AI/ML, Governance, Risk and Compliance, Application security

From browser control to agent control: Governing the new AI workforce

Robot workers in boiler suits standing in tidy formations on a factory floor.

AI agents create an unusual governance problem. They use the same web browsers, networks, applications and data as human employees, but conventional security tools can see only fragments of their activity. And unlike humans, AI agents do not undergo employee onboarding or learn corporate policies.

As Island Director of Product Management Roi Leibovich puts it in a recent blog post, enterprises have effectively acquired "a second workforce" in the form of AI agents — without interviewing or performing background checks on these new "employees."

Due to this lack of oversight, says Leibovich, "organizations are now dealing with disappearing audit trails, murky agent identities, an expanding attack surface, and uncontrolled AI costs."

Island's solution to this governance gap is to extend its Island Desktop control-plane architecture, originally developed to monitor and control human work, to autonomous agents and provide visibility and enforcement wherever those agents operate.

Why full-chain visibility matters

An AI agent can receive a prompt, invoke an MCP tool, execute code, access a file and transmit data externally, all as part of a single task. Unfortunately, traditional security tools won't get the whole picture.

A network monitor will see traffic, but without endpoint context. EDR sees endpoint activity but doesn't know what the initiating prompt is. Identity systems see credential use, but without the intent behind it. CASB or SaaS-security products see application activity, but not the preceding chain of events.

When data points are scattered among several tools, reconstructing agent activity becomes very difficult. It's much easier, however, when a unified control plane matches the original prompt with subsequent tool calls, execution and data movement.

In the age of autonomous, partly obscured AI agents, security teams need to understand not merely that an action occurred, but why it happened and what sequence produced it.

How extending browser and desktop controls to AI agents enables inline policies

The browser is particularly valuable as a control point because agents often use web applications just as humans do.

From the point of view of an endpoint or network tool, an agent clicking through a web application can look like a person performing the same actions. But if you're looking at it from inside the browser, the control plane can distinguish the agent's actions from a human's and enforce different policies.

Island extends that browser-based approach across its enterprise browser, extensions for third-party browsers, the Island Desktop and its network tools, as well as MCP and LLM gateways, APIs, EDR/MDM integrations and OpenTelemetry.

These controls, which operate as part of Island Desktop, can discover agents, MCP servers and skills running on endpoints, while agent identities can receive scoped, just-in-time credentials rather than persistent access.

How a unified policy engine and audit trail can provide multiple intervention points across an agent's execution chain

Full-chain visibility creates multiple opportunities to stop dangerous behavior. If an agent invokes an unapproved skill that launches a script, downloads a malicious package or attempts to exfiltrate sensitive information, defenders will not have to depend on one final control. Instead, they could prevent the skill from running, block access to the file or stop the outbound connection.

The agentic control plane brings those enforcement points under one policy engine and audit trail. Inline inspection can evaluate prompts, responses, tool calls and sub-agents for prompt injection, jailbreaks and sensitive-data movement, while content-level telemetry records prompts, MCP responses and file actions for subsequent investigation and compliance.

Governing AI agents requires more than just adding another security point solution. The broader objective is to connect existing observation and enforcement points so defenders can follow an autonomous action from intent through execution.

In this model, the browser and desktop take on expanded roles. They remain control points for human activity but also become components of a larger agentic governance architecture — one capable of identifying who or what is acting, what it intends to accomplish, what resources it touches and where defenders can intervene before an autonomous mistake becomes a security incident.

"Agents already have the run of your systems," Leibovich writes, but "they never got the handbook explaining what they're allowed to do with it. Island is what gives them one."

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.
Paul Wagenseil

Paul Wagenseil is a custom content strategist for CyberRisk Alliance, leading creation of content developed from CRA research and aligned to the most critical topics of interest for the cybersecurity community. He previously held editor roles focused on the security market at Tom’s Guide, Laptop Magazine, TechNewsDaily.com and SecurityNewsDaily.com.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds