KnowBe4 adds browser extension to curb shadow AI use
Fri, 2nd Oct 2026 (Today)
KnowBe4 has added a browser extension for Chrome and Edge to its Agent Risk Manager product, giving security teams real-time control over unsanctioned AI use in the browser.
The update targets what security teams often call shadow AI: employees using chatbots, coding assistants, meeting transcription tools and other browser-based AI services without approval from IT or security. The extension can identify access to known AI sites and allow administrators to permit, warn or block that access at the point of use.
The move comes as companies try to balance employee demand for AI tools with concerns about data leakage, governance and cyber risk. In research cited by KnowBe4, 52% of organisations said their AI use was unapproved or ungoverned. The same research found that more than a third of employees commonly source their own agentic AI tools when approved options are unavailable or restrictive.
That has created a new challenge for employers. Many businesses already track software use through dashboards or network monitoring, but those systems often show activity only after staff have used an external service. KnowBe4 is positioning the extension as a way to move from monitoring to intervention within the browser session itself.
Matt Duren, Senior Vice President of AI and Data at KnowBe4, said the main issue for security teams is not simply knowing that staff are using unauthorised AI tools, but being able to stop or manage that activity in time.
"Visibility alone does not stop a data leak, it just documents it," said Matt Duren, Senior Vice President of AI and Data at KnowBe4.
He said the launch also reflects broader pressure on security teams to take stock of AI use across their organisations.
"Security teams have been instructed to take an inventory of the AI tools running in their environment. While that is necessary, it is not enough. With this extension, the same capability that discovers shadow AI can now act on it in real time without forcing security teams to choose between locking AI down and letting it run unchecked," Duren said.
Platform link
The browser extension sits within KnowBe4's wider platform rather than operating as a standalone tool. In practice, that means data on shadow AI usage is intended to feed into the same user risk profile that already includes phishing simulation results, security awareness training and real-time coaching.
The approach draws on 16 years of behavioural risk data across more than 70,000 customers. For corporate security teams, that means AI-related behaviour is being treated as part of the same broader human risk picture as clicking phishing links or ignoring security prompts.
That reflects a wider shift in cybersecurity products towards combining user behaviour, access controls and security training in a single system. Vendors in the sector increasingly argue that AI use is not only a technology procurement issue but also a workforce risk issue, particularly when staff paste internal information into public tools or use consumer services to complete work tasks.
Access scope
The extension is available to Security Awareness Training Advanced customers on direct-sale US tenant accounts through an early access programme. Broader availability is planned in the coming months, though KnowBe4 did not provide a more detailed timetable.
The restricted rollout suggests the company is testing demand and operational use before a wider release. Early-access launches are common in cybersecurity, where vendors often need customer feedback on policy controls, false positives and administrative workflows before expanding a product across regions and account types.
For users, one practical issue will be how organisations define acceptable AI use. A system that can block, warn or allow access still requires companies to decide which tools fall into each category. That can be difficult in a market where consumer AI services change quickly, new browser-based assistants appear regularly and business units often adopt tools faster than central governance teams can review them.
Market pressure
KnowBe4 is best known for security awareness training and phishing simulations, and the extension adds another layer to a market that has traditionally focused on educating employees rather than directly controlling browser behaviour. By connecting browser activity to existing training and risk scoring, the company is extending its role from awareness into active policy enforcement around AI use.
The broader commercial logic is clear. As companies introduce internal AI rules, security buyers are looking for tools that can show where employees are using unsanctioned services and provide immediate options for handling that behaviour. Products that only list AI usage may satisfy reporting needs, but they may not address the problem of sensitive information entering external systems before a security team can respond.
Shadow AI activity captured in the browser does not sit in a separate console and instead feeds into the same organisational risk profile as phishing simulations, security awareness training and real-time coaching.