Control over AI
Blog
AI data leakage 7 min read

Browser extensions are AI tools too

An extension with read access to every site sees more than most AI services do. We are one ourselves, so this article is about us as well.

Admin reviewing installed browser extensions
Quick answer

A browser extension with read access to all sites can see the contents of every page you open: your mailbox, your CRM, your case system, and the field you are typing into. That is not a breach, it is the permission approved at install, usually by the employee. Since many extensions gained AI features, that reach expanded without any new decision being taken. So extensions belong in your inventory of AI usage, and the question per extension is the same as for any vendor: what leaves, and who receives it?

01

Read access to all sites means visibility of every page you open

02

Permissions were approved at install, usually by the employee alone

03

AI features were added to existing extensions with no new approval moment

04

An acquired extension inherits the previous owner's installed base

05

Extensions belong in your AI usage inventory

An AI usage inventory almost always produces the same list: ChatGPT, Copilot, Gemini, perhaps Claude. What rarely appears on it are the fourteen extensions installed on the same laptop, four of which hold access to all sites and two of which grew an AI feature last year.

This article is about us as well, because we ship a browser extension. That makes it an awkward subject, and that is exactly why it is worth writing.

What "access to all sites" means

At install, the browser shows which permissions an extension is requesting. The broadest variant is access to your data on all websites. In practice: the extension can read the contents of every page you open, and usually modify them.

That is a wider reach than most AI services have. ChatGPT sees what you type into ChatGPT. An extension with these permissions sees your webmail, your CRM, your case system, the intranet, and the field you are typing into, whatever site you are on.

No vulnerability is required to get there. It is a consent someone gave once, usually within two seconds, usually with no administrator present.

Three ways this gets away from you

The permissions stay, the function changes. An extension that adjusted colours three years ago gained an AI assistant last year. The permissions were already broad enough. There was no fresh approval moment, because nothing new was requested.

Acquisitions. A popular extension is bought and the new owner inherits the installed base and the permissions. There are documented cases where that was used to add behaviour the original author never wrote, with automatic updates pushing it to everyone.

The forgotten extension. Installed for one task two years ago, quietly present ever since with full read access.

What the three share: the risk does not arise at install, it arises afterwards, and no moment exists at which anyone looks again.

Why this belongs in your AI inventory

If you are mapping which AI services are in use, an extension with an AI feature is an AI service. It processes text, it sends it somewhere, and there is a vendor behind it with a jurisdiction and terms.

So the questions are the same as for any tool: what leaves, to whom, where is that party established, what is retained, and is there a processing agreement? See approving an AI tool: what to ask the vendor.

The difference is that extensions almost never went through procurement. They arrived the way most shadow AI arrives: through somebody trying to get their work done faster.

And about ourselves

BeeSensible is a browser extension with read access to the pages it works on. If we mean the above, we owe the same answers about ourselves.

The text you type is analysed to determine what is sensitive. In local mode that happens on your own machine and no text leaves the device, not even a check value of it. In cloud mode the text reaches our processing in the EU, is evaluated in working memory and discarded immediately, with no storage. What is recorded in either case, where the organisation has analytics enabled, are value-free events: which type of data, which level, which app, which timestamp, which action. No text.

That is the question you should be putting to us, and it is the same question the other thirteen extensions deserve.

Bringing them under control

  1. Inventory. In a managed browser estate you can read out which extensions are installed and what permissions they hold. Without management this becomes asking people, which produces an incomplete picture.
  2. Work from an allowlist. Blocking everything fails, because people need them. A short approved list works, provided there is a route to add something to it.
  3. Reassess on ownership change. The event most often missed.

The reason to spend effort here is not that extensions are more dangerous than other software. It is that they are the only category where the employee picks the vendor, approves the permissions and accepts the terms, all inside a single click.

FAQ

Common questions

What can a browser extension actually see?

It depends on its permissions. An extension with access to all sites can read the content of every page and usually modify it too. That includes webmail, your CRM, internal applications, and the text you type into a field before you send it.

Isn't that a security vulnerability?

No, those are the permissions displayed and approved at install. The problem is that almost nobody reads that screen, and approval happens once while the extension stays for years and can change function.

Why has this become more urgent?

Because many existing extensions added AI features. A writing helper that used to check spelling locally now sends text to a server to generate suggestions. The permissions did not change; the use made of them did.

What happens when an extension is acquired?

The new owner inherits the installed base and the permissions. There are documented cases of popular extensions being bought and then given behaviour the original authors never included, with automatic updates distributing it to everyone.

How should we handle this?

Inventory which extensions are in use, assess them the way you assess any vendor, and work from an allowlist rather than a blocklist. Managed browser policies make that enforceable.