security teams should focus on identity context, account separation, and data-sensitive enforcement rather than blanket blocking.
Q: Why do traditional network and endpoint controls miss so many browser attacks?
A: Because they observe traffic and device state, not the user’s actual actions inside the rendered page.
Q: What do organisations get wrong about browser security and zero trust?
A: Many organisations still think zero trust is only about verifying access before entry.
Practitioner guidance
- Map browser actions to policy outcomes Define which browser events matter most, including copy, paste, download, print, and AI prompt submission, then decide which ones require blocking, warning, logging, or step-up control.
- Separate access approval from in-session authority Review where your current access model stops and where session-level authority begins.
- Instrument shadow AI at the browser layer Track which browser-based AI tools are being used, what information is submitted, and whether those interactions are sanctioned.
What's in the full article
Island's full article covers the operational detail this post intentionally leaves for the source:
- Specific expectations CISOs are using to evaluate enterprise browser control across risk, visibility, and usability.
- Detailed examples of how browser-layer policy can restrict copy, paste, file saves, and print actions in active sessions.
- The article's discussion of unmanaged devices, contractors, and BYOD coverage without additional agents or proxies.
- The vendor's explanation of how browser-native controls differ from endpoint and SASE enforcement at the point of use.
👉 Read Island's article on what CISOs expect from an enterprise browser →
Enterprise browsers and last-mile control: are your policies keeping up?
Explore further
Browser-layer governance is becoming the missing control plane for modern work. When access and usage have moved into the browser, controls that stop at the gateway no longer define the real security boundary. That creates a policy gap between identity verification and in-session data handling, especially where AI tools are involved. Practitioners should treat browser governance as a distinct control domain rather than a convenience feature.
A question worth separating out:
Q: How do you know browser governance is actually working?
A: Look for fewer unauthorised extensions, consistent patching across approved browsers, broad password-manager coverage, and auditable identity provider handoff into SaaS applications. If users still bypass the approved browser or if exceptions are unmanaged, the control environment is fragmented. Effective governance shows up as standardisation and traceable policy enforcement, not just fewer tickets.
👉 Read our full editorial: Browser-layer control is now a governance problem, not just access