By the Shadow AI Policy team
**Most AI policies name ChatGPT, miss the extension reading every word your employees type.** Browser AI extensions are the governance gap that most acceptable use policies skip entirely. This post covers exactly what permissions these extensions request and why that matters, which popular extensions carry the highest data exposure risk, and what your policy needs to say to close the gap — including how browser management tools and an approved allowlist can give you real control instead of wishful thinking.An AI browser extension with "read and change all your data on websites you visit" permission has broader access to your company data than almost any SaaS tool you've formally approved. Treat extension governance the same way you treat SaaS procurement: require approval before install, not after an incident.
By the Shadow AI Policy team
When an employee installs an AI browser extension, they're not just adding a writing assistant. They're granting a third-party application a persistent window into everything that happens in their browser. The permission that makes most AI extensions work — "read and change all your data on the websites you visit" — is also the permission that lets it capture client emails in Gmail, patient data in your EHR's web portal, deal terms in your CRM, and credentials entered into any login form.
This isn't hypothetical. It's the documented permission scope of tools like Grammarly, and dozens of newer AI writing and summarization extensions. The extension sits at the browser layer, below your DLP tools and above your network monitoring, and it transmits whatever the user is reading or typing to the vendor's servers for processing. Most employees have no idea this is happening, and most HR and legal teams haven't thought to ask.
The four permission types that should trigger automatic review before any AI extension is approved:
Even extensions with narrower stated permissions often expand access through user-triggered features. A summarization tool that only activates when clicked still processes the full content of the active tab when it runs. "Opt-in" is not the same as "low risk."
Not all AI extensions handle data the same way, and the differences matter for your policy decisions. Here's how the most commonly installed AI extensions compare on the data practices that are most relevant to workplace risk:
| Extension | Typical Permission Scope | Training on User Data? | Enterprise/BAA Available? |
|---|---|---|---|
| Grammarly (free) | Read & change data on all sites | Yes (free tier) | Yes — Grammarly Business offers DPA; BAA available for healthcare |
| Compose AI | Read & change data on all sites | Yes (by default) | No enterprise tier as of 2024 |
| Merlin AI | Read & change data on all sites | Unclear — privacy policy vague | No |
| Microsoft Copilot (Edge sidebar) | Read page content in active tab | No for M365 commercial tenants | Yes — covered under M365 DPA |
| ChatGPT Web Extension (unofficial) | Varies by publisher — read all sites | Unknown — not from OpenAI | No — not an official OpenAI product |
One pattern worth flagging: a significant number of AI extensions in the Chrome Web Store are unofficial wrappers around OpenAI or other APIs, published by individual developers with no enterprise data agreements. Employees searching for "ChatGPT extension" may install one of these without realizing it isn't an OpenAI product. See ChatGPT's workplace risk profile for more on what the actual OpenAI product does and doesn't cover. For context on what shadow AI is in broader workplace terms, see our overview of shadow AI.
The right policy response isn't "ban everything with broad permissions." It's to distinguish between tools with a signed Data Processing Agreement (DPA), a clear no-training commitment for business accounts, and adequate vendor security controls — versus tools that have none of these. Your approved list should only include tools that pass that bar.
If your organization manages endpoints, you have more control over browser extensions than most teams realize. Both Google Chrome (via Google Admin Console) and Microsoft Edge (via Intune or Group Policy) allow IT to block extension installs by default and maintain an explicit allowlist. This is the most reliable technical control available — it prevents installation before it happens rather than detecting it after.
Here's what each platform gives you:
ExtensionInstallBlocklist to block all extensions by default, then use ExtensionInstallAllowlist to permit specific extensions by their Chrome Web Store ID. Force-installed extensions (like your approved security tools) are set via ExtensionInstallForcelist. This applies to managed Chrome profiles — see Google's Chrome Enterprise policy documentation for current implementation details.ExtensionInstallBlocklist and ExtensionAllowedTypes policies through Microsoft Endpoint Manager. Edge also supports "sidebar app" controls separately from browser extensions, which matters for Copilot governance.These controls only work on managed browser profiles on managed devices. They don't apply to personal browsers, personal devices, or employees who've signed into Chrome or Edge with a personal account on a work machine. That gap brings us to the next issue.
