Skip to content
TrendSeries: AI Interfaces, Devices & Personal Computing

AI Browsers: What AI-Native Browsers Can Do, and Why Companies Block Them

By Published 12 min read
A browser window with an agent's dotted path running from a tab to form fields and a final lit button — AI browsers
On this page

An AI browser is a web browser with a built-in AI assistant that can read the pages you're on and take actions for you: researching across tabs, filling forms, building shopping carts. In September 2026 the main options are Perplexity's Comet, Chrome with Gemini, Edge's Copilot Mode, Dia and Opera Neon; OpenAI's Atlas has already closed.

This guide compares the AI browsers available in 2026, shows what their agents can and can't do, explains the security problem that led Gartner to advise blocking them, covers what happens when an AI browser tries to shop, and sets out what it means for businesses, websites and users in the UAE.

Key takeaways

  • The first shake-out has happened. OpenAI shut its Atlas browser on 9 August 2026, less than a year after launch, and folded browsing into ChatGPT's desktop app.
  • Incumbents are adding agents. Chrome's Gemini "auto browse" and Edge's Copilot Mode bring agent features to browsers people already use, while standalone AI browsers have no measurable market share.
  • Agents pause before anything that matters. Comet and Chrome stop for confirmation before purchases, messages and posts — and agents are still slow and fail most long tasks.
  • Security is the brake. Prompt injection hidden in web pages keeps hijacking browser agents; OpenAI and the UK's NCSC say it may never be fully solved, and Gartner told companies to block AI browsers for now.
  • UAE users get partial access. Gemini in Chrome arrived in the Arab World in June 2026 in English first; Chrome's auto browse is US-only.

What is an AI browser?

An AI browser is a web browser whose built-in assistant can see the page and tab context you're working in and act on it — answering questions about what's open, and increasingly navigating, clicking and typing for you.

Definition

AI browser (or agentic browser) — a browser with an integrated AI assistant that uses the content of your open pages as context and can take actions on the web for you, such as navigating, filling forms or adding items to a cart. Vendors call the action mode "agent mode", "auto browse", "Actions" or simply the assistant; no standards body defines the term.

There are three ways to get one:

TypeExamplesHow it worksTrade-off
Standalone AI browserPerplexity Comet, Dia, Opera NeonA new browser built around the assistantSwitching cost; smaller vendors
AI built into a mainstream browserChrome with Gemini, Edge Copilot ModeAgent features added to the browser you already useFeature rollout is gradual and region-limited
Assistant extension or sidebarClaude in Chrome, ChatGPT's Chrome sidebarAn AI assistant that works inside an existing browserDepends on the extension's permissions

Which AI browsers are available in 2026?

Five matter for most people in September 2026, with very different access rules; OpenAI's Atlas is no longer one of them.

BrowserMakerAgent featureStatus and access
CometPerplexityComet Assistant can research, fill forms and complete tasksFree worldwide since October 2025 on Mac, Windows, Android and iOS; Enterprise edition
Chrome with GeminiGoogleAuto browse (preview)Gemini in Chrome widely available, including the UAE; auto browse for US adults on Google AI Pro (20 tasks a day) or Ultra (200)
Edge Copilot ModeMicrosoftActions and Journeys; agentic browsing for businessOpt-in; consumer actions launched as a US preview; Edge for Business agentic browsing in limited preview outside the EEA
DiaThe Browser Company (Atlassian)Assistant with context from your toolsGenerally available on macOS; AI features on paid plans at $20 or $100 a month
Opera NeonOperaExperimental agent that completes browsing tasksPublic, subscription-only at $19.90 a month

Brave's AI browsing is in opt-in early testing, and Firefox's Smart Window is a beta assistant rather than an action-taking agent.

What happened to ChatGPT Atlas?

OpenAI launched Atlas on macOS in October 2025, promising Windows and mobile versions "soon". In July 2026 it announced it was deprecating Atlas and moving browser-based agent work into the ChatGPT desktop app and a ChatGPT extension and sidebar for Chrome; Atlas stopped working on 9 August 2026. It never shipped beyond the Mac. The lesson for buyers is the same as with personal AI agents: new AI products can disappear quickly, so avoid building routines you can't move.

