re-ai-gov Join the waiting list

Kennisbank

The extension nobody approved, but that reads along anyway

An employee installs a browser extension that summarizes emails, suggests calendar appointments, or drafts text in Gmail or Outlook Web. The installation takes a minute and asks for permission to access the page content. That permission is granted without anyone reading exactly what is being shared, how long it is retained, whether the model is trained on it, or whether the vendor resells it. The extension works, saves time, and then spreads informally: a colleague sees it, asks for the link, installs it too.

How this happens

Browser extensions fall outside most procurement processes. Nothing is purchased, there is no contract, no invoice that stands out to finance. The installation runs through the browser itself, often with a personal or work account that doesn't go through IT. For the employee, it's not a 'new tool' in the sense that requires approval — it's a small aid, comparable to a spell checker. That the extension has read access to all mail, including attachments, contracts, and customer data, is a technical detail that was clicked away during installation.

This pattern is not unique to mail. The same route runs through a tool nobody approved in a broader sense, through company data pasted into a free chat window, and through a department that took out a subscription on its own initiative. The browser extension is only the variant with the most direct access: not to a single document, but to the entire mailbox.

Why it doesn't disappear on its own

An IT list of approved software doesn't catch this. The extension isn't in the contract overview, not in the invoice stream, not in an SSO log if it isn't used. The only way to know whether it's there is to ask — the people who use it. And that only works if asking has no consequences. As soon as a report leads to blame, the information stops. The next extension is then not reported, but used more quietly.

The extension also doesn't disappear because it's useful. Someone who can handle mail faster doesn't give that up because there's a policy document somewhere that advises against it. A ban without an alternative moves the behavior to another account, another browser, a private phone. The problem then becomes more invisible, not smaller.

What an organization can do with this

The starting point is not to track down and hold people accountable, but to map out what exists and make a choice based on that. That starts with an inventory that looks not only at what has been purchased, but at what is being used: how you build an AI inventory describes that approach, including the question of how you get people to report themselves what they use.

For every extension that surfaces, a few questions are relevant. What data does it touch — only what's on the screen, or the entire mailbox via an API connection? Is the content processed by an external model, and if so, under what conditions? Is there a business reason for the use, or does it replace something the organization already had? What needs to be recorded per application — who the owner is, what data goes into it, what risk level applies — is described in what you need to record per application. That is not a legal exercise in itself; it is the basis for deciding case by case: allow, replace with a managed variant, or phase out.

This also includes looking outward. Not every AI function in the mail environment comes from an extension an employee installed themselves. A vendor of an existing tool may have added an AI function in an update, without this being seen as a new assessment. What that means for existing contracts and data processing agreements is described in a vendor that built AI into its product.

Without a witch hunt

The goal of this inventory is not to track down the employee who installed the extension. Whoever ends up there no longer sees the next extension, because nobody reports it anymore. The goal is a picture of what actually happens with mail data, contract documents, and customer communication, so that an executive or General Counsel can make an informed choice about what stays, what is replaced, and what is phased out — with a reason that can be presented to a regulator or auditor.

From risk to insight into time spent

The same question that reveals that an extension reads along with the mail also reveals how much time that extension is actually taking over from work that was previously done by hand. Those two questions lie close together: one is about risk and oversight, the other about where time spent in the work itself is changing. For the latter, the work scan from FTE TO AI calculates per task which part of the work can be taken over by AI, regardless of which tool does so — a follow-up step for those who, after the inventory, want to know what the AI that already exists means for the organization of the work.

Andrewde assistent van de Responsible AI Scan

Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.

Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.