[{"data":1,"prerenderedAt":4485},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":36,"navbar-about-highlight":108,"navbar-resource-highlight":182,"trust-badges":226,"solution-nav":247,"fa-icon-solid-faUserSecret":373,"fa-icon-sharp-regular-faLaptopCode":377,"fa-icon-solid-faPlugCircleXmark":379,"fa-icon-sharp-regular-faPuzzlePiece":381,"fa-icon-solid-faFileCircleXmark":383,"fa-icon-solid-faGhost":386,"fa-icon-solid-faQrcode":389,"fa-icon-solid-faCookieBite":391,"fa-icon-sharp-regular-faFishingRod":393,"fa-icon-sharp-regular-faUserSecret":395,"fa-icon-sharp-regular-faRadar":397,"fa-icon-sharp-regular-faSatelliteDish":399,"fa-icon-sharp-regular-faShieldCheck":401,"fa-icon-sharp-regular-faBrainCircuit":403,"fa-icon-solid-faMobileScreenButton":405,"fa-icon-brands-faChrome":407,"fa-icon-solid-faDisplay":409,"fa-icon-solid-faFilter":411,"fa-icon-solid-faCloudArrowUp":413,"blog/shadow-ai-how-to-discover-govern-and-secure-ai-apps":415},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":22,"data":23,"variations":28,"lastUpdated":29,"firstPublished":30,"testRatio":31,"createdBy":32,"lastUpdatedBy":33,"folders":34,"rev":35},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":19,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},768,640,320,true,"data","",[],{"link":24,"text":25,"type":26,"url":27},{},"Get our latest report analyzing browser attack techniques in 2026","web-banner","https://pushsecurity.com/resources/browser-attacks-report",{},1774258294825,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],"apmmnmyt9j6",{"createdBy":37,"createdDate":38,"data":39,"folders":94,"id":95,"lastUpdated":96,"lastUpdatedBy":97,"meta":98,"modelId":102,"name":103,"published":13,"query":104,"testRatio":31,"variations":105,"firstPublished":106,"stageModifiedSincePublish":6,"rev":107},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":40,"text":41,"url":21,"blocks":42,"state":90},"ewrererw","testrfesssssssssss",[43,70,78],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":60},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":59},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https://pushsecurity.com/webinar/state-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Do you know how much AI is in your workforce? Find out August 20th.\u003C/p>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Save your seat →\u003C/p>","https://pushsecurity.com/webinar/shadow-ai",null,{"large":61},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66,"marginTop":67,"marginBottom":67,"fontSize":68,"fontWeight":69},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"@type":44,"@version":45,"id":71,"component":72,"responsiveStyles":76},"builder-a2e1f4b9f30b464bb814d7f5de5b0aa7",{"name":73,"options":74,"isRSC":59},"Custom Code",{"code":75,"scriptsClientOnly":6},"\u003Cstyle>\n  .top-banner.bg-web-orange{background:rgb(114, 79, 255);}\n\u003C/style>\n",{"large":77},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"id":79,"@type":44,"tagName":80,"properties":81,"responsiveStyles":85},"builder-pixel-jbnw0pjqfp8","img",{"src":82,"aria-hidden":83,"alt":21,"role":84,"width":65,"height":65},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":86},{"height":65,"width":65,"display":87,"opacity":65,"overflow":88,"pointerEvents":89},"block","hidden","none",{"deviceSize":91,"location":92},"large",{"path":21,"query":93},{},[],"fd266d0172cc47429be7ad10f48c99ad",1786155414606,"kYgMv6WsbvfmlOUYqR2SFwGzw6e2",{"breakpoints":99,"hasAutosaves":6,"hasErrors":6,"hasLinks":6,"kind":100,"lastPreviewUrl":101},{"medium":16,"small":17,"xsmall":18},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests%2CfusionHostingPublish&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"0tzf4hcksg8",[109,145],{"createdBy":32,"createdDate":110,"data":111,"folders":134,"id":135,"lastUpdated":136,"lastUpdatedBy":32,"meta":137,"modelId":139,"name":140,"published":13,"query":141,"stageModifiedSincePublish":6,"testRatio":31,"variations":142,"firstPublished":143,"rev":144},1776247359804,{"link":112,"testimonial":113,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":117},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":118,"folders":119,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":123,"variations":127,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":130,"rev":132},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":124,"jobTitle":125,"quote":121,"image":126},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,{"kind":20,"lastPreviewUrl":21,"breakpoints":131,"hasAutosaves":19},{"small":17,"medium":16},"ddyn8t2hffn","/customer-stories/inductive-automation",[],"9136a8f18b3b4a6ba29b8653a99372b1",1776247404986,{"breakpoints":138,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"20d9eaa352304613b3d1a794b400703d","testimonial-inductive-automation",[],{},1776247404973,"frgr55ruek9",{"createdBy":32,"createdDate":146,"data":147,"folders":174,"id":175,"lastUpdated":176,"lastUpdatedBy":32,"meta":177,"modelId":139,"name":172,"published":13,"query":179,"stageModifiedSincePublish":6,"testRatio":31,"variations":180,"firstPublished":181,"rev":144},1776255761419,{"description":148,"image":149,"link":150,"testimonial":153,"title":172,"type":173},"Learn about the latest techniques being used in the wild.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9",{"text":151,"url":152},"Download now","/resources/browser-attacks-report",{"@type":114,"id":154,"model":116,"value":155},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":156,"folders":157,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":160,"variations":166,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":169,"rev":171},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":20,"lastPreviewUrl":21,"breakpoints":170,"hasAutosaves":19},{"small":17,"medium":16},"7zm3o33eh63","Report: 2026 Browser Attack Techniques","resource",[],"05a9322735fc427db12e2740e4302300",1776255810913,{"breakpoints":178,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1776255810900,[183,205],{"createdBy":32,"createdDate":184,"data":185,"folders":195,"id":196,"lastUpdated":197,"lastUpdatedBy":32,"meta":198,"modelId":200,"name":172,"published":13,"query":201,"stageModifiedSincePublish":6,"testRatio":31,"variations":202,"firstPublished":203,"rev":204},1776256900280,{"description":148,"image":149,"link":186,"testimonial":187,"title":172,"type":173},{"text":151,"url":152},{"@type":114,"id":154,"model":116,"value":188},{"query":189,"folders":190,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":191,"variations":192,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":193,"rev":171},[],[],{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":194,"hasAutosaves":19},{"small":17,"medium":16},[],"1f429607996e4e5fae8fe3f9b9610e55",1776256937553,{"breakpoints":199,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"4829faa81e7c4ee8bd2d000e160e8d3c",[],{},1776256937540,"bkbx0ymp3i4",{"createdBy":32,"createdDate":206,"data":207,"folders":217,"id":218,"lastUpdated":219,"lastUpdatedBy":32,"meta":220,"modelId":200,"name":222,"published":13,"query":223,"stageModifiedSincePublish":6,"testRatio":31,"variations":224,"firstPublished":225,"rev":204},1776256949234,{"link":208,"testimonial":209,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":210},{"query":211,"folders":212,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":213,"variations":214,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":215,"rev":132},[],[],{"author":124,"jobTitle":125,"quote":121,"image":126},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":216,"hasAutosaves":19},{"small":17,"medium":16},[],"ce043785b71b4ece98eac811ecf4ba10",1776256974140,{"breakpoints":221,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"inductive-automation",[],{},1776256974130,[227,231,235,239,243],{"title":228,"logo":229,"createdDate":230},"SOC2","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":232,"logo":233,"createdDate":234},"GDPR","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":236,"logo":237,"createdDate":238},"Cyber essentials","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":240,"logo":241,"createdDate":242},"ISO IEC 27001","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":244,"logo":245,"createdDate":246},"ISO IEC 27701","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,[248,303,348],{"id":249,"label":250,"text":21,"navIcon":251,"items":252},"stop-browser-based-attacks","Stop browser-based attacks","solid:faShieldHalved",[253,258,263,268,273,278,283,288,293,298],{"title":254,"text":255,"url":256,"navIcon":257},"Adversary-in-the-Middle","Detect and block AiTM proxies stealing session tokens.","/solution/stop-browser-based-attacks/adversary-in-the-middle-attacks","solid:faUserSecret",{"title":259,"text":260,"url":261,"navIcon":262},"ClickFix (+Fix variants)","Block attacks that trick users into running malicious code.","/solution/stop-browser-based-attacks/clickfix-fix-variants","sharp-regular:faLaptopCode",{"title":264,"text":265,"url":266,"navIcon":267},"Malicious OAuth integrations","Detect suspicious OAuth consent flows and stop persistent access.","/solution/stop-browser-based-attacks/malicious-oauth-integrations","solid:faPlugCircleXmark",{"title":269,"text":270,"url":271,"navIcon":272},"Malicious browser extensions","Shine a light on risky browser extensions.","/solution/stop-browser-based-attacks/malicious-browser-extensions","sharp-regular:faPuzzlePiece",{"title":274,"text":275,"url":276,"navIcon":277},"Malicious file downloads","Gain visibility into browser downloads and block malicious files.","/solution/stop-browser-based-attacks/malicious-file-downloads","solid:faFileCircleXmark",{"title":279,"text":280,"url":281,"navIcon":282},"Ghost logins","Surface hidden login paths that bypass SSO and expose accounts.","/solution/stop-browser-based-attacks/ghost-logins","solid:faGhost",{"title":284,"text":285,"url":286,"navIcon":287},"Mobile phishing (QR & SMS)","Detect phishing links delivered via SMS and QR codes.","/solution/stop-browser-based-attacks/mobile-phishing-qr-code-sms","solid:faQrcode",{"title":289,"text":290,"url":291,"navIcon":292},"Credential stuffing","Identify reused and compromised credentials across SaaS logins.","/solution/stop-browser-based-attacks/credential-stuffing","custom:credentialStuffing",{"title":294,"text":295,"url":296,"navIcon":297},"Session hijacking","Detect and block stolen session tokens before attackers get access.","/solution/stop-browser-based-attacks/session-hijacking","solid:faCookieBite",{"title":299,"text":300,"url":301,"navIcon":302},"Zero-day phishing","Detect phishing TTPs directly in the browser and stop credential theft.","/solution/stop-browser-based-attacks/zero-day-phishing","sharp-regular:faFishingRod",{"id":304,"label":305,"text":21,"navIcon":306,"items":307},"achieve-security-outcomes","Achieve security outcomes","solid:faCheckToSlot",[308,313,318,323,328,333,338,343],{"title":309,"text":310,"url":311,"navIcon":312},"Stop account takeover","Stop ATO with stolen credential and compromised token detection.","/solution/achieve-security-outcomes/stop-account-takeover","sharp-regular:faUserSecret",{"title":314,"text":315,"url":316,"navIcon":317},"Harden unmanaged identities","Harden access paths with visibility, detection, and guardrails.","/solution/achieve-security-outcomes/harden-unmanaged-identities","sharp-regular:faRadar",{"title":319,"text":320,"url":321,"navIcon":322},"Investigate browser-related incidents","Investigate and respond faster with unique browser telemetry.","/solution/achieve-security-outcomes/investigate-browser-related-incidents","sharp-regular:faSatelliteDish",{"title":324,"text":325,"url":326,"navIcon":327},"Secure shadow SaaS","See and control shadow SaaS in the browser.","/solution/achieve-security-outcomes/secure-shadow-saas","sharp-regular:faShieldCheck",{"title":329,"text":330,"url":331,"navIcon":332},"Secure AI","See and control AI apps in the browser.","/solution/achieve-security-outcomes/secure-ai","sharp-regular:faBrainCircuit",{"title":334,"text":335,"url":336,"navIcon":337},"Secure BYOD","Extend consistent browser-based protection to unmanaged devices.","/solution/achieve-security-outcomes/secure-bring-your-own-device","solid:faMobileScreenButton",{"title":339,"text":340,"url":341,"navIcon":342},"Secure Chromebooks","Secure browser activity on Chromebooks without endpoint agents.","/solution/achieve-security-outcomes/secure-chromebooks","brands:faChrome",{"title":344,"text":345,"url":346,"navIcon":347},"Investigate and stop data loss","Detect and prevent data loss across AI tools, apps, and sessions.","/solution/achieve-security-outcomes/investigate-and-stop-data-loss","custom:investigateAndStopDataLoss",{"id":349,"label":350,"text":21,"navIcon":351,"items":352},"tool-replacements","Tool replacements","solid:faScrewdriverWrench",[353,358,363,368],{"title":354,"text":355,"url":356,"navIcon":357},"Remote browser isolation","Detect attacks that look like normal browsing.","/solution/tool-replacements/remote-browser-isolation","solid:faDisplay",{"title":359,"text":360,"url":361,"navIcon":362},"Secure web gateways","Detect attacks inside the browser after SWGs allowed the connection.","/solution/tool-replacements/secure-web-gateways","solid:faFilter",{"title":364,"text":365,"url":366,"navIcon":367},"Cloud access security broker","Catch browser-based identity threats in real time, not after the fact.","/solution/tool-replacements/cloud-access-security-broker","solid:faCloudArrowUp",{"title":369,"text":370,"url":371,"navIcon":372},"Security awareness training","Block real phishing instead of training users on simulations.","/solution/tool-replacements/security-awareness-training","custom:securityAwareness",{"w":374,"h":375,"d":376},448,512,"M171-16c-36.4 0-57.8 58.3-68.3 112L72 96c-13.3 0-24 10.7-24 24s10.7 24 24 24l24 0 0 32c0 17 3.3 33.2 9.3 48l-9.3 0 0 0-20.5 0c-15.2 0-27.5 12.3-27.5 27.5 0 3 .5 5.9 1.4 8.7l28.9 86.6C40.2 379.6 16 428.1 16 482.3 16 498.7 29.3 512 45.7 512l356.6 0c16.4 0 29.7-13.3 29.7-29.7 0-54.2-24.2-102.7-62.3-135.4l28.9-86.6c.9-2.8 1.4-5.7 1.4-8.7 0-15.2-12.3-27.5-27.5-27.5l-20.5 0 0 0-9.3 0c6-14.8 9.3-31 9.3-48l0-32 24 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-30.7 0c-10.4-53.7-31.9-112-68.3-112-9.6 0-19 3.9-27.5 8.2-8.2 4.1-18.4 7.8-25.5 7.8s-17.3-3.7-25.5-7.8C190-12.1 180.6-16 171-16zm93.7 484.4l-24.8-70.9 27.9-32.5c2.7-3.2 4.2-7.2 4.2-11.4 0-9.7-7.8-17.5-17.5-17.5l-61 0c-9.7 0-17.5 7.8-17.5 17.5 0 4.2 1.5 8.2 4.2 11.4l27.9 32.5-24.8 70.9-57-180.4 35.7 0c18.4 10.2 39.5 16 62 16s43.6-5.8 62-16l35.7 0-57 180.4zM224 256c-34.7 0-64.2-22.1-75.3-53 5.7 3.2 12.3 5 19.3 5l12.4 0c16.5 0 31.1-10.6 36.3-26.2 2.3-7 12.2-7 14.5 0 5.2 15.6 19.9 26.2 36.3 26.2l12.4 0c7 0 13.6-1.8 19.3-5-11.1 30.9-40.6 53-75.3 53z",{"w":17,"h":375,"d":378},"M112 80l416 0 0 224 48 0 0-272-512 0 0 272 48 0 0-224zM48 404.1l0-4.1 544 0 0 4.1-27.9 27.9-488.2 0-27.9-27.9zM592 352l-592 0 0 72 56 56 528 0 56-56 0-72-48 0zM281 169l17-17-33.9-33.9c-6.1 6.1-27.8 27.8-65 65l-17 17c6.1 6.1 27.8 27.8 65 65l17 17 33.9-33.9c-9-9-25-25-48-48l31-31zM393 135l-17-17-33.9 33.9c9 9 25 25 48 48-23 23-39 39-48 48L376 281.9c6.1-6.1 27.8-27.8 65-65l17-17c-6.1-6.1-27.8-27.8-65-65z",{"w":17,"h":375,"d":380},"M192-32c17.7 0 32 14.3 32 32l0 96 128 0 0-96c0-17.7 14.3-32 32-32s32 14.3 32 32l0 96 64 0c17.7 0 32 14.3 32 32s-14.3 32-32 32l0 48.7c-98.6 8.1-176 90.7-176 191.3 0 27.3 5.7 53.3 16 76.9l0 3.1c0 17.7-14.3 32-32 32s-32-14.3-32-32l0-66.7C165.2 398.1 96 319.1 96 224l0-64c-17.7 0-32-14.3-32-32S78.3 96 96 96l64 0 0-96c0-17.7 14.3-32 32-32zM496 256a144 144 0 1 1 0 288 144 144 0 1 1 0-288zm59.3 107.3c6.2-6.2 6.2-16.4 0-22.6s-16.4-6.2-22.6 0l-36.7 36.7-36.7-36.7c-6.2-6.2-16.4-6.2-22.6 0s-6.2 16.4 0 22.6l36.7 36.7-36.7 36.7c-6.2 6.2-6.2 16.4 0 22.6s16.4 6.2 22.6 0l36.7-36.7 36.7 36.7c6.2 6.2 16.4 6.2 22.6 0s6.2-16.4 0-22.6l-36.7-36.7 36.7-36.7z",{"w":375,"h":375,"d":382},"M201.1 57.3c-7 5.3-9.1 10.7-9.1 14.7 0 4.5 2.8 11.2 12.4 16.9l11.6 7 0 48.1-168 0 0 60.5c7.4-2.9 15.5-4.5 24-4.5 43.1 0 72 39.4 72 80s-28.9 80-72 80c-8.5 0-16.6-1.6-24-4.5l0 108.5 108.5 0c-2.9-7.4-4.5-15.5-4.5-24 0-43.1 39.4-72 80-72s80 28.9 80 72c0 8.5-1.6 16.6-4.5 24l60.5 0 0-168 48.1 0 7 11.6c5.8 9.6 12.4 12.4 16.9 12.4 4 0 9.5-2.1 14.7-9.1s9.3-17.9 9.3-30.9-4-23.8-9.3-30.9-10.7-9.1-14.7-9.1c-4.5 0-11.2 2.8-16.9 12.4l-7 11.6-48.1 0 0-120-120 0 0-48.1 11.6-7c9.6-5.8 12.4-12.4 12.4-16.9 0-4-2.1-9.5-9.1-14.7S245 48 232 48 208.2 52 201.1 57.3zM172.3 18.9C188.5 6.8 209.6 0 232 0S275.5 6.8 291.7 18.9 320 49.5 320 72c0 8.6-1.8 16.7-4.9 24l100.9 0 0 100.9c7.3-3.1 15.4-4.9 24-4.9 22.5 0 41 12.2 53.1 28.3s18.9 37.3 18.9 59.7-6.8 43.5-18.9 59.7-30.6 28.3-53.1 28.3c-8.6 0-16.7-1.8-24-4.9l0 148.9-168 0 0-49.3 8.2-7.2c5.4-4.7 7.8-10.3 7.8-15.5 0-9.9-10.7-24-32-24s-32 14.1-32 24c0 5.3 2.4 10.8 7.8 15.5l8.2 7.2 0 49.3-216 0 0-216 49.3 0 7.2 8.2c4.7 5.4 10.3 7.8 15.5 7.8 9.9 0 24-10.7 24-32s-14.1-32-24-32c-5.3 0-10.8 2.4-15.5 7.8L49.3 264 0 264 0 96 148.9 96c-3.1-7.3-4.9-15.4-4.9-24 0-22.5 12.2-41 28.3-53.1z",{"w":384,"h":375,"d":385},576,"M96 0C60.7 0 32 28.7 32 64l0 384c0 35.3 28.7 64 64 64l180 0c-22.7-31.5-36-70.2-36-112 0-100.6 77.4-183.2 176-191.3l0-38.1c0-17-6.7-33.3-18.7-45.3L290.7 18.7C278.7 6.7 262.5 0 245.5 0L96 0zM357.5 176L264 176c-13.3 0-24-10.7-24-24L240 58.5 357.5 176zM432 544a144 144 0 1 0 0-288 144 144 0 1 0 0 288zm59.3-180.7l-36.7 36.7 36.7 36.7c6.2 6.2 6.2 16.4 0 22.6s-16.4 6.2-22.6 0l-36.7-36.7-36.7 36.7c-6.2 6.2-16.4 6.2-22.6 0s-6.2-16.4 0-22.6l36.7-36.7-36.7-36.7c-6.2-6.2-6.2-16.4 0-22.6s16.4-6.2 22.6 0l36.7 36.7 36.7-36.7c6.2-6.2 16.4-6.2 22.6 0s6.2 16.4 0 22.6z",{"w":387,"h":375,"d":388},384,"M40.1 467.1l-11.2 9C25.7 478.6 21.8 480 17.8 480 8 480 0 472 0 462.2L0 192C0 86 86 0 192 0S384 86 384 192l0 270.2c0 9.8-8 17.8-17.8 17.8-4 0-7.9-1.4-11.1-3.9l-11.2-9c-13.4-10.7-32.8-9-44.1 3.9L269.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6l-26.6-30.5c-12.7-14.6-35.4-14.6-48.2 0L141.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6L84.2 471c-11.3-12.9-30.7-14.6-44.1-3.9zM160 192a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zm96 32a32 32 0 1 0 0-64 32 32 0 1 0 0 64z",{"w":374,"h":375,"d":390},"M64 160l64 0 0-64-64 0 0 64zM0 80C0 53.5 21.5 32 48 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48L0 80zM64 416l64 0 0-64-64 0 0 64zM0 336c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96zM320 96l0 64 64 0 0-64-64 0zM304 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96c0-26.5 21.5-48 48-48zM288 352a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm0 64c17.7 0 32 14.3 32 32s-14.3 32-32 32-32-14.3-32-32 14.3-32 32-32zm96 32c0-17.7 14.3-32 32-32s32 14.3 32 32-14.3 32-32 32-32-14.3-32-32zm32-96a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm-32 32a32 32 0 1 1 -64 0 32 32 0 1 1 64 0z",{"w":375,"h":375,"d":392},"M257.5 27.6c-.8-5.4-4.9-9.8-10.3-10.6-22.1-3.1-44.6 .9-64.4 11.4l-74 39.5C89.1 78.4 73.2 94.9 63.4 115L26.7 190.6c-9.8 20.1-13 42.9-9.1 64.9l14.5 82.8c3.9 22.1 14.6 42.3 30.7 57.9l60.3 58.4c16.1 15.6 36.6 25.6 58.7 28.7l83 11.7c22.1 3.1 44.6-.9 64.4-11.4l74-39.5c19.7-10.5 35.6-27 45.4-47.2l36.7-75.5c9.8-20.1 13-42.9 9.1-64.9-.9-5.3-5.3-9.3-10.6-10.1-51.5-8.2-92.8-47.1-104.5-97.4-1.8-7.6-8-13.4-15.7-14.6-54.6-8.7-97.7-52-106.2-106.8zM208 144a32 32 0 1 1 0 64 32 32 0 1 1 0-64zM144 336a32 32 0 1 1 64 0 32 32 0 1 1 -64 0zm224-64a32 32 0 1 1 0 64 32 32 0 1 1 0-64z",{"w":374,"h":375,"d":394},"M284.6 0l91.4 0 0 160-48 0 0-112-36.6 0-203.4 58.1 0 181.9 40 0 0 224-128 0 0-224 40 0 0-218.1 17.4-5 224-64 3.2-.9zM80 336l-32 0 0 128 32 0 0-128zm176 8c0-76.8 64-136 96-152 32 16 96 75.2 96 152 0 32-16 80-64 112l32 40 0 16-128 0 0-16 32-40c-48-32-64-80-64-112zm128-32a24 24 0 1 0 -48 0 24 24 0 1 0 48 0z",{"w":374,"h":375,"d":396},"M144-16l-48 112-48 0 0 48 48 0 0 32c0 17 3.3 33.2 9.3 48l-73.3 0 0 32 5.3 16 26.7 80-64 160 51.7 0 56.9-142.2 6.5-16.3c-1-3.1-10.1-30.3-27.2-81.5l51.4 0c22.6 19.9 52.2 32 84.7 32s62.1-12.1 84.7-32l51.4 0c-17.1 51.2-26.1 78.4-27.2 81.5l6.5 16.3 56.9 142.2 51.7 0-64-160 26.7-80 5.3-16 0-32-73.3 0c6-14.8 9.3-31 9.3-48l0-32 48 0 0-48-48 0-48-112-32 0-48 32-48-32-32 0zm80 272c-32.8 0-61-19.7-73.3-48l57.3 0 16-40 16 40 57.3 0c-12.3 28.3-40.5 48-73.3 48zm17.5 139.6l30.5-35.6 0-24-96 0 0 24 30.5 35.6-46.5 116.4 128 0-46.5-116.4z",{"w":375,"h":375,"d":398},"M497.4 49l17-17-33.9-33.9C473.6 4.9 453.3 25.2 419.7 58.8 375.4 22.1 318.5 0 256.4 0 115.1 0 .4 114.6 .4 256s114.6 256 256 256 256-114.6 256-256l-48 0c0 114.9-93.1 208-208 208s-208-93.1-208-208 93.1-208 208-208c48.8 0 93.7 16.8 129.1 44.9l-45.7 45.7c-23.5-16.8-52.3-26.6-83.4-26.6-79.5 0-144 64.5-144 144s64.5 144 144 144 144-64.5 144-144l-48 0c0 53-43 96-96 96s-96-43-96-96 43-96 96-96c17.8 0 34.5 4.8 48.8 13.3-52 52-79.5 79.5-82.7 82.7l33.9 33.9 17-17 224-224z",{"w":375,"h":375,"d":400},"M208 0l24 0C386.6 0 512 125.4 512 280l0 24-48 0 0-24C464 151.9 360.1 48 232 48l-24 0 0-48zm24 96c101.6 0 184 82.4 184 184l0 24-48 0 0-24c0-75.1-60.9-136-136-136l-24 0 0-48 24 0zM48 256c0 114.9 93.1 208 208 208 22.9 0 45-3.7 65.6-10.5l-263-263C51.7 211 48 233.1 48 256zM0 256c0-36.5 7.6-71.3 21.4-102.7 6.7-15.3 14.9-29.9 24.4-43.5 7.7 7.7 61.5 61.5 161.2 161.2 30.5-30.5 49.5-49.5 57-57L297.9 248c-7.5 7.5-26.5 26.5-57 57 99.7 99.7 153.5 153.5 161.2 161.2-13.6 9.5-28.2 17.7-43.5 24.4-31.4 13.8-66.2 21.4-102.7 21.4-141.4 0-256-114.6-256-256z",{"w":375,"h":375,"d":402},"M267.6 4.5l207.5 80.5 19.2 7.4 1.2 20.5c2.9 50-4.9 126.3-37.3 200.9-32.7 75.2-91.1 150-189.4 192.5l-12.7 5.5-12.7-5.5C144.9 463.9 86.6 389.2 53.9 313.9 21.5 239.3 13.7 162.9 16.6 113L17.8 92.5 37 85 244.5 4.5 256 0 267.6 4.5zM64.1 126C63.1 169.5 71 232.9 97.9 294.8 126.1 359.7 175 422.4 256 459.6 337.1 422.4 385.9 359.7 414.2 294.8 441 232.9 449 169.5 448 126L256 51.5 64.1 126zm302.3 44.7L352.3 190.1 249.8 330.9 233 354c-8.8-9.1-30.9-32-66.2-68.6l-16.7-17.3 34.5-33.3c9.5 9.8 23.9 24.7 43.2 44.7l85.6-117.7 14.1-19.4 38.8 28.2z",{"w":375,"h":375,"d":404},"M192 48l40 0 0 108-12.4 0c-7.6-16.5-24.3-28-43.6-28-26.5 0-48 21.5-48 48s21.5 48 48 48c19.4 0 36.1-11.5 43.6-28l12.4 0 0 56-92 0 0 56.4c-16.5 7.6-28 24.3-28 43.6 0 26.5 21.5 48 48 48s48-21.5 48-48c0-19.4-11.5-36.1-28-43.6l0-16.4 52 0 0 172-40 0c-16.8 0-31.2-10.3-37.1-25.1l-6.4-16-17.2 1c-1.1 .1-2.2 .1-3.2 .1-30.9 0-56-25.1-56-56 0-9.5 2.4-18.5 6.5-26.3l8.7-16.2-13.4-12.6c-11-10.2-17.8-24.8-17.8-40.9 0-21.6 12.2-40.4 30.3-49.8l22.6-11.7-13.1-21.9c-5-8.4-7.9-18.1-7.9-28.6 0-30.9 25.1-56 