Desk Trials

ARCHIVE / Setup & friction

Chrome's extension rules do not mention AI by name

Chrome Web Store's permissions and disclosure policies govern AI sidebar extensions without naming AI, machine learning, or LLMs anywhere in their text.

Preserved retrospective record

Historical source and event dates are not site publication dates. Product plans, policies and availability may have changed since retrieval.

The setup

An AI sidebar or summarizer extension reads the content of nearly every page a user visits and often sends it to a remote model for processing. Whether that is allowed at all is governed not by a dedicated AI policy but by the Chrome Web Store's general program policies on permissions and data handling, read as they stand on 16 September 2026.

What the documents show

Chrome's own Use of Permissions policy, last updated 2022-11-01, states developers must 'request access to the narrowest permissions necessary to implement your Product's features or services,' choosing the least-access option whenever more than one would work. Its Disclosure Requirements, also last updated 2022-11-01, require a developer to 'be transparent in how they handle user data,' to 'prominently disclose what user data will be collected and how it will be used,' to 'obtain the user's affirmative and informed consent for such use,' and to disclose it again if practices change after install. A separate Limited Use policy requires a public link confirming compliance with the store's User Data Policy.

The friction

None of these pages mentions 'AI,' 'artificial intelligence,' or 'machine learning' by name, despite governing the exact category of extension that reads page content and forwards it to a remote model — a gap visible directly in each page's own 'last updated' date, none of which has moved to reflect the current wave of AI browser extensions. That means an AI extension is evaluated against general host-permission and disclosure rules written for a broader category, with no AI-specific bar it has to clear or can point to as having passed.

What changed in the work

For a developer building an AI sidebar or summarizer, the setup work is identical to any extension requesting broad host permissions: justify the narrowest permission set that still works, publish a privacy policy, and disclose data collection and third-party sharing before install, with nothing added or changed specifically because a language model is involved. Editorially, that absence is itself the finding worth flagging to anyone assuming the store enforces something more specific for AI tools than for any other extension that reads a page.

  • Does the extension's privacy policy name that page content is sent to a remote AI model, not just that 'data is processed'?
  • Is the extension requesting access to every site, or only the ones its AI feature actually needs?
  • Would you know if the store added an AI-specific disclosure requirement, given none of today's policy pages mention AI at all?

A missing category in a store policy is not evidence of a gap in enforcement; Chrome's general rules still apply in full. It is evidence that a fast-growing class of extension is currently governed by rules that were not written with it specifically in mind.

Sources & verification

Preserved from the earlier archive. These sources have not all been freshly rechecked for this expansion.

  1. Use of Permissions — Chrome Web Store Program PoliciesSource date: not stated · Retrieved: 2026-09-16

    The narrowest-necessary-permissions requirement that governs how much page content an AI extension may request access to.

  2. Disclosure Requirements — Chrome Web Store Program PoliciesSource date: not stated · Retrieved: 2026-09-16

    The transparency and consent obligations for how an extension discloses collection and use of user data, with a 2022-11-01 last-updated date.

Continue the workflow

  1. Audit knowledge-base access with allowed and denied tests

    A minimum-rights test for a small team that checks both useful access and denied access across a shared knowledge base.

  2. Calculate the total cost of a workflow, not just the subscription

    Compare a manual process and an automated alternative without relying on volatile plan prices.

  3. Run a vendor exit drill before the exit is urgent

    Find out whether a team can leave a workflow vendor without losing data, behavior, access, or business continuity.

  4. Grammarly's generative writing tool shipped switched off by default

    Grammarly's archived 2023 launch page shows GrammarlyGO arrived off by default for Business and Education accounts, gated behind an admin toggle.