
EU AI Act compliance misses how employees actually use AI. Island's Matt Smith explains why browser-level governance is the missing piece.
European compliance teams are mapping AI systems, classifying risk levels, and building documentation trails the EU AI Act demands. This is serious work. Almost all of it targets AI tools that organisations formally procure and deploy.
The far harder problem, said Matt Smith, Field CTO, EMEA at Island, is governing how employees actually use AI in real time. Most employees access generative tools, coding assistants, and autonomous agentic AI through a browser tab. Sensitive business data moves into these tools routinely. Often there is no awareness of where that data is retained or who can access it.
Regulation is starting to catch up. The EU AI Act is the most significant attempt yet to place formal obligations around transparency, auditability, and data handling. Some headline deadlines have slipped, reflecting the difficulty of governing AI in practice. The compliance questions it raises -- who uses which AI tools, what data they handle, how to demonstrate oversight -- are ones every board should be asking, Smith said. Most organisations cannot answer them.
Compliance efforts cover approved and procured AI systems. They rarely account for the shadow AI problem: unsanctioned tools employees adopt independently, accessed through a browser session that leaves no audit trail and sits outside most security architectures. Agentic AI tools -- those that take actions autonomously rather than responding to prompts -- make this more urgent. They move data at speed and scale that makes after-the-fact detection redundant.
To understand the governance gap, Smith said, look at how the working day has changed. For most employees, the browser is no longer just a tool for accessing work. It is where work happens. SaaS platforms, cloud collaboration tools, financial systems, HR applications, and AI tools all live inside browser tabs.
Security architecture has not made the same journey. The controls most organisations depend on were built for a world of corporate networks, managed devices, and applications sitting behind a firewall. That model does not reflect reality. It still underpins how most businesses approach security. The result is a blind spot: most controls establish whether a user is permitted to reach an application, Smith said. They have no view of what happens once the user is inside it.
That gap matters beyond compliance. When an employee copies a customer record into a personal email, pastes financial data into an external AI platform, or downloads a sensitive report to an unmanaged device, none of those actions triggers an alert. The access was authorised. The behaviour was not governed.
Organisations have responded by adding tools -- data loss prevention solutions, cloud access security brokers, virtual desktop infrastructure, VPN layers. Each addresses a specific gap. Together they form a stack that is expensive to run, difficult to manage, and still leaves the browser session itself largely ungoverned, Smith said. The problem was not a shortage of tools. It was building on the wrong foundation.
The logical response to a governance gap that lives inside the browser is to move the enforcement layer there too. Not as another tool added to an already crowded stack. A fundamental shift in where security operates. An enterprise platform that governs all browser activity embeds governance directly into the workspace, including an enterprise browser built for organisational use and consumer browsers through a browser extension.
Real-time controls apply at the presentation layer, between the screen and the end user. A file downloaded to a personal device, a paste action directed at an unsanctioned AI tool, a screenshot of confidential data -- these become governable in real time without disrupting legitimate work, Smith said.
This changes what zero trust can deliver in practice. Most implementations check identity once at login and apply fixed controls from there. An endpoint-native model assesses session context throughout the working day, adjusting policy as circumstances change. The user's role, the data in motion, the tools being accessed, the device in use all inform what is permitted at any given moment.
For governance obligations that AI adoption creates, this visibility is critical, Smith said. Security and compliance teams can see which AI tools are in use across the organisation, what data is being shared with them, and enforce policy accordingly. They build the audit trail that regulators are beginning to require.
Hybrid working and personal device use fit naturally into this model. Organisational data is fully governed. Personal browsing remains genuinely private. The long-standing tension between employee privacy and organisational oversight resolves without either side conceding ground.
The question European boards should be asking is not which AI tools their organisation has approved, Smith said. It is whether they have visibility into how AI is used across the working day, by whom, and with what data. For most organisations, the honest answer is no.
Regulation is creating pressure to change that. The stronger argument is practical. Organisations carrying the cost and complexity of a sprawling security stack while still lacking governance at the point where risk materialises are neither well protected nor well positioned. The foundation needs to move to where work has already moved.
For most organisations, that journey starts with the browser.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.