Technology Intelligence
Cyber Intelligence

Could a Browser Extension Be Reading Your AI Conversations?

IT Club Editorial7 minutes read29 July 2026
Could a Browser Extension Be Reading Your AI Conversations?

Browser extensions can request permissions that allow them to read content on websites, including AI-chat services. This article explains how that access works, why HTTPS does not prevent it, what kinds of business information are most at risk, and the controls businesses should put in place.

Employees increasingly use AI chatbots for drafting, research, problem-solving and summarising information. Those conversations often contain far more than casual questions. Staff sometimes paste in customer information, financial figures, internal emails, contracts, medical details, source code, credentials or commercially sensitive plans.

Most businesses focus on whether the AI provider stores or trains on that information. That is an important question — but it is not the only one. A browser extension installed for an apparently unrelated purpose may have permission to read or alter content on the pages a user visits. Depending on its design and configuration, it may be capable of capturing prompts and responses while the conversation appears in the browser.

The wider risk

The privacy of an AI conversation depends on more than the AI provider—it also depends on everything that can see the conversation before, during and after it is sent.

A secure AI account cannot protect information from software that is already allowed to read the browser page.

Last checked: 29 July 2026.

What has been reported?

Security researchers and organisations have reported cases in which browser extensions captured content from AI-chat services. Extensions involved in these reports were marketed under a range of apparently helpful purposes:

  • Free VPN services
  • Ad blockers
  • AI sidebars and writing assistants
  • Productivity tools
  • Browser guards and search assistants

Some reportedly collected prompts, chatbot responses, conversation identifiers, timestamps, page URLs and device or user identifiers. Some of that information was then reportedly transferred to external services for analytics, advertising intelligence, data aggregation or other commercial purposes.

One security analysis reportedly identified a sample of AI-chat conversations that had been collected through browser extensions and were accessible through a commercial data service. The conversations included sensitive topics such as medical issues, financial difficulties and immigration matters, and some reportedly contained identifiable personal details. The precise methodology of that analysis, the number of users represented and the exact mechanism of collection have not been independently and fully corroborated at the time of publication. Where details remain unverified they should be treated as illustrative of a category of risk that has been documented across multiple research reports — rather than as confirmed statistics.

The key point

The significance lies less in the size of one sample and more in proof that intimate AI conversations can become commercially accessible when browser software is poorly controlled.

How can a browser extension read an AI conversation?

Browser extensions are small software applications operating inside the browser. To work effectively, many request permissions during installation. Depending on what is granted, an extension may be able to:

  • Read content displayed on specified websites
  • Alter page content
  • Monitor browser tabs and activity
  • Intercept or modify requests made by web pages
  • Access browsing history
  • Read copied information from the clipboard
  • Inject code into websites
  • Communicate with external servers

An extension that has permission to interact with an AI-chat page may therefore be able to observe what the user types, the submitted prompt, the chatbot's response appearing on screen, conversation titles, timestamps and identifiers. It does not need to break or bypass the AI provider's own security to do this — it operates at the browser level, where the content is already displayed.

A useful analogy

HTTPS is like an armoured vehicle carrying the conversation between the browser and the AI provider. A browser extension may be sitting inside the vehicle with the user, reading the document before it is locked away or after it is opened.

Not all extensions have equal access. Capability depends on the permissions requested and granted, the websites the extension is configured to access, whether it operates in private browsing sessions, central administrator policies and subsequent extension updates that may expand or change permissions.

Does HTTPS prevent this?

HTTPS protects information in transit between the browser and the AI provider. It prevents someone elsewhere on the network from casually intercepting the conversation as it travels. That protection is important and should remain in place.

However, HTTPS does not prevent software operating inside the browser from accessing information once it is available to the browser. Other examples of in-browser access include malware capturing keystrokes, screen-recording software, clipboard monitoring, session-replay scripts and compromised browser sessions.

The distinction

Encryption protects the journey. It does not automatically protect information from software at either end of that journey.

HTTPS remains essential for protecting data in transit. The extension risk is a separate problem — one that exists at the endpoint rather than on the network.

Why are AI conversations so valuable?

A browsing-history record may show that someone visited a financial or medical website. An AI conversation may reveal the specific debt problem, medical symptom, legal situation, immigration question, or business challenge the user is trying to solve.

