The browser extension reading your internal app

An AI browser extension helped an employee work faster. To do that, it could read every page they opened, including the internal tools full of customer data.

The browser extension reading your internal app

An IT lead at a services company told me about a risk that had been sitting in plain sight on people’s screens. An AI browser extension had become popular among the team, because it was genuinely helpful. It could summarize pages, draft text, and answer questions about whatever the employee was looking at. To do all of that, it needed to read the content of the pages, and it did, on every page the employee opened. That included the company’s internal tools, the admin panels, the customer records, the dashboards full of sensitive data. The extension was reading all of it and sending what it needed to a third-party service, and no one had connected the helpful sidebar to the fact that it had a view into the most sensitive screens in the company.

Browser extensions that read page content are a broad and easily overlooked data path. The permission that lets an extension be useful, reading what is on the page, is the same permission that lets it read anything the employee views, including internal systems that were never meant to be exposed to an outside service. The employee installed a productivity tool. What they actually granted was a third party a window into every page they open, which for many roles means a window into the customer data they work with all day.

The permission that helps is the permission that leaks

An AI extension earns its usefulness by seeing what you see. That is the whole value. It reads the page so it can summarize, draft, or answer. But the browser does not distinguish between a public article and your internal admin console. If the extension can read pages, it can read all of them, and the sensitive internal tools are just more pages as far as the extension is concerned.

So the risk scales with the employee’s access. A support agent’s browser shows customer records. An operations person’s browser shows internal dashboards. An admin’s browser shows almost everything. An extension reading those pages is reading exactly the data your access controls were built to protect, and then sending some of it to a service you never vetted. The access controls did their job of showing the right data to the right employee. The extension quietly forwarded that data onward.

This is a cousin of shadow AI, and it is worse in one respect. A person pasting data into a tool is making a choice each time, and might think twice. An extension reads continuously, in the background, without a decision per page. Once installed, it sees everything, and the leak is passive.

Assess extensions as data paths

The fix is to treat AI browser extensions as what they are, third-party services with read access to whatever your employees view, and to manage them accordingly.

What that involves:

  • Know what is installed. Get visibility into the AI extensions running in your employees’ browsers, because you cannot manage a data path you cannot see.
  • Understand what they can read and send. An extension that reads page content and calls a third party is a data path from your internal tools to that third party. Evaluate it as one.
  • Control extensions on managed devices. Where you can, manage which extensions are allowed, especially for roles with access to sensitive internal systems.
  • Give people a vetted option. As with any shadow AI, the demand is real. A sanctioned tool that meets the need keeps people from reaching for an unmanaged one.

The teams that handle this stop thinking of extensions as personal browser preferences and start thinking of them as connections between their internal systems and outside services. That reframing is most of the fix, because once an extension is a data path, it gets the scrutiny a data path deserves.

How we approach it at Density Labs

In the AI Opportunity Assessment, our fixed two-week, $2,500 engagement, we look at the paths sensitive data can take out of your systems, including the ones that run in employees’ browsers. AI extensions with read access to internal tools are a common and quiet exposure, because they were installed as productivity helpers, not recognized as third-party connections to your customer data. Naming them as data paths is the step most teams have not taken.

An AI extension that reads every page your employees open reads your internal tools too. Assess it as a connection to a third party, because that is what it quietly became.