Your browser can now do more than show you web pages. A new category called agentic browsers can click, fill out forms, compare prices, and complete purchases on your behalf, working through websites the same way a person would. It sounds like a small evolution of autocomplete. Security researchers who spent this summer testing these tools found something that should change how carefully you use them.
WHAT THESE BROWSERS ACTUALLY DO
Tools like Perplexity Comet, Opera Neon, and the AI features now built into Chrome and Edge let you type a plain instruction such as book me a flight next Friday under 300 dollars, and the browser goes and does it, clicking through booking sites and filling in your details without you touching each page yourself. This extends into shopping too, where an agent can monitor prices across retailers and complete a purchase automatically once conditions you set are met, a pattern the industry has started calling zero click commerce. For anyone who finds booking sites and long checkout forms tedious, the appeal is obvious.
THE LANDSCAPE JUST SHIFTED, WHICH IS PART OF WHY THIS IS CONFUSING
If the list of tools above feels different from what you read a few months ago, that is not your memory playing tricks. OpenAI is retiring its standalone ChatGPT Atlas browser, with the shutdown landing on August 9, 2026, folding the same agentic features into the regular ChatGPT desktop app and a Chrome extension instead of a separate browser. Chrome added automatic browsing on Android in late June. Microsoft folded its Copilot browsing features directly into Edge rather than keeping them as a separate branded mode. This is a genuinely fast moving space, and a tool you tried and dismissed a few months ago may already work quite differently now.
THE SECURITY PROBLEM NOBODY ADVERTISES
At Black Hat USA 2026, one of the security industry’s largest annual conferences, Brave’s security engineer Artem Chaikin presented a session testing exactly how well these agentic browsers hold up against attack. He tested Opera’s AI browser, Perplexity Comet, and ChatGPT Atlas. Every single one he tested turned out to be vulnerable to the same type of attack.
Here is what that attack actually looks like in plain terms. An AI browser reads everything on a page it visits as potential instructions, not just the visible text a human would read. An attacker can hide a second set of instructions inside a page, using white text on a white background or other invisible formatting, and the AI agent has no reliable way to tell that hidden text apart from a legitimate command you typed yourself. Ask the browser to simply summarize a page, and if that page contains hidden instructions telling the agent to open your email and forward a one time password, or to visit your banking portal, the agent may follow those instructions too, using your own login access to do it. Security researchers call this prompt injection, and it has been documented working against real, widely used tools, not just in a lab setting.
WHAT THIS MEANS FOR YOU IN PRACTICE
This does not mean agentic browsers are unsafe to use at all, but it does mean the sensible level of trust is lower than the marketing suggests. Treat an AI browser the way you would treat a capable but very literal assistant who has never learned to be suspicious of instructions, rather than as a trusted extension of yourself. Avoid connecting one to accounts that hold real money or sensitive personal data until you understand what permissions it actually has, and check whether the tool you are using offers tiered permissions that limit what it can do without your direct confirmation for anything involving payment or account changes.
This kind of healthy skepticism toward new AI tools is worth building generally, not just for browsers. We cover a related angle in our guide to spotting deepfakes and manipulated video, and the same instinct, checking rather than assuming a tool is trustworthy by default, applies directly here. If you are already careful about whether your phone is quietly tracking you or whether public wifi is actually safe to use, an agentic browser with account access deserves at least that same level of caution.
SHOULD YOU ACTUALLY USE ONE
For low stakes tasks, research, comparing products, summarizing long pages, an agentic browser is genuinely useful and the risk is minimal, since there is little of value for an attacker to steal. The caution matters most once you connect the tool to anything involving money, personal identification, or accounts you would not want a stranger accessing. Until the security research catches up with the feature set, a reasonable middle ground is using these tools for convenience tasks while keeping banking, healthcare, and anything involving stored payment details out of their reach for now.
FREQUENTLY ASKED QUESTIONS
- WHAT IS PROMPT INJECTION IN SIMPLE TERMS?
It is when an attacker hides instructions inside a webpage that an AI agent reads and follows as if you had typed them yourself, even though you never saw or approved them. - IS ANY AI BROWSER COMPLETELY SAFE FROM THIS?
As of the most recent public testing at Black Hat USA 2026, no major agentic browser tested was fully immune, including Opera, Perplexity Comet, and ChatGPT Atlas. Companies are actively working on defenses, but researchers describe this as an ongoing challenge rather than a solved problem. - WHAT HAPPENED TO CHATGPT ATLAS?
OpenAI is retiring the standalone Atlas browser, with the shutdown set for August 9, 2026, and moving its agentic browsing features into the main ChatGPT desktop app and a Chrome extension instead.
The convenience these tools offer is real, and the category is only going to grow from here. The sensible approach right now is using them where a mistake costs you nothing serious, and staying hands on anywhere a hidden instruction could actually cost you something.

Leave A Comment