The difference from ordinary tracking

An AI prompt may describe not only what someone is interested in, but exactly what problem they are trying to solve.

That level of detail makes AI transcripts potentially useful for advertising, behavioural profiling, lead generation, market research, competitive intelligence and social engineering. It also creates risk of fraud, phishing, extortion and identity correlation where information falls into the wrong hands.

Not every organisation that collects this kind of data uses it for harmful purposes. There is an important distinction between legitimate but intrusive commercial use, unclear secondary use, policy violations, malicious data exfiltration and criminal exploitation. Businesses should be aware of all these possibilities rather than assuming the worst or assuming the best.

What is a data broker?

A data broker is an organisation that collects, combines, analyses, licences or sells information about people, organisations or online activity. Information may come from public records, websites, applications, advertising networks, browser extensions, data partnerships, purchased datasets and tracking technologies.

Not every data broker offers raw named transcripts of AI conversations. A service might instead provide audience segments, behavioural trends, advertising insights, aggregated data, pseudonymised records or commercial APIs. However, even data described as aggregated or anonymised may remain sensitive where it includes detailed narrative, rare circumstances, names, locations, employers, medical details, case numbers, email addresses or unusual combinations of facts.

Why ‘anonymised’ does not always mean harmless

DescriptionWhat it meansThe limitation
Anonymised dataAltered so an individual is no longer identifiable by reasonably available meansMeeting the legal standard requires more than removing a name
Pseudonymised dataIdentifiers replaced or separated — the person may still be identifiable using additional informationDoes not meet the anonymisation standard under UK GDPR
De-identified or filtered dataA broader term — may or may not meet a legal definition of anonymisationThe label does not determine the legal position

Removing a name from a transcript does not make it anonymous if the content includes age, location, employer, medical condition, family circumstances, legal case, immigration history, precise dates or quoted correspondence.

The anonymisation test

Removing someone’s name does not make a detailed account of their life anonymous.

Which business information is most at risk?

Personal data

  • Customer details and contact records
  • Employee information and CVs
  • Medical information and special-category data
  • Identity documents
  • Complaints and disciplinary matters

Commercial information

  • Pricing, margins and forecasts
  • Business plans and acquisition discussions
  • Contracts, tenders and supplier terms
  • Product roadmaps

Technical information

  • Source code
  • Credentials, API keys and access tokens
  • Network diagrams and configuration
  • Security findings, vulnerabilities and incident details

Legal and regulatory information

  • Legal advice and claims
  • Ongoing investigations or disputes
  • Regulatory submissions and settlement discussions

Customer content

  • Support tickets, emails and recordings
  • Case notes and confidential reports
  • Customer documents pasted for summarising or drafting

A practical test

If the information would not be posted on a public website, it should not be pasted into an unapproved AI service from an unmanaged browser.

Official extension store does not mean risk-free

Browser extension stores perform security and policy checks. Those checks reduce some risks, but they do not remove them. An extension listed in an official store may:

  • Initially appear legitimate before changing ownership
  • Receive a harmful update after passing initial review
  • Add new data collection after original approval
  • Request excessive permissions through vague consent wording
  • Imitate a legitimate product
  • Be removed from the store only after detection
  • Contain a compromised dependency

Extension popularity, ratings and prominent store placement do not prove that the code is harmless, data handling is appropriate, the extension remains unchanged, or it is suitable for business use.

An important distinction

Available in the browser store is not the same as approved by your organisation.

Browser permissions in plain English

PermissionWhat it may allowWhy it mattersBusiness response
Read and change data on websitesInspect or modify page content on specified or all sitesMay allow reading AI prompts and responses where access covers AI-chat servicesAllow only for approved extensions and only on necessary websites
Read browsing historySee visited websites and browsing patternsReveals staff activity across all browsing, not only AI toolsTreat as sensitive; require a clear business justification
Manage downloadsObserve or influence downloaded filesMay monitor confidential documents obtained during a sessionRestrict to approved tools with a confirmed business need
Access clipboardRead or write copied informationHigh concern where staff copy passwords, keys or confidential contentReview carefully; consider whether the feature justifies the access
Communicate with native applicationsExchange information with installed software outside the browserMay allow data to leave through a different routeReview the associated application and understand the data destination
Run in private browsingExtend access into private or incognito sessionsPrivate browsing does not block extension access if the extension is allowed to runDo not assume private browsing prevents extension activity
Access all sitesBroad access beyond the extension’s apparent purposeNo technical limitation on which pages the extension can readAvoid unless there is a clear, approved and documented requirement

Permissions indicate capability — not necessarily behaviour. A broad permission does not prove malicious intent. The question is whether the access is justified given the purpose of the extension.

