Skip to content
redactsure
Book a demo

Explore.

Explainer · By Chris Sowa · Published
Last updated

Should an AI Agent Run in the Employee's Own Browser or Computer?

Avoid giving an agent an employee's unrestricted browser session for regulated work. Use a dedicated environment with explicit access and input controls, then verify what the model receives from each sensitive screen.

A browser full of folders connects through a narrow bridge to a separate browser containing one selected task folder.

Avoid giving an agent an employee's unrestricted browser session for regulated work. Use a dedicated environment with explicit access and input controls, then verify what the model receives from each sensitive screen. Desktop and browser agents can encounter records through sessions the employee already opened. Their reach depends on permissions, selected tabs and administrator settings, so it is not accurate to assume every session is automatically available. A separate profile reduces that reach; it still needs a policy for the fields passed to the model on an allowed page. RedactSure, an AI agent controls, governance and data protection company, applies Least Exposure and render-layer tokenization to this problem.

Key findings

What do the 2026 agents run on?

Three designs are on the market as of September 30, 2026. ChatGPT Work runs on the employee's desktop: a built-in browser and Computer Use that operates the machine across applications. It adds admin spend limits, a Compliance API and Auto-review of significant actions, per PPC Land. Claude in Chrome runs inside the employee's real Chrome as an extension and takes screenshots of the active tab. Organizations can set allowlists and blocklists and choose automatic or manual approval of actions. OpenAI Dots and Meta Muse run in a cloud computer the vendor operates and read page content within its permitted access there; the Dots page and the Muse page cover both. The three differ in where the screen is rendered and who owns the machine. They do not differ in what the model receives: the page as the user would see it, minus the credentials the vendor's sign-in flow keeps out.

What does an agent inherit from the user's session?

Everything the session carries. A screenshot of the active tab includes every field the tab shows; What Does an AI Agent See When It Takes a Screenshot? walks one field by field. Computer Use on the desktop extends the surface from the tab to the machine: other windows, files, the clipboard.

The sessions come with the screen. An employee's browser profile holds signed-in sessions to the claims platform, the EHR, the student information system, payroll and email. An agent in that profile may use existing sign-ins on sites its permissions allow, subject to the agent's own controls. The application logs show the employee. Least privilege was written for the user; it constrains the human, and the human's screen is what the agent reads. An adjuster who legitimately sees the claimant's SSN has an agent that sees it as well. Does Least Privilege Cover What the AI Sees? sets out why the answer is no.

What do the vendors themselves say?

Anthropic's guidance advises users to "avoid opening the extension while viewing sensitive information or documents." It suggests a separate browser profile for sensitive accounts and gives organizations allowlists and blocklists. The permissions guide covers what the extension may access. OpenAI's help center describes ChatGPT agent as seeing web pages via screenshots. It lists watch mode on certain sites, confirmations for high-impact actions, injection monitoring, and a takeover mode for logins during which screenshots are not captured.

The two vendors describe the same shape: strong controls on what the agent does, a screenshot as what it sees, and advice to keep it away from sensitive screens. A vendor that tells the customer not to open its agent near sensitive information has described the limit of the design. A regulated workflow is sensitive information from the first screen.

Does a separate browser profile fix it?

It moves the problem. A separate profile holds fewer sessions, so the agent inherits less. The claims platform is still in it, because that is where the work is. The profile still renders the record, the screenshot still captures the render, and the model still receives the claimant's name and SSN on every screen the task opens. Enterprise Browser vs Render-Layer Tokenization covers the same limit in managed-browser products. Those products govern where the page can go rather than what the model receives.

What does a governed environment change?

Three things. The agent is tethered: it works only inside the environment a named person connected it to, on the applications that person chose. It holds no session the employee's own browser holds, which is what a tethered agent means. The environment tokenizes at the render layer: every sensitive value chosen by policy becomes a consistent token, SSN_001, PATIENT_001, STUDENT_001, before any model reads the screen. The model receives the task's fields rather than a picture. The record is the environment's: every screen as tokens, every action and every approval with a name lands in the AI Control Record and exports to the employer's SIEM. The employee is still there, watching, pausing and taking over the same tokenized stream. The employee approves every consequential action under existing permissions. Does an AI Agent Need Its Own Virtual Machine? covers why the environment is a machine rather than a plugin.