Who owns Dia?

Atlassian, the maker of Jira. It agreed to buy The Browser Company, maker of Dia and Arc, in September 2025 and completed the deal on 20 October 2025. Atlassian's filings put the total purchase price at $488.3 million.

What can AI browsers actually do?

AI browsers are good at research and routine web chores, and deliberately stop before anything consequential; on long, multi-step tasks they are still slow and unreliable.

What works well:

  • Summarising and comparing information across open tabs.
  • Filling in forms with information you provide.
  • Building carts and itineraries for you to review.
  • Working in web email and calendars — drafting, scheduling, sorting.

Where they stop. Comet always pauses for confirmation before sending emails or messages, changing calendars, placing final orders or entering personal details it doesn't know. Chrome's auto browse pauses and asks before purchases and social-media posts. That's by design: the confirmation step is a security control.

How reliable they are. Reviewers found early agents slow — The Verge's hands-on found Atlas took 10 minutes to add three items to an Amazon cart. On OSWorld 2.0, a 2026 benchmark of long computer workflows that take people a median of about 1.6 hours, the best agent completed only 20.6%. The AI-native operating systems guide explains why short-task benchmark scores overstate what agents can do.

Are AI browsers safe?

Not fully, and not yet: an AI browser reads untrusted web content and holds your logged-in sessions, so hidden instructions on a page can steer it against you — a problem known as indirect prompt injection.

  • It keeps happening. Security researchers at Brave showed in August 2025 that hidden text in a Reddit comment could make Comet reveal the user's email address and a one-time login code, then read Gmail. Similar attacks have been shown against other AI browsers since.
  • It's on the open web. A 2026 study scanning 1.2 billion URLs found 15,300 confirmed hidden-instruction cases on 11,700 pages.
  • It may never be fully fixed. OpenAI has said prompt injection is unlikely ever to be fully "solved", comparing it to scams, and the UK's National Cyber Security Centre says it may never be mitigated the way SQL injection was.
  • Defences are improving. Google checks each Chrome agent action with a separate "User Alignment Critic" model, limits which sites an agent can touch and pays up to $20,000 for serious bugs. Anthropic cut the attack success rate on Claude in Chrome from 23.6% to 11.2% with mitigations at launch, and to about 1% later — which it still calls meaningful risk.

Common misconception

"The patches made AI browsers safe." Each fix closes one route, not the class of attack. Keep agent features for low-risk tasks, leave confirmation prompts on, and don't let a browser agent act on accounts that hold money, client data or admin rights.

Should companies block AI browsers?

Gartner's advice in December 2025 was blunt: its analysts titled a note "Cybersecurity Must Block AI Browsers for Now", warning that default settings prioritise user experience over security, that AI sidebars send page content, history and open tabs to the cloud, and that agents can take mistaken or malicious actions.

Nine months on, managed options exist, which gives security teams a middle path:

ControlWhere it existsWhat it does
Allow actions only on approved domainsComet Enterprise; Edge for Business; Chrome policiesKeeps the agent away from sensitive systems
Agent features off by defaultChrome for managed users (auto browse); Edge for BusinessNothing runs until IT enables it
Deploy and manage centrallyComet Enterprise via device management; Edge and Chrome policiesStandard configuration across devices
Audit and telemetryComet Enterprise; Microsoft and Google admin toolsA record of what the agent did

A sensible policy for 2026: block unmanaged AI browsers on company devices, allow a managed option for research and summarisation, restrict agent actions to an approved-sites list, and review logs. The AI governance guide covers the wider controls.

Can an AI browser shop for you?

Yes, up to the final click — but retailers and courts are still deciding how much access shopping agents get.

