AI browser extensions add functions directly to the pages a user opens – summarising text, translation, rewriting a paragraph, filling in a form, or helping draft a reply to an email. They are popular because they work without switching between tools. This, however, is precisely where their risk lies: an extension usually has access to the content of the pages you have open, including company systems, client data, and internal documents. On company devices, they therefore belong among the things internal policy should address – a list of approved extensions, a ban on installing others, and a check on the permissions an extension requests. Free add-ons from unknown publishers are especially risky here. Before installation, it is sensible to check what permissions the extension requires, because access to the content of every page visited means the tool also sees internal systems and customer data. In a corporate environment, it is therefore recommended to approve the list of allowed extensions centrally through browser management.
See also: Shadow AI, Internal AI usage policy, Access policy for company accounts.