The situation
You have sold AI governance to twelve clients. Four run Microsoft 365 with Intune. Three are on Google Workspace. Two still have an on-premises Active Directory domain, one of them with a handful of Macs in the design team. The rest are small offices where half the staff use Firefox because they always have. Every one of them needs the same browser control installed, configured for their own policies, and impossible for a busy employee to switch off.
Doing this by hand does not survive the first month. Users skip the install prompt, new hires start without it, and someone disables it the first time it interrupts them. The control has to arrive through the same browser management you already use for everything else, with a separate, documented configuration for each client. If you are still designing the offering itself, see adding an AI governance service line.
What the rules actually say
Here the rules are the browser vendors' own enterprise policies. All three major browsers document a way to install an extension silently and prevent users from removing it.
- Google Chrome. The ExtensionSettings policy controls extension management and overrides the older ExtensionInstallForcelist policy. Setting installation_mode to force_installed installs the extension without user interaction, and users cannot disable or remove it. It can be set by Windows Group Policy, and browsers enrolled in Chrome Enterprise Core can receive policies from the Google Admin console, with enrollment tokens that place a browser directly into a chosen organizational unit.
- Microsoft Edge. The ExtensionInstallForcelist policy installs listed extensions silently, and users cannot uninstall or turn them off. Edge also supports the same ExtensionSettings approach, with force_installed and an update URL pointing at the Microsoft Edge Add-ons site or the Chrome Web Store. Both can be set through Group Policy or, on Windows, through an Intune Settings Catalog profile assigned to Microsoft Entra groups.
- Mozilla Firefox. Firefox's ExtensionSettings policy has a force_installed mode that installs the extension and prevents the user from removing it. It can be delivered through a policies.json file, Windows Group Policy or macOS configuration profiles.
Three details matter for planning. First, the force-install policies in Chrome and Edge do not apply to Incognito or InPrivate windows, which both browsers can turn off by policy. Firefox lets an administrator allow a specific extension in private windows through the private_browsing setting in ExtensionSettings (Firefox 136 and later). Second, on Windows devices that are not joined to a domain (or, for Chrome, enrolled in Chrome Enterprise Core), Chrome and Edge limit forced installation to extensions listed in their own stores. Third, Chrome notes that on some operating systems its protection against removal is best efforts, so status needs checking, not assuming.
Why policies and bans fall short
A written rule that says "use only the managed browser" is not enforcement. Neither is a network block on AI sites: it stops at the office firewall, not at the laptop on a home network.
Manual installation fails at scale for the reasons above, and the softer normal_installed mode, which installs automatically but lets users disable the extension, invites exactly the behaviour you are trying to prevent. The point of the control is to act before content is submitted, because once it reaches a public AI tool it cannot be recalled. A control that a user can turn off at the moment of pressure provides little assurance.
Finally, be honest about scope. Browser policies reach managed browsers. A personal phone, a personal laptop, or an unsupported browser on a managed machine is outside that reach. Clients deserve to hear that from you before they hear it from an auditor. For the personal-account side of the problem, see interns and personal AI accounts.
What a practical control looks like
- Build one template per client. For each client, record which browsers are in use, which management tool reaches them, the extension's install settings for each browser, and that client's detection policies. Keep the template in your documentation system and the live configuration in the client's environment.
- Keep tenancy separate. Configure each client inside its own Intune tenant, Google Admin console or domain, through delegated administrator access. Never place two clients' devices in one policy scope, and name policies with the client and version so an audit trail is readable.
- Roll out in rings. Start with IT staff and one willing team, then one department, then everyone. Assign rings with Entra groups or organizational units so each step is a group change, not a new policy. Confirm policy status on sample devices at each step, for example on the chrome://policy page.
- Close the side doors. Decide per client whether to turn off private browsing, whether to block browsers the extension does not support, and whether work applications should require a managed device or browser.
- Document the gaps. Write down what is out of scope, such as personal devices and unsupported browsers, and have the client acknowledge it in the service agreement and in its AI policy.
- Tell staff. Announce the control before it arrives, including what it records and what it does not. Ontario clients with 25 or more employees should check with counsel whether it belongs in their written electronic monitoring policy.
- Check monthly. Compare managed-browser counts against devices reporting events, and chase the difference. Coverage belongs in the monthly client report.
Sanitized Ai deploys as a browser extension through the same browser management tools: Chrome, Edge and Firefox, installed by the policies described above, with no network changes. Once installed, it detects sensitive data in AI prompts and file uploads and redacts or blocks it before submission, with a plain-language explanation to the person about what was flagged and why. Administrators see flagged-event metadata (which tool, what type of data, which policy, when) and never prompt content. Confirm the current installation details for each browser with the Sanitized Ai team when you build your client templates, through the intake form.