A practical way to score browser, desktop, extension, and agent AI before you scale it.

Most everyday AI usage starts in a browser tab. Employees paste text into a chat assistant, upload a file to a summarization tool, or connect a personal account to a work device. None of this requires IT approval, so policy alone can't govern it.
A readiness assessment should start by checking what's visible at the browser level, including which AI tools are in use, what data moves into them, and whether that usage matches the acceptable use policy on paper. Our enterprise browser surfaces this activity directly, since it sits at the same layer where the AI usage happens.
These numbers show why relying on policy alone falls short. Compliance Week's 2026 AI Compliance Survey found that 83% of organizations already use AI tools, while only 25% describe their AI governance as strong. 98% of organizations have employees using unsanctioned AI tools, and 47% access AI through personal or unmanaged accounts. A browser-level check is one of the few places an organization can see this activity as it happens, rather than reconstructing it after the fact.
Browser visibility covers a lot of ground, but it doesn't cover everything. Desktop AI clients and browser extensions often operate outside the browser's own controls, and they tend to get less scrutiny during procurement because they look like ordinary productivity tools.
A thorough assessment treats these as a separate checkpoint rather than assuming browser coverage extends to them automatically. Teams that skip this step often find that their AI acceptable use policy technically applies to a desktop client, but has no way to be enforced there.
Sensitive data exposure follows the same pattern outside the browser. A KPMG survey found that 48% of employees admit to uploading sensitive data into AI tools, often through desktop clients or extensions that sit outside standard browser controls. An assessment that only checks browser activity will miss this kind of exposure, since the upload happens through a channel the browser never sees.
Agents raise different governance questions because they can act without a person reviewing each step. A browser extension or desktop app processes what a person gives it. An agent can take actions on its own, call other tools, and chain steps together through connections like "MCP," often without a person reviewing each step.
We found that 53% of AI interactions are now autonomous actions, taken by an agent working through a chain of steps rather than a person clicking through each one. Governing this well means tracking the full execution chain an agent runs through, including every step beyond the initial prompt.
Governing the AI workforce and protecting what agents do at runtime are a distinct category, separate from the tool vetting most teams already do for browser and desktop AI. Enterprise AI governance needs to treat agent and MCP oversight as its own line item, with its own visibility and control requirements.
Scoring AI governance readiness against an external framework gives teams a consistent way to track progress. The NIST AI RMF offers four functions that map cleanly onto an AI governance assessment: Govern, which covers policy and accountability; Map, which covers knowing where AI is used; Measure, which covers ongoing monitoring; and Manage, which covers response and enforcement.
Plotting browser, desktop, extension, and agent coverage against these four functions gives a maturity path based on a public, vendor-neutral framework. Read against the Compliance Week figures above, the Govern function is where most organizations already have something written down, while Measure and Manage are where the 25% strong-governance figure suggests most work remains. Our AI governance playbook builds out a fuller maturity matrix for teams who want to go deeper on this scoring.
Most organizations already have some form of AI acceptable use policy. Far fewer have a way to confirm that policy is followed at the point where AI usage happens. That distance between written policy and working control is where AI governance breaks down in practice.
The same figures bear this out at every layer discussed above: widespread AI use in the browser, unmanaged access through desktop clients and extensions, and a growing share of autonomous agent activity that no one reviews step by step. A readiness assessment should treat a written AI use policy as one input among several, alongside visibility data and enforcement checkpoints, rather than as proof that AI usage is under control.
Scoring browser, desktop, extensions, and agents against a maturity path like the NIST AI RMF is useful on its own. Working through it with a partner who can show what enforced controls look like in practice makes the process easier.
We can walk through how those visibility, control, and data exposure checkpoints apply when AI is the new threat surface.
What counts as "everyday AI usage" for a governance assessment?
It covers any AI tool an employee touches during normal work, including browser-based chat assistants, desktop AI clients, browser extensions with AI features, and agents that act on a person's behalf. Most of this usage happens outside formal procurement.
Is having an AI acceptable use policy enough to call an organization "ready"?
A policy sets expectations, but it doesn't enforce them. Readiness depends on whether an organization can see AI usage as it happens and control it in the moment, beyond describing acceptable behavior in a document.
Why do agents need a different governance approach than browser extensions?
Agents can take multi-step actions and call other tools, often through connections like MCP, going beyond processing what a person types. Governing that means tracking the full chain of actions an agent takes, including every step after the initial prompt.
What's a reasonable external framework to measure AI governance maturity against?
The NIST AI RMF is a common reference point. Its four functions, Govern, Map, Measure, and Manage, give a structure for checking whether policy, visibility, monitoring, and enforcement are all in place together.