In this article
The browser on your team's laptop is no longer just a window onto the web. Agentic AI browsers like ChatGPT Atlas, Perplexity Comet, and Microsoft's Copilot Mode in Edge can now navigate sites, fill in forms, and complete multi-step tasks on a person's behalf, using whatever accounts that person is already logged into.
What Is an Agentic AI Browser, and Why Is It Different From a Chatbot?
A chatbot answers questions inside its own window. An agentic browser acts inside the actual browser session, clicking, typing, and submitting forms the same way a person would. Microsoft describes its own version this way: a person can issue a high-level command such as researching competitor pricing and drafting a summary email, and Copilot will autonomously open tabs, parse web content, compare data, and compose the draft without being told each individual step.
That convenience is the entire point, and it is also the source of the risk. The agent is not working inside a sandbox built for it. It is working inside the same browser profile that holds your team's email, banking, HR system, and CRM logins.
Perplexity's own description of Comet Assistant makes the shift concrete: the tool is built to handle in-page research and summarization alongside autonomous, multi-step tasks such as booking flights, managing email, and filling out forms. A year ago, that list of capabilities belonged to a human assistant. Today it belongs to software running on the same device as the rest of your team's work.
How Are Employees Already Using These Without IT Approval?
Faster than most security or governance policies could keep up. Perplexity opened Comet to enterprise customers in March 2026, but Comet itself has been freely available to individuals for longer, and an employee does not need permission from anyone to install a browser on a personal or work device and start using it for real tasks. The same is true of ChatGPT Atlas. For a lot of teams, agentic browsing is not a future rollout to plan for. It is already running on someone's machine today, unmanaged and unlogged.
What Actually Goes Wrong When an Agent Browses on Your Behalf?
An agent that inherits every authenticated session at once also inherits every risk in every one of those sessions simultaneously. Security researchers describe this as excessive agency: an assistant asked to complete one narrow task in one application can be steered, deliberately or through a manipulated webpage, into taking action in a completely different connected system.
That is not a theoretical concern. In late 2025, researchers at LayerX Security disclosed a flaw in OpenAI's Atlas browser in which a malicious webpage could use a forged request to inject hidden instructions into ChatGPT's persistent memory, without the user seeing anything unusual happen. Once that memory was tainted, the researchers found that later, completely unrelated prompts could trigger data exfiltration or unauthorized actions, because the model was now quietly working from corrupted instructions it believed were its own. The attack did not require the user to click anything suspicious. It only required the agent to visit a page an attacker controlled.
This is the piece most existing security training misses. Your team has likely been taught to spot a suspicious email or a fake login page, and that training still matters. It says nothing about a webpage that looks completely normal to a person but contains instructions written specifically for the AI agent reading it on their behalf. The phishing target has quietly expanded from the employee to the software acting for the employee, and most awareness programs have not caught up yet.
Why Is This a Top Concern for Security Leaders Right Now?
Because the industry watching this closely does not consider it settled. A Dark Reading readership poll heading into 2026 found that 48% of security professionals named agentic AI and autonomous systems their top attack-vector concern, ahead of deepfakes and passwordless adoption. Separately, the Cloud Security Alliance's State of AI Cybersecurity 2026 survey found that 92% of security professionals are concerned about the impact AI agents will have on their organization's security. Federal agencies are wrestling with the same question at scale: FedScoop reported that agentic AI browsers were a defining 2026 risk for government IT teams, largely because these attacks are triggered by ordinary-looking language, so malicious activity and legitimate use can look identical from the outside.
None of this means agentic browsers are broken products that should be banned outright. It means the category is new enough that the vendors themselves are still building the guardrails while businesses are already adopting it. For a small or mid-sized team without a dedicated security operations function, that gap lands squarely on whoever approved the tool in the first place, usually a team lead or an office manager, not a security architect who has read the vendor's threat model.
What Are AI Platforms Doing to Govern This?