In a claims system, the adjuster's browser shows the claimant's name, SSN, bank account and, in an injury claim, provider notes. The insurer's data-security program is expected to limit nonpublic information to what a task needs; the Guidewire page shows the same screens as tokens. In an EHR, the nurse's screen shows the patient's name, MRN and full chart. The minimum necessary standard at 45 CFR 164.502(b) limits PHI to what the purpose requires; the Epic page walks the alternative. In a student information system, the registrar's screen shows the student's name, ID, grades and discipline record. FERPA's school official exception at 34 CFR 99.31(a)(1)(i)(B) requires the contractor to be under the school's direct control over those records. The district must establish that control through the agreement and the configured service; the PowerSchool page shows STUDENT_001. A screen showing a card number brings the machine that renders it into PCI DSS scope; the cardholder page takes that up.

Which of the three places should the agent run in?

Control Agent in the employee's browser or desktop Agent in a vendor cloud computer (Dots, Muse) Agent in a customer-owned governed environment (RedactSure)
What the model receives Screenshots of the tab or desktop, in full Page content within its permitted access, in the vendor's browser The task's fields, identifiers as tokens
Sessions inherited Sessions reachable under the agent's permissions The sessions the user connects Only the applications a named person connected
Who decides what it sees The employee, by what they open The user, per connection and rule The Planner; a named person confirms per task
Record Vendor's log, plus application logs showing the employee Vendor's activity view AI Control Record, exported to the customer's SIEM
Keys The employee's device and the vendor's service The vendor, by policy or undisclosed Customer-held; RedactSure holds ciphertext it cannot decrypt
Injection collects The page and every inherited session The page, credentials excepted Policy-selected values are tokens; consequential actions require approval

Where does RedactSure sit?

RedactSure's environment is the third column. It takes the agent off the employee's machine and out of the employee's sessions. AI co-workers do real work across an organization's applications inside a governed environment, with no per-application integration and no change to user permissions. Every sensitive value chosen by policy is replaced by a consistent token at the render layer before any model reads the screen. The model receives the task's fields rather than a picture of the screen. Amounts, dates, codes and the clinical or coverage facts the work runs on stay in clear where the policy says so. The Planner sets which values are tokenized and what the agent may do on each screen. A named person confirms that policy and approves every payment, submission and record change while it runs, which is Supervised Delegation.

What the employer avoids is an agent that inherits the visible screen content and signed-in sessions permitted to the agent. On the employee's machine, one prompt injection on one open tab can put the data and actions reachable in that session at risk. Inside the environment, a successful injection can expose tokens and any remaining task context, and the consequential action still stops for a named person. Every screen as tokens, every action and every approval lands in the AI Control Record and exports to the customer's SIEM. The environment is a secure virtual machine in the cloud the customer's posture requires, with keys the customer holds, and it works with any model. Deployments are in pilot.

Methodology and limitations

The HIPAA minimum necessary standard has exceptions, including certain treatment disclosures. Its application depends on the purpose and parties. Replacing direct identifiers does not by itself establish HIPAA de-identification or remove all PHI from the remaining context.

The vendor sources are OpenAI's help article "ChatGPT agent" and Anthropic's "Use Claude in Chrome safely" and "Claude in Chrome permissions guide," read as of September 30, 2026. The ChatGPT Work launch is taken from PPC Land's July 2026 report and cited as press. Regulation is cited from the text of 45 CFR 164.502(b), 34 CFR 99.31(a)(1)(i)(B) and the PCI SSC scoping guidance. Case law and enforcement actions are not surveyed. Vendor documentation is cited with their dates; where it is silent, the page says so rather than inferring.

No hands-on testing of ChatGPT Work, ChatGPT agent or Claude in Chrome was performed; the workflow examples are architectural inferences from the cited documents, not captured model requests. Anthropic's figure of attack success under 0.08% is its internal result, treated as the vendor's own claim. The help articles do not state the key holder, screenshot retention or the export path of the Compliance API. Enterprise terms that were not available could address them. The help articles carry no publication date of their own. Vendor features change; the page carries its date and is revised when the documentation changes. The claims, chart, student record and card examples describe record types, not any specific organization; no customer or prospect is described.

Whether a deployment meets the minimum necessary standard, FERPA's direct control condition or PCI DSS scope belongs to the organization's counsel, assessor or compliance officer, not to this page.

We did not run the vendor products or capture their model requests. Workflow examples are analysis, and RedactSure behavior is described from its current design.

What the record shows

Avoid giving an agent an employee's unrestricted browser session for regulated work. Use a dedicated environment with explicit access and input controls, then verify what the model receives from each sensitive screen. Compare a dedicated session with the employee profile using synthetic records. Check both the reachable applications and the fields in the model input.

Frequently asked questions

Is Claude in Chrome safe on a claims screen?

Anthropic's own guidance is to avoid opening the extension while viewing sensitive information or documents. A claims screen is sensitive information: the claimant's name, SSN, bank account and, in an injury claim, medical detail, all captured in the screenshot the agent works from. Anthropic's classifiers and approval settings govern what the agent does with that screen, not what it reads. RedactSure replaces those values with tokens before any model reads the screen.

