AI Browser Security Risks: What to Know and What to Do
AI browsers can follow hidden commands and act inside your logged-in accounts. See the real attacks, Gartner's advice to block them, and how to respond.
AI browsers can follow hidden commands and act inside your logged-in accounts. See the real attacks, Gartner's advice to block them, and how to respond.
AI browser security is the work of controlling a browser that can read pages, click, and act for you. These browsers can fall for hidden instructions on websites, and they can reach every account you are signed in to. In December 2025, Gartner told companies to block them for now. So if you cannot block them, limit pilots to low-risk tasks.
Table of Contents
ToggleA normal browser shows you a page and waits. An AI browser reads the page for you. Many have two parts. The first is a sidebar that summarizes pages and answers questions. The second is an agent mode that clicks, fills in forms, and finishes tasks on its own.
Examples include Perplexity’s Comet, OpenAI’s ChatGPT Atlas, and Fellou. Each one also runs inside your signed-in sessions. That means it can see your email, your banking, and your work apps, because you already logged in. So the browser is no longer just a window. It is a worker with your keys.
A chatbot only answers questions. In contrast, an AI browser takes actions, and it reads untrusted content all day. Three things come together: private data in your sessions, untrusted pages from the open web, and the power to send or click. Security researchers call this mix a lethal trifecta. Remove one part, and most attacks lose their payoff. An AI browser has all three by design.
The core flaw is simple. A language model reads commands and page text through the same channel. A hidden line on a website can therefore look like an order from you. This weakness is ranked first on the OWASP list of LLM risks, and no current model fully fixes it. Defenders must assume some hidden commands will work. That is why zero trust security matters here: never treat a session, or a page, as safe just because it loaded.
Discover how Threatcop protects your workforce from modern cyber threats.
So these are real findings about AI browsers, not predictions. Each one is a prompt injection attack, and together they show a pattern across the whole category.
In August 2025, Brave researchers showed that Perplexity’s Comet could follow attacker commands hidden in a public Reddit post. A user only had to ask the browser to summarize the page. In October 2025, Brave published more findings. Faint light-blue text on a yellow background was nearly invisible to people. Yet Comet’s text recognition read it from a screenshot and obeyed it. Brave also got the Fellou browser to follow hidden commands just by visiting a page.
Brave called this a systemic challenge for the whole category of AI browsers. Perplexity patched the flaw but disputed how Brave described it. Still, the pattern stands. Any page, image, or comment can carry a command.
Then, two days after OpenAI launched Atlas, researchers showed it could be fooled the same way. The Register repeated one of the attacks. OpenAI’s security chief, Dane Stuckey, said prompt injection remains a frontier, unsolved security problem. Another team, NeuralTrust, found that a poisoned link pasted into Atlas’s address bar could be treated as a command. LayerX described a related Comet attack, called CometJacking, that used a booby-trapped URL.
Links have always been a favorite attacker tool, because people trust them. The anatomy of a phishing scam starts with a link people trust. AI browsers now click such links for you, and they do it fast.
In December 2025, Gartner analysts Dennis Xu, Evgeny Mirolyubov, and John Watts published an advisory titled “Cybersecurity Must Block AI Browsers for Now.” As reported by The Register, they urged organizations to block all AI browsers for the foreseeable future.
They gave several reasons. First, sidebars often send page content, browsing history, and open tabs to a cloud back end. Second, agent modes can be tricked by hidden commands, make wrong choices on their own, or lose credentials by landing on a phishing site. Third, default settings favor convenience over security. The analysts also noted that employees might hand boring tasks to an AI browser, including mandatory security training.
Companies that want to experiment should keep pilots small. Gartner advised limiting them to low-risk tasks that are easy to check and easy to roll back. Some critics reply that a ban alone will not hold, because agent features are spreading into many other tools. That is fair. It means the real work is a risk assessment, not a single block rule.
Pick one of three paths, and write it down. Then tell staff which one applies.
Block by default. Use network and endpoint controls to stop installs. Then name AI browsers in your workplace security policy, so staff know the rule and the reason. A rule nobody can find will not be followed.
Pilot with limits. Choose a small group and low-risk tasks. Use a separate browser profile with no access to email, banking, or admin consoles. Turn on logged-out mode where the vendor offers it, and switch off history and memory. Require a person to approve any purchase, message, or file share. Review logs weekly.
Allow with controls. Only consider this after the pilot. Manage the browser centrally, keep a short approved list, and watch for strange behavior. Also look for AI browsers that staff installed on their own. Endpoint tools, such as data loss prevention, can flag sensitive data heading to unapproved AI services.
Whichever path you pick, review it each quarter, because the products change fast.
If you run a pilot, decide in advance what to record. Log which sites the agent visited, which actions it took, and which data left the browser. Also record every time a person had to step in. After 30 days, compare those notes with the goals you set. If the browser caused one serious surprise, pause the pilot and review the rules before you continue.
Policy works only when people understand it, so keep the message short and concrete.
Role-based security awareness training helps here, because finance, HR, and IT face different risks. Make reporting easy and blame-free, since staff often notice something is wrong before any tool does.
AI browsers promise speed, but they combine your sessions, the open web, and the power to act. Until vendors prove better controls, treat them as high-risk tools. Block them by default, pilot with strict limits, and teach people what to watch for. A one-click reporting workflow gives staff a fast way to flag anything strange.
An AI browser is a web browser with a built-in AI assistant. Many include a sidebar that summarizes pages and an agent mode that clicks and completes tasks for you. Perplexity’s Comet and OpenAI’s ChatGPT Atlas are well-known examples.
Not yet, according to Gartner. Its analysts advised blocking AI browsers for now. They cited data sent to the cloud, hidden-command attacks, and risky default settings. Companies that test them should use small, low-risk pilots.
Indirect prompt injection hides commands inside content an AI browser reads, such as a web page, image, or comment. The AI browser may then follow the attacker’s text instead of yours. Brave showed this against several AI browsers.
Many security teams do, at least for now. Blocking buys time while you assess the risk through a simple information security risk management process. However, a ban is not enough on its own. Update your policy, watch for shadow installs, and plan how you will handle approved pilots.
First, use a separate profile with no work accounts. Next, stay logged out where possible, and turn off history and memory. Require your approval before any purchase or message. Also avoid using it for banking or admin tasks.
Arpit Rao is a Product Manager at Kratikal, bringing a strong technical foundation and experience in building and managing cybersecurity products. His work spans product strategy, technology, user experience, and solving complex customer challenges. With a focus on translating technical capabilities into practical solutions, Arpit is interested in cybersecurity, AI, product innovation, and user-centric technology. He works on creating products that address evolving security and business needs.
Arpit Rao is a Product Manager at Kratikal, bringing a strong technical foundation and experience in building and managing cybersecurity products. His work spans product strategy, technology, user experience, and solving complex customer challenges. With a focus on translating technical capabilities into practical solutions, Arpit is interested in cybersecurity, AI, product innovation, and user-centric technology. He works on creating products that address evolving security and business needs.
Blocking AI backfires. Learn six steps to secure AI adoption: inventory, tiers, vendor review, limited pilots, role-based training, and...
Prompt injection turns any text an AI agent reads into a possible command. See the EchoLeak case, the lethal...
AI makes scams more personal and moves them across email, chat, and video. See the Arup deepfake case and...
Table of Contents
×