Warning signs that a browser extension needs reviewing

  • Unclear developer identity or no credible support website
  • Vague privacy policy that does not explain data collection clearly
  • Unexpected change of ownership
  • Permissions unrelated to the extension’s stated purpose
  • Request to read all websites without a clear need
  • Recent sudden expansion of permissions
  • Extension installed outside the approved process
  • Duplicate or misspelt brand name
  • Reviews mentioning redirects, data collection or unexpected behaviour
  • Extension requesting ‘anonymous analytics’ without further detail
  • No business justification for its installation
  • Very broad access for a minor convenience
  • Extension no longer receiving updates
  • Extension removed from its store
  • Unexplained browser advertisements or search-engine changes
  • Unfamiliar AI sidebar or toolbar appearing without installation
  • Staff unable to explain why it is installed

The right question

The question is not merely ‘Is this extension malicious?’ It is also ‘Does this extension need the access it has?’

Immediate steps for businesses

  1. 1Warn staff — tell employees not to enter confidential, personal or regulated information into unapproved AI services.
  2. 2Identify approved AI tools — publish a clear list of approved services, permitted account types, permitted data and prohibited data.
  3. 3Inventory browser extensions — review Chrome, Edge, Firefox and other browsers across managed devices.
  4. 4Remove unnecessary extensions — do not retain extensions simply because no problem has yet been reported.
  5. 5Block unapproved installation — use central browser-management policies where available.
  6. 6Review existing permissions — pay particular attention to extensions with access to all websites, clipboard data, browsing history or page content.
  7. 7Check AI usage — identify which AI services staff access and from which devices and browser profiles.
  8. 8Investigate high-risk extensions — review installation dates, versions, permissions, affected users and network logs.
  9. 9Reset access where necessary — if credentials, tokens, code or security information may have been exposed, follow the appropriate incident-response process.
  10. 10Consider data-breach obligations — escalate to the responsible data-protection and legal contacts.

An important limitation

Removing the extension stops future access; it does not answer what may already have been collected.

A practical browser-extension audit

  1. 1Discover — list all extensions installed across business browsers.
  2. 2Identify — record the extension name, ID, developer, store link, version, installation source and business owner.
  3. 3Justify — record the business reason for each extension.
  4. 4Review permissions — identify which websites and browser data it can access.
  5. 5Review data handling — check the privacy policy, subprocessors, analytics, data sharing, retention, location and security contact.
  6. 6Assess reputation — review developer history, security reports, ownership changes, marketplace status and update history.
  7. 7Approve, restrict or remove — use a formal allow, block or conditional decision.
  8. 8Enforce — apply central browser policies.
  9. 9Monitor — detect new or changed extensions.
  10. 10Revalidate — review approved extensions periodically and after significant updates.

The audit principle

Discover, justify, restrict and review—browser extensions should be managed software, not personal browser decorations.

What should happen after discovering a risky extension?

Immediate deletion may be appropriate to stop further collection, but the business should also preserve enough information to investigate. Where proportionate, record the extension name and ID, version, affected browser, affected account, installation date, permissions, store listing, developer details, security alerts, network destinations and likely exposure period.

  • Remove or disable the extension
  • Block its extension ID to prevent reinstallation
  • Check for related extensions across other browser profiles
  • Revoke relevant sessions
  • Rotate exposed credentials, keys or tokens
  • Notify security and data-protection contacts
  • Review logs
  • Assess notification requirements
  • Document all decisions

The investigation principle

Preserve evidence of the exposure without spreading the exposed information further.

Could this be a personal-data breach?

A personal-data breach may involve accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access to personal data. If a browser extension transmitted personal information without appropriate authority, the organisation may need to assess what data was involved, whether individuals can be identified, the likely recipients, potential harm, containment, contractual obligations and regulatory notification requirements.

