Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Shadow AI in the browser: what identity teams are missing


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Browser visibility is now central to seeing how employees use AI apps, while shadow AI and shadow SaaS create governance gaps that network controls miss, according to Push Security. The underlying problem is not just detection but the loss of control over unmanaged access paths and session-level activity.

NHIMG editorial — based on content published by Push Security: Shadow AI: how to discover, govern, and secure AI apps

Questions worth separating out

Q: How should security teams govern Shadow AI in everyday browser use?

A: Security teams should govern Shadow AI by enforcing controls where users actually interact with AI tools, not only at the network edge.

Q: Why do proxies miss so much browser-based identity risk?

A: Proxies inspect traffic in transit, but they do not reliably show the full session context after authentication.

Q: Why do browser security decisions matter for IAM teams?

A: Because the browser is where users enter credentials, approve OAuth grants, and reuse sessions, so it has become an identity control surface.

Practitioner guidance

  • Implement browser-level identity telemetry Collect session evidence for SaaS and AI app use so security teams can see which identities authenticated, which apps were accessed, and what actions occurred inside the browser.
  • Tie shadow AI discovery to identity ownership Do not stop at app discovery.
  • Extend incident response to browser sessions Add browser telemetry to triage for account takeover, suspected data loss, and AI session abuse so responders can reconstruct user activity without relying only on network logs.

What's in the full article

Push Security's full blog post covers the operational detail this post intentionally leaves for the source:

  • Browser security product positioning for detecting account takeover, shadow SaaS, and AI app usage in-session
  • Examples of the browser telemetry used to investigate identity abuse and browser-related incidents
  • How the vendor frames secure browsing across managed devices, BYOD, and Chromebooks
  • The specific browser-based use cases the product is designed to observe and control

👉 Read Push Security’s analysis of shadow AI and browser-based identity risk →

Shadow AI in the browser: what identity teams are missing?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Browser visibility is now an identity control problem, not a network monitoring problem. When users authenticate, reuse sessions, and move data inside the browser, the enforcement point shifts away from the proxy and toward the session itself. That means identity teams need to think in terms of governed access paths, not just authenticated traffic. The implication is that browser telemetry belongs in the same conversation as IAM, IGA, and session governance.

A few things that frame the scale:

  • 72% of breach incidents involve a human element, showing how identity and session misuse remain central to real-world compromise, according to 52 NHI Breaches Analysis.
  • 2.7 separate incidents was the average for organisations that experienced a compromised non-human identity in the 2024 ESG report, reinforcing how repeat exposure becomes a governance pattern.

A question worth separating out:

Q: What should organisations do when browser telemetry reveals unsanctioned AI use?

A: Classify the session, identify the identity behind it, and determine whether the behaviour represents policy violation, training need, or data exposure. Then feed the finding into access review, offboarding, and incident response processes so the same pattern does not recur.

👉 Read our full editorial: Browser-based AI use is exposing a new identity governance gap



   
ReplyQuote
Share: