Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should organisations do about ChatGPT extensions that…
Governance, Ownership & Risk

What should organisations do about ChatGPT extensions that access enterprise data?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 10, 2026 Domain: Governance, Ownership & Risk

They should govern them like privileged software, not casual add-ons. That means approving only known tools, limiting access to authenticated AI services, and removing any extension that can reach chat history or connected data sources without a clearly justified business need.

How should enterprise ChatGPT extensions be treated?

Enterprise ChatGPT extensions should be treated as privileged software, because they can extend an authenticated AI session into internal data sources, chat history, and external services. The practical question is not whether the extension is useful, but whether it is explicitly approved, narrowly scoped, and technically constrained to the minimum access required.

That means organisations should review extensions the way they review other high-trust software that can move data across boundaries. If an extension can read prompts, retrieve files, or trigger actions in connected systems, it is part of the organisation's access surface, not a casual productivity add-on.

What access should be allowed?

Allow only known tools with a clear business owner, documented purpose, and explicit data scope. An extension should not be able to connect to enterprise content by default just because a user installed it or because it improves workflow speed.

Access should be limited to authenticated AI services and approved connections, with separate review for any extension that can see chat history, internal documents, tickets, or connected data sources. Where possible, use the narrowest token, connector, or delegated permission model available, and deny anything that asks for broad retrieval or write access without a strong justification.

One useful decision rule is simple: if the extension can materially change what the AI system can see, retrieve, or do, then it needs the same kind of access review you would apply to a privileged integration.

What controls prevent extension sprawl from becoming data leakage?

The main failure mode is extension sprawl, where many small tools accumulate access faster than governance catches up. That creates hidden data pathways, weak approval discipline, and inconsistent revocation when a tool is no longer needed or its vendor changes behaviour.

Extensions that can reach chat history or connected systems should be inventory-controlled, access-reviewed, and removed quickly when they no longer serve a justified purpose. This is especially important for tools that can search across content, because broad retrieval is often more dangerous than obvious write access.

For identity and access governance, the same principle applies as with privileged integrations, only with more caution because AI sessions can amplify a user's reach across multiple systems at once. Samsung ChatGPT leak 2023 is a reminder that permissive generative AI use can quickly become a data handling problem, even without a classic breach path.

Risk and Threat Considerations

Extensions increase risk when they combine user trust, broad data visibility, and third-party code or services. A compromised or over-permissioned extension can expose chat content, internal records, or downstream systems, and the user may not notice because the access occurs inside an otherwise legitimate AI workflow.

Failure mechanism: The extension obtains more data than the business need justifies, or its permissions outlive the original use case, creating a hidden route for leakage, misuse, or unauthorised retrieval.

Impact: Sensitive enterprise content can be disclosed, retained, or moved outside intended controls, and the organisation may lose both visibility and confidence in what the AI environment can access.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIEnterprise AI extensions can inherit excessive data access.
NHI-02 — Secret LeakageExtensions and connectors can expose chat and connected data.
Recommendation — Restrict extension permissions to the minimum data scope needed. Prevent extensions from exposing secrets or sensitive content beyond approved scope.
NIST SP 800-53 Rev 5IA-9 — Identification and Authentication (Non-Organizational Users)Extensions should only access enterprise data through authenticated external or service connections.
AC-6 — Least PrivilegeExtension permissions should be narrowly scoped to justified business need.
Recommendation — Require strong authentication for every external AI integration that reaches enterprise data. Apply least privilege to every ChatGPT extension and connector.
ISO/IEC 27001:2022A.5.15 — Access controlExtensions that reach enterprise data are an access-control decision.
Recommendation — Approve only extensions with explicit access control and business justification.
CIS Controls v8CIS-6 — Access Control ManagementControl review and removal of extension access paths.
Recommendation — Inventory, review, and revoke extension access paths on a defined cadence.

Practitioner Guidance

What to prioritise: Start with an inventory of extensions that can read chat history, browse connected data sources, or interact with enterprise apps. Those are the highest-risk cases because they turn a convenience feature into a data access decision.

What to verify: Confirm the extension's exact permissions, its business owner, its data destinations, and whether revocation is possible without affecting the core AI service. If you cannot explain the permission model in one sentence, the access is probably too broad.

Common mistake: Teams often approve an extension because the function looks harmless, then discover it inherits a large trust boundary through the underlying connector. Treat the connector and the data scope as the real control point, not the marketing description.

Practitioner takeaway: The safest operating model is to approve extensions only when they have a narrow, justified purpose and a clean revocation path, because AI convenience should never outrun data-access governance.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org