This assessment should involve the data-protection officer where one is appointed, the senior information-risk owner, a legal adviser, the cyber-security provider, and the insurer where policy terms require notification. This article does not constitute legal advice on any particular situation.

The assessment principle

Do not wait for certainty that the information has been misused before beginning the breach assessment.

Safer business use of AI

The appropriate response is not a blanket ban where AI provides genuine business value. It is a structured approach to approved services, managed browsers and appropriate data.

  • Approved services — use organisation-approved AI services and account types
  • Data classification — define which information may and may not be entered
  • Managed browsers — use centrally managed browser profiles on business devices
  • Extension control — allow only reviewed and approved extensions
  • Identity and access — use business accounts, MFA and appropriate offboarding
  • Supplier review — understand provider terms, retention, training and data-location settings
  • User training — teach staff that deleting a chat may not erase third-party copies, that private browsing does not solve every risk, and that free tools may monetise data
  • Incident reporting — give staff a clear route for reporting mistakes without fear of concealment

The safe-use principle

Safe AI adoption combines an approved service, appropriate data, a managed device and a controlled browser.

Practical business implications

AI policy alone is not enough

A policy cannot protect data where unmanaged extensions are allowed to read the browser. Governance that ends at the acceptable-use document has not addressed the endpoint.

Browser extensions are software

They should be inventoried, approved, patched and removed like other business applications. Casual installation by individual staff members creates risk that cannot be identified or managed centrally.

Free services have a cost model

The cost of a free extension may be advertising, tracking, data collection or access to user behaviour. That is not automatically unlawful, but it is a business risk that requires a decision.

Enterprise AI does not fix an unmanaged endpoint

Strong controls on the AI provider's side can be undermined by unsafe or over-permissioned software on the device or in the browser. The security chain extends to the endpoint.

Where governance must reach

AI governance ends at the browser only if the organisation stops looking there.

Questions to ask about AI and browser extensions

  1. 1Which AI services are staff using?
  2. 2Are they using personal or business accounts?
  3. 3What information are employees entering?
  4. 4Which browser extensions are installed on business devices?
  5. 5Who approved each extension?
  6. 6What permissions does each extension have?
  7. 7Can any of those extensions access AI-chat websites?
  8. 8Can staff install new extensions themselves?
  9. 9Are browser profiles centrally managed?
  10. 10Is there an approved-extension list?
  11. 11Has any installed extension changed ownership?
  12. 12Does the privacy policy permit commercial data sharing?
  13. 13Do we monitor extension updates or permission changes?
  14. 14What would happen if a transcript contained customer data?
  15. 15Could credentials, code or security information have been entered?
  16. 16Do staff know how to report accidental disclosure?
  17. 17Have we tested the incident-response process?
  18. 18When was the extension inventory last reviewed?

The IT Club View

Most businesses approach AI privacy by asking whether ChatGPT, Copilot, Gemini or another provider stores their prompts. That is a sensible and necessary question. It is also incomplete.

The prompt starts life on an endpoint. Before it reaches the AI provider, it may be visible to the user’s device, browser, browser extensions, security and monitoring software, connected applications and any compromised account. After the answer returns, those same layers may also see the response.

The core lesson

You cannot secure an AI conversation by reviewing only the AI provider.

This is not simply a warning about AI. It is a reminder that the browser has become one of the most important business applications — and one of the least consistently governed. Businesses do not need to ban every extension. They need to replace casual installation with business justification, permission review, formal approval, central enforcement, regular revalidation and prompt incident response.

The IT Club View

The safest AI conversation is not created by one privacy setting. It is created by an approved tool, appropriate information, a managed browser and a user who understands what must remain confidential.

Ready to audit your browser extensions?

Could an unapproved browser extension access your business data? Use our Browser Extension Security Audit to identify installed extensions, review permissions and decide which software should be approved, restricted or removed.

View the Browser Extension Security Audit

Administrator Technical Note

This section is intended for IT administrators, security teams and compliance leads rather than general readers. It covers browser management, extension analysis and technical controls.

Browser-management strategy

Effective extension governance requires managed browser profiles, enterprise policies, extension allow-listing and block-listing, prevention of developer-mode extensions, control of external extension sources, restrictions on private-browsing access, reporting of installed extensions and monitoring of extension IDs and versions.

