
AI browsers can log into your accounts, fill out forms, and buy things on their own, and security researchers keep tricking them into doing it on fake sites. That's the whole problem in one sentence. The convenience is real. So is the new attack surface it opens on your business.
If your team is starting to use agentic browsers like Perplexity's Comet or the AI modes bolted onto Chrome and Edge, here's what changes about your security, and what to do about it.
What is an AI browser?
An AI browser is one that acts, not just displays. A regular browser shows you a page and waits. An agentic browser reads the page, decides what to do, and does it: clicks links, fills forms, logs into accounts, adds to cart, and completes checkout, all from a plain-language instruction like "reorder my usual supplies."
That's a genuine productivity jump. It's also a shift in who's making decisions. The moment a browser can act on your behalf, anything that can fool the browser can act on your behalf too. And browsers, it turns out, are easy to fool.
What did researchers actually find?
They found AI browsers hand over money and credentials to fake sites without a human ever checking. In its "Scamlexity" research, Guardio Labs pointed Perplexity's Comet at a fabricated online store and it completed the purchase automatically, then entered data on a real phishing page, with no human approval step.
The technique behind it is called prompt injection. Attackers hide instructions inside a page, in a fake captcha, in text the user never sees, and the agent reads those instructions as commands and follows them. Guardio's "PromptFix" test did exactly that: a bogus captcha carried hidden orders, and the browser obeyed.
It got worse. In a follow-up, a Guardio researcher tricked Comet into a phishing scam in under four minutes by watching the agent narrate its own reasoning and using that to shape a page it would trust. Here's the part that should stop you: once a fake page beats a given AI browser, it beats every user running that same browser. The target moves from your people to the software itself.
Why is this different from normal phishing?
Normal phishing has to fool a person. AI-browser attacks only have to fool the agent, once. Your security awareness training teaches people to slow down, check the sender, and hover over links. An AI browser doesn't hesitate, doesn't get a bad feeling, and doesn't check with anyone. It's built to complete the task.
So the human circuit breaker you've spent years building, the employee who pauses and thinks "this looks off," gets bypassed entirely. The agent runs at machine speed toward "done." That's the same instinct attackers already exploit with malvertising and SEO poisoning, except now there's no person in the loop to catch it.
Should small businesses ban AI browsers?
Not necessarily, but you should decide on purpose instead of finding out later. The wrong move is doing nothing while employees quietly install agentic browsers and point them at company email, banking, and SaaS logins. Shadow adoption is how this becomes your problem without anyone choosing it.
A workable middle path: allow AI browsers for low-stakes, read-only tasks, research, summarizing, drafting, and keep them away from anything that moves money or touches credentials. No autonomous checkout. No logging into your bank or payroll. No standing access to the email account that can reset every other password.
How do we use AI browsers safely?
Keep a human on the actions that matter and limit what the agent can reach. The tools are new and the guardrails are thin, so the safest posture treats an agentic browser like a fast, capable intern who is also weirdly gullible: useful, supervised, and not handed the company card.
Practical controls that hold up:
- Require human approval for sensitive actions — purchases, logins, and anything involving payment or personal data get a person's explicit yes, not the agent's judgment.
- Separate accounts — don't let the AI browser run in the same session that has standing access to banking, payroll, or admin consoles.
- Keep strong authentication on — phishing-resistant MFA and passkeys still matter, because credential theft is the goal. Related: how attackers get around MFA with session hijacking.
- Write it into your acceptable-use policy — say plainly which tools are allowed and for what, so "I didn't know" isn't the after-action report.
- Update the training — your team should know an AI browser can be scammed on their behalf, and that "the browser did it" is still their action.
None of this requires banning the technology. It requires deciding where an autonomous agent is allowed to act, and making sure the expensive decisions still route through a human.
By Karla Gilvergara. Karla covers AI tools and AI-driven fraud at The NetSys Group, which has delivered managed IT, cybersecurity, and cloud services since 1998 to businesses across NY, NJ, CT, PA, and Southwest Florida.
Frequently asked questions
What is an agentic AI browser?
It's a browser that takes actions for you instead of just showing pages. Given a plain-language request, it navigates sites, fills forms, logs in, and can complete purchases on its own. Perplexity's Comet is a well-known example, and Chrome and Edge are adding similar agentic features.
Can an AI browser really be scammed?
Yes, and repeatedly in testing. Guardio Labs showed Perplexity's Comet completing a purchase on a fake store and entering data on a phishing page with no human approval. The attack method, prompt injection, hides instructions inside a page that the agent reads and obeys.
What is prompt injection?
Prompt injection is hiding malicious instructions inside content an AI reads, so it treats attacker text as commands. On a web page, that can be invisible text or a fake captcha carrying orders the agent follows. It's the core weakness behind most AI-browser attacks documented so far.
Should I let employees use AI browsers for work?
Only with limits. Allow them for read-only tasks like research and drafting, and keep them away from banking, payroll, credentials, and autonomous purchases. Put the rules in your acceptable-use policy so adoption is a decision you made, not one that happened to you.
Does MFA still protect us?
It still matters, but it isn't a full answer here. Strong, phishing-resistant MFA and passkeys make stolen credentials harder to reuse, which is exactly what these attacks are after. Pair authentication with limits on what the agent can access and human approval for sensitive actions.
Not sure how AI tools are already being used inside your business? Contact The NetSys Group for a complimentary security assessment and we'll map the exposure before it costs you. See our cybersecurity services for how we help.
Turn insight into action.
Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.



