Do you need help & advice with AI & Automation or Cybersecurity?
AI browsers do something genuinely useful. You tell them what you want and they go off and do it: read your email, fill in the form, book the thing, summarise the page. Atlas from OpenAI and Comet from Perplexity are the two people are trying.
We have used Comet. Parts of it are clever. It is not something to put near your business, and the reason is more serious than it being early.
What is actually wrong with them?
Anything the browser reads can give it instructions, and it cannot reliably tell the difference between your instructions and a stranger’s.
This is called prompt injection. It is not a bug in one product, it is a consequence of how these things work: the page content and your commands arrive through the same door.
The version that matters for business is indirect. The hostile instruction is not typed by anyone. It is sitting inside a web page, an email, a PDF or a calendar invite that the browser reads while carrying out a perfectly ordinary task.
Will it be fixed?
OpenAI’s own position is that it is “unlikely to ever be fully solved”.
That statement, from December 2025, is the single most important fact on this page, and it changes what kind of decision this is. If the vendor building the most prominent AI browser says the core flaw may never be fully closed, then “we will allow it once it is mature” is not a plan.
Security researchers have since confirmed that the problem cannot be fully patched in Atlas, Comet or Dia. Gartner has recommended enterprises block them until there are major security upgrades, which is direct language by their standards.
Defences are improving and will keep improving. But the same property that makes these browsers useful, acting on what they read, is the property that makes them exploitable. That is a design tension, not a defect.
Why does this matter more than the usual AI risk?
Because it acts rather than answers, and it acts as your member of staff.
If ChatGPT gives somebody a wrong answer, a person reads it and decides what to do. If an AI browser is compromised, it is already signed into your email, your files and whatever else that person has access to, and it is doing things on their behalf.
| Ordinary AI tool | AI browser |
|---|---|
| Produces text for a person to check | Takes actions in systems you are signed into |
| Mistake is visible before it matters | Action has already happened |
| Your data goes where you paste it | Reaches everything that account can reach |
| Needs somebody to do something careless | Needs nothing but a page with hidden text on it |
What should we do about it?
Block them, tell people why, and give them something that does work.
The order matters. A ban on its own gets worked around, especially by the people keenest to try new things, who are usually the ones you least want going round you.
| Do this | |
|---|---|
| 1 | Block installation of Atlas, Comet and Dia on work machines. Your IT provider can do this in an afternoon |
| 2 | Say why, in one paragraph. “The vendor says the security flaw may never be fixed” is a reason people accept. “IT said no” is not |
| 3 | Name what they can use instead. If you are on Microsoft 365 there is a work Copilot already included, and it is not an agentic browser |
| 4 | Write it into your AI policy so it survives the next launch, because there will be one |
Step three is the one that makes the ban hold. People are not installing these to be difficult, they are installing them because the work is slow.
Personal machines and personal time are their business, not yours. Say that too. It makes the work rule easier to accept.
[VIDEO_PLACEHOLDER]
So, what now?
Ask your IT provider to block the three by name this week, and send one paragraph to staff explaining why. Then add a line to your AI policy about agentic browsers generally, so you are not doing this again in three months.
If you would rather somebody tracked this category on your behalf, and told you when something in it becomes worth allowing, that is what an AI Manager does. The wider basics are in getting started with AI in your business.
Frequently asked questions
What is an AI browser?
A web browser with an AI agent built in that can act on your behalf rather than just show you pages.
You give it a task, such as summarising your email or filling in a form, and it does it using the accounts you are signed into. Atlas from OpenAI, Comet from Perplexity and Dia are the main ones.
What is prompt injection?
Hiding instructions in content the AI reads, so it follows them instead of yours.
The browser cannot reliably tell your commands apart from text in a page or email, because both arrive the same way. The hostile version is usually hidden where nobody looks.
Will AI browsers ever be safe for business?
OpenAI has said prompt injection is unlikely to ever be fully solved for browser agents.
Defences will improve and some uses will become reasonable. But treat this as a category to watch rather than a product waiting on a patch.
Can staff use them on personal devices?
Their own machine on their own time is their business. The problem is signing into work accounts from one.
Make that the rule rather than banning the software from their lives. It is easier to explain and easier to follow.
Is Microsoft Copilot an AI browser?
No. Copilot works inside your Microsoft 365 apps and does not drive a browser session on your behalf.
It carries its own considerations, mainly around what it can see, but it is not the same risk. If you are on Microsoft 365 you probably already have a work version included.
This page names specific products in a fast-moving category. Last verified 17 August 2026 and reviewed quarterly. Owner: Dave Lane.