  • Retailers set terms. Amazon's Conditions of Use now require agents to identify themselves as agents in every request and not conceal it; its robots.txt disallows several AI user agents. eBay's user agreement bans buy-for-me agents and LLM-driven bots that place orders without human review.
  • The courts are involved. Amazon sued Perplexity over Comet's shopping in November 2025 and won a preliminary injunction in March 2026, but the Ninth Circuit vacated it in August, finding that on the facts before it the user — not Perplexity — accessed Amazon's systems. The case continues.
  • Websites want to know who's visiting. Cloudflare's signed agents let sites cryptographically recognise agent traffic and decide what to allow.
  • Shoppers aren't ready to delegate. Only 11% of US consumers were willing to let AI make purchase decisions, even for low-stakes categories, in a Gartner survey published in May 2026.

The commerce side — protocols, payments and liability — is covered in agent-to-agent transactions, and what it means for sellers in machine customers.

What does the latest data show?

Agent features are spreading through mainstream browsers, but standalone AI browsers are too small to register in market-share data.

What the data shows

  • Market share (August 2026, page views): Chrome 69.39%, Safari 15.83%, Edge 5.36%, Firefox 2.98% worldwide; in the UAE, Chrome 78.72%, Safari 10.21%, Edge 2.53%. No AI-native browser appears in either ranking. — StatCounter
  • Consumer appetite (survey, published May 2026): 11% of US consumers willing to let AI make purchase decisions. — Gartner
  • Threat prevalence (study, April 2026): 15,300 confirmed hidden prompt-injection instances on 11,700 pages across 1.2 billion URLs scanned. — arXiv
  • Reliability (June 2026): best agent completes 20.6% of long real-world computer workflows. — OSWorld 2.0

What this means

The browser war isn't being won by new AI browsers; it's being absorbed by the incumbents. For most people, the AI browser they'll actually use is Chrome, Edge or Safari with agent features switched on — which puts the security and policy questions onto the browsers companies already manage.

What does this mean for the UAE?

UAE users can use most AI browsers in English, but the headline agent features are gated by country and language.

  • Chrome. Google began rolling out Gemini in Chrome to desktop and iOS users in the Arab World on 11 June 2026, in English first. Auto browse is available only to adults in the US.
  • Edge. Microsoft's agentic browsing for Edge for Business is in limited preview worldwide except the EEA, so UAE organisations with Microsoft 365 Copilot appear eligible.
  • Comet. Free worldwide, including the UAE; Perplexity hasn't announced Arabic-specific features.
  • Regulation. We found no UAE guidance specific to AI browsers or prompt injection; company policy has to fill the gap, alongside data-protection obligations for what browser assistants send to the cloud.

What should businesses and websites do about AI browsers?

Treat AI browsers as both a security question for your staff and a new kind of visitor to your website.

  1. Set a browser policy. Decide which AI browsers and agent features are allowed on company devices, and enforce it through device management.
  2. Limit agent actions. Approved-domain lists for agents; no agent actions on banking, admin consoles or client databases.
  3. Keep confirmations on for sends, purchases and submissions.
  4. Make your website agent-friendly. Clear forms, labelled fields, structured data and accurate prices help agents complete tasks correctly; decide whether to allow, verify or block agent traffic.
  5. Test your own site with an AI browser. Watch where the agent gets stuck — the same places often confuse people.

For property businesses: Google's own auto browse examples include filtering apartment listings to match a buyer's criteria. Expect agents to fill in enquiry forms and request viewings on buyers' behalf — make those forms simple, respond fast, and route agent-originated leads the same way as human ones. The AI lead routing guide covers speed-to-lead, and AI search covers how assistants choose which sites to use.

What is likely to happen next?

Expect agent features to roll out country by country inside mainstream browsers, managed enterprise versions to become the norm at work, and websites to demand that agents identify themselves.

  • Wider rollout. Chrome's auto browse and Edge's actions expanding beyond the US and into more languages, including, eventually, Arabic.
  • Checkout protocols in the browser. Google has said Chrome will support its Universal Commerce Protocol, which would let agents check out through retailers' own systems rather than by clicking through pages.
  • Agent identification. Signed agents and rules like Amazon's will push browser agents to declare themselves.
  • Consolidation. Standalone AI browsers will need a distinct advantage to survive; OpenAI has already chosen the app over the browser.

