The cybersecurity landscape is changing at a pace we haven’t experienced since the dawn of cloud computing. The newest disruptor, the rise of AI browsers such as Perplexity Comet and OpenAI’s ChatGPT Atlas, promises to revolutionize user interaction with the web. But behind the innovation lies a long list of risks that enterprises cannot afford to ignore.
At Obrela, where our mission is to keep your business in business by making cybersecurity predictable, we view AI browsers as an emerging capability with immense potential, yet carrying dangers significant enough to warrant a firm, caution-first stance.
Traditional browsers are passive windows into the internet. AI browsers, however, are active participants.
We are witnessing a shift from direct manipulation to Agentic AI. This transforms the browser from a tool you use into a worker you command. When a user tells an AI browser to "Book a flight" or "Summarize my emails," the browser autonomously navigates portals, parses DOM elements, fills forms, and submits transactions.
This capability, known as agentic transactions, creates a "Black Box of Execution" where the browser acts on its own logic. This is groundbreaking but creates a "confused deputy" problem: a compromised agent doesn't just leak data; it can execute unauthorized business logic on your behalf.
These browsers can:
In other words, your browser is no longer a viewer. It is an actor, and one you do not fully control.
Enterprises should treat AI browsers as high-risk "Shadow IT" due to the following:
AI browsers are early-stage technologies, immature, untested at scale, and lacking enterprise-grade guardrails like centralized Group Policy management. Unlike mature enterprise tools, they provide no administrative console for CISOs to audit activity. They effectively function as an unapproved operating system for the web. CISOs should block these consumer variants for the foreseeable future.
To function, AI browsers transmit page content - including text, emails, form fields, and browsing history- to cloud-based inference engines. For example, to "summarize" a page, the browser reads the context and sends it to third-party servers (e.g., Perplexity or OpenAI). This creates an uncontrolled, continuous flow of sensitive data outside the corporate “perimeter”, often without a Data Processing Agreement (DPA) in place.
AI reasoning is fallible and susceptible to manipulation. AI browsers can:
Researchers have demonstrated attacks like "CometJacking," where a malicious webpage contains hidden instructions (indirect prompt injection) that hijack the browser's agent.
Without the user knowing, the browser could be tricked into:
While vendors are introducing reactive scanners like "BrowseSafe" to detect these prompts, these are probabilistic defenses in a game where attackers only need to win once.
Automation amplifies impact, errors happen faster and at scale.
Consumer AI browsers often retain user data to "improve models" or maintain "Browser Memories" indefinitely. Privacy is often an optional toggle hidden in settings, leading to "opt-out fatigue" among employees. In an enterprise environment, relying on individual users to manage privacy settings is a failed control strategy.
The rush to market has led to severe security regressions. Security researchers recently discovered that ChatGPT Atlas on macOS bypassed critical operating system sandboxing. It stored sensitive user conversations and OAuth access tokens in unencrypted plain-text files within the ~/Library/Application Support/ directory. This allowed any malware running on the device to harvest high-privilege credentials without user interaction. This flaw could allow account compromise at scale. Consumer AI browsers are moving fast, too fast for enterprise trust.
As a Cyber Risk management provider, we view AI browsers through a lens of operational risk and adversarial opportunity. The "Browser Wars" have returned, but this time, the stakes are the integrity of your decision-making loop.
Use endpoint detection and response (EDR) to flag installation binaries (e.g., Comet.exe, Atlas.app). Update Secure Web Gateways (SWG) to inspect User-Agent strings and block traffic to consumer AI API endpoints (e.g., api.perplexity.ai) originating from unmanaged processes. This is especially critical for organizations in:
Explicitly prohibit the use of "Agentic" or "Autonomous" browsing tools that perform actions without per-click user confirmation. Clarify that "Shadow AI" tools violate data handling policies for internal classification levels. The risk is not worth the productivity gain.
Update your SOC playbooks to:
Obrela firmly believes that the fusion of Strength, Discipline, and Intelligence - our human-plus-AI philosophy - is essential to safe AI operationalization. Where browsers remove human oversight, risk skyrockets.
AI browsers will eventually become a transformative enterprise tool. . In fact, enterprise-specific browsers like Microsoft Edge for Business are already bridging the gap by offering "Enterprise Data Protection" where data is not used for training and admins can manage "Agent Mode".
However, for consumer tools (Atlas, Comet) to be ready, they will need:
We estimate this is at least 2 years away for regulated sectors—if vendors prioritize security over speed. Until then, the risk profile remains unacceptable.
Whether organizations choose to block AI browsers outright or pilot them in limited sandboxes, Obrela supports clients through:
Detecting anomalous browser behavior, automation patterns, and unauthorized AI integrations.
Monitoring of third-party AI exposure, vendor risk, and policy compliance.
Rapid response to credential leaks, API misuse, or automation-driven incidents originating from AI browsers.
Unified visibility and real-time risk tracking across assets, identities, and AI-integrated workloads.
AI changes the battlefield. Obrela ensures you are not fighting blind.
AI browsers represent one of the most significant shifts in end-user computing since the introduction of JavaScript. But where technology leaps ahead, security must and will push back.
Today, unrestricted AI browser adoption is a strategic risk - a form of Shadow IT. Tomorrow, with the right controls, it may become an operational advantage.
At Obrela, our role is to ensure you operate in a world where cyber risk becomes predictable, not a by-product of unchecked innovation.