56-56l24 0 0-32c0-13.3 10.7-24 24-24zm88 148l12.4 0c7.6 16.5 24.3 28 43.6 28 26.5 0 48-21.5 48-48s-21.5-48-48-48c-19.4 0-36.1 11.5-43.6 28l-12.4 0 0-108 40 0c13.3 0 24 10.7 24 24l0 32 24 0c30.9 0 56 25.1 56 56 0 10.5-2.9 20.3-7.9 28.6l-13.1 21.9 22.6 11.7c18 9.3 30.3 28.1 30.3 49.8 0 16.1-6.8 30.7-17.8 40.9l-13.4 12.6 8.7 16.2c4.2 7.8 6.5 16.7 6.5 26.3 0 30.9-25.1 56-56 56-1.1 0-2.2 0-3.2-.1l-17.2-1-6.4 16C351.2 453.7 336.8 464 320 464l-40 0 0-76 92 0 0-56.4c16.5-7.6 28-24.3 28-43.6 0-26.5-21.5-48-48-48s-48 21.5-48 48c0 19.4 11.5 36.1 28 43.6l0 16.4-52 0 0-152zM192 512l128 0c31.1 0 58.4-16.2 74.1-40.5 52.7-5.1 93.9-49.5 93.9-103.5 0-11.5-1.9-22.5-5.3-32.9 13.4-17.5 21.3-39.4 21.3-63.1 0-32-14.5-60.6-37.1-79.7 3.3-10.2 5.1-21.1 5.1-32.3 0-49.6-34.8-91.1-81.3-101.5-6.3-33.3-35.6-58.5-70.7-58.5L192 0c-35.1 0-64.4 25.2-70.7 58.5-46.5 10.4-81.3 51.9-81.3 101.5 0 11.3 1.8 22.2 5.1 32.3-22.7 19.1-37.1 47.7-37.1 79.7 0 23.7 8 45.6 21.3 63.1-3.5 10.4-5.3 21.4-5.3 32.9 0 54 41.2 98.5 93.9 103.5 15.6 24.3 42.9 40.5 74.1 40.5zM336 192a16 16 0 1 1 0-32 16 16 0 1 1 0 32zm32 96a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zM176 352a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zm16-176a16 16 0 1 1 -32 0 16 16 0 1 1 32 0z",{"w":387,"h":375,"d":406},"M16 64C16 28.7 44.7 0 80 0L304 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L80 512c-35.3 0-64-28.7-64-64L16 64zm64 0l0 304 224 0 0-304-224 0zM192 472c17.7 0 32-14.3 32-32s-14.3-32-32-32-32 14.3-32 32 14.3 32 32 32z",{"w":375,"h":375,"d":408},"M0 256c0-46.6 12.5-90.4 34.3-128.9L144.1 318.3c21.9 39.2 63.8 65.7 111.9 65.7 14.3 0 27.1-2.3 40.8-6.6L220.5 509.6C95.9 492.3 0 385.3 0 256zm365.1 65.6c12.3-19.2 18.9-42.5 18.9-65.6 0-38.2-16.8-72.5-43.3-96l152.7 0c12 29.6 18.6 62.1 18.6 96 0 141.4-114.6 255.1-256 256L365.1 321.6zM477.8 128L256 128c-62.9 0-113.7 44.1-125.5 102.7L54.2 98.5C101 38.5 174 0 256 0 350.8 0 433.5 51.5 477.8 128zM344 256a88 88 0 1 1 -176 0 88 88 0 1 1 176 0z",{"w":375,"h":375,"d":410},"M448 96l0 256-384 0 0-256 384 0zM64 32C28.7 32 0 60.7 0 96L0 352c0 35.3 28.7 64 64 64l144 0-16 48-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l272 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-72 0-16-48 144 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 32z",{"w":375,"h":375,"d":412},"M32 64C19.1 64 7.4 71.8 2.4 83.8S.2 109.5 9.4 118.6L192 301.3 192 416c0 8.5 3.4 16.6 9.4 22.6l64 64c9.2 9.2 22.9 11.9 34.9 6.9S320 492.9 320 480l0-178.7 182.6-182.6c9.2-9.2 11.9-22.9 6.9-34.9S492.9 64 480 64L32 64z",{"w":384,"h":375,"d":414},"M144 480c-79.5 0-144-64.5-144-144 0-63.4 41-117.2 97.9-136.5-1.3-7.7-1.9-15.5-1.9-23.5 0-79.5 64.5-144 144-144 55.4 0 103.5 31.3 127.6 77.1 14.2-8.3 30.8-13.1 48.4-13.1 53 0 96 43 96 96 0 15.7-3.8 30.6-10.5 43.7 44 20.3 74.5 64.7 74.5 116.3 0 70.7-57.3 128-128 128l-304 0zM305 191c-9.4-9.4-24.6-9.4-33.9 0l-72 72c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l31-31 0 102.1c0 13.3 10.7 24 24 24s24-10.7 24-24l0-102.1 31 31c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-72-72z",{"id":416,"title":417,"authorsCollection":418,"content":426,"extension":1436,"faqItemsCollection":1437,"faqTitle":1625,"featured":6,"hashTags":59,"meta":1626,"metaTitle":1627,"ogImage":59,"publishedDate":1628,"relatedBlogPostsCollection":1629,"slug":4457,"stem":4458,"subtitle":4459,"summary":4460,"synopsis":4470,"sys":4471,"tagsCollection":4474,"__hash__":4484},"blog/blog/shadow-ai-how-to-discover-govern-and-secure-ai-apps.json","Shadow AI: how to discover, govern, and secure AI apps",{"items":419},[420],{"fullName":421,"firstName":422,"jobTitle":423,"socialLinks":59,"profilePicture":424},"Kelly Davenport","Kelly","Product Team",{"url":425},"https://images.ctfassets.net/y1cdw1ablpvd/1hi8bEuVfn5sF57LivAq6d/9a3b82426c697d765e2e450e33a18424/kelly_profile_pic.jpeg",{"json":427,"links":1282},{"nodeType":428,"data":429,"content":430},"document",{},[431,440,447,498,505,512,567,576,580,589,596,608,614,626,632,644,650,653,661,668,687,698,705,712,715,723,730,755,761,768,784,800,806,822,838,845,852,859,865,868,876,883,891,898,914,921,946,952,959,965,977,984,990,996,999,1007,1014,1033,1040,1048,1055,1067,1083,1089,1101,1135,1142,1158,1164,1180,1187,1194,1197,1205,1212,1219,1226,1233,1240,1247,1250,1257,1264],{"nodeType":432,"data":433,"content":434},"paragraph",{},[435],{"nodeType":436,"value":437,"marks":438,"data":439},"text","Every security team that's blocked an AI tool at the network level has had the same experience three months later: The tool they blocked isn't in use, but a dozen they've never heard of are.",[],{},{"nodeType":432,"data":441,"content":442},{},[443],{"nodeType":436,"value":444,"marks":445,"data":446},"The block didn't stop employees from using AI. It just prevented the security team from seeing what’s actually happening.",[],{},{"nodeType":432,"data":448,"content":449},{},[450,454,463,467,473,477,482,486,494],{"nodeType":436,"value":451,"marks":452,"data":453},"The data backs up this pattern. ",[],{},{"nodeType":455,"data":456,"content":458},"hyperlink",{"uri":457},"https://pushsecurity.com/blog/what-push-data-reveals-about-the-state-of-shadow-ai/",[459],{"nodeType":436,"value":460,"marks":461,"data":462},"Push telemetry",[],{},{"nodeType":436,"value":464,"marks":465,"data":466}," shows that the average organization has ",[],{},{"nodeType":436,"value":468,"marks":469,"data":472},"16 AI apps, 17 AI browser extensions,",[470],{"type":471},"bold",{},{"nodeType":436,"value":474,"marks":475,"data":476}," and ",[],{},{"nodeType":436,"value":478,"marks":479,"data":481},"17 AI OAuth integrations",[480],{"type":471},{},{"nodeType":436,"value":483,"marks":484,"data":485}," in active use during a typical week — most unapproved. Meanwhile, ",[],{},{"nodeType":455,"data":487,"content":489},{"uri":488},"https://www.okta.com/newsroom/articles/ai-agents-at-work-2026-agentic-enterprise-security/",[490],{"nodeType":436,"value":491,"marks":492,"data":493},"Okta found",[],{},{"nodeType":436,"value":495,"marks":496,"data":497}," that 80% of employees who use unapproved AI tools do so because it's easier to use their own accounts, and 57% because the approval process is too slow.",[],{},{"nodeType":432,"data":499,"content":500},{},[501],{"nodeType":436,"value":502,"marks":503,"data":504},"The organizations getting this right have stopped treating AI governance as an access-control problem — which tools to allow, which to block — and started treating it as an invitation to build out an infrastructure to enable appropriate use. Employees are going to use the tools they need to get their work done. The question is whether they'll use them on a path you built and instrumented, or on one they carved themselves.",[],{},{"nodeType":432,"data":506,"content":507},{},[508],{"nodeType":436,"value":509,"marks":510,"data":511},"This guide walks through how to build that paved path. Using Push, you can:",[],{},{"nodeType":513,"data":514,"content":515},"unordered-list",{},[516,527,537,547,557],{"nodeType":517,"data":518,"content":519},"list-item",{},[520],{"nodeType":432,"data":521,"content":522},{},[523],{"nodeType":436,"value":524,"marks":525,"data":526},"Identify shadow AI, including personal accounts on approved corporate apps, AI browser extensions, OAuth integrations into sensitive systems, and AI browser usage.",[],{},{"nodeType":517,"data":528,"content":529},{},[530],{"nodeType":432,"data":531,"content":532},{},[533],{"nodeType":436,"value":534,"marks":535,"data":536},"Enforce policies on data flows into and out of AI apps, including blocking unapproved file uploads, downloads, and clipboard pastes; and monitoring AI chat transcripts.",[],{},{"nodeType":517,"data":538,"content":539},{},[540],{"nodeType":432,"data":541,"content":542},{},[543],{"nodeType":436,"value":544,"marks":545,"data":546},"Use just-in-time guardrails to intercept users accessing unapproved AI tools and point them at approved alternatives.",[],{},{"nodeType":517,"data":548,"content":549},{},[550],{"nodeType":432,"data":551,"content":552},{},[553],{"nodeType":436,"value":554,"marks":555,"data":556},"Prevent unwanted MCP connections with app-agnostic controls.",[],{},{"nodeType":517,"data":558,"content":559},{},[560],{"nodeType":432,"data":561,"content":562},{},[563],{"nodeType":436,"value":564,"marks":565,"data":566},"Automate a lot of the work so you don’t burn out your team as the AI landscape continues to shift.",[],{},{"nodeType":568,"data":569,"content":575},"embedded-entry-block",{"target":570},{"sys":571},{"id":572,"type":573,"linkType":574},"29N8YH9As3GHypOve3br80","Link","Entry",[],{"nodeType":577,"data":578,"content":579},"hr",{},[],{"nodeType":581,"data":582,"content":583},"heading-1",{},[584],{"nodeType":436,"value":585,"marks":586,"data":588},"What is shadow AI, and why can't you manage it like shadow IT?",[587],{"type":471},{},{"nodeType":432,"data":590,"content":591},{},[592],{"nodeType":436,"value":593,"marks":594,"data":595},"Shadow AI is any use of AI tools, services, or integrations that happens outside an organization's security governance and visibility. Security teams have been managing shadow SaaS for years, but shadow AI can't be addressed with the same playbook — for three reasons.",[],{},{"nodeType":432,"data":597,"content":598},{},[599,604],{"nodeType":436,"value":600,"marks":601,"data":603},"First",[602],{"type":471},{},{"nodeType":436,"value":605,"marks":606,"data":607},", it spans multiple categories that each need different controls: unapproved AI apps, personal accounts on approved corporate AI tools, AI browser extensions, and OAuth integrations into corporate systems. Blocking unapproved apps doesn't address personal accounts on approved ones, and neither solves the extension or OAuth problem. ",[],{},{"nodeType":568,"data":609,"content":613},{"target":610},{"sys":611},{"id":612,"type":573,"linkType":574},"2hsKQ9DEspflhmtR0bE7QY",[],{"nodeType":432,"data":615,"content":616},{},[617,622],{"nodeType":436,"value":618,"marks":619,"data":621},"Second",[620],{"type":471},{},{"nodeType":436,"value":623,"marks":624,"data":625},", the tools most organizations rely on to manage shadow SaaS — SWGs, CASBs, EDR, IdP logs — are structurally blind to shadow AI. An SWG sees that someone visited an AI domain but can't tell you whether they logged in, pasted source code into a prompt, or granted OAuth access to your Google Workspace tenant. EDR doesn't see browser-layer activity at all. IdP logs capture OAuth grants routed through the identity provider but miss tools accessed via direct signup or personal accounts. Instead, the activity security teams need to see happens primarily inside the browser.",[],{},{"nodeType":568,"data":627,"content":631},{"target":628},{"sys":629},{"id":630,"type":573,"linkType":574},"1vE0dyAKdnTSjyAJ4Xoadd",[],{"nodeType":432,"data":633,"content":634},{},[635,640],{"nodeType":436,"value":636,"marks":637,"data":639},"Third",[638],{"type":471},{},{"nodeType":436,"value":641,"marks":642,"data":643},", the risk profile is different. Shadow AI tools increasingly function as hubs — connected via OAuth integrations and MCP to email, cloud storage, code repositories, and other high-value systems. They leak sensitive data outward (employees paste source code, credentials, and internal documents into prompts daily) while simultaneously expanding the attack surface inward (compromise a single AI app and an attacker inherits whatever access the employee granted it, turning one ungoverned tool into a pivot point across the SaaS estate). ",[],{},{"nodeType":568,"data":645,"content":649},{"target":646},{"sys":647},{"id":648,"type":573,"linkType":574},"3ldZ23OORTu7INBfSnE7R7",[],{"nodeType":577,"data":651,"content":652},{},[],{"nodeType":581,"data":654,"content":655},{},[656],{"nodeType":436,"value":657,"marks":658,"data":660},"Why blocking AI usage fails",[659],{"type":471},{},{"nodeType":432,"data":662,"content":663},{},[664],{"nodeType":436,"value":665,"marks":666,"data":667},"The instinct to block AI tools makes sense. Executives are asking about AI risk to the business, a new tool appears every week, and blocking unapproved apps feels like a quick way to stop the bleeding.",[],{},{"nodeType":432,"data":669,"content":670},{},[671,675,683],{"nodeType":436,"value":672,"marks":673,"data":674},"Unfortunately, blocking doesn't work for long. The latest security frameworks — including the ",[],{},{"nodeType":455,"data":676,"content":678},{"uri":677},"https://www.sans.org/mlp/2026-ai-security-maturity-model-ebook",[679],{"nodeType":436,"value":680,"marks":681,"data":682},"SANS AI Security Maturity Model",[],{},{"nodeType":436,"value":684,"marks":685,"data":686}," — all agree: Block-based AI policies drive usage underground rather than preventing it. ",[],{},{"nodeType":688,"data":689,"content":690},"blockquote",{},[691],{"nodeType":432,"data":692,"content":693},{},[694],{"nodeType":436,"value":695,"marks":696,"data":697},"A block-based AI policy may feel like risk management, but practitioner experience shows that it typically drives AI usage underground rather than preventing it. The goal is not to eliminate AI use; it is to bring it into visibility where it can be governed.",[],{},{"nodeType":432,"data":699,"content":700},{},[701],{"nodeType":436,"value":702,"marks":703,"data":704},"These kinds of barricades also fail for a structural reason: They're built on the network perimeter, and AI usage doesn't cross the perimeter in ways network tools can inspect.",[],{},{"nodeType":432,"data":706,"content":707},{},[708],{"nodeType":436,"value":709,"marks":710,"data":711},"The most damaging consequence of blocking isn't the workarounds themselves — it's the loss of visibility. To begin building a better path for employees, you have to start with seeing what's actually happening.",[],{},{"nodeType":577,"data":713,"content":714},{},[],{"nodeType":581,"data":716,"content":717},{},[718],{"nodeType":436,"value":719,"marks":720,"data":722},"Using Push to discover, govern, and control shadow AI",[721],{"type":471},{},{"nodeType":432,"data":724,"content":725},{},[726],{"nodeType":436,"value":727,"marks":728,"data":729},"Push Security is a browser security platform that gets you the vantage point you need to start addressing shadow AI. Push deploys as a lightweight extension to employees' existing browsers rather than requiring a full browser migration, giving security teams visibility into browser-layer activity that network and endpoint tools structurally lack.",[],{},{"nodeType":432,"data":731,"content":732},{},[733,737,742,746,751],{"nodeType":436,"value":734,"marks":735,"data":736},"Push discovers AI tools through ",[],{},{"nodeType":436,"value":738,"marks":739,"data":741},"automatic",[740],{"type":471},{},{"nodeType":436,"value":743,"marks":744,"data":745}," ",[],{},{"nodeType":436,"value":747,"marks":748,"data":750},"app discovery",[749],{"type":471},{},{"nodeType":436,"value":752,"marks":753,"data":754},", allowing you to identify applications from actual browser login events rather than network traffic logs. ",[],{},{"nodeType":568,"data":756,"content":760},{"target":757},{"sys":758},{"id":759,"type":573,"linkType":574},"4eTkgU2dxhMueHPiwuCWDl",[],{"nodeType":432,"data":762,"content":763},{},[764],{"nodeType":436,"value":765,"marks":766,"data":767},"When an employee signs into a new AI service, Push registers the authentication event, identifies the application, and logs how the employee authenticated — corporate SSO, OIDC, a standalone password, or a personal account. ",[],{},{"nodeType":432,"data":769,"content":770},{},[771,775,780],{"nodeType":436,"value":772,"marks":773,"data":774},"Push then applies ",[],{},{"nodeType":436,"value":776,"marks":777,"data":779},"app categories ",[778],{"type":471},{},{"nodeType":436,"value":781,"marks":782,"data":783},"automatically, classifying the discovered application by type without requiring security teams to build or maintain manual lists.",[],{},{"nodeType":432,"data":785,"content":786},{},[787,791,796],{"nodeType":436,"value":788,"marks":789,"data":790},"Push extends the same discovery across the other three shadow AI dimensions. The platform’s ",[],{},{"nodeType":436,"value":792,"marks":793,"data":795},"browser extension discovery ",[794],{"type":471},{},{"nodeType":436,"value":797,"marks":798,"data":799},"capability catalogs every AI-related extension installed across the workforce, including the specific permissions each extension has requested (access to page content, browsing history, clipboard data), allowing you to review whether those permission combinations could enable data exfiltration or account takeover. ",[],{},{"nodeType":568,"data":801,"content":805},{"target":802},{"sys":803},{"id":804,"type":573,"linkType":574},"1z56sTWWN9E35dE3HhbRNY",[],{"nodeType":432,"data":807,"content":808},{},[809,813,818],{"nodeType":436,"value":810,"marks":811,"data":812},"Push’s ",[],{},{"nodeType":436,"value":814,"marks":815,"data":817},"OAuth integration discovery",[816],{"type":471},{},{"nodeType":436,"value":819,"marks":820,"data":821}," identifies OAuth connections between AI tools and corporate systems — the grants that create persistent API-level access to platforms like Google Workspace.",[],{},{"nodeType":432,"data":823,"content":824},{},[825,829,834],{"nodeType":436,"value":826,"marks":827,"data":828},"For each discovered tool, Push also captures authentication context that points to ",[],{},{"nodeType":436,"value":830,"marks":831,"data":833},"where hidden security risks lie",[832],{"type":471},{},{"nodeType":436,"value":835,"marks":836,"data":837},": SSO vs. password vs. personal account, MFA status, and password strength. An AI tool accessed via corporate SSO with MFA is a different risk than the same tool accessed through a personal Gmail account with a reused password. Similarly, employees using only a password to access AI tools that they’ve integrated with other sensitive corporate systems introduces another level of downstream risk. That context is what makes the inventory actionable.",[],{},{"nodeType":432,"data":839,"content":840},{},[841],{"nodeType":436,"value":842,"marks":843,"data":844},"Push also detects when employees are adopting agentic browsers — autonomous AI-powered browsers like Comet, Atlas, and Dia that browse the web and interact with applications on behalf of users or automated workflows. ",[],{},{"nodeType":432,"data":846,"content":847},{},[848],{"nodeType":436,"value":849,"marks":850,"data":851},"These represent an emerging category of non-human AI identity. They authenticate to SaaS applications, access corporate data, and make API calls, but they aren't managed through traditional identity infrastructure. Push helps you identify these agentic browsers as they appear in the environment, before they become a blind spot.",[],{},{"nodeType":432,"data":853,"content":854},{},[855],{"nodeType":436,"value":856,"marks":857,"data":858},"Returning to the paved path metaphor, this step is about surveying the site before you figure out where to put in the path. You need to understand who’s already doing what, where, so you can find the risks you need to address.",[],{},{"nodeType":568,"data":860,"content":864},{"target":861},{"sys":862},{"id":863,"type":573,"linkType":574},"5iXyJbxwWiUt7WoP7FF0Y2",[],{"nodeType":577,"data":866,"content":867},{},[],{"nodeType":581,"data":869,"content":870},{},[871],{"nodeType":436,"value":872,"marks":873,"data":875},"Step-by-step guide to enforcing AI governance without blocking everything",[874],{"type":471},{},{"nodeType":432,"data":877,"content":878},{},[879],{"nodeType":436,"value":880,"marks":881,"data":882},"The barricade approach favored by existing solutions like network proxies gives you two options: Allow or block. Enforcing AI policy effectively requires a third approach with a bit more nuance: Guide the user to do the right thing. ",[],{},{"nodeType":884,"data":885,"content":886},"heading-2",{},[887],{"nodeType":436,"value":888,"marks":889,"data":890},"Building the \"paved path\" with Push",[],{},{"nodeType":432,"data":892,"content":893},{},[894],{"nodeType":436,"value":895,"marks":896,"data":897},"Push provides all three options as configurable enforcement modes for a variety of readymade controls. Progressing between them is how organizations can move from \"we don't know what people are doing with AI\" to evidence-based governance.",[],{},{"nodeType":432,"data":899,"content":900},{},[901,905,910],{"nodeType":436,"value":902,"marks":903,"data":904},"Push can be deployed silently and begin observing AI usage with no employee-facing intervention. This is effectively Push in ",[],{},{"nodeType":436,"value":906,"marks":907,"data":909},"Monitor",[908],{"type":471},{},{"nodeType":436,"value":911,"marks":912,"data":913}," mode.",[],{},{"nodeType":432,"data":915,"content":916},{},[917],{"nodeType":436,"value":918,"marks":919,"data":920},"The platform records which tools are in use, how employees authenticated, and what usage patterns are emerging. Most organizations should start here to generate a baseline. Telemetry can be streamed to your SIEM or other downstream system to get alerted to newly adopted apps and extensions, and to surface security risks like insecure accounts.",[],{},{"nodeType":432,"data":922,"content":923},{},[924,928,933,937,942],{"nodeType":436,"value":925,"marks":926,"data":927},"Next, most organizations will transition to ",[],{},{"nodeType":436,"value":929,"marks":930,"data":932},"Acknowledge",[931],{"type":471},{},{"nodeType":436,"value":934,"marks":935,"data":936}," mode for controls like in-browser ",[],{},{"nodeType":436,"value":938,"marks":939,"data":941},"App banners",[940],{"type":471},{},{"nodeType":436,"value":943,"marks":944,"data":945},". With this control, you can warn employees when they attempt to use an unapproved AI tool and point them to approved alternatives.",[],{},{"nodeType":568,"data":947,"content":951},{"target":948},{"sys":949},{"id":950,"type":573,"linkType":574},"17nT8JDTyHLExwhb2upb6T",[],{"nodeType":432,"data":953,"content":954},{},[955],{"nodeType":436,"value":956,"marks":957,"data":958},"The employee isn't blocked — they're guided toward the governed path at the moment they're about to step off it. This is more effective than a policy document because it arrives right when they need the