What does ChatGPT Work's Computer Use see?

Computer Use operates the person's computer across applications, "clicking, typing, and moving files," and ChatGPT agent sees web pages via screenshots, per OpenAI's documentation. On the desktop that is the active application and whatever else is visible; screenshots pause only during a user takeover for logins. The Compliance API gives an admin visibility afterward, not a change in what the model received.

Does a separate browser profile fix it?

It reduces the sessions the agent inherits, which shrinks what a bad action or a successful injection can reach, and Anthropic suggests it for sensitive accounts. It does not change what the model receives from the record the task is about, because the profile still renders that record and the screenshot still captures it. The regulator's question is about the record.

Is a vendor cloud computer better than the employee's machine?

On one axis, yes: the agent no longer inherits every session on the employee's device, and the vendor's design isolates each user's computer. On the axes a regulated buyer asks about, the page is still read in full, the record lives in the vendor's app, and the keys are the vendor's. It is a smaller surface in the same design, not a different design. RedactSure's environment is the different design: the customer owns the machine, the keys and the record.

What does the employee see inside a governed environment?

The same tokenized stream the agent sees: SSN_001 where the SSN is, PATIENT_001 where the name is, amounts and dates in clear where the policy says so. The operator can watch, pause and take over the run, and approves every consequential action with their name on the record. In the application itself, outside the environment, the employee's view is unchanged.

Does this change the employee's permissions?

No. Permissions stay exactly as they are; an adjuster, a nurse or a registrar with access to a full record keeps it. What changes is what the AI can see. The environment decides, per task and before any model reads the screen, which values reach the model as tokens. A named person confirms that decision.

Sources

Vendor documentation

  1. OpenAI Help Center, "ChatGPT agent." https://help.openai.com/en/articles/11752874-chatgpt-agent
  2. Claude Help Center, "Use Claude in Chrome safely." https://support.claude.com/en/articles/12902428-use-claude-in-chrome-safely
  3. Claude Help Center, "Claude in Chrome permissions guide." https://support.claude.com/en/articles/12902446-claude-in-chrome-permissions-guide

Regulation and standards

  1. 45 CFR 164.502, minimum necessary standard. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.502
  2. 34 CFR 99.31, FERPA school official exception. https://www.ecfr.gov/current/title-34/subtitle-A/part-99/subpart-D/section-99.31
  3. PCI Security Standards Council, "Guidance for PCI DSS Scoping and Network Segmentation." https://www.pcisecuritystandards.org/documents/Guidance-PCI-DSS-Scoping-and-Segmentation_v1.pdf

Independent analysis and press

  1. PPC Land, "OpenAI kills Atlas browser, folds it into new ChatGPT Work agent" (July 2026). https://ppc.land/openai-kills-atlas-browser-folds-it-into-new-chatgpt-work-agent/

RedactSure documents

  1. RedactSure, "The Two Gaps AI Agents Opened in Your Security Stack" (2026). https://redactsure.com/blog/two-gaps-ai-agents-opened-in-your-security-stack/
  2. RedactSure, "Accountable AI and Workflow Governance" (2026). https://redactsure.com/blog/accountable-ai-and-workflow-governance/
  3. RedactSure, "Your AI Strategy Is Probably Wrong" (2026). https://redactsure.com/blog/your-ai-strategy-is-probably-wrong/
  4. RedactSure Research, "Does an AI Agent Need Its Own Virtual Machine?" (2026). https://redactsure.com/research/does-an-ai-agent-need-its-own-virtual-machine
  5. RedactSure Research, "What Is Least Exposure?" (2026). https://redactsure.com/research/what-is-least-exposure
  6. RedactSure Research, "What Is Render-Layer Tokenization?" (2026). https://redactsure.com/research/what-is-render-layer-tokenization
  7. RedactSure Research, "What Is Supervised Delegation?" (2026). https://redactsure.com/research/what-is-supervised-delegation
  8. RedactSure Research, "What Is an AI Control Record?" (2026). https://redactsure.com/research/what-is-an-ai-control-record
  9. Product behavior described on this page reflects RedactSure's current design. OpenAI, ChatGPT and Dots are trademarks of OpenAI; Claude is a trademark of Anthropic; Chrome is a trademark of Google LLC; Meta and Muse are trademarks of Meta Platforms, Inc.; named to identify the product. Compliance determinations belong to the organization's counsel.

See it on your workflow.

Bring one billing, collections, claims or patient-account workflow and your questions.

Book a demo

Book a demo

Having trouble? Open the booking page or email us.