Introducing AI Security in WithSecure™ Elements: Seeing Shadow AI Before It Becomes a Breach

WithSecure™ Elements is rolling out AI security in stages, starting with visibility. The first release surfaces shadow AI software, AI browser extensions, and AI or agentic identities across the organisation, so partners and IT teams can finally see what’s already running before deciding what to do about it. 

✓  AI software, including shadow AI nobody approved, now shows up directly in software inventory, with no need for the app to be installed locally. 

✓  Browser extension discovery flags AI sidebar tools such as ChatGPT and Perplexity running on managed endpoints. 

✓  AI and agentic identities, agents, chat assistants, coding assistants, and GenAI tools, become visible through the existing Microsoft Entra ID integration. 

✓  Machine identities are on track to outnumber human identities by more than 80 to 1, making this visibility gap urgent rather than theoretical.[1]

✓  This is the first of several planned steps: visibility now, broader commercial AI security outcomes to follow. 

Picking up where we left off 

In our previous post, we looked at why AI security has become a board-level issue: security teams brought in too late, shadow AI spreading by default, and AI agents multiplying faster than identity management can track them. This post is about what WithSecure is actually doing about it, starting with the part every other control depends on: visibility. 

Why visibility has to come first 

Shadow AI is what happens when employees start using AI tools and browser extensions on their own, without IT ever knowing. And an organisation can’t protect data its security team doesn’t know is leaving the building. Left unmonitored, these tools can quietly collect large amounts of corporate information in the background, opening the door to compliance violations and, in the worst case, intellectual property walking out with it. 

What makes AI browser extensions risky? 

Many AI extensions ask for broad permissions just to work, including the ability to read and change data on every site a person visits. That’s a lot of trust to hand over. If the extension turns out to be malicious, or is compromised after the fact, an attacker can use that same access to pull sensitive data, credentials, and proprietary code straight from the pages an employee works in. 

Why can’t traditional antivirus catch this? 

Antivirus and endpoint tools were built to scan files sitting on a hard drive. They weren’t built for threats that live entirely inside the browser. Malicious extensions often load their payload dynamically from a remote server after installation, so there’s no file to catch in the first place. Watching what happens in the browser at runtime, not just what’s sitting on disk, is what closes that gap. 

Identity is the other half of the problem 

Visibility into AI and agentic identities is increasingly the foundation the rest of AI security sits on: an organisation can’t govern, restrict, or monitor what it can’t see. Machine identities are expected to outnumber human identities by more than 80 to 1, and privileged AI agent identities are rising steeply.[1]

Every new AI agent, integration, or extension typically spins up its own credentials, tokens, or service accounts, most of which escape central tracking. Agents also tend to carry more privilege than the humans who built them, accumulating broad, standing access to move fast. Without visibility into what an agent can reach, that excess privilege becomes an unmonitored path for data exfiltration or lateral movement, the same logic as the browser-extension problem, just at agent scale. 

What’s shipping: baseline visibility into the AI attack surface 

The first release focuses on one job: showing how AI is actually being used across the organisation, in a single place, for everyone already on WithSecure™ Elements. 

Shadow AI software visibility. A dedicated AI Assets view inside software inventory lists every AI tool used within the organisation, including tools that were never formally installed. 

AI browser extension discovery. Browser extensions installed across endpoints are discovered and tracked in the same software inventory, catching sidebar tools such as ChatGPT’s OpenAI extension or Perplexity before they become blind spots. 

Browsing Protection for AI usage. Existing Browsing Protection capability extends to AI-specific visibility and control at the browser level. 

AI and agentic identity visibility. AI agents, AI chat assistants, AI coding assistants, and GenAI tools become visible through the existing Microsoft Entra ID integration, the same place identity is already managed. 

 

Where AI hides  The risk  What Elements now shows 
Shadow AI software  Employees adopt AI tools without IT ever knowing  AI Assets view in software inventory lists every AI tool in use, installed or not 
AI browser extensions  Sidebar AI tools (e.g. ChatGPT, Perplexity) request broad page access  Browser extension discovery plus Browsing Protection flag and control AI usage at the browser 
AI and agentic identities  Agents, assistants, and GenAI tools spin up their own credentials, often unseen  Visibility into AI and agentic identities through the existing Microsoft Entra ID integration 

  

The thinking behind it 

Two ideas anchor this: confidence with AI, meaning the ability to defend at the speed AI-driven attacks move, not behind it, and confidence for AI, meaning being able to see what AI is doing across the estate and prove it’s controlled. 

For partners, the aim is just as practical: a new angle inside the security services already being sold, fitting inside the bundles partners already offer rather than requiring a new console, plus the productivity uplift that comes from AI-assisted detection and response. 

What’s next 

Visibility comes first, because nothing else works without it. Broader, commercial AI security outcomes, extending from visibility into remediation and response, are next in the pipeline, with a fuller AI-native layer within Elements to follow further out. We’ll cover each step as it ships. 

Frequently asked questions 

What is shadow AI? 

Shadow AI is any AI tool or extension employees use without IT’s knowledge or approval, from browser-based chat assistants to standalone apps. It creates a security blind spot because nobody has assessed what data it can access. 

Why can’t antivirus catch malicious AI browser extensions? 

Antivirus tools scan files on disk. Many malicious extensions load their payload dynamically from a remote server after installation, so there’s no file to scan. Runtime, browser-level visibility is needed instead. 

What counts as an agentic identity? 

Any credential, token, or service account created for an AI agent, chat assistant, coding assistant, or GenAI tool to act on a system, often with more standing privilege than the human who set it up. 

Do I need to install anything to see shadow AI usage? 

No. AI software shows up in the software inventory view whether or not the tool was formally installed, and browser extensions are discovered automatically across managed endpoints. 

Is this a new product or part of an existing subscription? 

These initial capabilities are included in the existing WithSecure™ Elements offering. Broader AI security outcomes are planned as the roadmap develops. 

See it for yourself 

If AI is already running somewhere in your environment, and it almost certainly is, the first step is simply seeing it. Log in to WithSecure™ Elements to check what’s showing up in your AI Assets view, or talk to us if you want a walkthrough. 

Sources: 

[1] Forrester, “Global IAM Market Forecast, 2024 to 2029,” January 2026

Blog post

Read our latest blogs

Blog

AI AI Security

AI Security: Why It’s Now a Board-Level Priority

AI security is now a board-level issue. See the real pain points, what AI security actually means, and the steps to get ahead of it.

Industry Recognition

Endpoint Security

Certified Leader in AV-Comparatives’ Endpoint Prevention and Response

AV-Comparatives named WithSecure ‘Certified Leader’ for Endpoint Prevention and Response (EPR), ‘Advanced+ Performance’ for Windows, ‘Advanced Real-World Protection’ for Windows, ‘Approved Mac Security’ for MacOS and ‘Approved Mobile Security’ for Android.

Blog

AI Security Exposure Management Identity Security Proactive Security

Exposure Management That Keeps MSPs Ahead of Attackers

One workflow from exposure to containment. WithSecure Elements gives MSPs near real-time exposure management with one-click response across every customer.