How do I stop staff using AI browser extensions that can read company systems?

30 September 2026

How do I stop staff using AI browser extensions that can read company systems?

The reliable fix is technical control, not a policy email. Enrol work browsers in Google Admin, Microsoft Intune or another device management service, block extensions by default, and allow only approved extension IDs. Review every approved tool's permissions, data use and owner at least quarterly, and provide an approved AI workspace so staff are not forced back into shadow IT.

Why AI browser extensions are a different kind of risk

A browser extension can sit between an employee and almost every web system they use. Depending on the permissions granted, it may be able to read page contents, inspect text typed into forms, access cookies, alter pages or send selected content to an external service. An AI writing assistant that improves an email may therefore see more than the sentence being edited. On the wrong page, it could be exposed to customer records, a draft contract, an HR note or financial information.

The UK's National Cyber Security Centre says browser extensions can potentially read and access all web data in the browser and interact with pages. Its ChromeOS guidance tells administrators to block unknown extensions, use an allowlist for trusted tools and monitor updates to approved extensions. Read the NCSC ChromeOS guidance. That advice matters even if your business uses Windows or macOS because the risk comes from the browser permission model, not only the operating system.

Do not assume an extension is safe because it came from an official store or has many users. In December 2024, attackers used a phishing attack to compromise an employee at security company Cyberhaven and published a malicious update to its legitimate Chrome extension. Darktrace reported that the wider campaign affected more than 30 extensions and more than 2.6 million users. The malicious update could collect session cookies and authentication tokens. Read Darktrace's incident analysis. The lesson is not that every extension is malicious. It is that trust must be reviewed continuously, including after installation.

What should you do in the next 48 hours?

Start by finding out what is installed. Ask staff to open the extensions page in every browser used for work and export or record the extension name, publisher, extension ID and permissions. If you have Google Workspace, Chrome Enterprise Core, Microsoft Intune or another endpoint management product, use its inventory instead of relying on screenshots. Include personal browser profiles used on company devices because that is where unapproved tools often hide.

Remove extensions that have no clear business purpose, no named owner, an unknown publisher, excessive permissions or duplicated functionality. Treat permissions such as reading and changing data on all websites, access to cookies, browsing history, downloads or clipboard data as high risk. Pause any extension that can see a CRM, webmail, online banking, accounts package, HR system or client portal until it has been reviewed. Reset active sessions for important systems if you find an extension you suspect has captured cookies or tokens. Changing only the password may not invalidate every stolen session.

Then write a one-page temporary rule: staff may use only the listed extensions for work; new extensions require approval; client files, personal data, contracts, passwords and financial records must not be submitted to an unapproved AI service; and suspected exposure must be reported immediately. Do not punish someone for reporting quickly. You need the evidence while browser history, timestamps and supplier logs still exist.

This is not theoretical cyber hygiene. The UK Government's Cyber Security Breaches Survey 2025/2026 found that phishing was experienced by 38% of businesses and was the most disruptive attack type for 69% of affected businesses and charities. A convincing extension approval email or developer account takeover can turn that familiar entry route into access through software staff already trust.

How do you block extensions without an IT department?

For Google-managed browsers, set the default to block all extensions and create an allowlist containing only approved extension IDs. Google's administration guidance explains that an administrator can block all apps and extensions, allow selected tools, and block extensions based on permissions such as access to cookies. See Google's allow and block instructions. For Microsoft environments, use Edge management policies through Intune or Group Policy to apply the same principle: block by default, then allow named extension IDs from approved stores.

A microbusiness with five to ten users can often complete the first review and policy setup in half a day if devices are already managed. If they are not, allow one to three days to enrol browsers, separate work from personal profiles, test policies and support staff. A sensible UK budget is £300 to £1,500 for a small one-off setup by an IT support provider, or roughly £3 to £10 per user per month where browser management forms part of a wider managed device service. Complex environments, multiple domains and unmanaged personal devices cost more. These are practical budgeting ranges, not fixed supplier prices.

Do not rely on a blacklist of known bad extensions. New tools and renamed products appear too quickly, and an approved product can change ownership. An allowlist reverses the burden: nothing runs until somebody has checked it. Keep the approved list short. For each item, record the extension ID, publisher, business purpose, permissions, data processed, approved user group, owner, approval date and next review date.

Give staff a request route that takes days, not months. Ask five questions: What job does it solve? Which sites can it read? What data leaves the browser? Does the supplier train models on that data? Can the same outcome be achieved with an approved web app or built-in feature? If the benefit is small and the requested permission is broad, decline it.

What is a safer alternative to banning every AI tool?

A blanket ban often drives the activity into personal accounts and unmanaged devices. Staff install AI extensions because they want to summarise long pages, draft replies, take meeting notes or avoid repetitive copying. Remove the unsafe route, but provide an approved way to complete the legitimate task.

For writing and summarising, an approved business AI workspace used in a separate tab is usually safer than an extension with access to every page. Staff can paste only the minimum necessary, after removing personal or confidential details. For repetitive CRM or support work, a narrow integration using documented APIs, limited permissions and audit logs is safer than allowing a browser extension to inspect the whole screen. For meeting notes, choose a reviewed product with clear participant disclosure, retention controls and a named data owner rather than letting individuals add whichever bot they find first.