reminder. ",[],{},{"nodeType":568,"data":960,"content":964},{"target":961},{"sys":962},{"id":963,"type":573,"linkType":574},"2lDFCuc48jcGODcwD6nYhK",[],{"nodeType":432,"data":966,"content":967},{},[968,973],{"nodeType":436,"value":969,"marks":970,"data":972},"Block",[971],{"type":471},{},{"nodeType":436,"value":974,"marks":975,"data":976}," mode prevents access entirely — Push presents a blocking banner to users who attempt to log in to unapproved apps. ",[],{},{"nodeType":432,"data":978,"content":979},{},[980],{"nodeType":436,"value":981,"marks":982,"data":983},"Push makes the Monitor → Acknowledge → Block progression practical through automatic app categorization. This means that new AI tools inherit whatever governance mode the team has set for that category, without manual blocklist updates. All controls are configurable per user group — the data science team can use AI coding assistants while uploads from finance are restricted — because different teams have different risk profiles.",[],{},{"nodeType":568,"data":985,"content":989},{"target":986},{"sys":987},{"id":988,"type":573,"linkType":574},"5EBOHy6X6iJfmzJ65txGOv",[],{"nodeType":568,"data":991,"content":995},{"target":992},{"sys":993},{"id":994,"type":573,"linkType":574},"31JnX2KNCAnlaVS9Qqqh8W",[],{"nodeType":577,"data":997,"content":998},{},[],{"nodeType":581,"data":1000,"content":1001},{},[1002],{"nodeType":436,"value":1003,"marks":1004,"data":1006},"Guardrails: how to prevent data loss to AI tools",[1005],{"type":471},{},{"nodeType":432,"data":1008,"content":1009},{},[1010],{"nodeType":436,"value":1011,"marks":1012,"data":1013},"Even on the paved path, you need guardrails because preventing data loss to AI tools is a separate problem from controlling which tools employees use. An employee on an approved AI tool can still paste an AWS access key into a prompt, upload a customer spreadsheet, or share confidential documents in a conversation.",[],{},{"nodeType":432,"data":1015,"content":1016},{},[1017,1020,1029],{"nodeType":436,"value":21,"marks":1018,"data":1019},[],{},{"nodeType":455,"data":1021,"content":1022},{"uri":488},[1023],{"nodeType":436,"value":1024,"marks":1025,"data":1028},"Okta's data",[1026],{"type":1027},"underline",{},{"nodeType":436,"value":1030,"marks":1031,"data":1032}," on what employees actually share shows what’s at stake: 54% share internal messages and emails with AI tools, 39% share confidential company documents, and 28% share banking and payment information.",[],{},{"nodeType":432,"data":1034,"content":1035},{},[1036],{"nodeType":436,"value":1037,"marks":1038,"data":1039},"Blocking is too much of a blunt instrument here, as obviously, you want employees to be able to use approved tools. The answer is controlling what data enters them.",[],{},{"nodeType":884,"data":1041,"content":1042},{},[1043],{"nodeType":436,"value":1044,"marks":1045,"data":1047},"Browser-layer controls for AI data leakage",[1046],{"type":471},{},{"nodeType":432,"data":1049,"content":1050},{},[1051],{"nodeType":436,"value":1052,"marks":1053,"data":1054},"Push addresses this problem with four browser-layer data controls, each targeting a distinct exfiltration path and supporting the same Monitor → Warn → Block enforcement modes:",[],{},{"nodeType":432,"data":1056,"content":1057},{},[1058,1063],{"nodeType":436,"value":1059,"marks":1060,"data":1062},"Clipboard blocking",[1061],{"type":471},{},{"nodeType":436,"value":1064,"marks":1065,"data":1066}," addresses the most common path for sensitive data into AI tools: copy-paste. Push matches clipboard content against preconfigured patterns for AWS access keys, GitHub tokens, API keys, credit card numbers, and personal identifiers, plus custom content rules for organization-specific data like internal project codes. ",[],{},{"nodeType":432,"data":1068,"content":1069},{},[1070,1074,1079],{"nodeType":436,"value":1071,"marks":1072,"data":1073},"In ",[],{},{"nodeType":436,"value":1075,"marks":1076,"data":1078},"Warn",[1077],{"type":471},{},{"nodeType":436,"value":1080,"marks":1081,"data":1082}," mode, Push offers a redacted version of the sensitive data so the employee can continue their work — getting help with their code, for instance — without exposing the actual credential.",[],{},{"nodeType":568,"data":1084,"content":1088},{"target":1085},{"sys":1086},{"id":1087,"type":573,"linkType":574},"1JarUdbe8AkJlgB0LjchNR",[],{"nodeType":432,"data":1090,"content":1091},{},[1092,1097],{"nodeType":436,"value":1093,"marks":1094,"data":1096},"File upload blocking",[1095],{"type":471},{},{"nodeType":436,"value":1098,"marks":1099,"data":1100}," prevents files from being uploaded to specific AI apps, configurable by app, user group, and file type (Push provides a list for fast configuration).",[],{},{"nodeType":432,"data":1102,"content":1103},{},[1104,1109,1113,1122,1126,1131],{"nodeType":436,"value":1105,"marks":1106,"data":1108},"File download blocking",[1107],{"type":471},{},{"nodeType":436,"value":1110,"marks":1111,"data":1112}," addresses a different common risk: Employees downloading desktop versions of AI tools, which moves usage outside the browser where Push has visibility. Download blocking also covers files generated inside web applications, such as an AI tool that produces a downloadable asset. (Push’s detection and response capabilities also protect against scenarios in which attackers present users with ",[],{},{"nodeType":455,"data":1114,"content":1116},{"uri":1115},"https://pushsecurity.com/blog/llmshare-malvertising-campaign",[1117],{"nodeType":436,"value":1118,"marks":1119,"data":1121},"faked AI tool download pages",[1120],{"type":1027},{},{"nodeType":436,"value":1123,"marks":1124,"data":1125}," as part of phishing campaigns, a technique we dubbed ",[],{},{"nodeType":436,"value":1127,"marks":1128,"data":1130},"LLMShare",[1129],{"type":471},{},{"nodeType":436,"value":1132,"marks":1133,"data":1134},".)",[],{},{"nodeType":432,"data":1136,"content":1137},{},[1138],{"nodeType":436,"value":1139,"marks":1140,"data":1141},"Push also provides telemetry streams on all file upload and download events in your environment, so you can get a baseline pattern of life and identify anomalies that could indicate insider risk. ",[],{},{"nodeType":432,"data":1143,"content":1144},{},[1145,1149,1154],{"nodeType":436,"value":1146,"marks":1147,"data":1148},"The Push platform also provides the capability to write your own ",[],{},{"nodeType":436,"value":1150,"marks":1151,"data":1153},"custom detections",[1152],{"type":471},{},{"nodeType":436,"value":1155,"marks":1156,"data":1157},", which you can use for other organization-specific use cases, or even to extend your control over GenAI tool usage, such as by blocking unapproved MCP server connections.",[],{},{"nodeType":568,"data":1159,"content":1163},{"target":1160},{"sys":1161},{"id":1162,"type":573,"linkType":574},"5XYVgJjgUPUfY1W1Zcgrvm",[],{"nodeType":432,"data":1165,"content":1166},{},[1167,1171,1176],{"nodeType":436,"value":1168,"marks":1169,"data":1170},"Finally, ",[],{},{"nodeType":436,"value":1172,"marks":1173,"data":1175},"AI conversation visibility",[1174],{"type":471},{},{"nodeType":436,"value":1177,"marks":1178,"data":1179}," gives you a window into what is being shared in AI chats, consumable as a stream of events to your SIEM or SOAR. Over time, you can build up a picture of what’s normal or what violates company policy, and create a queryable history to identify potential data loss during an incident response process.",[],{},{"nodeType":432,"data":1181,"content":1182},{},[1183],{"nodeType":436,"value":1184,"marks":1185,"data":1186},"Traditional DLP at the endpoint or network layer misses these paths. Network DLP and SWGs can't inspect clipboard pastes into AI prompts — there's no network event to intercept. Endpoint DLP sees file-system operations but not in-browser activity. ",[],{},{"nodeType":432,"data":1188,"content":1189},{},[1190],{"nodeType":436,"value":1191,"marks":1192,"data":1193},"Push's controls operate where the data is flowing — inside the browser session.",[],{},{"nodeType":577,"data":1195,"content":1196},{},[],{"nodeType":884,"data":1198,"content":1199},{},[1200],{"nodeType":436,"value":1201,"marks":1202,"data":1204},"How to keep up with AI tool sprawl",[1203],{"type":471},{},{"nodeType":432,"data":1206,"content":1207},{},[1208],{"nodeType":436,"value":1209,"marks":1210,"data":1211},"Pragmatically, the hardest part of generative AI security isn't the initial steps you take — it's keeping up with the sprawl. Point-in-time audits quickly become outdated when the landscape changes so quickly.",[],{},{"nodeType":432,"data":1213,"content":1214},{},[1215],{"nodeType":436,"value":1216,"marks":1217,"data":1218},"Push addresses this with continuous discovery, telemetry streams for the most important points of user interaction with AI apps, and controls that allow you to adapt quickly with simple configuration changes.",[],{},{"nodeType":432,"data":1220,"content":1221},{},[1222],{"nodeType":436,"value":1223,"marks":1224,"data":1225},"With automatic app categorization, if an employee starts using a new AI code assistant that didn't exist last quarter, Push discovers it, classifies it, and applies your governance rules — no manual intervention required.",[],{},{"nodeType":432,"data":1227,"content":1228},{},[1229],{"nodeType":436,"value":1230,"marks":1231,"data":1232},"All AI-related telemetry — app logins, file uploads and downloads, clipboard events, browser extensions, AI chat transcripts — can be sent as structured data to your SIEM.",[],{},{"nodeType":432,"data":1234,"content":1235},{},[1236],{"nodeType":436,"value":1237,"marks":1238,"data":1239},"This gives you all the information you need to track your progress, check your compliance status, and identify trends in AI usage and risk across your business as you make progress toward your goal, armed with the right data you didn't have before.",[],{},{"nodeType":432,"data":1241,"content":1242},{},[1243],{"nodeType":436,"value":1244,"marks":1245,"data":1246},"The goal isn't perfect control over every AI interaction. It's having enough visibility to make informed decisions and enough control to enforce them, without intensifying the shadow AI usage problem you set out to solve. Push can help you get there.",[],{},{"nodeType":577,"data":1248,"content":1249},{},[],{"nodeType":432,"data":1251,"content":1252},{},[1253],{"nodeType":436,"value":1254,"marks":1255,"data":1256},"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",[],{},{"nodeType":432,"data":1258,"content":1259},{},[1260],{"nodeType":436,"value":1261,"marks":1262,"data":1263},"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",[],{},{"nodeType":432,"data":1265,"content":1266},{},[1267,1270,1279],{"nodeType":436,"value":21,"marks":1268,"data":1269},[],{},{"nodeType":455,"data":1271,"content":1273},{"uri":1272},"https://pushsecurity.com/demo",[1274],{"nodeType":436,"value":1275,"marks":1276,"data":1278},"Book a live demo to learn more.",[1277],{"type":1027},{},{"nodeType":436,"value":21,"marks":1280,"data":1281},[],{},{"entries":1283},{"hyperlink":1284,"inline":1285,"block":1286},[],[],[1287,1294,1303,1310,1348,1355,1362,1368,1375,1402,1410,1424,1430],{"sys":1288,"__typename":1289,"type":1290,"ctaText":1291,"buttonLabel":1292,"buttonColour":1293,"buttonUrl":58},{"id":572},"CtaWidget","Custom","Don't miss our upcoming webinar on Shadow AI and how to manage it in your organization.","Register Now","sunny orange",{"sys":1295,"__typename":1296,"title":1297,"caption":1298,"layoutMode":59,"file":1299},{"id":612},"Image","ai-sprawl-infographic","AI sprawl is worse than most organizations realize. ",{"url":1300,"width":1301,"height":1302},"https://images.ctfassets.net/y1cdw1ablpvd/7vCbQdyRkjLs5EmsjBBAQp/3bfb13e7ec19be76325cdc69297c48c3/ai-sprawl-infographic_2x__3_.png",1800,1192,{"sys":1304,"__typename":1296,"title":1305,"caption":1305,"layoutMode":59,"file":1306},{"id":630},"Shadow AI visibility gaps using traditional tools",{"url":1307,"width":1308,"height":1309},"https://images.ctfassets.net/y1cdw1ablpvd/7HQl2qfsTiCwa2pRzCVqDE/d87180dd96358326097565d8a60e8591/image9.png",1999,1125,{"sys":1311,"__typename":1312,"content":1313,"name":1347,"title":59},{"id":648},"InsightTextBlockComponent",{"json":1314},{"data":1315,"content":1316,"nodeType":428},{},[1317],{"data":1318,"content":1319,"nodeType":432},{},[1320,1324,1331,1335,1343],{"data":1321,"marks":1322,"value":1323,"nodeType":436},{},[],"Attackers are already exploiting this interconnectivity — from ",{"data":1325,"content":1326,"nodeType":455},{"uri":1115},[1327],{"data":1328,"marks":1329,"value":1330,"nodeType":436},{},[],"malvertising campaigns that impersonate AI tools",{"data":1332,"marks":1333,"value":1334,"nodeType":436},{},[]," to steal credentials, to ",{"data":1336,"content":1338,"nodeType":455},{"uri":1337},"https://pushsecurity.com/blog/analyzing-the-instructure-breach",[1339],{"data":1340,"marks":1341,"value":1342,"nodeType":436},{},[],"leveraging OAuth consent grants in supply chain attacks",{"data":1344,"marks":1345,"value":1346,"nodeType":436},{},[],". ","Shadow AI guide IB3",{"sys":1349,"__typename":1296,"title":1350,"caption":1350,"layoutMode":59,"file":1351},{"id":759},"Push automatically discovers and inventories AI apps from browser login events.",{"url":1352,"width":1353,"height":1354},"https://images.ctfassets.net/y1cdw1ablpvd/5krEecjMxIJgVCa74A79xa/3bb94ca3b496e9486f94526d708e34d5/image8.png",1469,850,{"sys":1356,"__typename":1296,"title":1357,"caption":1357,"layoutMode":59,"file":1358},{"id":804},"Push discovers AI browser extensions used by your users, across every browser.",{"url":1359,"width":1360,"height":1361},"https://images.ctfassets.net/y1cdw1ablpvd/14lMFifCBB9RwQpt101tNd/dabe2713e58e787175701ec0d35076ca/image2.png",1470,851,{"sys":1363,"__typename":1296,"title":1364,"caption":1364,"layoutMode":59,"file":1365},{"id":863},"Push's four-step path to secure AI adoption",{"url":1366,"width":1308,"height":1367},"https://images.ctfassets.net/y1cdw1ablpvd/E1wuJW4EzmjeLTpnHHM9f/895569f4b215b1b7b82e697c40462cbc/image3.png",1013,{"sys":1369,"__typename":1296,"title":1370,"caption":1370,"layoutMode":59,"file":1371},{"id":950},"Push in-browser warning screen guiding the user toward the preferred AI app",{"url":1372,"width":1373,"height":1374},"https://images.ctfassets.net/y1cdw1ablpvd/3ouLBkKhiEcBmY8V2XAaUz/71a3cb221adba7d2744ff8b02bab3891/image4.png",1435,738,{"sys":1376,"__typename":1312,"content":1377,"name":1401,"title":59},{"id":963},{"json":1378},{"data":1379,"content":1380,"nodeType":428},{},[1381],{"data":1382,"content":1383,"nodeType":432},{},[1384,1388,1397],{"data":1385,"marks":1386,"value":1387,"nodeType":436},{},[],"“A published policy is not the same thing as people actually doing that,” explains Push customer Stephen Shkardoon, cybersecurity manager at Te Herenga Waka — Victoria University of Wellington in New Zealand, on one of the drivers for their ",{"data":1389,"content":1391,"nodeType":455},{"uri":1390},"https://pushsecurity.com/customer-stories/te-herenga-waka-victoria-university-of-wellington",[1392],{"data":1393,"marks":1394,"value":1396,"nodeType":436},{},[1395],{"type":1027},"selection of Push Security",{"data":1398,"marks":1399,"value":1400,"nodeType":436},{},[]," to get control of AI usage at their organization.","Shadow AI guide IB1",{"sys":1403,"__typename":1296,"title":1404,"caption":1405,"layoutMode":59,"file":1406},{"id":988},"Rules for AI app controls can be configured on a variety of conditions, including user groups, app attributes, and what mode of enforcement you wish to use.","Rules for AI app controls can be configured on a variety of conditions, including user groups, app attributes, and the mode of enforcement.",{"url":1407,"width":1408,"height":1409},"https://images.ctfassets.net/y1cdw1ablpvd/7czh28QGwm0ZStUmeWXBaq/667ee2441911fa4006a2ec75ebf727ea/image6.png",692,830,{"sys":1411,"__typename":1312,"content":1412,"name":1423,"title":59},{"id":994},{"json":1413},{"data":1414,"content":1415,"nodeType":428},{},[1416],{"data":1417,"content":1418,"nodeType":432},{},[1419],{"data":1420,"marks":1421,"value":1422,"nodeType":436},{},[],"Push customers love the flexibility of this control compared to an SWG or CASB, which often rely on binary enforcement at the domain level only. ","Shadow AI guide IB2",{"sys":1425,"__typename":1296,"title":1426,"caption":1426,"layoutMode":59,"file":1427},{"id":1087},"Push blocks clipboard copy events that violate your policy.",{"url":1428,"width":1308,"height":1429},"https://images.ctfassets.net/y1cdw1ablpvd/jjUt4bChHcCWQJXqNzyQ8/c16974d72ef2bbc65689bf46bcb59e6f/image5.png",1295,{"sys":1431,"__typename":1296,"title":1432,"caption":1432,"layoutMode":59,"file":1433},{"id":1162},"Push can block unapproved MCP connection requests in real time.",{"url":1434,"width":1308,"height":1435},"https://images.ctfassets.net/y1cdw1ablpvd/wTAwk90bIA1B3XSkRf4M4/e4d3630af83501e6b4b05217fdf2e600/image1.png",1203,"json",{"items":1438},[1439,1452,1465,1485,1505,1525,1545,1565,1585,1605],{"answer":1440,"question":1451},{"json":1441},{"nodeType":428,"data":1442,"content":1443},{},[1444],{"nodeType":432,"data":1445,"content":1446},{},[1447],{"nodeType":436,"value":1448,"marks":1449,"data":1450},"Network monitoring tools see domain-level traffic but can't tell you what's actually happening inside an AI session — whether an employee is browsing a tool's marketing page or pasting source code into a prompt. IdP logs capture OAuth grants routed through the identity provider but miss AI tools accessed via direct signup or personal accounts. Browser-based security tools like Push Security monitor AI activity where it actually happens: inside the browser session. Push captures login events, clipboard pastes, file uploads, extension installations, and OAuth grants, providing structured telemetry on what data is moving into which AI tools, through which accounts, and whether those accounts are corporate or personal.",[],{},"How do you monitor what employees are doing with AI tools?",{"answer":1453,"question":1464},{"json":1454},{"nodeType":428,"data":1455,"content":1456},{},[1457],{"nodeType":432,"data":1458,"content":1459},{},[1460],{"nodeType":436,"value":1461,"marks":1462,"data":1463},"Binary allow/block decisions — whether enforced through a SWG, CASB, or enterprise browser — treat every AI interaction as equivalent, which pushes employees toward tools you can't see at all. Graduated enforcement offers a middle path. Push Security lets teams start with monitoring to build an accurate picture of AI usage, then introduce in-browser prompts that explain why a tool hasn't been approved and direct employees toward sanctioned alternatives, before applying hard blocks only where the data sensitivity or tool risk justifies it. Controls are configurable per user group, and new AI tools automatically inherit governance rules through automatic categorization — so enforcement keeps pace with the landscape without manual blocklist updates.",[],{},"How do you restrict AI usage without blocking everything?",{"answer":1466,"question":1484},{"json":1467},{"nodeType":428,"data":1468,"content":1469},{},[1470,1477],{"nodeType":432,"data":1471,"content":1472},{},[1473],{"nodeType":436,"value":1474,"marks":1475,"data":1476},"Network monitoring tools, IdP logs, and endpoint agents each catch a slice of shadow AI but miss entire categories. SWGs see domain traffic but can't confirm whether someone authenticated or what they did after login. IdPs capture OAuth grants routed through the identity provider but miss AI tools accessed via direct signup or personal accounts. EDR is blind to browser-layer activity entirely. ",[],{},{"nodeType":432,"data":1478,"content":1479},{},[1480],{"nodeType":436,"value":1481,"marks":1482,"data":1483},"Browser-based security tools like Push Security identify AI tools from actual login events, catching the four categories other tools miss: unapproved AI apps, personal accounts on approved tools, AI browser extensions with broad permissions, and OAuth integrations granting persistent API access to corporate systems. Each discovered app is automatically categorized and enriched with authentication context — SSO vs. password, MFA status, corporate vs. personal account — so security teams can assess actual risk rather than treating every AI tool as equivalent.",[],{},"How do you discover what AI tools employees are using?",{"answer":1486,"question":1504},{"json":1487},{"nodeType":428,"data":1488,"content":1489},{},[1490,1497],{"nodeType":432,"data":1491,"content":1492},{},[1493],{"nodeType":436,"value":1494,"marks":1495,"data":1496},"This is a gap that traditional DLP architectures weren't designed for. Network DLP and SWGs can't intercept clipboard pastes into AI prompts because there's no network event to inspect — the data moves from the clipboard to the browser DOM without crossing the wire. Endpoint DLP sees file-system operations but not in-browser activity. Browser-based controls operate where the paste actually happens. ",[],{},{"nodeType":432,"data":1498,"content":1499},{},[1500],{"nodeType":436,"value":1501,"marks":1502,"data":1503},"Push Security matches clipboard content against patterns for credentials, API keys, credit card numbers, and custom content rules, then offers the employee a redacted version so they can continue working without exposing the actual sensitive data. The same approach extends to file uploads and downloads, covering the exfiltration paths that network and endpoint DLP leave open.",[],{},"How do you prevent sensitive data from being pasted into AI tools?",{"answer":1506,"question":1524},{"json":1507},{"nodeType":428,"data":1508,"content":1509},{},[1510,1517],{"nodeType":432,"data":1511,"content":1512},{},[1513],{"nodeType":436,"value":1514,"marks":1515,"data":1516},"Policy documents distributed during onboarding don't change behavior at the moment someone reaches for an unapproved AI tool. SWGs can block a domain, but they can't explain why or point to an approved alternative — the employee sees an error page. ",[],{},{"nodeType":432,"data":1518,"content":1519},{},[1520],{"nodeType":436,"value":1521,"marks":1522,"data":1523},"Enterprise browsers like Push Security can deliver policy enforcement at the point of decision: when an employee navigates to an unsanctioned AI tool, an in-browser message explains why the tool hasn't been approved and directs them to approved alternatives. Controls are configurable per user group — and new AI tools automatically inherit