
Blog Post
Reading AI Use From the Browser When the Network Sees Nothing
October 3, 2026
A session to a sanctioned AI provider looks the same on the network whichever account it ran under and whatever was in it. Transport encryption means a proxy sees a connection to an approved domain and a payload size.
Which is fine until somebody asks whether an exposure is reportable. The question turns on three facts the network never held, and none of them can be reconstructed from a log afterward.
What Does the Network Record?
Destination and volume, which answer a different question from the one that gets asked.
A firewall or proxy observing encrypted traffic sees that a connection was established with a trusted domain and how much data moved. The pair is enough to answer whether an unsanctioned tool was reached, and it is the whole of what is available without decryption or an endpoint.
Which Makes the Sanctioned Case the Blind One
An unsanctioned destination is visible precisely because the domain is the signal. A sanctioned destination produces an ordinary record, so the traffic pattern most likely to carry a serious exposure is the pattern that looks least interesting, and a personal account inside a sanctioned tool is invisible by construction rather than by oversight.
Which Three Facts Decide Reportability?
Account, content category and action, and the network holds none of them.

- Which account: A corporate identity and a personal one on the same device reach the same domain over the same transport.
- What category of content: Whether the payload contained a sensitive data category, client confidences or a harmless question.
- What action occurred: Whether text was typed, pasted from another document, or a file attached.
Each of those is determined at the moment of the interaction and observable only where the interaction happens, which is inside the browser before anything is encrypted.
Why Can't a Log Reconstruct Them Later?
Because they were never recorded rather than recorded and lost, which is a different problem from a retention shortfall.
A provider's own audit export may show which account made a request and when, subject to the tier and the retention period. It will not show what was pasted versus typed, and it holds nothing at all for a personal account outside the organization's tenancy. So the account question is sometimes answerable afterward and the action question never is.
Which Determines the Response
Establishing whether an exposure is reportable requires knowing what categories of data were involved. Where that was never captured, the organization is left arguing from volume and destination, which is an argument about plausibility rather than a determination, and having no governed record to produce is the position that follows.
What Does the Browser Layer Add?
Classification before encryption, which is the only point in the path where the content and the identity are both present.

Inspection inside the browser reads the interaction before transport encryption applies, so it can determine the category, the account and the action while they are still visible. What leaves the device can be the finding rather than the content, meaning a category flag, a severity, the action taken and a timestamp.
Which Answers the Privacy Objection
Monitoring AI use is frequently read as reading employees' prompts, and it does not have to be. A local classifier producing a category and no content records the fact a reportability question needs while holding nothing a works council would object to, and enforcement at the browser is where that distinction is implemented.
Where Does the Browser Layer Not Reach?
Two places, and stating them prevents the coverage being overclaimed.
A desktop application talking directly to a provider's interface does not pass through a browser. An unmanaged device has no extension on it. So the browser is the right instrument for the portion of AI use that happens in a browser on a managed device, which is most of it and not all of it.
What Covers the Remainder?
Endpoint and network signals, which see that something happened without seeing what. Combining them gives existence from one source and content category from another, and establishing what each source is authoritative for is the exercise that keeps the claim honest.
Does Decryption Solve It Instead?
Partly, at a cost, and the trade is worth stating because it is the usual alternative.
Intercepting the handshake and inspecting the payload centrally gives content visibility without an endpoint deployment. It carries computational overhead, breaks applications that pin certificates, and places the full content in a central inspection point rather than leaving it on the device. Where a local classifier reports a category, a decrypting proxy holds the material itself.
Which Is the Sharper Distinction
Both approaches see the content. They differ in what they retain and where, so the choice is about data handling rather than about visibility, and an organization concerned about holding prompt text centrally has a reason to prefer local classification independent of coverage.
What Should the Browser Layer Record?
Six fields, and the list is short enough to state precisely, which matters because scope creep here is what turns a control into a surveillance objection.