Managed browser policies are only as effective as your enforcement of which browser profile employees use. If an employee signs into Chrome with their personal Google account — even on a company-issued laptop — they're operating in an unmanaged profile where your extension blocklists don't apply. They can install any extension they want, and it has full access to whatever they're doing in that session, including company applications they open in that same browser window.
The technical control and the policy have to work together. A managed device policy that doesn't address browser profile separation is only half a governance program.
Your AI acceptable use policy should explicitly state:
For organizations where employees use personal devices for work (BYOD), the governance is harder. At minimum, your policy should require that any AI extension installed on a personal device is excluded from browser sessions that access company applications — and practically, this means requiring employees to use a separate browser or profile for work access on BYOD. Mobile Device Management (MDM) with a managed browser container (like Intune's managed Edge on iOS/Android) is the more reliable option if your risk tolerance is low.
Industries subject to HIPAA Privacy Rule (45 CFR § 164.502), GDPR Article 32 security obligations, or FINRA Rule 4370 should treat unmanaged browser profiles accessing regulated data as a compliance gap, not just an IT preference issue.
An allowlist approach — where extensions are blocked by default and employees must request approval — is the right default posture for any organization where employees handle sensitive data. It shifts the burden where it belongs: vendors must demonstrate data safety, not employees prove their extension caused harm. For a complete framework on structuring the broader acceptable use policy that governs this, see our AI acceptable use policy template guide.
To get an extension onto your allowlist, require the requesting employee (or vendor) to demonstrate:
Maintain the allowlist as a living document, not a one-time decision. Extensions update their permissions and change their data practices. Review your approved list at least annually, and any time a vendor announces a material change to its privacy policy or terms of service.
The approval process doesn't need to be bureaucratic. A simple request form routed to IT and Legal, with a two-week SLA for review, is enough to stop casual shadow installs while keeping the process usable. If you want a policy that addresses this and the broader AI tool landscape, you can generate a tailored policy kit that includes extension governance language.
About Shadow AI Policy: We build AI acceptable use policy tools for HR and operations teams at 50–500 person companies. We publish guides on shadow AI, acceptable use policies, and AI governance, updated as regulations and AI tools change.
A SaaS AI tool typically receives only the data a user intentionally pastes or uploads into it. A browser extension sits inside the browser and can read everything in an active tab — including data the user never meant to share — because of how browser permissions work. This makes extensions a broader data exposure risk than most SaaS tools, and it's why they need separate governance treatment in your AI policy rather than just being lumped in with "approved applications."
A policy-only approach without technical enforcement is unreliable for browser extensions because installs take about 30 seconds and leave no visible footprint in most IT systems. Policy language matters — it establishes the rule and the consequence — but it should be backed by managed browser settings that require IT approval before an extension can be installed. Without the technical control, you're relying entirely on employee compliance and have no reliable way to detect violations before a data incident occurs.
Neither law names AI browser extensions specifically, but both apply to how personal and protected data is processed — and an AI extension that transmits that data to a third-party vendor triggers existing obligations. Under GDPR Article 28, any vendor processing personal data on your behalf must have a signed Data Processing Agreement. Under HIPAA, any vendor handling Protected Health Information (PHI) must have a signed Business Associate Agreement (45 CFR § 164.502(e)). If an employee installs an unapproved AI extension and it processes PHI or EU personal data, your organization may be in breach regardless of whether you knew about the install.
Start with a grace period amnesty rather than immediate discipline — announce the new policy, explain the risk, and give employees 30 days to self-report extensions they've installed and either seek approval through the new process or remove them. This gets you a realistic picture of what's installed without driving behavior underground. After the grace period, enforce the policy going forward and use technical controls (managed browser allowlists) to prevent new installs. For extensions that were installed before the policy existed, the priority is understanding what data they may have accessed, not retroactive punishment.
Tailored to your industry and the AI tools your team uses. Free preview, then $149/mo to keep it current as the rules and vendor terms change — or $79 for a one-time snapshot.
Generate my policy kit →Writing policies for several clients? MSPs, IT consultancies and fractional CISOs keep a roster of client kits that refresh monthly, under their own branding. See partner plans →