governance rules through automatic categorization, without manual blocklist updates.",[],{},"How do you enforce an AI acceptable use policy in real time?",{"answer":1526,"question":1544},{"json":1527},{"nodeType":428,"data":1528,"content":1529},{},[1530,1537],{"nodeType":432,"data":1531,"content":1532},{},[1533],{"nodeType":436,"value":1534,"marks":1535,"data":1536},"No single traditional tool covers all aspects of shadow AI (apps, tenants, integrations, extensions) and the user interaction with those categories of tool. SWGs and CASBs see domain-level traffic but can't identify personal account usage, extension activity, or clipboard pastes into AI prompts. IdPs capture federated logins but miss direct signups and personal accounts entirely. EDR doesn't see browser-layer activity. DSPM monitors data at rest in cloud storage but not data in motion through browser sessions. ",[],{},{"nodeType":432,"data":1538,"content":1539},{},[1540],{"nodeType":436,"value":1541,"marks":1542,"data":1543},"Most organizations will need browser-layer visibility alongside their existing stack — not as a replacement, but to close the gaps those tools weren't designed to address. Tools like Push Security operate at the layer where AI activity actually happens, covering all shadow AI categories with graduated enforcement (monitor, warn, block), per-user-group policies, and telemetry on authentication methods, clipboard events, file uploads, and OAuth grants. ",[],{},"What tools do you need to manage shadow AI?",{"answer":1546,"question":1564},{"json":1547},{"nodeType":428,"data":1548,"content":1549},{},[1550,1557],{"nodeType":432,"data":1551,"content":1552},{},[1553],{"nodeType":436,"value":1554,"marks":1555,"data":1556},"AI browser extensions are a blind spot for most security stacks. Endpoint management tools may detect that an extension is installed but typically can't evaluate what permissions it has requested or whether those permissions create data exfiltration risk. SWGs and CASBs don't see extension activity at all — extensions operate within the browser, not over the network. ",[],{},{"nodeType":432,"data":1558,"content":1559},{},[1560],{"nodeType":436,"value":1561,"marks":1562,"data":1563},"Push Security inventories every AI-related extension installed across the workforce, surfaces the specific permissions each extension has requested (access to page content, browsing history, clipboard data), and identifies permission combinations that could enable account takeover or data exfiltration. Security teams can then apply monitor, warn, or block enforcement to extension categories — and new extensions automatically inherit governance rules without maintaining manual allowlists that go stale as new AI extensions appear daily.",[],{},"How do I stop employees installing AI browser extensions?",{"answer":1566,"question":1584},{"json":1567},{"nodeType":428,"data":1568,"content":1569},{},[1570,1577],{"nodeType":432,"data":1571,"content":1572},{},[1573],{"nodeType":436,"value":1574,"marks":1575,"data":1576},"Point-in-time audits — whether run through an IdP, a CASB, or manual surveys — tell you what was true when you ran them. AI tool adoption changes weekly; Gartner projects 150,000 AI agents per Fortune 500 enterprise by 2028. SWGs can log new domains but can't classify them or apply governance rules automatically. ",[],{},{"nodeType":432,"data":1578,"content":1579},{},[1580],{"nodeType":436,"value":1581,"marks":1582,"data":1583},"Push Security discovers new AI tools as employees start using them: when someone logs in to a new AI app, Push identifies it from the login event, automatically categorizes it, and applies the organization's existing governance rules without manual intervention. All AI-related telemetry — app access, file uploads, clipboard events, extension activity — streams as structured data to the customer's SIEM, providing the material for governance dashboards and compliance reporting that stays current as the landscape shifts.",[],{},"How do you get visibility into AI tool sprawl?",{"answer":1586,"question":1604},{"json":1587},{"nodeType":428,"data":1588,"content":1589},{},[1590,1597],{"nodeType":432,"data":1591,"content":1592},{},[1593],{"nodeType":436,"value":1594,"marks":1595,"data":1596},"AI visibility means knowing which AI tools employees are using, how they're accessing them, and what data flows into those tools. AI control is the ability to enforce rules on that usage — blocking unapproved tools, restricting data flows, requiring approved accounts. AI governance is the broader program that encompasses both: defining acceptable use policies, establishing risk frameworks for evaluating new tools, and building the organizational processes that turn visibility and control into sustained security outcomes. ",[],{},{"nodeType":432,"data":1598,"content":1599},{},[1600],{"nodeType":436,"value":1601,"marks":1602,"data":1603},"Most organizations that struggle with AI governance have a visibility problem first — they're trying to write policies for tools they don't know their employees are using. But visibility without control is just watching the problem happen. Push Security provides both: discovery and monitoring across all four categories of shadow AI, plus graduated enforcement controls that let you apply different responses based on the risk profile of each tool, account, and data flow, at the point of interaction in the browser for real-time enforcement.",[],{},"What is the difference between AI governance, AI visibility, and AI control?",{"answer":1606,"question":1624},{"json":1607},{"nodeType":428,"data":1608,"content":1609},{},[1610,1617],{"nodeType":432,"data":1611,"content":1612},{},[1613],{"nodeType":436,"value":1614,"marks":1615,"data":1616},"Data Security Posture Management (DSPM) tools monitor data at rest in cloud storage and SaaS applications, identifying misconfigurations, overly permissive access, and sensitive data exposure. They don't monitor data in motion through browser sessions — which is the primary path for shadow AI risk. ",[],{},{"nodeType":432,"data":1618,"content":1619},{},[1620],{"nodeType":436,"value":1621,"marks":1622,"data":1623},"When an employee pastes source code into an AI prompt or uploads a customer spreadsheet to an unapproved AI tool, that data movement happens entirely inside the browser and never touches the cloud storage layer that DSPM tools monitor. DSPM and browser security are complementary: DSPM secures data where it is stored, while browser-layer tools like Push Security secure data where it moves.",[],{},"Does Data Security Posture Management (DSPM) prevent shadow AI?","Shadow AI discovery and governance: Frequently asked questions",{},"How to discover AI, enforce policies, and prevent data loss","2026-08-13T00:00:00.000Z",{"items":1630},[1631,2316,3201],{"__typename":1632,"sys":1633,"content":1635,"title":2294,"synopsis":2295,"hashTags":59,"publishedDate":2296,"slug":2297,"tagsCollection":2298,"authorsCollection":2308},"BlogPosts",{"id":1634},"4NY2NbkAPucFOJY45yrrrE",{"json":1636},{"data":1637,"content":1638,"nodeType":428},{},[1639,1646,1653,1660,1666,1669,1677,1684,1717,1724,1749,1755,1758,1766,1773,1781,1825,1831,1838,1843,1846,1854,1861,1869,1876,1883,1899,1907,1932,1939,1945,1952,1960,1975,2003,2009,2027,2033,2041,2048,2073,2080,2087,2094,2100,2103,2111,2118,2125,2144,2152,2159,2167,2190,2202,2208,2211,2219,2226,2233,2240,2260,2263,2269,2275],{"data":1640,"content":1641,"nodeType":432},{},[1642],{"data":1643,"marks":1644,"value":1645,"nodeType":436},{},[],"Employees have been self-adopting apps, creating unmanaged accounts, and introducing third-party software dependencies into their organizations for years, and the core problem hasn't changed: unmanaged software expanding your attack surface without your knowledge.",{"data":1647,"content":1648,"nodeType":432},{},[1649],{"data":1650,"marks":1651,"value":1652,"nodeType":436},{},[],"But the rate at which employees are signing up for AI tools is unprecedented, and the depth of interconnectivity those tools demand is fundamentally different from traditional shadow SaaS. ",{"data":1654,"content":1655,"nodeType":432},{},[1656],{"data":1657,"marks":1658,"value":1659,"nodeType":436},{},[],"AI tools aren't just standalone apps that employees sign into — they're increasingly used as agents that drive other applications, pulling data from one platform, acting on another — they are becoming a core that other apps are integrating to, and that users are integrating with their wider SaaS stack. It’s becoming a focal integration point for app access and functionality in a way that's more comparable to an enterprise cloud platform than a typical SaaS tool. ",{"data":1661,"content":1665,"nodeType":568},{"target":1662},{"sys":1663},{"id":1664,"type":573,"linkType":574},"2Vxb48M5JN9Jdy8BG6nbUJ",[],{"data":1667,"content":1668,"nodeType":577},{},[],{"data":1670,"content":1671,"nodeType":581},{},[1672],{"data":1673,"marks":1674,"value":1676,"nodeType":436},{},[1675],{"type":471},"What is shadow AI? A quick 101",{"data":1678,"content":1679,"nodeType":432},{},[1680],{"data":1681,"marks":1682,"value":1683,"nodeType":436},{},[],"Shadow AI is any use of AI tools, services, or integrations that happens outside an organization's security governance and visibility. Shadow AI risks cut in two directions:",{"data":1685,"content":1686,"nodeType":513},{},[1687,1702],{"data":1688,"content":1689,"nodeType":517},{},[1690],{"data":1691,"content":1692,"nodeType":432},{},[1693,1698],{"data":1694,"marks":1695,"value":1697,"nodeType":436},{},[1696],{"type":471},"Data exposure:",{"data":1699,"marks":1700,"value":1701,"nodeType":436},{},[]," source code, credentials, internal documents, and customer data routinely get pasted into AI prompts or uploaded as context, and once shared, that data is outside the organization's control. ",{"data":1703,"content":1704,"nodeType":517},{},[1705],{"data":1706,"content":1707,"nodeType":432},{},[1708,1713],{"data":1709,"marks":1710,"value":1712,"nodeType":436},{},[1711],{"type":471},"Attack surface:",{"data":1714,"marks":1715,"value":1716,"nodeType":436},{},[]," Every shadow AI app is an unmanaged identity with credentials that can be phished or stuffed, OAuth grants that give persistent API access to corporate systems, and browser extensions that can be compromised in supply chain attacks. ",{"data":1718,"content":1719,"nodeType":432},{},[1720],{"data":1721,"marks":1722,"value":1723,"nodeType":436},{},[],"AI tools increasingly function as hubs, connected via OAuth and MCP to email, cloud storage, code repositories, and other high-value systems. Every app connection an employee grants turns that AI tool into a node in a web of interconnected services, which means the more you hook in, the larger the attack surface across all the connected apps — and the greater the blast radius if the account used to access the AI tool is compromised.",{"data":1725,"content":1726,"nodeType":432},{},[1727,1731,1737,1740,1746],{"data":1728,"marks":1729,"value":1730,"nodeType":436},{},[],"Each integration creates a persistent trust relationship that survives password resets and MFA changes. Compromise a single AI app and an attacker inherits whatever access the employee granted it, turning one ungoverned tool into a pivot point across the SaaS estate. Attackers are already exploiting this interconnectivity — from ",{"data":1732,"content":1733,"nodeType":455},{"uri":1115},[1734],{"data":1735,"marks":1736,"value":1330,"nodeType":436},{},[],{"data":1738,"marks":1739,"value":1334,"nodeType":436},{},[],{"data":1741,"content":1742,"nodeType":455},{"uri":1337},[1743],{"data":1744,"marks":1745,"value":1342,"nodeType":436},{},[],{"data":1747,"marks":1748,"value":1346,"nodeType":436},{},[],{"data":1750,"content":1754,"nodeType":568},{"target":1751},{"sys":1752},{"id":1753,"type":573,"linkType":574},"1BWCa7AHCMlYw7XgPLx3h7",[],{"data":1756,"content":1757,"nodeType":577},{},[],{"data":1759,"content":1760,"nodeType":581},{},[1761],{"data":1762,"marks":1763,"value":1765,"nodeType":436},{},[1764],{"type":471},"The state of shadow AI, using Push data",{"data":1767,"content":1768,"nodeType":432},{},[1769],{"data":1770,"marks":1771,"value":1772,"nodeType":436},{},[],"We analyzed a snapshot of AI activity across Push customers during an average week in April 2026. We wanted to make sure it captured actual activity, not just historical data on apps that were added once and no longer used.",{"data":1774,"content":1775,"nodeType":432},{},[1776],{"data":1777,"marks":1778,"value":1780,"nodeType":436},{},[1779],{"type":471},"The numbers paint a picture that most security teams will find uncomfortable.",{"data":1782,"content":1783,"nodeType":432},{},[1784,1788,1793,1797,1802,1806,1811,1815,1821],{"data":1785,"marks":1786,"value":1787,"nodeType":436},{},[],"The average organization has ",{"data":1789,"marks":1790,"value":1792,"nodeType":436},{},[1791],{"type":471},"16 unique AI apps",{"data":1794,"marks":1795,"value":1796,"nodeType":436},{},[]," in active use, ",{"data":1798,"marks":1799,"value":1801,"nodeType":436},{},[1800],{"type":471},"17 unique AI browser extensions",{"data":1803,"marks":1804,"value":1805,"nodeType":436},{},[],", and ",{"data":1807,"marks":1808,"value":1810,"nodeType":436},{},[1809],{"type":471},"17 unique AI OAuth integrations",{"data":1812,"marks":1813,"value":1814,"nodeType":436},{},[]," connected into just Google Workspace and Microsoft 365 — with some organizations reaching as high as 40 unique AI apps, 163 AI extensions, and 55 OAuth connections to AI apps respectively. At the other end, the smallest organization with the ",{"data":1816,"marks":1817,"value":1820,"nodeType":436},{},[1818],{"type":1819},"italic","lowest",{"data":1822,"marks":1823,"value":1824,"nodeType":436},{},[]," adoption level is actively using two. ",{"data":1826,"content":1830,"nodeType":568},{"target":1827},{"sys":1828},{"id":1829,"type":573,"linkType":574},"2AfeiHub5kyZN8wuf6CJch",[],{"data":1832,"content":1833,"nodeType":432},{},[1834],{"data":1835,"marks":1836,"value":1837,"nodeType":436},{},[],"If most organizations have sanctioned one or two core AI assistants/platforms for business use, the gap between what's approved and what's actually happening is significant.",{"data":1839,"content":1842,"nodeType":568},{"target":1840},{"sys":1841},{"id":612,"type":573,"linkType":574},[],{"data":1844,"content":1845,"nodeType":577},{},[],{"data":1847,"content":1848,"nodeType":581},{},[1849],{"data":1850,"marks":1851,"value":1853,"nodeType":436},{},[1852],{"type":471},"Understanding the four categories of shadow AI",{"data":1855,"content":1856,"nodeType":432},{},[1857],{"data":1858,"marks":1859,"value":1860,"nodeType":436},{},[],"Shadow SaaS has always been a problem, but in the context of AI apps there are four categories of shadow IT that security teams need to understand, because each one introduces a different kind of risk and requires a different approach to tackling it.",{"data":1862,"content":1863,"nodeType":884},{},[1864],{"data":1865,"marks":1866,"value":1868,"nodeType":436},{},[1867],{"type":471},"Shadow AI apps",{"data":1870,"content":1871,"nodeType":432},{},[1872],{"data":1873,"marks":1874,"value":1875,"nodeType":436},{},[],"Shadow apps are AI tools that employees have signed up to and are using for business purposes without approval. This is the most visible dimension of the problem, and the one most people think of when they hear \"shadow AI\" — an employee pastes sensitive internal documents into ChatGPT, uploads confidential files to an AI assistant, or uses an unapproved coding tool to generate production code.",{"data":1877,"content":1878,"nodeType":432},{},[1879],{"data":1880,"marks":1881,"value":1882,"nodeType":436},{},[],"All of that is sensitive data leaving the organization through channels the security team can't see - and often accessible using personal accounts that can be compromised on personal devices or workstations. ",{"data":1884,"content":1885,"nodeType":432},{},[1886,1890,1895],{"data":1887,"marks":1888,"value":1889,"nodeType":436},{},[],"The 2026 DBIR's data loss prevention analysis underscores the scale — shadow AI is now the ",{"data":1891,"marks":1892,"value":1894,"nodeType":436},{},[1893],{"type":471},"third most common non-malicious insider action",{"data":1896,"marks":1897,"value":1898,"nodeType":436},{},[]," in DLP data, a 4x increase year-over-year. Across 858,000+ DLP events targeting GenAI tools, the most common data types being submitted were source code (28%), images (16%), structured data (14%), documents (13%), and PDFs (10%). That's not employees asking ChatGPT to fix their grammar — it's core intellectual property, production code, and internal documentation flowing into platforms the security team has no visibility into. But shadow apps themselves are only the most obvious part of the problem.",{"data":1900,"content":1901,"nodeType":884},{},[1902],{"data":1903,"marks":1904,"value":1906,"nodeType":436},{},[1905],{"type":471},"Shadow tenants",{"data":1908,"content":1909,"nodeType":432},{},[1910,1914,1919,1923,1928],{"data":1911,"marks":1912,"value":1913,"nodeType":436},{},[],"Even when an organization has approved an AI tool — say, an enterprise ChatGPT deployment — employees frequently access the same app with personal accounts, creating shadow tenants that sit entirely outside organizational control. The DBIR found that ",{"data":1915,"marks":1916,"value":1918,"nodeType":436},{},[1917],{"type":471},"67% of GenAI users on corporate devices are using non-corporate accounts",{"data":1920,"marks":1921,"value":1922,"nodeType":436},{},[],", and our own data shows that ",{"data":1924,"marks":1925,"value":1927,"nodeType":436},{},[1926],{"type":471},"38% of file uploads to AI tools are made from shadow accounts",{"data":1929,"marks":1930,"value":1931,"nodeType":436},{},[]," rather than approved organizational ones.",{"data":1933,"content":1934,"nodeType":432},{},[1935],{"data":1936,"marks":1937,"value":1938,"nodeType":436},{},[],"When an organization approves Claude, ChatGPT, or another core AI platform, you typically also approve the OAuth integration and browser extension for core apps (e.g. M365, Google Workspace, and so on). When that integration is approved, it is approved for all tenants — not just your corporate tenant. ",{"data":1940,"content":1944,"nodeType":568},{"target":1941},{"sys":1942},{"id":1943,"type":573,"linkType":574},"3Rvw0n28AYIM3FQXtHyafD",[],{"data":1946,"content":1947,"nodeType":432},{},[1948],{"data":1949,"marks":1950,"value":1951,"nodeType":436},{},[],"This means that even if you've deployed enterprise controls around your sanctioned AI tools — DLP policies, retention settings, admin oversight — more than a third of the file uploads hitting AI tools are bypassing those controls entirely because they're happening through personal accounts on corporate devices.",{"data":1953,"content":1954,"nodeType":884},{},[1955],{"data":1956,"marks":1957,"value":1959,"nodeType":436},{},[1958],{"type":471},"Shadow extensions",{"data":1961,"content":1962,"nodeType":432},{},[1963,1967,1971],{"data":1964,"marks":1965,"value":1966,"nodeType":436},{},[],"Many AI tools come with a browser extension counterpart, and there's a large ecosystem of third-party AI extensions that offer everything from writing assistance to automated data extraction. The average organization in our dataset has ",{"data":1968,"marks":1969,"value":1801,"nodeType":436},{},[1970],{"type":471},{"data":1972,"marks":1973,"value":1974,"nodeType":436},{},[]," deployed across its workforce, with the highest we observed reaching 163 — and since each of those average 17 different extensions may be installed by multiple employees, the actual number of individual extension installs across the organization is much higher still.",{"data":1976,"content":1977,"nodeType":432},{},[1978,1982,1990,1994,1999],{"data":1979,"marks":1980,"value":1981,"nodeType":436},{},[],"The extension dimension is particularly concerning because most extensions operate with significant privilege inside the browser — they can read and modify page content, access cookies and session tokens, and interact with virtually every web application an employee uses. As we detailed in our recent analysis of ",{"data":1983,"content":1985,"nodeType":455},{"uri":1984},"https://pushsecurity.com/blog/why-browser-extension-risk-scoring-wont-predict-your-next-breach/",[1986],{"data":1987,"marks":1988,"value":1989,"nodeType":436},{},[],"browser extension risk scoring",{"data":1991,"marks":1992,"value":1993,"nodeType":436},{},[],", at least ",{"data":1995,"marks":1996,"value":1998,"nodeType":436},{},[1997],{"type":471},"46.76% of all extensions across Push customers have the permission combinations needed to perform account takeover with no user interaction",{"data":2000,"marks":2001,"value":2002,"nodeType":436},{},[],", and the extensions involved in every major supply chain breach of the past 18 months scored as normal or low-risk beforehand.",{"data":2004,"content":2008,"nodeType":568},{"target":2005},{"sys":2006},{"id":2007,"type":573,"linkType":574},"3z4JOMALI52xoOXZkzPHLD",[],{"data":2010,"content":2011,"nodeType":432},{},[2012,2016,2023],{"data":2013,"marks":2014,"value":2015,"nodeType":436},{},[],"AI extensions add a specific wrinkle to this problem: many are branded to look like official companions to well-known AI tools but are actually third-party creations with no affiliation to the original vendor. They're not necessarily malicious at the point of installation, but they're exactly the kind of extension that's likely to be ",{"data":2017,"content":2018,"nodeType":455},{"uri":1984},[2019],{"data":2020,"marks":2021,"value":2022,"nodeType":436},{},[],"acquired and weaponized",{"data":2024,"marks":2025,"value":2026,"nodeType":436},{},[]," down the line — and in the meantime, they're collecting data that their permissions entitle them to (which, in most cases, means everything the user can see in their browser).",{"data":2028,"content":2032,"nodeType":568},{"target":2029},{"sys":2030},{"id":2031,"type":573,"linkType":574},"6K3z67rohss6H3lCsSn12B",[],{"data":2034,"content":2035,"nodeType":884},{},[2036],{"data":2037,"marks":2038,"value":2040,"nodeType":436},{},[2039],{"type":471},"Shadow integrations",{"data":2042,"content":2043,"nodeType":432},{},[2044],{"data":2045,"marks":2046,"value":2047,"nodeType":436},{},[],"The