Security
What are the security risks of AI browsers for your business?
An AI browser is an agent with your sessions and permissions, and any page it reads can try to give it orders.

The short answer
The main security risk of AI browsers is prompt injection: hidden instructions on a web page, email or document that the built-in AI agent follows as if they came from you. Because the agent uses your logged-in sessions, it can leak or change company data without malware. The UK NCSC says this may never be fully fixed, only reduced.
Key takeaways
- AI browsers such as ChatGPT Atlas and Perplexity Comet can read pages, fill in forms and act in connected apps using the user's own logged-in sessions.
- Indirect prompt injection hides instructions in content the agent reads; OWASP ranks prompt injection as LLM01, the top risk for large language model applications.
- The UK NCSC and OpenAI both say prompt injection is unlikely ever to be fully solved, so plan to limit its impact rather than wait for a patch.
- Gartner advised in December 2025 that organisations block AI browsers for the foreseeable future; if you allow them, restrict them to approved tools and low-privilege accounts.
- Because some incidents will get through, keep isolated, immutable backups of Microsoft 365, Google Workspace and endpoint data so you can undo deletions and corruption.
What is an AI browser, and why is it different?
An AI browser is a web browser with a built-in AI agent that can read pages, summarise content, fill in forms and take actions in other web apps on your behalf. That autonomy is the feature, and it's also the attack surface.
Picture a marketing team that starts using an AI browser to summarise reports. It works, so colleagues follow. Weeks later the assistant reads a page with hidden instructions and sends the contents of an open SharePoint document to an outside address. Nobody clicked anything suspicious, and no malware ran.
That's why an AI browser isn't "a browser with a chatbot". It's an agent working with your sessions and permissions. Endpoint tooling, including an EDR platform, sees a normal browser process; the risk lives in what the agent is told to do.
How does prompt injection work in an AI browser?
Prompt injection tricks the AI into treating attacker text as instructions. OWASP calls it LLM01, the top risk in its list for large language model applications, and separates direct injection (typed by the user) from indirect injection, which arrives in external content such as websites or files.
The four stages of an indirect prompt injection
- The trap. An attacker hides instructions in web content: white text on a white background, an HTML comment, a hidden comment on a forum, or a compromised page you'd normally trust.
- The read. You ask the agent to summarise the page, or it browses there on its own. The hidden text enters the model's context.
- The action. The model can't reliably tell your instructions from the attacker's, so it follows them: copy visible data, open a URL, draft and send an email.
- The silence. No exploit code ran and no file was downloaded, so traditional security tools see an ordinary browsing session.
This has already happened in practice. Brave's researchers showed in August 2025 that Perplexity's Comet browser could be made to follow instructions hidden behind a spoiler tag on a Reddit page and leak a one-time password for the user's account, The Register reported. Brave later said the issue was not yet fully mitigated.
Why is prompt injection so hard to stop?
Because a language model has no hard boundary between instructions and data. Classic defences like input validation, which solved SQL injection, don't carry over.
In "Prompt injection is not SQL injection (it may be worse)", published 8 December 2025, the UK National Cyber Security Centre explains that inside an LLM "there's no distinction made between 'data' or 'instructions'; there is only ever 'next token.'" The NCSC warned that prompt injection "may never be totally mitigated in the way SQL injection attacks can be" and that efforts should focus on reducing risk and impact.
Vendors agree. In Continuously hardening ChatGPT Atlas against prompt injection (December 2025), OpenAI wrote that prompt injection, "much like scams and social engineering on the web, is unlikely to ever be fully 'solved'."
Are AI browsers safe to use at work?
Not by default. An AI browser inherits every permission of the logged-in user, from mailbox to file shares to admin consoles, and hands them to an agent that page content can steer.
Analysts have reacted strongly. On 9 December 2025, Gartner advised that "CISOs must block all AI browsers in the foreseeable future to minimize risk exposure", TechNewsWorld reported. Gartner's concerns included sidebars that send active web content, open tabs and browsing history to a cloud back end, and agents acting on a user's behalf without explicit consent.
For EU organisations there are three specific concerns:
- Data transfers. If the agent sends page content or personal data to processing outside the EEA, Chapter V of the GDPR (from Article 44) applies to that transfer.
- Breach reporting. A leak of personal data through an injected agent can be a personal data breach, which GDPR Article 33 requires you to report to the supervisory authority within 72 hours where it is likely to result in a risk to people.
- Risk management. For entities in scope of NIS2, Article 21(2) covers supply chain security (d), cyber hygiene and training (g) and access control (i), all of which apply to AI tools that act on company data. See our Article 21 overview.
A blanket ban often pushes usage underground, so if you don't block AI browsers outright, treat them like any software that can act on company data: approved versions only, restricted accounts, monitored use.
How do you reduce AI browser risk? A five-step plan
No single control removes prompt injection risk, so layer them. The first four steps reduce the chance of harm; the fifth limits the damage when something gets through.
