TL;DR: AI regulations across the US, EU, and UK are converging on obligations that most organisations cannot meet without browser visibility into AI tool use, according to Push Security. That makes browser-level control a governance issue for NHI, human access, and emerging agentic workflows rather than a point product decision.
Editorial analysis by NHI Mgmt Group, based on content published by Push Security: “Meet with Push Security at Infosec”.
Key questions
Q: How should security teams govern employee use of public AI tools in the browser?
A: They should treat browser AI use as an identity and data-control problem, not just an acceptable-use issue.
Q: Why do IdP and EDR controls miss some AI activity?
A: IdP confirms authentication and EDR observes the endpoint, but neither always captures what a user does inside a browser-based AI session.
Practitioner guidance
- Define the browser as a governance boundary Map which AI use cases are only visible inside the browser and document which policy decisions depend on that visibility.
- Correlate identity and browser telemetry Pair IdP authentication logs with browser-layer events so AI tool usage can be evaluated in the context of the authenticated session.
- Classify browser-based AI activity separately Create a distinct policy category for browser-mediated AI interactions, including uploads, prompts and delegated tool use.
Bottom line: Browser visibility has moved from a tactical control to a governance requirement because much of AI use now happens inside the session.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Browser visibility is becoming part of identity governance, not a separate control category. The browser is where human intent, SaaS access, and AI tool use increasingly meet, which means security teams can no longer treat it as a passive delivery layer. If the browser is where decisions and data movement occur, then governance has to observe that layer as part of access control. Practitioners should treat browser telemetry as a governance input, not just an endpoint signal.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- That same research found that only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.
A question worth separating out:
Q: Who is accountable when browser-based AI activity causes data exposure?
A: Accountability usually sits with the organisation that owns the identity, the policy, and the monitoring gap. If browser activity is not observable, then neither user intent nor policy enforcement can be demonstrated cleanly. That is why governance teams need shared ownership across IAM, security, and compliance for browser-mediated AI activity.
👉 Read our full editorial: Browser visibility is now a control plane for AI governance
Browser visibility is becoming part of identity governance, not a separate control category. The browser is where human intent, SaaS access, and AI tool use increasingly meet, which means security teams can no longer treat it as a passive delivery layer. If the browser is where decisions and data movement occur, then governance has to observe that layer as part of access control. Practitioners should treat browser telemetry as a governance input, not just an endpoint signal.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- That same research found that only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.
A question worth separating out:
Q: Who is accountable when browser-based AI activity causes data exposure?
A: Accountability usually sits with the organisation that owns the identity, the policy, and the monitoring gap. If browser activity is not observable, then neither user intent nor policy enforcement can be demonstrated cleanly. That is why governance teams need shared ownership across IAM, security, and compliance for browser-mediated AI activity.
👉 Read our full editorial: Browser visibility is now a control plane for AI governance
Browser visibility is becoming the practical enforcement layer for AI governance. Policies about AI use are only meaningful if organisations can observe the action where it happens, and that is increasingly the browser. Identity systems can confirm who authenticated, but they often do not show what was typed, pasted, uploaded or delegated inside the session. The implication is that governance teams need to treat browser-layer evidence as part of the control plane, not as supplemental telemetry.
A question worth separating out:
Q: What is the difference between browser visibility and endpoint monitoring for AI risk?
A: Endpoint monitoring focuses on device behaviour, while browser visibility shows the session-level actions where AI interaction often happens. For AI governance, that distinction matters because the control question is frequently about prompts, uploads and tool use inside the browser, not just activity on the host.
👉 Read our full editorial: Browser visibility is now a control plane for AI governance