AI Security, Privacy and Compliance

Should Your Staff Use an AI Browser Like Comet for Work?

Last updated 19 August 2026 · 6 min read

Direct Answer

Not without real limits. AI browsers — Perplexity's Comet is the best-known example — can read a webpage, click, fill in forms, and carry out multi-step tasks on your behalf, which makes them genuinely useful, but that same autonomy is exactly what security researchers have repeatedly shown can be hijacked: a maliciously crafted webpage, email, or even a URL can contain hidden instructions the AI reads as legitimate commands and quietly acts on, potentially exposing emails, calendar data, or logged-in accounts. Security analysts, including Gartner, have recommended businesses restrict or block AI browsers in the workplace until the risk is better understood, rather than adopting them the way a normal browser would be adopted. The practical approach for most small businesses is to keep AI browsers off accounts with access to sensitive data and financial systems, treat any use as a deliberate, approved exception rather than a default tool, and set that expectation in writing before someone downloads one because it looks convenient.

Detailed Explanation

An AI browser — Perplexity's Comet is the best-known consumer example, and OpenAI briefly ran a competing product called Atlas before folding it back into ChatGPT — is a web browser built around an AI agent that can read a page, understand what's on it, and take actions: clicking links, filling in forms, navigating across multiple sites, and completing a task described in plain language rather than requiring you to click through it yourself. The pitch is genuinely appealing for busy small-business owners and staff: "book this appointment," "compare these three suppliers' prices," or "fill out this form using the details in this document" described once instead of done by hand.

The risk sits in exactly the capability that makes it useful. An AI browser doesn't just read a page for you — it can act on what it reads, using whatever accounts you're logged into at the time. Security researchers through 2025 and 2026 have repeatedly demonstrated that a webpage, an email, or even a specially crafted link can hide instructions the AI treats as legitimate commands rather than untrusted content — a form of prompt injection specific to agentic browsing. Documented cases have shown attackers using this technique to exfiltrate emails and calendar data, or to plant false information into an AI browser's persistent memory so it acts on bad instructions later, in a different session. Independent testing has also found some AI browsers block a meaningfully smaller share of known phishing and malicious pages than a standard, non-agentic browser does — the added intelligence hasn't yet translated into added safety.

This risk profile is serious enough that Gartner, a major enterprise technology research firm, has recommended businesses restrict or outright block AI browsers in the workplace until the security model matures — a notably blunt recommendation for a mainstream productivity category, and one worth taking at face value rather than assuming it's overly cautious.

Setting a Sensible Policy

Don't treat an AI browser as a drop-in replacement for a normal one. The risk isn't hypothetical or limited to sophisticated attacks — a single malicious webpage or email is enough to trigger some of the documented exploits. Adopting an AI browser business-wide the way you'd roll out a new version of Chrome or Edge skips past a risk category those browsers don't carry.

Keep AI browsers off accounts with access to sensitive systems. Email, banking, accounting software, and customer data systems are exactly the accounts a hijacked AI browser session could reach — if any use is approved at all, keep it away from logins with that level of access.

Treat any adoption as a deliberate, scoped exception, not a default. A specific, low-risk, well-understood use case (research browsing with no logged-in accounts, for instance) is a very different proposition from letting staff use an AI browser for whatever they'd normally do online. Write down what's approved and what isn't, rather than leaving it to individual judgement.

Watch for shadow adoption. Because these tools are free or cheap consumer downloads, staff can install one without IT or management ever being aware — the same "unapproved tool" risk this site covers for other AI tools applies here, arguably with higher stakes given the account-access exposure. See what should an employee AI usage policy include for turning this into a written rule the whole team follows, not an assumption everyone happens to share.

Revisit the policy as the category matures. This is a genuinely fast-moving space — security postures, independent testing results, and even which products exist have changed significantly within 2026 alone. A policy written today should be checked again within six months, not treated as settled.

Things to Consider

  • The underlying risk is a form of prompt injection, not a bug specific to one vendor. See what is prompt injection for the general mechanism — an AI browser is simply one of the highest-consequence places for it to show up, since it combines reading untrusted content with the ability to act on real accounts.
  • Product churn is itself a business risk. OpenAI's Atlas launched and was discontinued as a standalone product within roughly a year — a business that builds a workflow around any single AI browser product should expect the product landscape to keep shifting, not assume today's leading option is a safe long-term bet.
  • This sits alongside, not instead of, general AI-agent risk. See what can go wrong when an AI agent can take real actions for the broader pattern of risk that applies whenever an AI system can act rather than just respond.
  • A blanket ban is a legitimate policy choice, not an overreaction. Given the current state of independent security testing, a small business with no compelling use case for an AI browser has a reasonable, defensible option in simply not permitting one — this isn't a category every business needs to adopt to stay competitive.

Common Mistakes

  • Letting staff install an AI browser because it looks like "just a browser." The interface is familiar, but the risk model is fundamentally different from Chrome, Edge, or Safari — treat the decision to use one as a distinct, deliberate choice, not routine software installation.
  • Approving AI browser use without restricting which accounts it can touch. Even an approved, scoped use case should stay away from logins with access to sensitive data or financial systems.
  • Assuming a well-known vendor means the product is safe by default. Documented vulnerabilities have been found in major products from well-resourced companies — vendor reputation is not a substitute for checking current, independent security research.
  • Treating this as settled after writing one policy. The specific products, their security postures, and the independent research about them are all moving quickly enough in 2026 that a policy needs periodic review, not a one-time decision.
  • Ignoring shadow adoption because "nobody asked to use one." Free, easy-to-download consumer AI browsers don't require IT approval to install — assume some staff may already be experimenting with one and address it proactively rather than waiting for a problem to surface first.

Frequently Asked Questions

What happened to ChatGPT Atlas?
OpenAI discontinued Atlas as a standalone browser, with the shutdown taking effect 9 August 2026, folding its agentic browsing capability directly into ChatGPT instead. It's a useful data point about how fast this product category is moving — a business that adopted Atlas specifically expecting it to be a stable, standalone tool would have had to change course within about a year of launch. Check current product status before relying on any specific AI browser as a long-term fixture.
Is an AI browser the same risk as a normal AI chatbot?
No — it's a meaningfully bigger one. A chatbot generally only acts within its own conversation window unless it has been deliberately connected to other systems. An AI browser is built to read whatever web content it encounters and take real actions with your logged-in accounts — clicking, submitting forms, navigating between sites — which is a much larger blast radius if it's tricked into doing something it shouldn't. See what can go wrong when an AI agent can take real actions for the broader category this risk sits inside.
Are all AI browsers equally risky?
No, but treat any of them as higher-risk than a standard browser until you've checked current, independent security testing for the specific product. Testing through 2026 has found meaningful differences between products in how well they resist malicious test pages, and those results change as vendors patch known issues — check current, independent security research rather than relying on a vendor's own safety claims or a general reputation.

References

Related Questions