AI browsers are having their moment. ChatGPT Atlas, Perplexity Comet, Dia — all built on the same pitch: an agent that reads pages, fills forms, and finishes tasks for you. Here's the part that should slow you down: the design that makes them useful also makes them steerable, by any web page they happen to read.
The attack is almost embarrassingly simple
It's called prompt injection, and it needs no malware, no phishing link, no stolen password. Someone plants instructions inside content your agent will process — a web page, a calendar invite, a Reddit comment, a shared doc. The AI reads that text through the exact same pipeline as your commands, and it can't reliably tell the two apart. You asked for a summary. The page asked for something else. Sometimes the page wins.
This isn't theoretical. A demonstration against Perplexity's Comet — researchers nicknamed it CometJacking — showed the hijack working in practice, and versions of it have been documented across the whole category.
Nobody's promising a fix. Literally nobody.
The most telling fact here came from OpenAI itself, back in December: prompt injection is "unlikely to ever be fully 'solved.'" That's the maker of Atlas talking about its own product line. And by June, independent researchers had landed in the same place — you can't fully patch this out of Atlas, Comet, or Dia, because it's not a bug. It exploits how language models process text at all.
So this isn't a wait-for-the-next-update problem. It's a permanent property of the tool. Plan accordingly.
Why you specifically should care
An AI browser is only valuable because it acts with your access — your inbox, your saved cards, your logged-in everything. Which is exactly what a successful injection inherits. Corporate security teams figured this out fast: by spring the standard enterprise posture was approved tools only, no shadow adoption, and sensitive workflows kept off agentic browsers, full stop.
Nobody sends regular users that memo. The logic applies to you anyway.
The practical version
Treat the agent like a very capable stranger at your keyboard. Research, summaries, comparisons — great, let it run, in a session where nothing important is signed in. Keep banking, your main email, and anything payment-enabled out of its reach; a separate browser or profile for agent work is the cleanest way to draw that line. Read what it wants to send before it sends it. And when money or passwords are involved, do that step yourself.
The convenience is real. So is the open door. The vendors are telling you, in writing, that they can't close it — so assume anything your AI browser can touch, a hostile page can touch too.
Image: cottonbro studio, via Pexels





