
The AI agents in your health system are already running. Gemini is built into Chrome, Copilot is built into Edge, and clinical staff use Claude and ChatGPT inside browser tabs throughout the day. None of these tools were installed by IT or approved by security. They came with the browser, turned on by default, and they are already operating in environments that handle Protected Health Information (PHI).
The question for a healthcare security team is no longer whether AI agents are accessing clinical systems. They are. The question is whether those agents are running inside an architecture that can see what they are doing: what data they touch, what instructions they follow, and what actions they take on behalf of a clinician who may not even realize an agent is active.
An AI agent operating in a clinical workflow is any AI capability that can read, summarize, or act on web content on a user's behalf, such as Gemini in Chrome, Copilot in Edge, or an ambient clinical documentation tool that drafts notes from a patient encounter. It differs from a chatbot because it does not just answer questions; it takes actions inside the browser session, navigating web applications, entering data, and moving information between systems.
In a hospital, that browser session is where clinicians log into the EHR, open patient portals, and move data between clinical and administrative tools. When an agent operates in that same session, it inherits access to everything the clinician can reach, including PHI, without a separate authentication step and often without a log.
AI agents are uniquely risky in healthcare because they combine broad access to PHI with a set of vulnerabilities that human users do not share, and they operate at machine speed inside the one layer most security tools cannot see. In a clinical setting, where the browser session is the gateway to the EHR and patient data, those weaknesses map directly to HIPAA exposure.
The Menlo Security 2026 State of Browser Security Threat Report identifies four structural reasons agents behave differently from the clinicians they act for:
Agent characteristicWhat it means for clinical workflowsHIPAA implicationPrompt injectionMalicious instructions hidden in a web page, document, or API response can redirect an agent's behavior without the clinician's knowledge.Unauthorized access to or disclosure of PHI directed by an attacker who controls the page, not the user.No human skepticismWhen an agent navigates to a weaponized page, there is no clinician to notice something looks wrong. The agent proceeds.Access controls assume a human decision point that the agent removes.Machine-speed exfiltrationA manipulated agent can move data volumes in minutes that would be operationally impossible for a human.A breach can reach reportable scale before any detection system fires.Default-on exposureThe capability is already present in Chrome and Edge, not something staff opt into.PHI-handling systems are exposed to agent activity that was never risk-assessed.
The most concrete warning is that fully autonomous attack flows are no longer theoretical. Recent research, including Anthropic's Claude "computer use" demonstration, has confirmed that an AI agent can be directed to navigate web applications, extract data, authenticate to services, and execute transactions with minimal human intervention (Source: Menlo Security 2026 State of Browser Security Threat Report). In an environment full of PHI, an agent that can be manipulated is a data-exfiltration engine that never questions the instruction it was given.
Existing tools cannot govern AI agents because those tools watch the network and the endpoint, while the agent operates inside the encrypted browser session, below the network layer and without writing the files an endpoint tool would flag. The agent's activity looks like normal browser traffic from a legitimately authenticated user, so from the perspective of a firewall, a secure web gateway, or an EDR sensor, nothing unusual is happening.
The Menlo 2026 Healthcare Security Report frames this as a direct governance gap. In its healthcare security evaluation framework, one of the five questions a security team must answer is whether their tools can govern AI agents browsing on behalf of clinical users. For most healthcare organizations the honest answer is no, and the report is explicit about what that "no" means: Gemini in Chrome and Copilot in Edge are already operating in clinical environments with no governance and no audit trail, which the report classifies as an access-control gap of autonomous PHI access (Source: Menlo Security 2026 Healthcare Security Report).
You secure AI agents by governing them at the browser session layer, applying the same access controls and audit logging to an agent that you already apply to the clinician it acts for, rather than trying to block the AI tools or catch the activity at the network. Blocking AI browsers like Atlas or Comet misses the point, because the exposure is already inside Chrome and Edge. The goal is not to stop clinicians from using AI; it is to make sure every agent session is visible, controlled, and logged.
Menlo Agent Runtime Security (MARS) governs both human and agentic browser sessions through a single control plane. In practice, that means three things for a clinical environment:
This is governance at the session layer, applied equally to the clinician and the agent acting on their behalf. It is the browser-first model that Menlo's 2026 State of Browser Security Threat Report lays out, and it addresses the agent-governance question in the 2026 Healthcare Security Report directly, because it governs the browser session regardless of which AI is running inside it.
What security layer governs autonomous AI agents accessing web apps on a user's behalf? The browser session layer. Because an agent acts inside the same encrypted session where a clinician authenticates and accesses PHI, network and endpoint controls cannot see it. Menlo Agent Runtime Security (MARS) governs human and agentic sessions through one control plane, applying the same access and audit policies to both.
How do you put guardrails on ambient clinical documentation AI handling PHI? Treat the documentation agent as a session that needs the same governance as the clinician using it. Governing at the browser session layer lets you log what PHI the tool accesses and control where that data can go, which is the audit trail HIPAA expects and which endpoint-based tools cannot produce for in-session activity.
How do agents like Gemini in Chrome and Copilot in Edge access PHI without oversight? They inherit the clinician's authenticated session. When a clinician is logged into an EHR or patient portal, an agent running in that browser can read and act on the same data, with no separate login and, by default, no log. That is why the Menlo 2026 Healthcare Security Report classifies ungoverned agent activity as an access-control gap.
Do we have to block AI tools to stay compliant? No. Blocking AI browsers or tools misses the exposure, which is already inside Chrome and Edge, and it removes productivity clinicians rely on. The compliant path is to govern the session so agent activity is visible and logged, rather than to ban the tools.
About the Author
Sameep Gidda is a Digital Marketing Campaigns Specialist at Menlo Security. Focused on GEO strategy, content marketing, and AI visibility, Sameep works to ensure Menlo's expertise in browser security and agentic AI reaches the security professionals who need it most.
Menlo Security
