SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
Manifold adds browser support for AI governance platform

Manifold adds browser support for AI governance platform

Tue, 29th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Manifold Security has launched browser support for its AI governance platform, extending monitoring to AI assistants and browser-driving agents in managed Chromium-based browsers.

The new support lets security teams trace AI agent activity across browser and endpoint runtime from a single control plane on macOS, Windows and Linux. The product has been running in customer deployments for several months and is now generally available to organisations using managed Chromium-based browsers.

The launch comes as companies face closer scrutiny of AI tools that can do more than generate text. Manifold linked the release to the spread of autonomous browser agents and to recent incidents in which AI systems were reported to have taken unauthorised actions on external systems.

The browser support is designed for two categories of tools. One covers AI assistants used inside browser tabs, including Claude, ChatGPT, Gemini, Cursor and Perplexity. The other covers browser-driving agents that can operate a browser on a user's behalf, including Claude in Chrome, Replit and agent tools from ChatGPT and Gemini.

Manifold said its platform is the first able to monitor Claude in Chrome. It added that its browser monitoring follows an AI agent from the initial prompt through tool calls to the final outcome.

What it does

For in-browser assistants, the platform can block denied prompts before they leave the browser, stop access to denied AI sites and enforce rules around the use of corporate accounts. It also records policy breaches in real time and ties them to the user, device and conversation.

Another element focuses on activity rather than prompts alone. Manifold said the system can detect what an AI tool actually did, including which tools it called, where data was sent and which combinations of functions were used. The browser layer also adds connected MCP servers, skills and plug-ins to the same AI inventory used for endpoint activity.

For browser-driving agents, the product monitors actions taken through the browser and applies the same policies and detections used for endpoint agent tool calls. It also creates auditable timelines that reconstruct an agent's activity, including the prompt, each tool call, approval decisions, results and page-level evidence, linked by browser tab and time.

Manifold said the browser support uses the same policy engine, inventory and audit pipeline as its endpoint product, so customers do not need a separate governance layer. Deployment is handled through existing mobile device management tools rather than requiring users to install extensions themselves.

Privacy limits

The extension is restricted in scope. Host access is limited to the AI services it governs, it does not read browsing history and it reads only signed-in account identity data to enforce account policies. Conversation content is not captured unless an organisation explicitly enables prompt capture.

For browser-driving agents such as Claude in Chrome, Manifold said its monitoring uses the same browser access available to the agent itself, and no more. That point may matter to companies weighing the trade-off between governance and employee privacy as AI oversight moves closer to everyday browser activity.

The launch reflects a broader shift in how security teams are approaching AI use in the workplace. Monitoring which tools employees access has become less useful as AI systems increasingly search the web, interact with applications, use authenticated sessions and take actions across external systems.

That has pushed governance beyond simple app inventories towards tracing outcomes and decision paths. Manifold's launch emphasises observing conduct at runtime, especially in the browser, where many mainstream AI tools are now accessed and where more autonomous agent behaviour is beginning to appear.

Manifold was founded in 2025 by the creators of LLM Guard and is based in New York and Berlin. It said it has raised USD $15 million from investors including Costanoa Ventures, Cherry Ventures, Rain Capital and Modern Technical Fund.

Oleksandr Yaremchuk, Co-Founder and CTO of Manifold Security, said: "Security is changing because AI is changing. GPT-6 Astra and the incidents we've seen around autonomous agents, from the Hugging Face breach to agents interacting with external websites, are all pointing in the same direction: AI is no longer just generating an answer. It can take action, make decisions and keep going when nobody is watching. The browser is becoming one of the places where that happens. If an agent can operate through a user's browser, security teams need to know what it accessed, what it did, what it was allowed to do and what happened afterwards. You cannot govern an agent you cannot see. Manifold brings that visibility and control into the browser, using the same policies and audit trail as the rest of the enterprise."

Neal Swaelens, Co-Founder and CEO of Manifold Security, said: "As AI agents move from answering questions to taking actions, the browser is becoming another part of the agent runtime. Security teams need to see what those agents actually do, not just what they were prompted to do. We're bringing that visibility and control to the browser today, with more browser platforms and AI surfaces planned throughout 2026."