Separate browser profiles help too. A managed work profile should contain company bookmarks, approved extensions and work accounts. Personal profiles should not hold company sessions. On shared or high-risk tasks, use a dedicated browser profile with no extensions at all. Require multi-factor authentication, but remember that a stolen session cookie can sometimes bypass the point where a password and second factor are entered. That is why extension control and session monitoring still matter.

Be transparent with staff about the decision. Explain that the business is not blocking useful AI because management dislikes new tools. It is controlling software that can read systems carrying customer and company data. Publish the approved alternatives, show people how to request an exception and commit to reviewing requests promptly. A workable policy might approve a paid business AI account for general drafting, prohibit client data in consumer accounts, and reserve browser extensions for tools that cannot reasonably work another way.

How should approved extensions be reviewed?

Review the allowlist every quarter and whenever an extension asks for new permissions, changes publisher, changes privacy terms or behaves differently. High-risk tools that can access email, CRM, finance or file storage deserve monthly monitoring. Remove extensions that are no longer used. Fewer approved tools mean fewer suppliers, updates and permission changes to watch.

The review should cover the supplier's legal entity, support contact, privacy notice, security information, data locations, retention, subprocessors, model training terms, breach notification process and exit route. Under UK GDPR, your organisation remains responsible for having a lawful basis, using appropriate security and telling people how their data is used. A browser store approval badge does not perform that assessment for you. If an extension will process sensitive or large-scale personal data, involve whoever handles data protection and consider whether a data protection impact assessment is needed.

Set a simple incident plan. If a risky extension is found, disable it centrally, preserve its name, ID and version, record affected users and systems, revoke sessions, rotate credentials where appropriate, check audit logs and contact the supplier. Assess what data may have been viewed or transferred. If personal data may have been compromised, document the decision about whether the incident is reportable to the Information Commissioner's Office and whether affected people must be told. Obtain specialist advice for a serious event.

Measure whether the control works. Useful figures include the number of installed extensions, percentage with a named owner, number of blocked installation attempts, average approval time, exceptions older than 90 days and incidents linked to browser add-ons. The goal is not zero requests. A healthy process may receive regular requests and reject some of them quickly. The goal is that no extension capable of reading company systems operates without a conscious, recorded decision.

When this does not apply

Do not spend thousands of pounds on enterprise browser management if you are a one-person business with one device, no employees and little sensitive data. Review extensions manually, remove anything unnecessary, use a separate work profile and keep your browser updated. The control should match the risk.

Do not assume browser controls solve every form of shadow AI. Staff can still use personal phones, upload files to web services or install desktop applications. Extension management is one layer within a wider AI usage policy, device policy and supplier approval process. It also does not replace backups, multi-factor authentication, password management, access reviews or staff training.

Finally, do not use monitoring as covert staff surveillance. Collect the minimum information needed to manage software and protect company systems. Tell employees what is monitored and why. If you want to inspect detailed browsing or content, take employment and data protection advice before doing so. The proportionate objective is to control software permissions, not to record every page a person visits.

Is This Right For You?

This approach is right for you if staff use company email, CRM, accounts, cloud storage or project systems through Chrome or Edge, especially if people can currently install extensions without approval. It is also sensible if you handle confidential client information, personal data, financial records or commercially sensitive documents.

It is probably too much for a sole trader using one locked-down device with no staff and no sensitive client data. In that case, a manual extension review, separate work browser profile and clear rule may be enough. It is not right for any business that wants to solve the problem by banning AI while leaving personal accounts, unmanaged browsers and unknown extensions untouched. That creates the appearance of control without the control itself.

If you want help deciding what to allow, start with a browser and AI use review. The useful outcome is a short approved list, named owners and a practical route for staff to request a tool, not a 40-page policy nobody follows.

Frequently Asked Questions

Can a browser extension really read everything in our CRM?

It can if its permissions allow it to read and change data on that site or on all sites. Review the exact permission scope and test it in a managed profile. Do not rely on the extension's marketing description.

Is an extension safe if it is in the Chrome Web Store or Microsoft Edge Add-ons store?

Store review reduces some risk but does not remove it. Extensions can be compromised, sold to a new owner or updated with broader permissions. You still need an allowlist and recurring review.

Should we ban all AI browser extensions?

Block them by default, then approve only tools with a clear business need, acceptable permissions and reviewed data terms. A permanent ban on every tool is usually less effective than a short, controlled allowlist.

Can we control Chrome extensions without buying Chromebooks?

Yes. Managed Chrome browser policies can be applied on Windows and macOS, and Microsoft Edge can be managed through Intune or Group Policy. You may need suitable business administration or device management licensing.

What should staff do if they already installed an unapproved AI extension?

They should stop using it and report the name, extension ID, version, installation date and systems used while it was active. An administrator should remove it, review permissions and logs, revoke relevant sessions and assess possible data exposure.

How often should we review approved browser extensions?

Review the full allowlist at least quarterly. Monitor high-risk extensions monthly and review immediately after a permission change, ownership change, security alert or significant product update.

Does UK GDPR ban AI browser extensions?

No. UK GDPR does not ban them, but you need a lawful basis, transparency, data minimisation, appropriate security and suitable supplier terms when personal data is processed. High-risk use may require a data protection impact assessment.