Microsoft Edge

Microsoft Edge supports central extension management through group policy, Microsoft Intune administrative templates and the Microsoft Edge management service. Relevant policies include ExtensionInstallBlocklist, ExtensionInstallAllowlist and ExtensionSettings, which allow administrators to block specific extension IDs, allow only a defined set of extensions, and configure permissions and settings centrally. Force-installed extensions can be deployed without user action. Microsoft Defender for Endpoint provides additional visibility into browser extensions across managed devices. Verify all policy names and capabilities against current Microsoft Learn documentation before deployment.

Google Chrome

Google Chrome Enterprise Core provides extension management through Chrome policies, including extension allow and block lists, force-installation, permission controls and browser reporting. Managed browser profiles can be configured to enforce organisation-level extension policies. Chrome Browser Cloud Management offers centralised reporting. Verify all policy capabilities against current Google Chrome Enterprise documentation before deployment.

Other browsers

Firefox, Safari and other Chromium-based browsers may require separate controls and inventories. Where staff use multiple browsers, each should be covered by the extension audit and management process.

Extension analysis

For a suspicious extension, examine where lawful and within your competence: extension ID, manifest version, declared permissions, host permissions, content scripts, service workers, externally connected domains, update URL, installation source, developer identity, ownership history, network telemetry, version history and security-vendor detections. Do not encourage reverse engineering beyond your organisation’s competence or authority.

Endpoint and network controls

  • Endpoint detection and response
  • DNS filtering and secure web gateway
  • Firewall telemetry
  • Cloud-access security broker
  • Data-loss prevention
  • Browser isolation
  • Application control
  • Managed-device compliance and conditional access
  • Security information and event management
  • Threat-intelligence feeds

Network controls may not reveal the content of encrypted traffic but can help identify unexpected destinations and unusual connection behaviour.

AI data controls

  • Blocking unapproved AI domains
  • Approved enterprise AI accounts with appropriate data-handling terms
  • Data-loss prevention policies targeting AI-service traffic
  • Sensitivity labels and user-risk policies
  • Application governance and cloud-app discovery
  • Upload controls and clipboard restrictions where proportionate
  • Audit logging for AI service access

Investigation checklist

  • Affected extension IDs and versions
  • User and device scope
  • First-seen and last-seen dates
  • Affected browser profiles
  • Affected chatbot services
  • Likely data categories involved
  • Network destinations
  • Authentication tokens and API keys potentially exposed
  • Shared conversation links
  • Related extensions on the same device or profile
  • Containment actions taken
  • Credential rotation completed
  • Breach assessment status
  • Supplier notification where relevant
  • Lessons learned

Do not assume that uninstalling the extension removes previously transmitted data or revokes access tokens that may already have been exposed.

Operational Heartbeat

Browser-extension risk changes continuously. Staff install new extensions. Extensions update and ownership changes. Permissions expand. New browsers are adopted. AI usage grows. Developers alter privacy terms. Extensions are removed from stores. Staff use personal browser profiles. New devices join the organisation.

A recurring review should check browser inventory, managed and unmanaged browsers, installed extensions, new extension IDs, the approved-extension list, the blocked-extension list, extension permissions, ownership changes, store status, privacy-policy changes, AI-service usage, shadow AI, personal accounts, data-loss alerts, security incidents, user training, policy exceptions and corrective actions.

Operational Heartbeat

Browser security needs an operational heartbeat: extensions, permissions, AI usage, incidents and approval decisions should be reviewed rather than assumed to remain safe.

Plain-English Takeaway

Browser extensions can sometimes read information displayed inside websites, including prompts and responses from AI chat services. Do not enter confidential information into unapproved AI tools, and do not assume that an official extension store, HTTPS or private-browsing mode makes every extension safe. Businesses should approve AI services, control browser extensions and investigate any software with unnecessary access to page content.

Need the practical steps?

A short, instruction-led version of this topic is available in the Knowledge Centre.

View the Knowledge Centre Guide

Enjoyed this article?

Follow The IT Club Briefing on WhatsApp for short daily technology updates and practical business insights.

Have a question we should answer?

Ask the IT Club Advisor