- Inventory and decide. Find out which AI browsers and extensions are already in use. Then either block them, as Gartner advises, or publish an approved list and block everything else through device management.
- Restrict what the agent can reach. No AI browsing from admin accounts. Keep agents away from finance, HR and patient or client systems. OpenAI itself recommends logged-out mode when the task doesn't need your accounts, and giving agents narrow, specific instructions.
- Keep a human in the loop. Require confirmation before the agent sends messages, submits forms or makes payments, in line with OWASP's advice on human approval for high-risk actions.
- Train for the new phishing. Staff know to distrust links. Teach them that a web page can attack their assistant, and add prompt injection scenarios to awareness training.
- Assume failure and protect the data. Keep isolated, immutable backups of Microsoft 365, Google Workspace and endpoints, with separate credentials, so an agent that deletes or corrupts data can't take the backups with it.
Prevention or recovery: where does each control fit?
Prevention reduces how often an injected agent can act; recovery undoes what it did. Because injection can't be eliminated, you need both.
| Prevention (governance and access) | Recovery (backup and restore) | |
|---|---|---|
| Goal | Stop injected agents from acting | Undo what an agent changed or deleted |
| Key controls | Approved tools, least privilege, human confirmation, training | Immutable and air-gapped copies, granular restore |
| Protects against | Data leaks, unwanted actions | Deletion, corruption, follow-on ransomware |
| Limitation | Can't fully block prompt injection | Can't un-leak data that left the organisation |
Remember that native tools have limits too: the Microsoft 365 recycle bin keeps deleted items for up to 93 days, and anything an agent deletes from it, or that ages out, is gone. Read more in does Microsoft 365 back up your data? and when MFA fails.
What to do next
AI browsers bring real productivity gains, but they also bring an attack that today's tools can't reliably block and vendors say they can't fully patch. Treat the agent as a capable but fallible user: decide whether to allow it, limit what it can reach, confirm its risky actions and keep a tested way to roll back its mistakes.
Mindtime backs up Microsoft 365, Google Workspace and endpoints to our own Tier III data centres in the Netherlands and Germany, as immutable copies (Object Lock) plus an air-gapped copy, with granular restore of individual items and admin actions protected by MFA. For MSPs, the Mindtime EDR platform helps keep client endpoints patched and configured to CIS benchmarks, while the MSP runs the service.
Want to know how recoverable your SaaS data would be after an AI-driven incident? Book a free 15-minute demo.
This article is information, not legal advice.
Frequently asked questions
What is a prompt injection attack?
A prompt injection attack hides instructions inside content an AI system reads, so the AI follows the attacker instead of the user. In an AI browser the instructions can sit in a web page, email or document, often invisible to the person using it. The UK NCSC treats it as a lasting class of weakness, because language models can't reliably separate instructions from data.
Can antivirus or EDR detect prompt injection?
Not reliably. A prompt injection contains no malware, exploit code or malicious file; it's plain text the AI interprets as an instruction. Endpoint tools see a normal browser process. Detection therefore focuses on consequences, such as unusual outbound traffic or unexpected actions in connected apps, which is why access limits, human confirmation and recoverable backups matter more than any single detection tool.
Should companies ban AI browsers?
Gartner advised in December 2025 that organisations block AI browsers for the foreseeable future. If you don't ban them, use an approved-tools policy: sanctioned browsers only, low-privilege accounts, no use on admin or finance systems, human confirmation for actions and training on injection risks. Keep immutable backups of business data so an incident stays recoverable.
Is using an AI browser a GDPR risk?
It can be. If the agent sends personal data to processing outside the EEA, GDPR's Chapter V transfer rules apply. If an injected agent leaks personal data, that may be a personal data breach, which Article 33 requires you to report within 72 hours where there is a risk to individuals. Check the vendor's data processing terms before approving any AI browser.
Can backups help after an AI browser incident?
Yes, for deletion and corruption, not for leaks. If an injected agent deletes mail, files or documents, an isolated, immutable backup lets you restore the affected items. Backups can't recall data that has already been sent outside the organisation, so combine them with prevention controls and breach-response procedures.
Sources
- Prompt injection is not SQL injection (it may be worse)National Cyber Security Centre (UK), 2025
- Mistaking AI vulnerability could lead to large-scale breaches, NCSC warnsNational Cyber Security Centre (UK), 2025
- Continuously hardening ChatGPT Atlas against prompt injection attacksOpenAI, 2025
- Gartner Recommends Enterprises Avoid AI Browsers — for NowTechNewsWorld, 2025
- Perplexity's Comet browser naively processed pages with evil instructionsThe Register, 2025
- LLM01:2025 Prompt InjectionOWASP Gen AI Security Project, 2025
- Regulation (EU) 2016/679 (General Data Protection Regulation)EUR-Lex, Publications Office of the European Union, 2016
- Directive (EU) 2022/2555 (NIS2 Directive)EUR-Lex, Publications Office of the European Union, 2022


