Skip to main content

The Browser That Drives Itself: What Happens When AI Gets Your Login

· 6 min read
Seth Davis
Founder & AI Educator

For thirty years, a web browser has done one job: show you a page and wait for you to click something. In 2026, a handful of browsers stopped waiting. Tell one of them "book the cheapest direct flight to Denver next Friday" or "clean out my inbox from newsletters I never open," and it opens the tabs, reads the pages, fills the forms, and clicks the buttons itself — logged in as you, the whole time.

That last part is the whole story. It's also the whole risk.

From searching to doing

Regular AI chat answers questions. An agentic browser — think Perplexity's Comet, OpenAI's Atlas, or Claude for Chrome — takes an instruction and executes it across the open web using your actual, logged-in sessions: your email, your saved payment methods, your shopping accounts, your calendar. You're not copying an AI's answer into a form anymore. The AI is looking at the form itself and typing into it.

Adoption has moved fast. Claude for Chrome went from roughly 40,000 installs to over 10 million between December 2025 and June 2026. Enterprise use jumped from almost nothing to 27.7% of companies running agentic browsers in production within about two years. Analysts still peg all AI browsers combined at only 1-3% of the overall browser market — this is early, not mainstream — but the trajectory inside that sliver is steep.

What people are actually using it for

Skip the demo-reel tasks and the pattern that emerges is pretty ordinary: it's the browsing you already do, minus the part where you do it.

  • Research that used to eat an afternoon. Point it at a question — compare five vendors, summarize a stack of reviews, pull specs across a dozen product pages — and it returns a structured answer instead of thirty open tabs. Analysts and researchers report saving five to ten hours a week this way.
  • Shopping with fewer steps. Product search, price comparison, and even checkout on sites you're already logged into. Retail sites saw a reported 4,700% year-over-year jump in traffic from AI agents by mid-2025, and that curve hasn't flattened.
  • The small stuff that piles up. Booking a restaurant reservation, drafting an email reply in a different tone, unsubscribing from a mailing list, updating a spreadsheet from data spread across three tabs.

None of this is exotic. It's the same list of chores that made "just add it to my calendar" useful a decade ago — just applied to every tab instead of one.

The tradeoff nobody's papering over

Here's the part worth slowing down for. The single thing that makes an agentic browser useful — standing access to your logged-in email, banking sessions, and saved passwords, all at once, by design — is also the thing security researchers say cannot currently be made fully safe.

The attack is called prompt injection, and the browser version of it is sneaky because you never see it happen. An agent reading a web page, an email, or even a calendar invite on your behalf can encounter hidden instructions planted by an attacker — white text on a white background, a comment buried in a PDF, invisible text in an HTML element — and follow them as if you'd typed them yourself. Security teams have demonstrated working versions of this attack against Comet, Atlas, and Opera's AI browser. In December 2025, OpenAI itself wrote that prompt injection is "unlikely to ever be fully 'solved.'" That's the company building one of these browsers saying so, not a critic.

This is why the smart move right now isn't "avoid agentic browsers" or "trust them completely" — it's using them the way you'd use a very capable but occasionally gullible assistant.

How to use one without getting burned

  • Keep it out of your highest-stakes accounts. Let it book a reservation or draft an email. Think twice before handing it standing access to banking, tax filing, or anything with real money attached, at least until you've watched it work on lower-stakes tasks first.
  • Review before it submits, not after. Most agentic browsers will show you the action before it commits — a form filled, an item in a cart, an email drafted. That preview is the actual safety mechanism right now. Use it every time, even on the tenth identical task.
  • Be extra cautious with anything the agent reads from outside your control. A page you didn't write, an email from a stranger, a document someone else shared — these are exactly where hidden instructions get planted. If a task suddenly asks the agent to do something unrelated to what you requested, that's the signature of an injection attempt.
  • Match the tool to the task, not the hype. For genuinely open-ended, multi-step chores, an agentic browser can save real time. For anything involving money movement or credentials you'd hate to lose, do it yourself for now, or use a tool built specifically for that narrower job.

If you want the deeper mechanics of why this attack is hard to close off, our AI Agent Safety guide covers it in the broader context of autonomous agents, and the AI Safety & Privacy Checklist is a fast pre-flight check before you give any tool standing access to your accounts.

Key takeaways

  • Agentic browsers act, they don't just answer — they click, fill forms, and check out using your real, logged-in sessions across the web.
  • Adoption is early but accelerating fast. Claude for Chrome alone went from ~40,000 to over 10 million installs in six months; enterprise production use hit 27.7% from near zero in two years.
  • The everyday use cases are mundane on purpose — research, shopping, bookings, inbox cleanup — the same chores you already do, minus the manual clicking.
  • Prompt injection is the real, unresolved risk. Hidden instructions in a web page or email can hijack an agent's actions, and even the companies building these browsers say it can't be fully patched.
  • Use the built-in preview step every time, and keep agentic browsers away from your highest-stakes accounts until you trust the workflow on smaller tasks first.

Curious how this fits into the bigger shift toward AI that acts instead of just answers? Start with Getting Started with AI Agents, then read AI Agent Safety before you connect one to anything that matters.

info

This post was developed with AI assistance and is regularly reviewed for accuracy.