The two most enterprise-focused vendors have both shipped real controls this year, and they are worth understanding even if your team uses neither one directly, because they show what "governed" now looks like in practice. Perplexity's Comet Enterprise lets administrators deploy the browser across company devices, restrict which domains the agent can act on, and require explicit human approval, with a full audit trail and a kill switch, before it can take a sensitive action.
Microsoft's Copilot Mode for Edge for Business, in limited preview since May 2026, works from the opposite direction: IT sets allow and block lists for which sites Copilot can operate on, applies data loss prevention rules through its Purview compliance tools, and feeds every browsing session into the same security monitoring the rest of the organization already uses. In both cases, the vendor's default assumption is now that an agentic browser needs its own permission model, not the same blanket trust a person's own browsing already carries.
The pattern underneath both products is the same, even though the implementation differs: limit what the agent can reach, require a person to sign off on the actions that matter, and log everything so a review after the fact is actually possible. That pattern is worth learning on its own, separate from whichever specific browser your team ends up using, because the next agentic platform your team adopts will likely expect you to configure the same three things.
What Should Your Team Verify Before Anyone Turns This On?
Whether or not your organization has formally adopted an agentic browser, someone on your team likely already has one installed. Start with a short, concrete review rather than a blanket policy no one reads.
| Before you allow agentic browsing | Why it matters |
|---|---|
| Which accounts and sessions could the agent reach if it were manipulated? | The agent's blast radius is every session open in that browser, not just the task it was given. |
| Can you restrict which sites or domains it is allowed to act on? | Unrestricted browsing means any page it visits is a potential instruction source. |
| Does a sensitive action require a human approval step? | Without one, a single manipulated page can turn into an unsupervised transaction. |
| Is there an audit log of what the agent actually did on each site? | Without logs, you cannot tell an approved task from a hijacked one after the fact. |
A few common signs your team is already exposed:
- Someone has installed Comet, Atlas, or a similar tool on a work laptop without a security conversation first.
- Your AI platform's browsing or "agent mode" feature is switched on by default rather than something IT explicitly enabled.
- No one could tell you today which sites an AI agent on your network is allowed, or not allowed, to act on.
Building This Into How Your Team Adopts AI
This is not a reason to slow down AI adoption. It is a reason to make sure the people adopting it can tell the difference between a genuinely useful agent and one that has quietly been handed the keys to everything a person is logged into. That distinction is exactly what Securafy's AI University certifications are designed to build, because knowing which permissions an AI feature actually needs is now as important a workplace skill as knowing how to write a good prompt.
If you are not sure whether an agentic browser is already running somewhere on your team's devices, an AI readiness assessment is the fastest way to find out before it becomes an incident instead of a policy decision. Teaching people to recognize what a new AI capability actually changes about their risk, not just what it lets them do faster, is the whole premise behind AI University.
Agentic browsers are going to keep spreading through ordinary workdays because they genuinely save time. Your job is not to stop that. It is to make sure someone has actually looked at what each one can reach before it gets used on something that matters.
Next Step
If your team is adopting AI browsing tools faster than your policies can keep up, talk it through with Securafy. Book a strategy call to walk through what is already running on your team's devices and what to govern first.
Not sure where you stand? Take the AI Readiness Assessment before you commit budget to tools.
Take the assessment
Rodney Hall is the President and COO of Securafy, with 2 decades of experience in IT service management and operations.
He writes about the less glamorous but essential side of IT: support systems, documentation, business continuity, recurring issues, downtime, and the processes that keep client environments running well. His perspective comes from years spent improving how service is delivered, how teams respond, and how small problems are prevented from becoming much larger ones.
Outside of work, Rodney enjoys home improvement projects, woodworking, and dirt bike riding. His personal mission mirrors Securafy’s: helping businesses stay secure, compliant, and ready for whatever comes next.
Writes about: Managed IT, IT operations, service delivery, business continuity, downtime prevention, support processes, operational risk
Join the conversation
Have a question or a different take on this? Add it below.