fourth dimension — and arguably the most dangerous — is shadow integrations: OAuth connections between AI tools and core enterprise apps that aren't known or approved by the security team. Even if an organization has approved an AI tool for standalone use, plugging that tool directly into Google Workspace, Microsoft 365, Salesforce, or any other one of the dozen or so SaaS apps in a typical user’s work stack is a fundamentally different risk decision, because it creates a persistent, programmatic bridge between your environment and a third party.",{"data":2049,"content":2050,"nodeType":432},{},[2051,2055,2060,2064,2069],{"data":2052,"marks":2053,"value":2054,"nodeType":436},{},[],"On average, we see ",{"data":2056,"marks":2057,"value":2059,"nodeType":436},{},[2058],{"type":471},"17 unique AI app OAuth integrations per organization",{"data":2061,"marks":2062,"value":2063,"nodeType":436},{},[]," in ",{"data":2065,"marks":2066,"value":2068,"nodeType":436},{},[2067],{"type":1819},"just",{"data":2070,"marks":2071,"value":2072,"nodeType":436},{},[]," Google Workspace and Microsoft 365 (to be clear: this number excludes the dozens of downstream apps the AI assistants are integrated with as well), with the highest reaching 55. Each of those represents a unique AI product that has been granted OAuth access — the total number of individual consent grants across users is larger, because popular integrations get authorized by multiple employees independently.",{"data":2074,"content":2075,"nodeType":432},{},[2076],{"data":2077,"marks":2078,"value":2079,"nodeType":436},{},[],"The actual number of AI-related OAuth connections across the full SaaS estate is considerably higher again, because AI tools that automate workflows need to be connected to be useful — pulling data from one app, analyzing it in another, presenting results in a third.",{"data":2081,"content":2082,"nodeType":432},{},[2083],{"data":2084,"marks":2085,"value":2086,"nodeType":436},{},[],"MCP connections use OAuth to achieve this interconnectivity in the same way, and AI coding agents create a particularly concentrated version of the risk: a single agent configuration can hold OAuth tokens for Jira, Confluence, Salesforce, GitHub, and more, meaning that compromising one agent — whether through prompt injection, a malicious repository config, or a supply chain attack on an MCP server — yields persistent, broadly scoped tokens for every service it was connected to, tokens that survive session restarts and generate audit log entries indistinguishable from legitimate user activity.",{"data":2088,"content":2089,"nodeType":432},{},[2090],{"data":2091,"marks":2092,"value":2093,"nodeType":436},{},[],"It's also worth noting that OAuth blast radius is almost always larger than organizations expect. A single well-permissioned user can expose secrets, dashboards, and internal tooling without tenant-wide admin access. And every new AI tool an employee connects makes the web of abusable permissions a little wider.",{"data":2095,"content":2099,"nodeType":568},{"target":2096},{"sys":2097},{"id":2098,"type":573,"linkType":574},"4SnzJ9T93gHzFIUASx7Yb3",[],{"data":2101,"content":2102,"nodeType":577},{},[],{"data":2104,"content":2105,"nodeType":581},{},[2106],{"data":2107,"marks":2108,"value":2110,"nodeType":436},{},[2109],{"type":471},"Why shadow AI needs a different solution to shadow SaaS",{"data":2112,"content":2113,"nodeType":432},{},[2114],{"data":2115,"marks":2116,"value":2117,"nodeType":436},{},[],"The reason it's worth distinguishing between these four dimensions isn't academic. Each one requires a different control, and addressing one doesn't solve the others.",{"data":2119,"content":2120,"nodeType":432},{},[2121],{"data":2122,"marks":2123,"value":2124,"nodeType":436},{},[],"Blocking unsanctioned AI apps does nothing for the personal accounts accessing approved ones, and neither addresses the average 17 different AI extensions running with broad browser permissions, let alone the dozens of OAuth integrations that have already been granted persistent access to core enterprise apps — and even auditing OAuth in Google Workspace and Microsoft 365, where the controls are relatively mature, leaves the broader SaaS estate unaddressed, where admin tooling is inconsistent and visibility is limited.",{"data":2126,"content":2127,"nodeType":432},{},[2128,2132,2140],{"data":2129,"marks":2130,"value":2131,"nodeType":436},{},[],"The tooling gap compounds the policy gap. ",{"data":2133,"content":2135,"nodeType":455},{"uri":2134},"https://pushsecurity.com/blog/7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market/",[2136],{"data":2137,"marks":2138,"value":2139,"nodeType":436},{},[],"Omdia found",{"data":2141,"marks":2142,"value":2143,"nodeType":436},{},[]," that 58% of organizations rely on secure web gateways to secure GenAI usage — but an SWG can tell you that a user visited ChatGPT, not whether they pasted your source code into the prompt. That link between knowing where data went and knowing what the user actually did is the fundamental visibility gap that makes GenAI policies unenforceable without browser-layer tooling.",{"data":2145,"content":2146,"nodeType":884},{},[2147],{"data":2148,"marks":2149,"value":2151,"nodeType":436},{},[2150],{"type":471},"Advice for security teams",{"data":2153,"content":2154,"nodeType":432},{},[2155],{"data":2156,"marks":2157,"value":2158,"nodeType":436},{},[],"The principles behind managing shadow AI are the same ones that have governed shadow SaaS and software supply chain management for years: default-deny where feasible, comprehensive inventory where it isn't, and continuous monitoring for changes that signal increased risk. But it's vital that teams act fast to stop the snowball.",{"data":2160,"content":2161,"nodeType":432},{},[2162],{"data":2163,"marks":2164,"value":2166,"nodeType":436},{},[2165],{"type":471},"That starts with visibility into which AI tools employees are actually using and which accounts they're using to access them — without that baseline, every other control is built on assumptions.",{"data":2168,"content":2169,"nodeType":432},{},[2170,2175,2179,2186],{"data":2171,"marks":2172,"value":2174,"nodeType":436},{},[2173],{"type":471},"Extensions",{"data":2176,"marks":2177,"value":2178,"nodeType":436},{},[]," need the same ",{"data":2180,"content":2181,"nodeType":455},{"uri":1984},[2182],{"data":2183,"marks":2184,"value":2185,"nodeType":436},{},[],"default-deny allowlisting approach",{"data":2187,"marks":2188,"value":2189,"nodeType":436},{},[]," that has been best practice for software management elsewhere: build a complete inventory, allowlist what's vetted, block everything else, and monitor the approved set for changes that precede weaponization.",{"data":2191,"content":2192,"nodeType":432},{},[2193,2198],{"data":2194,"marks":2195,"value":2197,"nodeType":436},{},[2196],{"type":471},"OAuth",{"data":2199,"marks":2200,"value":2201,"nodeType":436},{},[]," demands the most urgency, because each unmanaged integration is a persistent trust relationship that survives password resets and MFA changes — adopt default-deny for consent grants in your primary enterprise apps, routinely audit what's already connected, and critically extend that visibility beyond Google and Microsoft to the broader SaaS estate where the controls are weaker and the sprawl is harder to track.",{"data":2203,"content":2207,"nodeType":568},{"target":2204},{"sys":2205},{"id":2206,"type":573,"linkType":574},"3RFLFtJtDXvhTz1mVztfV9",[],{"data":2209,"content":2210,"nodeType":577},{},[],{"data":2212,"content":2213,"nodeType":581},{},[2214],{"data":2215,"marks":2216,"value":2218,"nodeType":436},{},[2217],{"type":471},"Browser visibility and control is key to de-risking AI adoption",{"data":2220,"content":2221,"nodeType":432},{},[2222],{"data":2223,"marks":2224,"value":2225,"nodeType":436},{},[],"AI usage is fundamentally browser-based activity — every LLM interaction, every prompt containing sensitive data, every AI agent authorization, every OAuth consent grant happens inside a browser session — which makes the browser the natural control point for AI governance across the workforce. ",{"data":2227,"content":2228,"nodeType":432},{},[2229],{"data":2230,"marks":2231,"value":2232,"nodeType":436},{},[],"Push tracks AI app usage and login security across the workforce, inventories and controls AI browser extensions, monitors and blocks OAuth consent flows across any app (not just the primary enterprise platforms), and gives security teams a single view of the full shadow AI picture across all four dimensions.",{"data":2234,"content":2235,"nodeType":432},{},[2236],{"data":2237,"marks":2238,"value":2239,"nodeType":436},{},[],"Shadow AI isn't a problem that will age well if ignored. Every week that passes without visibility adds more apps, more extensions, more integrations, and more potential breach paths into the environment — and as the Vercel breach demonstrated, it only takes one forgotten OAuth grant to turn an employee's idle curiosity into an organization-wide incident.",{"data":2241,"content":2242,"nodeType":432},{},[2243,2247,2256],{"data":2244,"marks":2245,"value":2246,"nodeType":436},{},[],"Learn more about how you can tackle ",{"data":2248,"content":2250,"nodeType":455},{"uri":2249},"https://pushsecurity.com/uc/shadow-ai",[2251],{"data":2252,"marks":2253,"value":2255,"nodeType":436},{},[2254],{"type":1027},"Shadow AI",{"data":2257,"marks":2258,"value":2259,"nodeType":436},{},[]," with Push. ",{"data":2261,"content":2262,"nodeType":577},{},[],{"data":2264,"content":2265,"nodeType":432},{},[2266],{"data":2267,"marks":2268,"value":1254,"nodeType":436},{},[],{"data":2270,"content":2271,"nodeType":432},{},[2272],{"data":2273,"marks":2274,"value":1261,"nodeType":436},{},[],{"data":2276,"content":2277,"nodeType":432},{},[2278,2282,2290],{"data":2279,"marks":2280,"value":2281,"nodeType":436},{},[],"Book a ",{"data":2283,"content":2284,"nodeType":455},{"uri":1272},[2285],{"data":2286,"marks":2287,"value":2289,"nodeType":436},{},[2288],{"type":1027},"live demo",{"data":2291,"marks":2292,"value":2293,"nodeType":436},{},[]," to learn more.","Shadow AI: what Push data reveals about the scale of the problem","Push telemetry shows the average organization has 16 AI apps, 17 AI browser extensions, and 17 AI OAuth integrations in use. Here's what it means for security.","2026-05-28T00:00:00.000Z","what-push-data-reveals-about-the-state-of-shadow-ai",{"items":2299},[2300,2304],{"sys":2301,"name":2303},{"id":2302},"1gZi8NrRy2v9OqPV7C4dwD","Risk management",{"sys":2305,"name":2307},{"id":2306},"3pjES4THCIfSAwhGdNwBcy","Browser security",{"items":2309},[2310],{"fullName":2311,"firstName":2312,"jobTitle":2313,"profilePicture":2314},"Dan Green","Dan","Threat Research",{"url":2315},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"__typename":1632,"sys":2317,"content":2319,"title":3183,"synopsis":3184,"hashTags":59,"publishedDate":3185,"slug":3186,"tagsCollection":3187,"authorsCollection":3193},{"id":2318},"6Xn377JQfbDz49Np74cbGl",{"json":2320},{"data":2321,"content":2322,"nodeType":428},{},[2323,2330,2361,2379,2384,2391,2407,2410,2418,2436,2500,2507,2513,2520,2603,2610,2617,2633,2636,2644,2651,2658,2666,2673,2685,2691,2698,2705,2712,2715,2723,2739,2755,2762,2769,2776,2797,2883,2890,2897,2900,2908,2924,2931,2938,2946,2949,2957,2975,2982,2989,3022,3029,3036,3039,3047,3054,3066,3072,3084,3096,3102,3114,3136,3143,3146,3154,3161,3167],{"data":2324,"content":2325,"nodeType":432},{},[2326],{"data":2327,"marks":2328,"value":2329,"nodeType":436},{},[],"Most security leaders I talk to know they have an AI problem. They've seen the board questions, read the reports, maybe even drafted a policy. But when they start measuring where they stand — not plans or roadmaps, but actual current state — the gap between awareness and operational capability comes into focus.",{"data":2331,"content":2332,"nodeType":432},{},[2333,2337,2345,2349,2357],{"data":2334,"marks":2335,"value":2336,"nodeType":436},{},[],"The ",{"data":2338,"content":2340,"nodeType":455},{"uri":2339},"https://pushsecurity.com/blog/verizon-dbir-2026-review",[2341],{"data":2342,"marks":2343,"value":2344,"nodeType":436},{},[],"2026 Verizon DBIR",{"data":2346,"marks":2347,"value":2348,"nodeType":436},{},[]," quantifies the scale: 45% of employees are now regular AI users on corporate devices (up from 15% the prior year), with 67% using personal accounts. ",{"data":2350,"content":2352,"nodeType":455},{"uri":2351},"https://pushsecurity.com/blog/what-push-data-reveals-about-the-state-of-shadow-ai",[2353],{"data":2354,"marks":2355,"value":2356,"nodeType":436},{},[],"Push data",{"data":2358,"marks":2359,"value":2360,"nodeType":436},{},[]," further shows that 38% of file uploads to AI tools come from those shadow accounts rather than approved organizational ones — and the DBIR shows what's going into them: of 858,000+ DLP events targeting GenAI applications, the most common data types were source code (28%), structured data (14%), and documents and PDFs (23% combined).",{"data":2362,"content":2363,"nodeType":432},{},[2364,2368,2375],{"data":2365,"marks":2366,"value":2367,"nodeType":436},{},[],"The average organization now has ",{"data":2369,"content":2370,"nodeType":455},{"uri":2351},[2371],{"data":2372,"marks":2373,"value":2374,"nodeType":436},{},[],"16 unique AI apps, 17 AI browser extensions, and 17 AI OAuth integrations",{"data":2376,"marks":2377,"value":2378,"nodeType":436},{},[]," in active use, most unapproved. Shadow AI was the third most common non-malicious insider action in the DBIR, up 4x year over year.",{"data":2380,"content":2383,"nodeType":568},{"target":2381},{"sys":2382},{"id":612,"type":573,"linkType":574},[],{"data":2385,"content":2386,"nodeType":432},{},[2387],{"data":2388,"marks":2389,"value":2390,"nodeType":436},{},[],"These statistics expose an attack surface and unmanaged risks at a high level. But the real problem is that most organizations can't produce a basic inventory of which AI tools are in use, let alone demonstrate controls around any of them. ",{"data":2392,"content":2393,"nodeType":432},{},[2394,2398,2403],{"data":2395,"marks":2396,"value":2397,"nodeType":436},{},[],"That gap between awareness and capability is where most organizations are stuck. And understanding ",{"data":2399,"marks":2400,"value":2402,"nodeType":436},{},[2401],{"type":1819},"why",{"data":2404,"marks":2405,"value":2406,"nodeType":436},{},[]," they're stuck requires a framework for what progress actually looks like.",{"data":2408,"content":2409,"nodeType":577},{},[],{"data":2411,"content":2412,"nodeType":581},{},[2413],{"data":2414,"marks":2415,"value":2417,"nodeType":436},{},[2416],{"type":471},"A model for measuring what most organizations already feel",{"data":2419,"content":2420,"nodeType":432},{},[2421,2425,2432],{"data":2422,"marks":2423,"value":2424,"nodeType":436},{},[],"Chris Cochran's ",{"data":2426,"content":2428,"nodeType":455},{"uri":2427},"https://sansorg.egnyte.com/dl/XtgqfjkjBjp8",[2429],{"data":2430,"marks":2431,"value":680,"nodeType":436},{},[],{"data":2433,"marks":2434,"value":2435,"nodeType":436},{},[],", published earlier this year, provides a framework for addressing this gap. It defines five stages of AI security maturity across three pillars:",{"data":2437,"content":2438,"nodeType":513},{},[2439,2455,2471],{"data":2440,"content":2441,"nodeType":517},{},[2442],{"data":2443,"content":2444,"nodeType":432},{},[2445,2451],{"data":2446,"marks":2447,"value":2450,"nodeType":436},{},[2448,2449],{"type":471},{"type":1027},"Protect AI:",{"data":2452,"marks":2453,"value":2454,"nodeType":436},{},[]," Defending against AI-enabled threats like adversarial attacks, prompt injection, compromised browser extensions, and AI agents operating with unchecked permissions.",{"data":2456,"content":2457,"nodeType":517},{},[2458],{"data":2459,"content":2460,"nodeType":432},{},[2461,2467],{"data":2462,"marks":2463,"value":2466,"nodeType":436},{},[2464,2465],{"type":471},{"type":1027},"Utilize AI:",{"data":2468,"marks":2469,"value":2470,"nodeType":436},{},[]," Using AI to strengthen security operations by using AI-powered detection and triage, behavioral analytics, and automated response playbooks.",{"data":2472,"content":2473,"nodeType":517},{},[2474],{"data":2475,"content":2476,"nodeType":432},{},[2477,2483,2487,2496],{"data":2478,"marks":2479,"value":2482,"nodeType":436},{},[2480,2481],{"type":471},{"type":1027},"Govern AI:",{"data":2484,"marks":2485,"value":2486,"nodeType":436},{},[]," Managing how the organization adopts and uses AI tools. Things like acceptable use policies, shadow AI discovery, data classification, access controls, and risk assessment. This is the pillar that gets the most attention in boardroom conversations today, driven in part by ",{"data":2488,"content":2490,"nodeType":455},{"uri":2489},"https://pushsecurity.com/blog/browser-visibility-and-control-can-achieve-ai-compliance",[2491],{"data":2492,"marks":2493,"value":2495,"nodeType":436},{},[2494],{"type":1027},"regulatory pressure",{"data":2497,"marks":2498,"value":2499,"nodeType":436},{},[],".",{"data":2501,"content":2502,"nodeType":432},{},[2503],{"data":2504,"marks":2505,"value":2506,"nodeType":436},{},[],"How an organization invests across these three pillars, and whether it invests across all of them, determines whether it advances toward maturity in this area or stalls out at the early steps.",{"data":2508,"content":2512,"nodeType":568},{"target":2509},{"sys":2510},{"id":2511,"type":573,"linkType":574},"1JV3KG97JQNFKwODnMCMq2",[],{"data":2514,"content":2515,"nodeType":432},{},[2516],{"data":2517,"marks":2518,"value":2519,"nodeType":436},{},[],"The SANS AI maturity model outlines 5 stages that organizations must progress through in order to reach an optimal security posture:",{"data":2521,"content":2522,"nodeType":513},{},[2523,2539,2555,2571,2587],{"data":2524,"content":2525,"nodeType":517},{},[2526],{"data":2527,"content":2528,"nodeType":432},{},[2529,2535],{"data":2530,"marks":2531,"value":2534,"nodeType":436},{},[2532,2533],{"type":471},{"type":1027},"Stage 1 (Unaware / Ad Hoc)",{"data":2536,"marks":2537,"value":2538,"nodeType":436},{},[]," is where employees are freely using AI tools with no oversight, no inventory exists, and leadership may not even know how much AI is in use. There's no policy to violate, so technically it's not even shadow AI yet; it's just unmanaged adoption.",{"data":2540,"content":2541,"nodeType":517},{},[2542],{"data":2543,"content":2544,"nodeType":432},{},[2545,2551],{"data":2546,"marks":2547,"value":2550,"nodeType":436},{},[2548,2549],{"type":471},{"type":1027},"Stage 2 (Reactive / Policy-Emerging)",{"data":2552,"marks":2553,"value":2554,"nodeType":436},{},[]," means a policy exists, but it's course-grained: \"Don't use AI\" or \"use with caution.\" Known AI tools may be blocked at the network level. Security teams are learning about AI-specific threats but don't have dedicated expertise or tooling.",{"data":2556,"content":2557,"nodeType":517},{},[2558],{"data":2559,"content":2560,"nodeType":432},{},[2561,2567],{"data":2562,"marks":2563,"value":2566,"nodeType":436},{},[2564,2565],{"type":471},{"type":1027},"Stage 3 (Defined / Risk-Informed)",{"data":2568,"marks":2569,"value":2570,"nodeType":436},{},[]," is where things get intentional. AI usage is governed through enterprise tools rather than outright bans. AI systems are included in security assessments. The organization can demonstrate mature governance to regulators and partners. For many organizations, this is a strong and defensible operating position.",{"data":2572,"content":2573,"nodeType":517},{},[2574],{"data":2575,"content":2576,"nodeType":432},{},[2577,2583],{"data":2578,"marks":2579,"value":2582,"nodeType":436},{},[2580,2581],{"type":471},{"type":1027},"Stage 4 (Managed / Integrated)",{"data":2584,"marks":2585,"value":2586,"nodeType":436},{},[]," means AI is deeply embedded in security operations with measurable outcomes. AI systems are secured by design. Risk is quantified, not estimated. Decisions are data-driven. This is where organizations can handle AI-specific threats and operate at the tempo that AI-augmented adversaries demand.",{"data":2588,"content":2589,"nodeType":517},{},[2590],{"data":2591,"content":2592,"nodeType":432},{},[2593,2599],{"data":2594,"marks":2595,"value":2598,"nodeType":436},{},[2596,2597],{"type":471},{"type":1027},"Stage 5 (Optimizing / Adaptive)",{"data":2600,"marks":2601,"value":2602,"nodeType":436},{},[]," is the frontier of AI-native security with self-improving defenses. Elements of this stage exist primarily in large technology companies, defense contractors, and AI-native firms. For most organizations, this is a multi-year journey.",{"data":2604,"content":2605,"nodeType":432},{},[2606],{"data":2607,"marks":2608,"value":2609,"nodeType":436},{},[],"Most of the security leaders I talk to land between Stage 1 and Stage 2. They have awareness, maybe a policy, but not the tooling or telemetry to demonstrate much beyond that. ",{"data":2611,"content":2612,"nodeType":432},{},[2613],{"data":2614,"marks":2615,"value":2616,"nodeType":436},{},[],"The model is pragmatic about these challenges. It doesn't expect every organization to reach Stage 5, and it adjusts maturity targets by sector. ",{"data":2618,"content":2619,"nodeType":432},{},[2620,2624,2629],{"data":2621,"marks":2622,"value":2623,"nodeType":436},{},[],"But it ",{"data":2625,"marks":2626,"value":2628,"nodeType":436},{},[2627],{"type":1819},"does",{"data":2630,"marks":2631,"value":2632,"nodeType":436},{},[]," require evidence of progress, not just intent. And for the majority sitting at Stage 2, the hard part is identifying the right steps to move from being merely reactive to a posture of operational readiness. That’s the chasm to cross.",{"data":2634,"content":2635,"nodeType":577},{},[],{"data":2637,"content":2638,"nodeType":581},{},[2639],{"data":2640,"marks":2641,"value":2643,"nodeType":436},{},[2642],{"type":471},"The chasm",{"data":2645,"content":2646,"nodeType":432},{},[2647],{"data":2648,"marks":2649,"value":2650,"nodeType":436},{},[],"For the organizations sitting at Stage 2, current state often looks like this: They've written an AI acceptable use policy, and maybe they've blocked known AI apps at the network level. They've trained employees on what's allowed and what isn't. ",{"data":2652,"content":2653,"nodeType":432},{},[2654],{"data":2655,"marks":2656,"value":2657,"nodeType":436},{},[],"To be sure, blocking is the fastest lever a security team can pull, and it represents visible progress to the business. The problem is that it rarely stays effective. ",{"data":2659,"content":2660,"nodeType":432},{},[2661],{"data":2662,"marks":2663,"value":2665,"nodeType":436},{},[2664],{"type":471},"SANS calls the pattern that traps most organizations at Stage 2 the \"Framework of No.