2.95 (L1) Ensure 'Allow pages to use the built-in AI APIs' is set to 'Disabled'

Information

This setting controls whether external websites can access Chrome's built-in AI APIs, such as the LanguageModel, Summarization, Writer, and Rewriter APIs. Disabling this policy blocks web pages from accessing the browser's integrated generative AI engines to process or generate text.

Chrome's built-in AI APIs allow any website to invoke local or cloud-assisted AI models directly through the browser architecture. Leaving this enabled grants third-party web scripts the ability to pipe local page data, user inputs, or clipboard content into an AI processor without the user's explicit consent. Disabling these APIs shuts down a covert channel where malicious or compromised sites could abuse the browser's AI engine to rewrite content, summarize secure internal documents, or interact with sensitive data via unauthorized prompt manipulation.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Allow pages to use the built-in AI APIs

Impact:

Web applications that rely on Chrome's native AI APIs for in-page translation, text generation, or automated document summarization will break and return errors when attempting to call these specific functions.

See Also

https://workbench.cisecurity.org/benchmarks/23110

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-6(9), 800-53|AU-2, 800-53|AU-12, 800-53|CM-10, 800-53|SC-18, CSCv7|7.1, CSCv7|13.3

Plugin: Windows

Control ID: 7db6437078322eacb33db8f7bc2e5695393e61f69e4f65bf3d3b6726e6a261cc