A category identifier for what was detected, a severity, the action taken, a timestamp, the application involved and the employee profile. The six answer which account, what category and what action, and it answers nothing else. Prompt text, message content, form submissions, file contents, attachments and keystrokes are all outside it.
Why Does the Exclusion List Matter?
Because it is the part a works council, a data protection officer or an employee representative will ask about, and an affirmative list of what is never transmitted is a stronger answer than an assurance about intent. A configuration that cannot capture content is different from a policy of not looking at it.
Should Employees See Their Own Findings?
It is the option most likely to make the control acceptable. Where an employee sees the finding raised against their session at the moment it is raised, the mechanism reads as a guardrail rather than an audit, and the same record serves both purposes, which the mechanism by which regulated data arrives suggests is where behavior changes.
What Should Be Established?
Three questions, and the answers are usually already known.
Whether any current source records which account an AI session ran under, rather than which device. Whether any source records the category of data involved, as distinct from the volume. Then what proportion of AI use happens in a browser on a managed device, since that sets what browser-layer coverage would reach. An AI Interaction Data Fabric joins the browser finding to the identity and the destination, which is the combination none of the three sources holds alone.
The Missing Facts Are the Deciding Ones
Encrypted traffic to a sanctioned provider produces an ordinary network record, so the pattern most likely to carry a serious exposure is the one that looks least interesting. Three facts decide whether an exposure is reportable, being which account, which category of data and what action, and the network holds none of them. A provider export may answer the account question afterward, subject to tier and retention, and nothing answers the action question later because it was never recorded. Inspection inside the browser reads the interaction before encryption applies, so a category flag can leave the device while the content stays on it. The coverage limit is also honest, since desktop applications and unmanaged devices sit outside it. Kovrr's AI Interaction Data Fabric joins the browser finding to the identity behind it.
To see which account, category and action sit behind each AI interaction in your environment, book a demo mapped to your own estate.
Browser Visibility FAQs
Speak to an ExpertWhat can a network proxy see about AI use over encrypted traffic?
Destination and volume only. A firewall or proxy observing TLS-encrypted traffic sees that a connection was established with a trusted domain and how much data moved, which is enough to establish whether an unsanctioned tool was reached and is the whole of what is available without decryption or an endpoint agent. The sanctioned case is therefore the blind one, since an approved destination produces an ordinary record.
Which facts decide whether an AI exposure is reportable?
Three, and the network holds none of them. Which account the session ran under, since a corporate identity and a personal one on the same device reach the same domain over the same transport. What category of content was involved, meaning whether the payload contained regulated data, client confidences or a harmless question. And what action occurred, meaning whether text was typed, pasted from another document, or a file attached.
Can provider audit logs reconstruct what was sent to an AI tool?
Partly. A provider's own audit export may show which account made a request and when, subject to the subscription tier and the retention period, so the account question is sometimes answerable afterward. It will not show what was pasted versus typed, and it holds nothing at all for a personal account outside the organization's tenancy, so the action question is never answerable later.
Does browser-based AI monitoring mean reading employees' prompts?
It does not have to. Inspection inside the browser reads the interaction before transport encryption applies, so it can determine the category, the account and the action while they are visible, and what leaves the device can be the finding rather than the content, meaning a category flag, a severity, the action taken and a timestamp. A local classifier records the fact a reportability question needs while holding nothing sensitive centrally.
Where does browser-layer AI visibility not reach?
Two places. A desktop application talking directly to a provider's interface does not pass through a browser, and an unmanaged device has no extension on it. So the browser is the right instrument for the portion of AI use that happens in a browser on a managed device, which is most of it and not all of it, with endpoint and network signals covering existence for the remainder without covering content.
Is TLS decryption an alternative to browser inspection?
Partly, at a cost. Intercepting the handshake and inspecting the payload centrally gives content visibility without an endpoint deployment, and it carries computational overhead, breaks applications that pin certificates, and places the full content in a central inspection point rather than leaving it on the device. Both approaches see the content, so the choice is about what is retained and where rather than about visibility.




