Your IAM strategy has a blind spot: Embedded AI
AI is embedded in browsers, Teams apps, and plugins — and your IAM strategy probably can't see it.
In a previous article, I argued that identity is the new security perimeter. The question isn't just "who has access?" but "what has access?" — because non-human identities now vastly outnumber humans in the average enterprise.
But there's a gap I didn't cover. One that's more immediate and harder to see.
Your IAM strategy manages users and applications. But what about AI that's embedded in everyday tools — browser extensions, Teams apps, Slack bots, meeting assistants — that employees are granting permissions to right now, without IT involvement?
That's the blind spot. It's one I've been thinking about a lot — and I suspect most organisations are still figuring out how to address it.
AI isn't just chatting anymore — it's doing
The conversation about AI risk often focuses on employees using ChatGPT. That's yesterday's problem.
Today, AI is embedded everywhere. It's not a separate tool employees go to; it's woven into the tools they already use. Browser extensions that summarise pages or draft emails. Teams apps that record and transcribe meetings. Slack bots that answer questions by scanning your channels. Productivity plugins that read your calendar, email, and files to "help" you work faster.
Each of these tools has an identity. Each one requests permissions. Each one is granted access to company data — often by employees who click "Allow" without understanding what they're approving.
This isn't theoretical. In a recent company meeting, I watched an AI tool called Read.ai pop up in Teams asking permission to record. No one had approved this tool. No one in IT knew it was there. But someone had installed it, and now it was requesting access to record executive conversations.
Read.ai is a cautionary example. The tool can attach itself to calendars and join meetings automatically — even when the user who installed it isn't present — transcribing and summarising without other attendees' awareness or consent. The security concerns are significant enough that University of Washington and Chapman University have blocked the app entirely, citing risks to institutional data and privacy.
This is the shift most companies haven't absorbed: AI moved from something employees use to something embedded in what they use. And your traditional IAM framework probably can't see it.
And now there's a new category: AI browsers and desktop agents
Browser extensions were just the beginning. Now entire browsers and desktop applications have AI built in.
OpenAI's Atlas browser launched in late 2025. This isn't an extension — it's an entire browser with AI integrated throughout. It operates within your authenticated sessions, seeing everything you see. It has persistent memory that retains context across sessions. And OpenAI is explicit about the limitations: according to their enterprise documentation, "Atlas is not currently in scope for OpenAI SOC 2 or ISO attestations" and "existing ChatGPT Enterprise security and compliance commitments do not apply to Atlas at this time."
Anthropic's Claude Cowork takes a different approach — a desktop agent that, according to Anthropic's product page, "works on your computer, local files, and applications to return a finished deliverable." It moves between applications, synthesises information across multiple sources, and completes tasks autonomously.
These tools offer genuine productivity benefits. But they're also new categories of identity with deep access to company data — and most IAM strategies have no way to account for them.
What this looks like in practice
Here's what I've observed — and what I keep running into in conversations with other IT and security teams:
Device management covers the basics, not the gap. MDM solutions like Intune enforce encryption, password policies, updates, and antivirus. Good. But if every user has local admin rights, they can install any browser extension, AI browser, or desktop agent they want. No visibility. No control.
Phones are a blind spot. Many organisations don't enrol mobile devices. That means employees access company email, Teams, and files from devices IT has zero control over — while installing AI apps that request access to the same data.
AI tools request broad access. Sales teams and executives constantly request AI tools that promise to summarise meetings, automate follow-ups, or generate insights. These tools don't just want access to one person's data. They often request permissions across Entra ID — access to all users, calendars, and contacts. One approval grants access to the entire organisation.
No policy on plugins or software. Without policies blocking unauthorised installations, employees accumulate browser extensions and desktop apps. Each one is a potential data exfiltration channel.
Permissions are granted, never reviewed. Someone approves an AI app once, and that access persists indefinitely. There's no audit, no review, no deprovisioning. Sound familiar? It's the same problem we discussed with employee offboarding — except now it's AI tools with standing access to company data.
The risk: Data leakage at scale
This isn't a future problem. The data is already leaving.
According to IBM's 2025 Cost of a Data Breach Report, one in five organisations experienced breaches due to shadow AI. Those breaches came with a $670,000 cost premium over standard incidents. Shadow AI breaches also compromised more sensitive data: 65% involved personally identifiable information (versus 53% average), and 40% involved intellectual property (versus 33% average).