\" ",{"data":2667,"content":2668,"nodeType":432},{},[2669],{"data":2670,"marks":2671,"value":2672,"nodeType":436},{},[],"\"A block-based AI policy may feel like risk management, but practitioner experience shows it typically drives AI usage underground rather than preventing it,” the report notes. “This is the pattern SANS has documented as the 'Framework of No,' and it is why the Stage 2 to Stage 3 transition is so critical.\"",{"data":2674,"content":2675,"nodeType":432},{},[2676,2681],{"data":2677,"marks":2678,"value":2680,"nodeType":436},{},[2679],{"type":1819},"This",{"data":2682,"marks":2683,"value":2684,"nodeType":436},{},[]," is the chasm. On one side: awareness and policy. On the other: operational capability - the tooling, telemetry, and controls that let a security team see what's happening and respond to it. Most organizations are standing on the awareness side, looking across, not sure how to get over.",{"data":2686,"content":2690,"nodeType":568},{"target":2687},{"sys":2688},{"id":2689,"type":573,"linkType":574},"187mKPZV8tVbsw17L2cWIU",[],{"data":2692,"content":2693,"nodeType":432},{},[2694],{"data":2695,"marks":2696,"value":2697,"nodeType":436},{},[],"The model is specific about what crossing requires. The steps from Stage 2 to Stage 3 include technical BYOAI discovery (not a survey, but automated discovery), AI-specific data classification, AI-aware controls, and a cross-functional governance body. Data classification is a critical prerequisite: \"You cannot write an effective AI policy without knowing where sensitive data lives,\" the report emphasizes.",{"data":2699,"content":2700,"nodeType":432},{},[2701],{"data":2702,"marks":2703,"value":2704,"nodeType":436},{},[],"These are visibility and measurement problems before they're policy problems. You can't govern what you can't see. You can't classify risk you can't measure. And a blocklist that pushes usage underground doesn't give you either: it just makes the gap between your policy and your reality harder to detect.",{"data":2706,"content":2707,"nodeType":432},{},[2708],{"data":2709,"marks":2710,"value":2711,"nodeType":436},{},[],"Getting this visibility right is necessary for crossing the chasm. But it’s not the only step organizations must undertake if they want to address their AI risk.",{"data":2713,"content":2714,"nodeType":577},{},[],{"data":2716,"content":2717,"nodeType":581},{},[2718],{"data":2719,"marks":2720,"value":2722,"nodeType":436},{},[2721],{"type":471},"Governance is key, but don't forget about protection",{"data":2724,"content":2725,"nodeType":432},{},[2726,2730,2735],{"data":2727,"marks":2728,"value":2729,"nodeType":436},{},[],"Most AI security conversations today - the vendor pitches, board decks, and compliance checklists - are about the ",{"data":2731,"marks":2732,"value":2734,"nodeType":436},{},[2733],{"type":471},"Govern",{"data":2736,"marks":2737,"value":2738,"nodeType":436},{},[]," pillar. Shadow AI discovery. Usage policies. Data classification. Controls around what employees paste into AI prompts or upload to AI tools. It's important work.",{"data":2740,"content":2741,"nodeType":432},{},[2742,2746,2751],{"data":2743,"marks":2744,"value":2745,"nodeType":436},{},[],"But the SANS model gives roughly equal weight to a second pillar that gets almost no attention: ",{"data":2747,"marks":2748,"value":2750,"nodeType":436},{},[2749],{"type":471},"Protect",{"data":2752,"marks":2753,"value":2754,"nodeType":436},{},[]," - defending against AI-enabled attacks.",{"data":2756,"content":2757,"nodeType":432},{},[2758],{"data":2759,"marks":2760,"value":2761,"nodeType":436},{},[],"The Protect pillar starts from a stark baseline. At Stage 1, most organizations have no visibility into which AI agents or browser extensions have access to their corporate environment, let alone a framework for understanding how those could be attacked. ",{"data":2763,"content":2764,"nodeType":432},{},[2765],{"data":2766,"marks":2767,"value":2768,"nodeType":436},{},[],"By Stage 3, the model expects runtime validation of AI tools and plugins, detection capabilities mapped to AI-specific attack frameworks, and controls that cover the growing surface area of agentic AI. ",{"data":2770,"content":2771,"nodeType":432},{},[2772],{"data":2773,"marks":2774,"value":2775,"nodeType":436},{},[],"By Stage 4, organizations need real-time monitoring of AI agent behavior and defenses against attacks that exploit trust relationships between AI systems — capabilities most security teams haven't started scoping, much less building or procuring.",{"data":2777,"content":2778,"nodeType":432},{},[2779,2783,2793],{"data":2780,"marks":2781,"value":2782,"nodeType":436},{},[],"These are detection and response capabilities, not governance exercises — and the attacks they address are already well underway. ",{"data":2784,"content":2786,"nodeType":455},{"uri":2785},"https://pushsecurity.com/blog/the-cisos-data-problem-and-how-browser-telemetry-can-help/",[2787],{"data":2788,"marks":2789,"value":2792,"nodeType":436},{},[2790,2791],{"type":1027},{"type":471},"One in three phishing payloads",{"data":2794,"marks":2795,"value":2796,"nodeType":436},{},[]," intercepted by Push arrive outside of email, through channels where most security controls don't exist. Evidence of the growth of browser-based attack methods enabled by AI tooling abounds:",{"data":2798,"content":2799,"nodeType":513},{},[2800,2822,2844],{"data":2801,"content":2802,"nodeType":517},{},[2803],{"data":2804,"content":2805,"nodeType":432},{},[2806,2810,2818],{"data":2807,"marks":2808,"value":2809,"nodeType":436},{},[],"CrowdStrike's 2026 Global Threat Report documented a ",{"data":2811,"content":2813,"nodeType":455},{"uri":2812},"https://www.crowdstrike.com/explore/2026-global-threat-report",[2814],{"data":2815,"marks":2816,"value":2817,"nodeType":436},{},[],"563% increase in ClickFix lures",{"data":2819,"marks":2820,"value":2821,"nodeType":436},{},[]," — fake CAPTCHA pages that trick users into executing malicious commands on their own machines.",{"data":2823,"content":2824,"nodeType":517},{},[2825],{"data":2826,"content":2827,"nodeType":432},{},[2828,2832,2840],{"data":2829,"marks":2830,"value":2831,"nodeType":436},{},[],"Push has tracked a ",{"data":2833,"content":2835,"nodeType":455},{"uri":2834},"https://pushsecurity.com/blog/device-code-phishing/",[2836],{"data":2837,"marks":2838,"value":2839,"nodeType":436},{},[],"37x increase in device code phishing",{"data":2841,"marks":2842,"value":2843,"nodeType":436},{},[]," since the start of 2026, with 18+ distinct kits now offering the technique.",{"data":2845,"content":2846,"nodeType":517},{},[2847],{"data":2848,"content":2849,"nodeType":432},{},[2850,2853,2862,2866,2871,2875,2880],{"data":2851,"marks":2852,"value":21,"nodeType":436},{},[],{"data":2854,"content":2856,"nodeType":455},{"uri":2855},"https://www.anthropic.com/news/AI-enabled-cyber-threats-mitre-attack",[2857],{"data":2858,"marks":2859,"value":2861,"nodeType":436},{},[2860],{"type":1027},"Anthropic",{"data":2863,"marks":2864,"value":2865,"nodeType":436},{},[]," identified ",{"data":2867,"marks":2868,"value":2870,"nodeType":436},{},[2869],{"type":471},"793 threat actors using AI",{"data":2872,"marks":2873,"value":2874,"nodeType":436},{},[]," for malicious cybersecurity purposes between March 2025 and February 2026, with the 2026 Verizon DBIR finding that ",{"data":2876,"marks":2877,"value":2879,"nodeType":436},{},[2878],{"type":471},"44% of AI-assisted initial access was phishing-related",{"data":2881,"marks":2882,"value":2499,"nodeType":436},{},[],{"data":2884,"content":2885,"nodeType":432},{},[2886],{"data":2887,"marks":2888,"value":2889,"nodeType":436},{},[],"Attackers are already vibecoding phishing kits, rotating infrastructure daily, and exploiting identity flows that traditional endpoint and network tools can't see.",{"data":2891,"content":2892,"nodeType":432},{},[2893],{"data":2894,"marks":2895,"value":2896,"nodeType":436},{},[],"The SANS model makes the speed argument a central focus at Stage 4: Detection built for human-pace adversaries is increasingly insufficient when threats operate at machine speed. For organizations investing exclusively in AI governance, AI-enabled threats represent an entire category of risk that is not being addressed.",{"data":2898,"content":2899,"nodeType":577},{},[],{"data":2901,"content":2902,"nodeType":884},{},[2903],{"data":2904,"marks":2905,"value":2907,"nodeType":436},{},[2906],{"type":471},"Why governance alone can't close the gap",{"data":2909,"content":2910,"nodeType":432},{},[2911,2915,2920],{"data":2912,"marks":2913,"value":2914,"nodeType":436},{},[],"An organization can have an AI policy, shadow AI discovery, data classification, and usage controls, and ",{"data":2916,"marks":2917,"value":2919,"nodeType":436},{},[2918],{"type":1819},"still",{"data":2921,"marks":2922,"value":2923,"nodeType":436},{},[]," be exposed. When an employee hits a device code phishing page or a ClickFix lure, the governance program documented the risk perfectly. It just couldn't stop the attack. The policy existed but the detection (and ideally, mitigation) didn't.",{"data":2925,"content":2926,"nodeType":432},{},[2927],{"data":2928,"marks":2929,"value":2930,"nodeType":436},{},[],"The reverse is equally true, and it's why the SANS model treats the pillars as interdependent rather than sequential. Detection capabilities that fire into a void with no policy to act on findings, no classification to assess exposure, and no governance body to shape proactive policy just create alerts, not security. ",{"data":2932,"content":2933,"nodeType":432},{},[2934],{"data":2935,"marks":2936,"value":2937,"nodeType":436},{},[],"Yet most organizations are only investing heavily in one side of the solution, which is almost always Govern. The maturity model is explicit about the risks of this approach: Governance with no attack detection leaves a critical gap. ",{"data":2939,"content":2940,"nodeType":432},{},[2941],{"data":2942,"marks":2943,"value":2945,"nodeType":436},{},[2944],{"type":471},"Closing the gap requires a control point where both problems are visible and addressable.",{"data":2947,"content":2948,"nodeType":577},{},[],{"data":2950,"content":2951,"nodeType":581},{},[2952],{"data":2953,"marks":2954,"value":2956,"nodeType":436},{},[2955],{"type":471},"Crossing the chasm requires addressing both pillars at once",{"data":2958,"content":2959,"nodeType":432},{},[2960,2964,2971],{"data":2961,"marks":2962,"value":2963,"nodeType":436},{},[],"The bottleneck for most security programs ",{"data":2965,"content":2966,"nodeType":455},{"uri":2785},[2967],{"data":2968,"marks":2969,"value":2970,"nodeType":436},{},[],"isn't frameworks or strategy — it's data quality",{"data":2972,"marks":2973,"value":2974,"nodeType":436},{},[],". For teams taking on the dual problems of shadow AI and AI-enabled attacks, browser telemetry is the foundation to any meaningful solution. That’s because both problems converge in the same place.",{"data":2976,"content":2977,"nodeType":432},{},[2978],{"data":2979,"marks":2980,"value":2981,"nodeType":436},{},[],"AI-enabled phishing attacks, credential theft, malicious browser extensions, and OAuth exploitation happen in the browser. So do shadow AI adoption, sensitive data pasted into AI prompts, file uploads to unapproved tools, and unauthorized integrations. The browser is where external attacks and internal misuse are both visible and stoppable.",{"data":2983,"content":2984,"nodeType":432},{},[2985],{"data":2986,"marks":2987,"value":2988,"nodeType":436},{},[],"For the security team trying to advance past the Framework of No, browser telemetry replaces the blunt instrument of network-level blocking with actual visibility:",{"data":2990,"content":2991,"nodeType":513},{},[2992,3002,3012],{"data":2993,"content":2994,"nodeType":517},{},[2995],{"data":2996,"content":2997,"nodeType":432},{},[2998],{"data":2999,"marks":3000,"value":3001,"nodeType":436},{},[],"which AI apps are in use (including personal account usage)",{"data":3003,"content":3004,"nodeType":517},{},[3005],{"data":3006,"content":3007,"nodeType":432},{},[3008],{"data":3009,"marks":3010,"value":3011,"nodeType":436},{},[],"what data is moving into them (file uploads, clipboard activity)",{"data":3013,"content":3014,"nodeType":517},{},[3015],{"data":3016,"content":3017,"nodeType":432},{},[3018],{"data":3019,"marks":3020,"value":3021,"nodeType":436},{},[],"graduated controls - per-app, per-user group, per-content pattern - that can monitor, warn, or block based on context rather than allow/deny",{"data":3023,"content":3024,"nodeType":432},{},[3025],{"data":3026,"marks":3027,"value":3028,"nodeType":436},{},[],"The same browser-layer instrumentation can also provide real-time detection of credential phishing, ClickFix, adversary-in-the-middle attacks, and device code phishing. And it can detect and disable malicious browser extensions based on confirmed threat intelligence, monitor OAuth integrations, and generate the identity attack surface data (login behaviors, MFA gaps, SSO coverage) that the Protect pillar requires at Stage 3 maturity and beyond.",{"data":3030,"content":3031,"nodeType":432},{},[3032],{"data":3033,"marks":3034,"value":3035,"nodeType":436},{},[],"We built Push around this insight: that the browser is where both problems converge, and a single deployment can advance AI security maturity in both areas simultaneously. The SANS model makes the same argument.",{"data":3037,"content":3038,"nodeType":577},{},[],{"data":3040,"content":3041,"nodeType":581},{},[3042],{"data":3043,"marks":3044,"value":3046,"nodeType":436},{},[3045],{"type":471},"Where to start: 5 steps to maturity with Push",{"data":3048,"content":3049,"nodeType":432},{},[3050],{"data":3051,"marks":3052,"value":3053,"nodeType":436},{},[],"The chasm closes when organizations make meaningful strides forward in both AI governance and proactive defense against AI-enabled attacks. Here's the starting plan that I'd recommend, and Push can provide the tooling to automate these steps:",{"data":3055,"content":3056,"nodeType":432},{},[3057,3062],{"data":3058,"marks":3059,"value":3061,"nodeType":436},{},[3060],{"type":471},"1. Build an AI inventory automatically.",{"data":3063,"marks":3064,"value":3065,"nodeType":436},{},[]," Every stage transition in the SANS model starts with knowing what's in your environment. A manual survey won't cut it; employees won't self-report the tools they're not sure they're allowed to use, and may overlook apps where AI is a feature but not the core function (AI-enabled apps). Instead, organizations should deploy automated discovery for AI apps, browser extensions, and OAuth integrations across the workforce - including the ones using personal accounts. Until this inventory exists, every policy decision is based on incomplete information.",{"data":3067,"content":3071,"nodeType":568},{"target":3068},{"sys":3069},{"id":3070,"type":573,"linkType":574},"2t3u0NydllImv6NzvAY058",[],{"data":3073,"content":3074,"nodeType":432},{},[3075,3080],{"data":3076,"marks":3077,"value":3079,"nodeType":436},{},[3078],{"type":471},"2. Classify what you find.",{"data":3081,"marks":3082,"value":3083,"nodeType":436},{},[]," Not all AI usage carries the same risk. A developer pasting code into ChatGPT and a salesperson using an AI notetaker are different problems. Once you can see the tools, categorize them by data sensitivity, authorization status, and access scope. The SANS model calls out data classification as a critical prerequisite; you can't write an effective AI policy without knowing where sensitive data lives.",{"data":3085,"content":3086,"nodeType":432},{},[3087,3092],{"data":3088,"marks":3089,"value":3091,"nodeType":436},{},[3090],{"type":471},"3. Turn on browser-layer detection.",{"data":3093,"marks":3094,"value":3095,"nodeType":436},{},[]," This is the step most organizations skip, and it's why addressing only the Protect pillar will keep you at Stage 1. AI-enabled phishing, ClickFix attacks, device code phishing, malicious extension updates, and OAuth exploitation all execute in the browser. Without detection in that layer, there's no visibility into the fastest-growing attack category, and no path to advancing beyond basic AI usage awareness.",{"data":3097,"content":3101,"nodeType":568},{"target":3098},{"sys":3099},{"id":3100,"type":573,"linkType":574},"1fzuGjA6VSbVl1p7vM1mt7",[],{"data":3103,"content":3104,"nodeType":432},{},[3105,3110],{"data":3106,"marks":3107,"value":3109,"nodeType":436},{},[3108],{"type":471},"4. Move from blocking to graduated controls.",{"data":3111,"marks":3112,"value":3113,"nodeType":436},{},[]," The Framework of No fails because it's binary: allow or deny, with nothing in between. Organizations that cross the chasm adopt monitor, warn, and block modes — per app, per user group, per content pattern. Monitor first to see what's happening, warn to change behavior without disrupting workflows, and block only where the risk justifies it. This is the operational difference between Stage 2 and Stage 3.",{"data":3115,"content":3116,"nodeType":432},{},[3117,3122,3126,3132],{"data":3118,"marks":3119,"value":3121,"nodeType":436},{},[3120],{"type":471},"5. Assess yourself honestly against evidence, not aspiration.",{"data":3123,"marks":3124,"value":3125,"nodeType":436},{},[]," The ",{"data":3127,"content":3128,"nodeType":455},{"uri":2427},[3129],{"data":3130,"marks":3131,"value":680,"nodeType":436},{},[],{"data":3133,"marks":3134,"value":3135,"nodeType":436},{},[]," includes a self-assessment and industry-specific weighting profiles. The value isn't in the score, but in identifying which pillar is keeping you from advancing.",{"data":3137,"content":3138,"nodeType":432},{},[3139],{"data":3140,"marks":3141,"value":3142,"nodeType":436},{},[],"The organizations that cross the AI security chasm will be the ones that recognize early that AI security isn't one problem with one solution. It's two problems that happen to share a control point. The most efficient path forward is a platform that addresses both.",{"data":3144,"content":3145,"nodeType":577},{},[],{"data":3147,"content":3148,"nodeType":581},{},[3149],{"data":3150,"marks":3151,"value":3153,"nodeType":436},{},[3152],{"type":471},"Learn more about Push",{"data":3155,"content":3156,"nodeType":432},{},[3157],{"data":3158,"marks":3159,"value":3160,"nodeType":436},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser - high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",{"data":3162,"content":3163,"nodeType":432},{},[3164],{"data":3165,"marks":3166,"value":1261,"nodeType":436},{},[],{"data":3168,"content":3169,"nodeType":432},{},[3170,3173,3180],{"data":3171,"marks":3172,"value":2281,"nodeType":436},{},[],{"data":3174,"content":3175,"nodeType":455},{"uri":1272},[3176],{"data":3177,"marks":3178,"value":2289,"nodeType":436},{},[3179],{"type":1027},{"data":3181,"marks":3182,"value":2293,"nodeType":436},{},[],"Crossing the AI security chasm with the SANS AI security maturity model","Most organizations know they have an AI security problem. A new SANS framework shows why so few are making progress - and what it actually takes to get unstuck.","2026-06-24T00:00:00.000Z","crossing-the-ai-security-chasm-sans-security-maturity-model",{"items":3188},[3189,3191],{"sys":3190,"name":2307},{"id":2306},{"sys":3192,"name":2303},{"id":2302},{"items":3194},[3195],{"fullName":3196,"firstName":3197,"jobTitle":3198,"profilePicture":3199},"Mark Orlando","Mark","Field CTO",{"url":3200},"https://images.ctfassets.net/y1cdw1ablpvd/592PMwIQQFaa24k5SKBEKF/a33090d0ad95d1e3081f5d16a46ba826/image__68_.png",{"__typename":1632,"sys":3202,"content":3204,"title":4440,"synopsis":4441,"hashTags":59,"publishedDate":4442,"slug":4443,"tagsCollection":4444,"authorsCollection":4450},{"id":3203},"6MoHWfQlVildcFYKSbfMcE",{"json":3205},{"data":3206,"content":3207,"nodeType":428},{},[3208,3224,3230,3237,3244,3250,3253,3261,3269,3288,3336,3342,3357,3360,3368,3375,3403,3444,3451,3454,3462,3470,3477,3483,3490,3493,3501,3508,3550,3586,3593,3596,3604,3611,3636,3643,3688,3695,3698,3706,3714,3759,3766,3772,3775,3783,3791,3823,3830,3836,3843,3846,3854,3862,3891,3898,3905,3912,3915,3923,3931,3938,3944,3951,3974,4003,4006,4014,4022,4029,4036,4039,4047,4109,4112,4120,4127,4421,4424],{"data":3209,"content":3210,"nodeType":432},{},[3211,3215,3220],{"data":3212,"marks":3213,"value":3214,"nodeType":436},{},[],"Browser security solutions are one of the most significant additions to the enterprise security stack in recent years — and the data shows it. The browser is where ",{"data":3216,"marks":3217,"value":3219,"nodeType":436},{},[3218],{"type":471},"85% of work now happens",{"data":3221,"marks":3222,"value":3223,"nodeType":436},{},[],", where AI tools are accessed, and where attackers increasingly choose to strike.",{"data":3225,"content":3229,"nodeType":568},{"target":3226},{"sys":3227},{"id":3228,"type":573,"linkType":574},"5P6PyFbn4EakRNlIWtNzyL",[],{"data":3231,"content":3232,"nodeType":432},{},[3233],{"data":3234,"marks":3235,"value":3236,"nodeType":436},{},[],"But browser security is a nascent category. Getting a clear picture of which solution is right for your team, and how to get the most out of it, isn't straightforward. Current solutions on the market serve a wide range of IT and security use cases, with varying degrees of depth and differentiation across them. Not all use cases are equal in terms of their security value, and not all of them are best addressed in the browser.",{"data":3238,"content":3239,"nodeType":432},{},[3240],{"data":3241,"marks":3242,"value":3243,"nodeType":436},{},[],"This article ranks the security problems that browser security solutions can address by the value they deliver: a combination of the risk reduction on offer, and the degree to which the browser is genuinely the best (or only) layer to solve the