Final takeaway

AI browsers are real but early: they research and fill forms well, pause before anything consequential, and struggle with long tasks. The first standalone flagship, OpenAI's Atlas, is already gone, and the mainstream future looks like Chrome and Edge with agents built in. Prompt injection is the unsolved problem, which is why Gartner said block them for now. Use managed versions at work, keep agents on low-risk tasks with confirmations on, and make your own website easy for well-behaved agents to use.

AI strategy

Working out where AI fits in your business?

I help teams separate the use cases worth automating from the ones that only demo well — then build the workflow, the integrations and the guardrails.

Sources

Primary sources checked for this article. Figures reflect the dates shown.

  1. Introducing Comet: Browse at the speed of thought — Perplexity, July 9, 2025
  2. The Internet is Better on Comet — Perplexity, October 2, 2025
  3. Mitigating Prompt Injection in Comet — Perplexity, October 22, 2025
  4. Comet Enterprise is here — Perplexity, March 17, 2026
  5. Introducing ChatGPT Atlas — OpenAI, October 21, 2025
  6. Evolving Atlas into ChatGPT for browser-based agentic work — OpenAI Help Center, July 9, 2026
  7. The ChatGPT Atlas browser still feels like Googling with extra steps — The Verge, October 23, 2025
  8. Atlassian Quarterly Report (Form 10-Q) for the period ended December 31, 2025 — U.S. Securities and Exchange Commission, February 6, 2026
  9. Dia Browser | Plans — The Browser Company
  10. Opera opens public access to Opera Neon, its agentic AI browser — Opera, December 11, 2025
  11. Meet Copilot Mode in Edge: Your AI browser — Microsoft Edge Blog, October 23, 2025
  12. New in Edge for Business: AI for work, safe from day one — Microsoft Edge Blog, May 20, 2026
  13. Chrome gets new Gemini 3 features, including auto browse — Google, January 28, 2026
  14. Ask Gemini in Chrome to complete tasks for you with auto browse — Google Gemini Apps Help
  15. Gemini in Chrome for enterprises — Google Chrome Enterprise Help
  16. Gemini is coming to Chrome in the Arab World — Google MENA, June 11, 2026
  17. Classic, Private, or Smart? Choose the Right Firefox Window — Mozilla, September 24, 2026
  18. Browser Market Share Worldwide — StatCounter Global Stats
  19. Browser Market Share United Arab Emirates — StatCounter Global Stats
  20. Agentic Browser Security: Indirect Prompt Injection in Perplexity Comet — Brave, August 20, 2025
  21. Indirect Prompt Injection in the Wild: An Empirical Study of Prevalence, Techniques, and Objectives — arXiv, April 29, 2026
  22. Continuously hardening ChatGPT Atlas against prompt injection attacks — OpenAI, December 22, 2025
  23. Prompt injection is not SQL injection (it may be worse) — National Cyber Security Centre (UK), December 8, 2025
  24. Architecting Security for Agentic Capabilities in Chrome — Google Security Blog, December 8, 2025
  25. Piloting Claude in Chrome — Anthropic, August 25, 2025
  26. Mitigating prompt injections in browser use — Anthropic, November 24, 2025
  27. Block all AI browsers for the foreseeable future: Gartner — The Register, December 8, 2025
  28. Cybersecurity Must Block AI Browsers for Now — Gartner, December 1, 2025
  29. Gartner Survey Finds Consumers Want AI Shopping Help, But Not AI Purchase Decisions — Gartner, May 27, 2026
  30. Conditions of Use — Amazon
  31. User Agreement — eBay
  32. Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (opinion) — U.S. Court of Appeals for the Ninth Circuit, August 4, 2026
  33. The age of agents: cryptographically recognizing agent traffic — Cloudflare, August 28, 2025
  34. OSWorld 2.0: Benchmarking Computer Use Agents on Long-Horizon Real-World Tasks — arXiv, June 28, 2026
Share
  • #AI Agents
  • #Browsers
  • #Security
  • #E-commerce
  • #Enterprise AI

FAQ

Frequently asked questions

Keep reading

Next step

Have a project in mind? Let's build something great together.

Book a free consultation call — get a clear, honest read on your lead-gen, SEO or web project within 24 hours.