Perhaps most concerning: 63% of breached organisations lack AI governance policies entirely or are still developing them. Only 34% of those with policies actually audit for unauthorised AI usage.
Embedded AI tools operate continuously in the background. Browser extensions reading page content. Meeting assistants transcribing conversations. Desktop agents accessing local files. Each one is potentially siphoning data to external services, often without employees realising what they've permitted.
If you don't have visibility into what AI tools exist in your environment and what permissions they hold, you likely have a data leakage problem. You just don't know how big it is yet.
The position: Provide before you prohibit
Some organisations respond by trying to ban AI entirely. This doesn't work.
When you block AI without providing alternatives, employees go underground. They use personal devices, personal accounts, and tools IT can't see. The shadow grows darker, not smaller. Prohibition doesn't stop usage; it just eliminates visibility.
The better approach is to provide before you prohibit.
Give employees approved AI tools. If you want people to stop using shadow AI, give them something better. Deploy enterprise-grade AI solutions — ChatGPT Enterprise, Microsoft Copilot, or domain-specific tools that meet your security requirements. When employees have sanctioned options that actually work, they have less reason to go rogue.
Company devices are company devices. This sounds obvious, but many organisations treat company laptops like personal machines. They're not. Enforce that boundary. Remove local admin rights. Control what can be installed. Enrol phones that access company data. If employees want unrestricted devices, those devices shouldn't touch company systems.
Apply conditional access to BYOD. If you allow personal devices, don't give them the same access as managed devices. Use conditional access policies to restrict what BYOD devices can reach. Personal phone? Fine for email. But accessing sensitive systems or data? That requires a managed device.
Governance enables speed, not the opposite. The fastest way to scale AI is the safest way. Companies that govern AI well will adopt it faster because they won't be constantly stopping to address breaches, compliance violations, and tool sprawl. Governance isn't the brake pedal. It's what keeps you on the road.
Extend your IAM thinking
This isn't a new discipline. It's an extension of what you already know.
The IAM fundamentals still apply: Administration, Authentication, Authorisation, Auditing. The new territory is applying them to AI identities embedded in everyday tools.
Visibility is oxygen. You cannot govern what you cannot see. The first step is discovering what AI tools exist in your environment — browser extensions, AI browsers, desktop agents, Teams apps, Slack integrations, installed software. Pull the shadow into the light.
Least privilege applies to AI too. Every AI tool should have only the minimum permissions required for its function. A meeting transcription tool doesn't need access to all users in Entra ID. A browser extension that summarises articles doesn't need to read your authentication cookies. Grant the smallest key for each tool.
Authorisation requires review. Just as you should audit user access periodically, you need to audit AI tool permissions. What was granted? When? By whom? Is that access still appropriate? This is the authorisation pillar applied to a new category of identity.
Restrict app consent at the platform level. In Entra ID, you can configure user consent settings to prevent employees from granting permissions to third-party apps without admin approval. Enable the admin consent workflow so that requests are routed to IT for review rather than approved on the spot by individual users. This single configuration change closes a significant gap.
Audit trails matter. When data leaves your organisation through an AI tool, you need to know. Automated logging and monitoring should track what data flows to which AI services. Evidence beats promises. If you can't prove what happened, you can't prove compliance.
Questions worth asking
These are the questions I keep asking — both of my own team and in conversations with peers. They're not gotcha questions. They're the ones that reveal where the gaps actually are:
-
What AI tools, browser extensions, AI browsers, and desktop agents are installed across our devices — and what permissions have they been granted?
-
Do we have an approved AI tools list, and are we providing alternatives before blocking?
-
Are all devices that access company data enrolled and managed — including phones?
-
Can an employee grant an AI app access to Entra ID data without approval?
-
When was the last time we audited permissions granted to third-party apps and integrations?
I don't always like the answers we get. But asking honestly is where progress starts.
The bottom line
Your IAM strategy was built for a world of users and applications. That world has changed. AI is now embedded in browsers, collaboration tools, plugins, desktop agents, and even entire AI-native browsers — each one with an identity, each one with permissions, most of them invisible to IT.
The fundamentals haven't changed: know what has access, enforce least privilege, audit continuously. But the scope has expanded. The organisations that extend their IAM thinking to cover embedded AI will operate securely and scale AI confidently. Those that don't will likely discover their blind spot the hard way. None of us want to learn through a breach.
The blind spot is now visible. What we do about it — individually and as an industry — will shape how safely we scale AI.
Start here: Launch an AI tool audit this quarter. Discovery comes first. You can't govern what you don't know exists.