problem. ",{"data":3245,"content":3249,"nodeType":568},{"target":3246},{"sys":3247},{"id":3248,"type":573,"linkType":574},"6SJPvEHizSYk29lEvVVNj",[],{"data":3251,"content":3252,"nodeType":577},{},[],{"data":3254,"content":3255,"nodeType":581},{},[3256],{"data":3257,"marks":3258,"value":3260,"nodeType":436},{},[3259],{"type":471},"#1 — Account takeover prevention: detecting credential attacks across all vectors",{"data":3262,"content":3263,"nodeType":432},{},[3264],{"data":3265,"marks":3266,"value":3268,"nodeType":436},{},[3267],{"type":471},"Security value: Very high | Browser fit: Uniquely suited",{"data":3270,"content":3271,"nodeType":432},{},[3272,3276,3284],{"data":3273,"marks":3274,"value":3275,"nodeType":436},{},[],"Account takeover (ATO) is the dominant entry point for enterprise breaches: ",{"data":3277,"content":3279,"nodeType":455},{"uri":3278},"https://www.crowdstrike.com/en-gb/resources/infographics/identity-security-risk-review/",[3280],{"data":3281,"marks":3282,"value":3283,"nodeType":436},{},[],"80% of all modern breaches involve compromised or stolen identities",{"data":3285,"marks":3286,"value":3287,"nodeType":436},{},[],". The attack surface is far wider than most identity tooling can see: credential stuffing, password spraying, ghost logins (password-based fallback authentication that persists after SSO is configured), weak or reused credentials on shadow SaaS apps, and accounts where MFA was never enforced.",{"data":3289,"content":3290,"nodeType":432},{},[3291,3295,3303,3307,3312,3315,3320,3324,3332],{"data":3292,"marks":3293,"value":3294,"nodeType":436},{},[],"According to ",{"data":3296,"content":3298,"nodeType":455},{"uri":3297},"https://cf-assets.www.cloudflare.com/slt3lc6tev37/sWDBUMNVtEJB9ZFLt1dUU/8d69e92de2edfb3bf59e7d21d57e7e1a/Cloudflare-2026-threat-report.pdf",[3299],{"data":3300,"marks":3301,"value":3302,"nodeType":436},{},[],"Cloudflare's 2026 Threat Report",{"data":3304,"marks":3305,"value":3306,"nodeType":436},{},[],", ",{"data":3308,"marks":3309,"value":3311,"nodeType":436},{},[3310],{"type":471},"63% of all human logins involve credentials already compromised elsewhere",{"data":3313,"marks":3314,"value":1805,"nodeType":436},{},[],{"data":3316,"marks":3317,"value":3319,"nodeType":436},{},[3318],{"type":471},"94% of all login attempts originate from bots",{"data":3321,"marks":3322,"value":3323,"nodeType":436},{},[],". The ",{"data":3325,"content":3327,"nodeType":455},{"uri":3326},"https://pushsecurity.com/blog/snowflake-retro/",[3328],{"data":3329,"marks":3330,"value":3331,"nodeType":436},{},[],"Snowflake breach",{"data":3333,"marks":3334,"value":3335,"nodeType":436},{},[]," — 165+ organizations compromised, 1 billion+ records stolen — was powered almost entirely by ghost logins: accounts missing MFA that were susceptible to credential stuffing. It's particularly telling that 80% of the accounts impacted had prior breach exposure.",{"data":3337,"content":3341,"nodeType":568},{"target":3338},{"sys":3339},{"id":3340,"type":573,"linkType":574},"HbZ66kp5DiAZtwNGFJK7d",[],{"data":3343,"content":3344,"nodeType":432},{},[3345,3349,3354],{"data":3346,"marks":3347,"value":3348,"nodeType":436},{},[],"For organizations with contractors and BYOD users, the browser extension is also the only enterprise control deployable on devices that can't be MDM-enrolled — extending ATO detection to exactly the place where, per Verizon DBIR 2025, ",{"data":3350,"marks":3351,"value":3353,"nodeType":436},{},[3352],{"type":471},"46% of infostealer infections originate",{"data":3355,"marks":3356,"value":2499,"nodeType":436},{},[],{"data":3358,"content":3359,"nodeType":577},{},[],{"data":3361,"content":3362,"nodeType":581},{},[3363],{"data":3364,"marks":3365,"value":3367,"nodeType":436},{},[3366],{"type":471},"#2 — Detecting and stopping advanced phishing: AiTM, multi-channel delivery, and zero-day lures",{"data":3369,"content":3370,"nodeType":432},{},[3371],{"data":3372,"marks":3373,"value":3268,"nodeType":436},{},[3374],{"type":471},{"data":3376,"content":3377,"nodeType":432},{},[3378,3382,3390,3394,3399],{"data":3379,"marks":3380,"value":3381,"nodeType":436},{},[],"Adversary-in-the-Middle (AiTM) phishing — where an attacker's reverse proxy intercepts credentials and session tokens in real time — has become the standard technique for bypassing MFA at scale. ",{"data":3383,"content":3385,"nodeType":455},{"uri":3384},"https://www.esentire.com/resources/library/2026-threat-report",[3386],{"data":3387,"marks":3388,"value":3389,"nodeType":436},{},[],"eSentire's 2026 Threat Report",{"data":3391,"marks":3392,"value":3393,"nodeType":436},{},[]," attributes ",{"data":3395,"marks":3396,"value":3398,"nodeType":436},{},[3397],{"type":471},"63% of account compromise incidents to PhaaS kits",{"data":3400,"marks":3401,"value":3402,"nodeType":436},{},[],", with account compromise surging 389% year-over-year.",{"data":3404,"content":3405,"nodeType":432},{},[3406,3410,3418,3422,3427,3431,3440],{"data":3407,"marks":3408,"value":3409,"nodeType":436},{},[],"Traditional phishing controls are also no longer in the right place to intercept these attacks. The delivery channel has shifted decisively away from email: ",{"data":3411,"content":3413,"nodeType":455},{"uri":3412},"https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026",[3414],{"data":3415,"marks":3416,"value":3417,"nodeType":436},{},[],"Mandiant M-Trends 2026",{"data":3419,"marks":3420,"value":3421,"nodeType":436},{},[]," found email phishing dropped from 14% to 6% as an infection vector, and Push data shows ",{"data":3423,"marks":3424,"value":3426,"nodeType":436},{},[3425],{"type":471},"roughly 1 in 3 phishing payloads intercepted were delivered outside email entirely",{"data":3428,"marks":3429,"value":3430,"nodeType":436},{},[]," — via search engine malvertising, social platforms, and compromised websites. Meanwhile, ",{"data":3432,"content":3434,"nodeType":455},{"uri":3433},"https://www.spamhaus.com/resource-center/supporting-researchers-with-passive-dns/",[3435],{"data":3436,"marks":3437,"value":3439,"nodeType":436},{},[3438],{"type":471},"89% of phishing domains are active for less than two days",{"data":3441,"marks":3442,"value":3443,"nodeType":436},{},[],", making blocklist-based detection structurally too slow — attackers can spin up, tear down, and move on before blocklists can catch up.",{"data":3445,"content":3446,"nodeType":432},{},[3447],{"data":3448,"marks":3449,"value":3450,"nodeType":436},{},[],"Modern phishing plays out entirely inside the browser session. The only detection layer that can see the phishing page structure, the credential entry, and the anomalous token context is the browser itself. Browser-native detection analyses page behavior rather than matching known-bad domains, which means it fires on zero-day kits regardless of how recently the infrastructure was stood up. Controls like credential entry guardrails add an additional layer — blocking corporate passwords from being submitted to unauthorized domains independently of content and behavior-based detections.",{"data":3452,"content":3453,"nodeType":577},{},[],{"data":3455,"content":3456,"nodeType":581},{},[3457],{"data":3458,"marks":3459,"value":3461,"nodeType":436},{},[3460],{"type":471},"#3 — Identity posture hardening: enforcing security across the apps your IdP doesn't manage",{"data":3463,"content":3464,"nodeType":432},{},[3465],{"data":3466,"marks":3467,"value":3469,"nodeType":436},{},[3468],{"type":471},"Security value: High | Browser fit: Uniquely suited",{"data":3471,"content":3472,"nodeType":432},{},[3473],{"data":3474,"marks":3475,"value":3476,"nodeType":436},{},[],"The first challenge is knowing what you're protecting. Every identity an employee creates — every app they sign up to, every password they set, every login that bypasses SSO — is an authentication event that happens inside a browser session. The browser is the only layer that observes all of these events regardless of whether the app is sanctioned, managed, or even known to IT. Solutions that rely on API-level integrations with known apps, network traffic inspection, or email sign-up notifications can only ever build a partial picture, because they can only see apps they already know about. The browser sees the login itself, which means it discovers the identity at the moment it's created or used — authentication method, password strength, MFA status, and all.",{"data":3478,"content":3482,"nodeType":568},{"target":3479},{"sys":3480},{"id":3481,"type":573,"linkType":574},"HETvBCPsKGkqLVtaasXH0",[],{"data":3484,"content":3485,"nodeType":432},{},[3486],{"data":3487,"marks":3488,"value":3489,"nodeType":436},{},[],"But discovery without enforcement is just an inventory problem. Being in the browser means that you're in a great position to act on what it finds at the moment of authentication. Browser-native guardrails that prompt MFA enrollment, guide users toward stronger credentials, and redirect to SSO login paths close the gap at scale, on every app, including those the IdP has never seen. They also produce the continuous, auditable evidence of MFA coverage and credential hygiene across the full application estate that regulators, insurers, and auditors increasingly require — evidence that no IdP-centric tool can provide for apps outside its scope.",{"data":3491,"content":3492,"nodeType":577},{},[],{"data":3494,"content":3495,"nodeType":581},{},[3496],{"data":3497,"marks":3498,"value":3500,"nodeType":436},{},[3499],{"type":471},"#4 — Browser extension security",{"data":3502,"content":3503,"nodeType":432},{},[3504],{"data":3505,"marks":3506,"value":3469,"nodeType":436},{},[3507],{"type":471},{"data":3509,"content":3510,"nodeType":432},{},[3511,3515,3524,3527,3535,3538,3546],{"data":3512,"marks":3513,"value":3514,"nodeType":436},{},[],"Browser extensions have become one of the most talked-about attack surfaces in security over the past 18 months, and understandably so — a string of high-profile supply chain compromises have collectively impacted tens of millions of users since late 2024 (",{"data":3516,"content":3518,"nodeType":455},{"uri":3517},"https://www.cyberhaven.com/blog/cyberhavens-chrome-extension-security-incident-and-what-were-doing-about-it",[3519],{"data":3520,"marks":3521,"value":3523,"nodeType":436},{},[3522],{"type":1027},"Cyberhaven",{"data":3525,"marks":3526,"value":3306,"nodeType":436},{},[],{"data":3528,"content":3530,"nodeType":455},{"uri":3529},"https://thehackernews.com/2025/12/darkspectre-browser-extension-campaigns.html",[3531],{"data":3532,"marks":3533,"value":3534,"nodeType":436},{},[],"DarkSpectre",{"data":3536,"marks":3537,"value":3306,"nodeType":436},{},[],{"data":3539,"content":3541,"nodeType":455},{"uri":3540},"https://thehackernews.com/2025/12/trust-wallet-chrome-extension-hack.html",[3542],{"data":3543,"marks":3544,"value":3545,"nodeType":436},{},[],"Trust Wallet",{"data":3547,"marks":3548,"value":3549,"nodeType":436},{},[],", among many others).",{"data":3551,"content":3552,"nodeType":432},{},[3553,3556,3564,3568,3573,3577,3582],{"data":3554,"marks":3555,"value":21,"nodeType":436},{},[],{"data":3557,"content":3558,"nodeType":455},{"uri":1984},[3559],{"data":3560,"marks":3561,"value":3563,"nodeType":436},{},[3562],{"type":1027},"Analysis of 20,000+ extensions across Push customers",{"data":3565,"marks":3566,"value":3567,"nodeType":436},{},[]," found ",{"data":3569,"marks":3570,"value":3572,"nodeType":436},{},[3571],{"type":471},"46.76% have the permission combinations needed to perform account takeover with no user interaction",{"data":3574,"marks":3575,"value":3576,"nodeType":436},{},[],", making permissions-based risk scoring effectively useless as a triage tool. The real threat model is not malicious extensions at install time — it's legitimate extensions that ",{"data":3578,"marks":3579,"value":3581,"nodeType":436},{},[3580],{"type":1819},"become",{"data":3583,"marks":3584,"value":3585,"nodeType":436},{},[]," malicious after an ownership transfer, developer account compromise, or silent update push. Every major extension supply chain breach of the past 18 months scored as low-risk immediately before compromise.",{"data":3587,"content":3588,"nodeType":432},{},[3589],{"data":3590,"marks":3591,"value":3592,"nodeType":436},{},[],"SWGs and network tools are structurally blind to this attack surface: a malicious extension exfiltrating session tokens generates no anomalous network signal — its traffic is indistinguishable from normal browsing. Endpoint agents have no visibility into extension behavior at the session level. Extension inventory, supply chain change monitoring — ownership transfers, permission escalations, developer contact changes — and enforcement all require browser-layer access by definition.",{"data":3594,"content":3595,"nodeType":577},{},[],{"data":3597,"content":3598,"nodeType":581},{},[3599],{"data":3600,"marks":3601,"value":3603,"nodeType":436},{},[3602],{"type":471},"#5 — Shadow SaaS discovery and OAuth integration governance",{"data":3605,"content":3606,"nodeType":432},{},[3607],{"data":3608,"marks":3609,"value":3469,"nodeType":436},{},[3610],{"type":471},{"data":3612,"content":3613,"nodeType":432},{},[3614,3618,3623,3627,3632],{"data":3615,"marks":3616,"value":3617,"nodeType":436},{},[],"Shadow SaaS discovery shares DNA with identity posture hardening (#3) — both start with the same browser-native visibility into login events that no other layer can replicate. Where identity posture focuses on hardening ",{"data":3619,"marks":3620,"value":3622,"nodeType":436},{},[3621],{"type":1819},"how",{"data":3624,"marks":3625,"value":3626,"nodeType":436},{},[]," employees authenticate, shadow SaaS discovery focuses on ",{"data":3628,"marks":3629,"value":3631,"nodeType":436},{},[3630],{"type":1819},"what",{"data":3633,"marks":3634,"value":3635,"nodeType":436},{},[]," they authenticate to: surfacing the full estate of applications in use across the organization, including those that IT has never sanctioned or even heard of.",{"data":3637,"content":3638,"nodeType":432},{},[3639],{"data":3640,"marks":3641,"value":3642,"nodeType":436},{},[],"OAuth integration governance is the component of shadow SaaS that is both the most potentially damaging and the hardest to surface through other means. The SaaS-to-SaaS OAuth pivot is now an industrialized attack pattern.",{"data":3644,"content":3645,"nodeType":513},{},[3646,3667],{"data":3647,"content":3648,"nodeType":517},{},[3649],{"data":3650,"content":3651,"nodeType":432},{},[3652,3655,3663],{"data":3653,"marks":3654,"value":2336,"nodeType":436},{},[],{"data":3656,"content":3658,"nodeType":455},{"uri":3657},"https://pushsecurity.com/blog/analyzing-the-instructure-breach/",[3659],{"data":3660,"marks":3661,"value":3662,"nodeType":436},{},[],"ShinyHunters",{"data":3664,"marks":3665,"value":3666,"nodeType":436},{},[]," Salesforce campaign — which compromised 1,000+ organizations and 1.5 billion records — demonstrated the full chain: the attacker didn't stop at stealing customer data but harvested OAuth tokens, AWS access keys, and Snowflake tokens from breached tenants and pivoted through connected services like Salesloft, Drift, and Gainsight to reach hundreds more organizations.",{"data":3668,"content":3669,"nodeType":517},{},[3670],{"data":3671,"content":3672,"nodeType":432},{},[3673,3676,3684],{"data":3674,"marks":3675,"value":2336,"nodeType":436},{},[],{"data":3677,"content":3679,"nodeType":455},{"uri":3678},"https://pushsecurity.com/blog/unpacking-the-vercel-breach/",[3680],{"data":3681,"marks":3682,"value":3683,"nodeType":436},{},[],"Context.ai → Vercel",{"data":3685,"marks":3686,"value":3687,"nodeType":436},{},[]," chain followed the same logic — stored OAuth tokens from a forgotten AI app trial provided the bridge into Google Workspace, internal dashboards, and API keys. These are not isolated incidents; they are the repeatable playbook for extracting maximum value from a single compromise through the trust relationships that OAuth connections encode.",{"data":3689,"content":3690,"nodeType":432},{},[3691],{"data":3692,"marks":3693,"value":3694,"nodeType":436},{},[],"Every OAuth consent grant transits the browser — the authorization prompt, the scope disclosure, the user's approval click, and the redirect that completes the grant all happen inside a browser session — which makes the browser the only layer where an unwanted grant can be intercepted before the token is issued and the persistent access path is created. Once a token exists, the damage is done: it survives password resets, MFA changes, and session revocations, and revoking it after the fact requires first knowing it was granted, which most organizations do not.",{"data":3696,"content":3697,"nodeType":577},{},[],{"data":3699,"content":3700,"nodeType":581},{},[3701],{"data":3702,"marks":3703,"value":3705,"nodeType":436},{},[3704],{"type":471},"#6 — Blocking ClickFix and social engineering-based malware delivery",{"data":3707,"content":3708,"nodeType":432},{},[3709],{"data":3710,"marks":3711,"value":3713,"nodeType":436},{},[3712],{"type":471},"Security value: High | Browser fit: Strong for interception — shared with endpoint security for execution. ConsentFix is a browser-native exception that is T1-aligned.",{"data":3715,"content":3716,"nodeType":432},{},[3717,3721,3726,3730,3737,3741,3746,3750,3755],{"data":3718,"marks":3719,"value":3720,"nodeType":436},{},[],"ClickFix was the most common initial access vector reported by Microsoft in 2025, accounting for ",{"data":3722,"marks":3723,"value":3725,"nodeType":436},{},[3724],{"type":471},"47% of observed attacks",{"data":3727,"marks":3728,"value":3729,"nodeType":436},{},[],". CrowdStrike's ",{"data":3731,"content":3732,"nodeType":455},{"uri":2812},[3733],{"data":3734,"marks":3735,"value":3736,"nodeType":436},{},[],"2026 Global Threat Report",{"data":3738,"marks":3739,"value":3740,"nodeType":436},{},[]," identified fake CAPTCHA lures as the most common malware download type, increasing ",{"data":3742,"marks":3743,"value":3745,"nodeType":436},{},[3744],{"type":471},"563% year-over-year",{"data":3747,"marks":3748,"value":3749,"nodeType":436},{},[],". The technique writes a malicious command to the victim's clipboard and social-engineers them into executing it. It is fileless (bypassing download scanning), user-executed (bypassing endpoint behavioral detections), and ",{"data":3751,"marks":3752,"value":3754,"nodeType":436},{},[3753],{"type":471},"4 in 5 ClickFix payloads intercepted by Push arrived via search engines",{"data":3756,"marks":3757,"value":3758,"nodeType":436},{},[]," — not email (bypassing email anti-phishing controls).",{"data":3760,"content":3761,"nodeType":432},{},[3762],{"data":3763,"marks":3764,"value":3765,"nodeType":436},{},[],"The browser is the earliest and most effective intervention point — detecting the clipboard injection and social engineering lure before anything reaches the endpoint in executable form. But the problem doesn't end at the browser boundary: once the command has been pasted and run, detection and remediation become endpoint problems, and a mature defense requires both layers. The broader *Fix family — FileFix, InstallFix, and similar derivatives — follows the same pattern, with the browser providing the critical early-warning layer within a defense that spans browser and endpoint.",{"data":3767,"content":3771,"nodeType":568},{"target":3768},{"sys":3769},{"id":3770,"type":573,"linkType":574},"39alMHtw9FPHbQINqbAgBN",[],{"data":3773,"content":3774,"nodeType":577},{},[],{"data":3776,"content":3777,"nodeType":581},{},[3778],{"data":3779,"marks":3780,"value":3782,"nodeType":436},{},[3781],{"type":471},"#7 — AI visibility and control: enforcing which AI tools employees can use and how",{"data":3784,"content":3785,"nodeType":432},{},[3786],{"data":3787,"marks":3788,"value":3790,"nodeType":436},{},[3789],{"type":471},"Security value: High | Browser fit: Strong for access enforcement — but AI governance is not a new security problem so much as a force multiplier on existing ones",{"data":3792,"content":3793,"nodeType":432},{},[3794,3798,3806,3810,3819],{"data":3795,"marks":3796,"value":3797,"nodeType":436},{},[],"AI adoption is outpacing security governance at nearly every organization, and ",{"data":3799,"content":3800,"nodeType":455},{"uri":2134},[3801],{"data":3802,"marks":3803,"value":3805,"nodeType":436},{},[3804],{"type":471},"71% of organizations are concerned about data leakage via unsanctioned AI apps",{"data":3807,"marks":3808,"value":3809,"nodeType":436},{},[],". But the security problems that AI creates are not, for the most part, novel — they are existing Tier 1 problems amplified by a new category of tooling. Shadow AI apps are shadow SaaS (#5). AI OAuth integrations are OAuth governance (#5). AI browser extensions are extension security (#4). The risk of employees using personal AI accounts — ",{"data":3811,"content":3813,"nodeType":455},{"uri":3812},"https://keepaware.com/blog/46-of-sensitive-data-bypasses-your-dlp",[3814],{"data":3815,"marks":3816,"value":3818,"nodeType":436},{},[3817],{"type":471},"46% of sensitive inputs to AI tools are sent via personal accounts",{"data":3820,"marks":3821,"value":3822,"nodeType":436},{},[]," — is an identity posture problem (#3).",{"data":3824,"content":3825,"nodeType":432},{},[3826],{"data":3827,"marks":3828,"value":3829,"nodeType":436},{},[],"The component parts that allow you to govern AI are individually Tier 1 capabilities, and the browser is the best single layer for gaining visibility and control over AI usage — it sees the apps, the OAuth grants, the extensions, and the account context. But a complete end-to-end solution also requires a presence on the endpoint layer (for local AI tools, IDE-integrated agents, and API-level usage that never touches the browser), and prompt-level DLP on sanctioned tools is better handled by platform-native controls than by browser-layer observation.",{"data":3831,"content":3835,"nodeType":568},{"target":3832},{"sys":3833},{"id":3834,"type":573,"linkType":574},"6Py3z9VgjhKrchmYvhmbsq",[],{"data":3837,"content":3838,"nodeType":432},{},[3839],{"data":3840,"marks":3841,"value":3842,"nodeType":436},{},[],"The browser is what makes platform controls effective — if employees are using personal accounts, there are no enterprise audit logs to inspect. And for the growing category of AI agents, agentic browsers, and MCP-connected tools that operate through OAuth grants rather than direct user interaction, the browser is where the consent decisions that authorize those agents are made.",{"data":3844,"content":3845,"nodeType":577},{},[],{"data":3847,"content":3848,"nodeType":581},{},[3849],{"data":3850,"marks":3851,"value":3853,"nodeType":436},{},[3852],{"type":471},"#8 — Investigation acceleration and incident response: closing the missing middle",{"data":3855,"content":3856,"nodeType":432},{},[3857],{"data":3858,"marks":3859,"value":3861,"nodeType":436},{},[3860],{"type":471},"Security value: High | Browser fit: Strong — fills a structural gap complementary to endpoint, network, and identity telemetry",{"data":3863,"content":3864,"nodeType":432},{},[3865,3869,3874,3878,3887],{"data":3866,"marks":3867,"value":3868,"nodeType":436},{},[],"Endpoint logs show what processes executed. Network logs show traffic destinations. IdP logs show authentication events. None of them show what happened ",{"data":3870,"marks":3871,"value":3873,"nodeType":436},{},[3872],{"type":1819},"inside the browser session",{"data":3875,"marks":3876,"value":3877,"nodeType":436},{},[]," — the phishing page the user saw, the credentials they entered, the malicious OAuth consent grant, the data uploaded or pasted to an unsanctioned service. This is the missing middle of modern incident investigations, and for the ",{"data":3879,"content":3881,"nodeType":455},{"uri":3880},"https://www.paloaltonetworks.co.uk/resources/research/unit-42-incident-response-report",[3882],{"data":3883,"marks":3884,"value":3886,"nodeType":436},{},[3885],{"type":471},"48% of intrusions involving browser-based activity",{"data":3888,"marks":3889,"value":3890,"nodeType":436},{},[],", the absence of browser telemetry is a significant investigative gap.",{"data":3892,"content":3893,"nodeType":432},{},[3894],{"data":3895,"marks":3896,"value":3897,"nodeType":436},{},[],"Browser-layer telemetry fills that gap with a fundamentally different quality of signal: what users actually clicked, what pages loaded and how they behaved, what credentials were entered, what session activity followed — structured, high-fidelity data from inside the session where the attack played out. That's the difference between inferring what happened and seeing it directly, and it determines scope, drives containment decisions, and provides the direct evidential record that neither endpoint DLP nor network monitoring can supply for browser-native attacks.",{"data":3899,"content":3900,"nodeType":432},{},[3901],{"data":3902,"marks":3903,"value":3904,"nodeType":436},{},[],"Browser telemetry is a key addition to the investigative picture. Investigations are inherently multi-source — without browser data, reconstructing an incident from EDR, network, and IdP logs won't tell you the full picture (particularly when attacks are increasingly delivered outside of email, intercepting users as they browse the internet normally).",{"data":3906,"content":3907,"nodeType":432},{},[3908],{"data":3909,"marks":3910,"value":3911,"nodeType":436},{},[],"The browser provides the causal link that other sources miss: the bridge between \"a user visited a URL\" and \"credentials were submitted to a phishing page that issued a session token now being replayed from an attacker-controlled browser.\" Integrated with SIEM and SOAR platforms, that signal enables automated response workflows to execute on high-confidence detections without waiting for manual triage.",{"data":3913,"content":3914,"nodeType":577},{},[],{"data":3916,"content":3917,"nodeType":581},{},[3918],{"data":3919,"marks":3920,"value":3922,"nodeType":436},{},[3921],{"type":471},"#9 — Infostealer defense: detecting exposure and blocking delivery",{"data":3924,"content":3925,"nodeType":432},{},[3926],{"data":3927,"marks":3928,"value":3930,"nodeType":436},{},[3929],{"type":471},"Security value: High | Browser fit: Strong for delivery interception and stolen factor detection — complementary to endpoint security for execution",{"data":3932,"content":3933,"nodeType":432},{},[3934],{"data":3935,"marks":3936,"value":3937,"nodeType":436},{},[],"Infostealers are the upstream supply chain for a disproportionate share of the most damaging enterprise attacks — harvesting credentials, session cookies, and browser profile data en masse from infected devices, then selling the outputs on infostealer markets for use in credential stuffing, ATO, and ransomware campaigns.",{"data":3939,"content":3943,"nodeType":568},{"target":3940},{"sys":3941},{"id":3942,"type":573,"linkType":574},"5NF1afwu3zFGThZTtStVQA",[],{"data":3945,"content":3946,"nodeType":432},{},[3947],{"data":3948,"marks":3949,"value":3950,"nodeType":436},{},[],"The browser is relevant at two points in the infostealer kill chain. First, delivery interception: ClickFix (covered in #6) is now the primary infostealer delivery mechanism, and the browser is the only layer that can intercept it before execution. Second, detecting stolen factors when attackers attempt to use them — and infostealers produce two categories of stolen factor that the browser can guard against.",{"data":3952,"content":3953,"nodeType":513},{},[3954,3964],{"data":3955,"content":3956,"nodeType":517},{},[3957],{"data":3958,"content":3959,"nodeType":432},{},[3960],{"data":3961,"marks":3962,"value":3963,"nodeType":436},{},[],"Stolen credentials can be identified at the point of login: browser-layer detection flags credentials that appear in known breach datasets, catching infostealer-harvested passwords being replayed in credential stuffing campaigns before the account is compromised.",{"data":3965,"content":3966,"nodeType":517},{},[3967],{"data":3968,"content":3969,"nodeType":432},{},[3970],{"data":3971,"marks":3972,"value":3973,"nodeType":436},{},[],"Stolen session tokens are caught through a different mechanism: sessions originating in instrumented browsers carry a marker, and when a token subsequently appears in an un-instrumented browser it is a confirmed stolen session — catching infostealer-harvested cookies being replayed regardless of how or where the token was originally harvested.",{"data":3975,"content":3976,"nodeType":432},{},[3977,3981,3990,3994,3999],{"data":3978,"marks":3979,"value":3980,"nodeType":436},{},[],"This is particularly critical for the ",{"data":3982,"content":3984,"nodeType":455},{"uri":3983},"https://www.verizon.com/business/en-gb/resources/reports/dbir/",[3985],{"data":3986,"marks":3987,"value":3989,"nodeType":436},{},[3988],{"type":471},"46% of infected devices that are unmanaged",{"data":3991,"marks":3992,"value":3993,"nodeType":436},{},[]," where EDR is absent and the stolen credentials and session tokens will never be detected at the endpoint. Infostealer ",{"data":3995,"marks":3996,"value":3998,"nodeType":436},{},[3997],{"type":1819},"execution",{"data":4000,"marks":4001,"value":4002,"nodeType":436},{},[]," remains an endpoint problem; the browser closes the delivery and replay gaps that endpoint tools miss.",{"data":4004,"content":4005,"nodeType":577},{},[],{"data":4007,"content":4008,"nodeType":581},{},[4009],{"data":4010,"marks":4011,"value":4013,"nodeType":436},{},[4012],{"type":471},"#10 — Data loss prevention: a key component of effective DLP, but not the full picture",{"data":4015,"content":4016,"nodeType":432},{},[4017],{"data":4018,"marks":4019,"value":4021,"nodeType":436},{},[4020],{"type":471},"Security value: Medium-high | Browser fit: Partial — complementary to dedicated DLP",{"data":4023,"content":4024,"nodeType":432},{},[4025],{"data":4026,"marks":4027,"value":4028,"nodeType":436},{},[],"File uploads to unsanctioned services, sensitive data pasted into AI tools, and exfiltration through personal accounts are genuine and growing risks that traditional email and endpoint-centric DLP tools were not designed to catch. Browser-layer controls provide real value here — particularly for BYOD users and contractors, where endpoint DLP agents cannot be deployed and the browser is the only available data loss visibility.",{"data":4030,"content":4031,"nodeType":432},{},[4032],{"data":4033,"marks":4034,"value":4035,"nodeType":436},{},[],"The honest scope: browser-layer DLP does not cover email-based loss, endpoint-to-endpoint transfers, or cloud API exfiltration. It closes specific and important gaps within a broader DLP strategy, not a replacement for one. A further distinction for organizations evaluating browser DLP for secure third-party access: full-stack enterprise browsers can enforce deeper output controls — watermarking, obfuscation, screenshot and print restrictions — at the OS rendering level that browser extensions cannot reliably replicate. Extension-based browser DLP is strongest for upload, input, and access control use cases rather than OS-level output restriction.",{"data":4037,"content":4038,"nodeType":577},{},[],{"data":4040,"content":4041,"nodeType":581},{},[4042],{"data":4043,"marks":4044,"value":4046,"nodeType":436},{},[4045],{"type":471},"Tier 3 — Lower Value: A problem best addressed outside of the browser",{"data":4048,"content":4049,"nodeType":513},{},[4050,4065,4080,4095],{"data":4051,"content":4052,"nodeType":517},{},[4053],{"data":4054,"content":4055,"nodeType":432},{},[4056,4061],{"data":4057,"marks":4058,"value":4060,"nodeType":436},{},[4059],{"type":471},"Browser exploit protection",{"data":4062,"marks":4063,"value":4064,"nodeType":436},{},[]," (narrow RCE/sandbox sense) ranks lower because browser zero-days represent just 9% of all zero-days reported to Google, and 82% of attack detections are now malware-free (CrowdStrike 2026). This is a problem for browser vendors to solve, and it's not a big enough problem to warrant enterprises investing in additional mitigating controls.",{"data":4066,"content":4067,"nodeType":517},{},[4068],{"data":4069,"content":4070,"nodeType":432},{},[4071,4076],{"data":4072,"marks":4073,"value":4075,"nodeType":436},{},[4074],{"type":471},"Domain and URL category controls",{"data":4077,"marks":4078,"value":4079,"nodeType":436},{},[]," offer genuine browser-layer value but are commoditized by SWG and DNS filtering tools most organizations already operate. This can be provided in the browser, sure (and it's something we do at Push) but offers limited security value in terms of making a difference against modern attacks that quickly rotate these kinds of indicators and are designed to blend in.",{"data":4081,"content":4082,"nodeType":517},{},[4083],{"data":4084,"content":4085,"nodeType":432},{},[4086,4091],{"data":4087,"marks":4088,"value":4090,"nodeType":436},{},[4089],{"type":471},"Access management",{"data":4092,"marks":4093,"value":4094,"nodeType":436},{},[]," — ZTNA, VPN replacement, PAM, BYOD access control — is an IT infrastructure and access architecture problem, not a security operations problem, and belongs to a different buyer with a different evaluation frame. There are numerous (typically full-stack) Enterprise Browser solutions on the market that address IT use cases like this well.",{"data":4096,"content":4097,"nodeType":517},{},[4098],{"data":4099,"content":4100,"nodeType":432},{},[4101,4105],{"data":4102,"marks":4103,"value":354,"nodeType":436},{},[4104],{"type":471},{"data":4106,"marks":4107,"value":4108,"nodeType":436},{},[]," addresses browser exploit risk rather than the identity-first attacks that represent the majority of current enterprise browser risk, and introduces UX friction that limits deployment at scale. When it triggers, it introduces latency but still fails to detect and stop browser-native attacks.",{"data":4110,"content":4111,"nodeType":577},{},[],{"data":4113,"content":4114,"nodeType":581},{},[4115],{"data":4116,"marks":4117,"value":4119,"nodeType":436},{},[4118],{"type":471},"How Push Security maps to the highest-value security use cases",{"data":4121,"content":4122,"nodeType":432},{},[4123],{"data":4124,"marks":4125,"value":4126,"nodeType":436},{},[],"Push is purpose-built to address all of these problems using a flexible browser extension — plug into any browser with no migration, no host agent deployment, and no IT overhead — that delivers telemetry and control from day one, and extends coverage to every enrolled browser regardless of device ownership.",{"data":4128,"content":4129,"nodeType":4420},{},[4130,4157,4181,4205,4229,4253,4277,4301,4325,4349,4373,4397],{"data":4131,"content":4132,"nodeType":4156},{},[4133,4145],{"data":4134,"content":4135,"nodeType":4144},{},[4136],{"data":4137,"content":4138,"nodeType":432},{},[4139],{"data":4140,"marks":4141,"value":4143,"nodeType":436},{},[4142],{"type":471},"Security use case","table-cell",{"data":4146,"content":4147,"nodeType":4144},{},[4148],{"data":4149,"content":4150,"nodeType":432},{},[4151],{"data":4152,"marks":4153,"value":4155,"nodeType":436},{},[4154],{"type":471},"How Push addresses it","table-row",{"data":4158,"content":4159,"nodeType":4156},{},[4160,4171],{"data":4161,"content":4162,"nodeType":4144},{},[4163],{"data":4164,"content":4165,"nodeType":432},{},[4166],{"data":4167,"marks":4168,"value":4170,"nodeType":436},{},[4169],{"type":471},"Account takeover prevention",{"data":4172,"content":4173,"nodeType":4144},{},[4174],{"data":4175,"content":4176,"nodeType":432},{},[4177],{"data":4178,"marks":4179,"value":4180,"nodeType":436},{},[],"Surfaces and fixes ghost logins, weak and breached credentials and missing MFA controls across every app and device — including shadow SaaS and unmanaged devices invisible to the IdP. Push also detects and stops the attack techniques that typically lead to ATO early in the kill chain and before an account can be compromised.",{"data":4182,"content":4183,"nodeType":4156},{},[4184,4195],{"data":4185,"content":4186,"nodeType":4144},{},[4187],{"data":4188,"content":4189,"nodeType":432},{},[4190],{"data":4191,"marks":4192,"value":4194,"nodeType":436},{},[4193],{"type":471},"Advanced phishing detection",{"data":4196,"content":4197,"nodeType":4144},{},[4198],{"data":4199,"content":4200,"nodeType":432},{},[4201],{"data":4202,"marks":4203,"value":4204,"nodeType":436},{},[],"Behavioral page analysis detects phishing kits regardless of whether the domain is known-bad. Credential entry guardrails block corporate passwords from being submitted to unauthorized domains. TTP-based detection remains effective as attacker infrastructure rotates.",{"data":4206,"content":4207,"nodeType":4156},{},[4208,4219],{"data":4209,"content":4210,"nodeType":4144},{},[4211],{"data":4212,"content":4213,"nodeType":432},{},[4214],{"data":4215,"marks":4216,"value":4218,"nodeType":436},{},[4217],{"type":471},"Identity posture hardening",{"data":4220,"content":4221,"nodeType":4144},{},[4222],{"data":4223,"content":4224,"nodeType":432},{},[4225],{"data":4226,"marks":4227,"value":4228,"nodeType":436},{},[],"Enforces MFA, strong credentials, and SSO adoption across every app the IdP doesn't manage. Produces continuous, auditable MFA coverage and credential hygiene evidence across the full application and device estate.",{"data":4230,"content":4231,"nodeType":4156},{},[4232,4243],{"data":4233,"content":4234,"nodeType":4144},{},[4235],{"data":4236,"content":4237,"nodeType":432},{},[4238],{"data":4239,"marks":4240,"value":4242,"nodeType":436},{},[4241],{"type":471},"Browser extension security",{"data":4244,"content":4245,"nodeType":4144},{},[4246],{"data":4247,"content":4248,"nodeType":432},{},[4249],{"data":4250,"marks":4251,"value":4252,"nodeType":436},{},[],"Live extension inventory with supply chain change event monitoring — ownership transfers, permission escalations, developer contact changes — rather than static risk scoring. Supports default-deny allowlisting and remote extension removal. Blocks known-bad malicious extensions automatically.",{"data":4254,"content":4255,"nodeType":4156},{},[4256,4267],{"data":4257,"content":4258,"nodeType":4144},{},[4259],{"data":4260,"content":4261,"nodeType":432},{},[4262],{"data":4263,"marks":4264,"value":4266,"nodeType":436},{},[4265],{"type":471},"Shadow SaaS and OAuth governance",{"data":4268,"content":4269,"nodeType":4144},{},[4270],{"data":4271,"content":4272,"nodeType":432},{},[4273],{"data":4274,"marks":4275,"value":4276,"nodeType":436},{},[],"Discovers shadow SaaS from actual login events with full authentication context. Monitors and blocks OAuth consent flows — including AI and MCP integrations — in real time before persistent access paths are created.",{"data":4278,"content":4279,"nodeType":4156},{},[4280,4291],{"data":4281,"content":4282,"nodeType":4144},{},[4283],{"data":4284,"content":4285,"nodeType":432},{},[4286],{"data":4287,"marks":4288,"value":4290,"nodeType":436},{},[4289],{"type":471},"ClickFix and the *Fix family",{"data":4292,"content":4293,"nodeType":4144},{},[4294],{"data":4295,"content":4296,"nodeType":432},{},[4297],{"data":4298,"marks":4299,"value":4300,"nodeType":436},{},[],"Detects and blocks ClickFix lures, clipboard injection, and browser-native variants like ConsentFix in real time — before the payload executes or OAuth key material is captured.",{"data":4302,"content":4303,"nodeType":4156},{},[4304,4315],{"data":4305,"content":4306,"nodeType":4144},{},[4307],{"data":4308,"content":4309,"nodeType":432},{},[4310],{"data":4311,"marks":4312,"value":4314,"nodeType":436},{},[4313],{"type":471},"AI visibility & control",{"data":4316,"content":4317,"nodeType":4144},{},[4318],{"data":4319,"content":4320,"nodeType":432},{},[4321],{"data":4322,"marks":4323,"value":4324,"nodeType":436},{},[],"Enforces which AI tools employees can access and routes usage to corporate tenants. Governs AI browser extensions and blocks OAuth consent grants to unapproved AI applications — drawing on the same Tier 1 capabilities (OAuth governance, extension security, shadow SaaS discovery) that make this possible.",{"data":4326,"content":4327,"nodeType":4156},{},[4328,4339],{"data":4329,"content":4330,"nodeType":4144},{},[4331],{"data":4332,"content":4333,"nodeType":432},{},[4334],{"data":4335,"marks":4336,"value":4338,"nodeType":436},{},[4337],{"type":471},"Security investigations & incident response",{"data":4340,"content":4341,"nodeType":4144},{},[4342],{"data":4343,"content":4344,"nodeType":432},{},[4345],{"data":4346,"marks":4347,"value":4348,"nodeType":436},{},[],"High-fidelity session telemetry — page loads, credential entries, DOM changes, OAuth grants — fills the missing middle that endpoint, network, and IdP logs leave open. Feeds directly into SIEM and SOAR for automated response.",{"data":4350,"content":4351,"nodeType":4156},{},[4352,4363],{"data":4353,"content":4354,"nodeType":4144},{},[4355],{"data":4356,"content":4357,"nodeType":432},{},[4358],{"data":4359,"marks":4360,"value":4362,"nodeType":436},{},[4361],{"type":471},"Infostealer defense",{"data":4364,"content":4365,"nodeType":4144},{},[4366],{"data":4367,"content":4368,"nodeType":432},{},[4369],{"data":4370,"marks":4371,"value":4372,"nodeType":436},{},[],"Intercepts ClickFix-based infostealer delivery before execution. Detects token replay in unenrolled browser contexts — catching post-theft abuse from AiTM-sourced tokens and infostealer-harvested cookies, including from unmanaged devices.",{"data":4374,"content":4375,"nodeType":4156},{},[4376,4387],{"data":4377,"content":4378,"nodeType":4144},{},[4379],{"data":4380,"content":4381,"nodeType":432},{},[4382],{"data":4383,"marks":4384,"value":4386,"nodeType":436},{},[4385],{"type":471},"Data loss prevention",{"data":4388,"content":4389,"nodeType":4144},{},[4390],{"data":4391,"content":4392,"nodeType":432},{},[4393],{"data":4394,"marks":4395,"value":4396,"nodeType":436},{},[],"Observes file uploads, downloads, and sensitive data inputs across all applications. Extends data loss visibility to BYOD and contractor devices where endpoint DLP cannot reach.",{"data":4398,"content":4399,"nodeType":4156},{},[4400,4410],{"data":4401,"content":4402,"nodeType":4144},{},[4403],{"data":4404,"content":4405,"nodeType":432},{},[4406],{"data":4407,"marks":4408,"value":4075,"nodeType":436},{},[4409],{"type":471},{"data":4411,"content":4412,"nodeType":4144},{},[4413],{"data":4414,"content":4415,"nodeType":432},{},[4416],{"data":4417,"marks":4418,"value":4419,"nodeType":436},{},[],"Custom URL blocklists with wildcard support and REST API management for threat intelligence feed sync. Application category blocking restricts access to classes of apps (file-sharing, unsanctioned AI tools) configurable by user group. Domain categorization bringing SWG-style category blocking natively to the browser without a network proxy.","table",{"data":4422,"content":4423,"nodeType":577},{},[],{"data":4425,"content":4426,"nodeType":432},{},[4427,4431,4437],{"data":4428,"marks":4429,"value":4430,"nodeType":436},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. ",{"data":4432,"content":4433,"nodeType":455},{"uri":1272},[4434],{"data":4435,"marks":4436,"value":1275,"nodeType":436},{},[],{"data":4438,"marks":4439,"value":21,"nodeType":436},{},[],"The top 10 security problems you can solve in the browser — ranked by value","Ranking the security problems you can solve in the browser by security value and browser fit.","2026-05-14T00:00:00.000Z","the-top-10-security-problems-you-can-solve-in-the-browser-ranked-by-value",{"items":4445},[4446,4448],{"sys":4447,"name":2307},{"id":2306},{"sys":4449,"name":2303},{"id":2302},{"items":4451},[4452],{"fullName":4453,"firstName":4454,"jobTitle":423,"profilePicture":4455},"Alex Henshall","Alex",{"url":4456},"https://images.ctfassets.net/y1cdw1ablpvd/2rz3Pre3b1MexPIQ4hzPUe/0ef8a092b7e7df00fbce3f7d1ccb96d1/Alex_Henshall.jpeg","shadow-ai-how-to-discover-govern-and-secure-ai-apps","blog/shadow-ai-how-to-discover-govern-and-secure-ai-apps","Why you need paved paths, not barricades, for secure AI adoption",{"json":4461},{"data":4462,"content":4463,"nodeType":428},{},[4464],{"data":4465,"content":4466,"nodeType":432},{},[4467],{"data":4468,"marks":4469,"value":4470,"nodeType":436},{},[],"Blocking AI tools doesn't stop employees from using AI — it stops you seeing how they use it. The solution: make the governed path easier than the workaround.",{"id":4472,"publishedAt":4473},"7MB9tEe6mrdNXbkYVhgyWn","2026-08-13T13:06:46.644Z",{"items":4475},[4476,4480],{"sys":4477,"name":4479},{"id":4478},"3SA5H01UkKauuiTdt0KC6q","Shadow IT",{"sys":4481,"name":4483},{"id":4482},"7ohk9lIkxMvJMwnp2Lhuad","SaaS security","ZSqOIywJotHxF2QvSwPSfiNNkPzMaRcVoRhK-0zYdL0",1786626737520]