Your Browser Has a Mind of Its Own Now: What AI Agents Can Actually Do (and What's Already Gone Wrong)

AI tools can now click, type, and navigate your browser on their own — Claude in Chrome, Perplexity Comet, and OpenAI's new ChatGPT Work agent all do it today. Here's what these tools actually do, where it's already gotten weird, and why two of the biggest players just killed their standalone AI browsers in the last few months.

Your Browser Has a Mind of Its Own Now: What AI Agents Can Actually Do (and What's Already Gone Wrong)

Until recently, every AI tool you used worked the same basic way: you typed a question, it typed back. Even the fancier ones — the ones that could "search the web" for you — were still just fetching text and handing it to you to act on.

That's no longer true. A growing set of AI tools can now open your browser, click things, fill in forms, navigate between tabs, and carry out multi-step tasks — on their own, using your actual accounts and your actual screen. Not "search and summarize." Click. Type. Submit.

If that sounds like a small technical upgrade, it isn't. It's a different category of tool, and it's moving fast enough that two of the biggest names in the space have already discontinued their first attempts at it — in just the last few months. Here's what's actually real right now, what it's genuinely useful for, where it's already gotten uncomfortable, and what I'd actually do about it if I ran a small business.

What These Tools Actually Do

A few concrete, currently-available examples, as of mid-2026:

  • Claude in Chrome (Anthropic) is a browser extension that can navigate to websites, read what's on screen, click buttons, fill out forms, manage multiple tabs, and run multi-step workflows while you do something else — including scheduled tasks that repeat on their own. It works alongside Claude Code and Claude Desktop for handoffs between coding and browsing work.
  • Perplexity Comet launched as a full AI-native browser and has since expanded into an in-page assistant that can research, summarize, and carry out autonomous multi-step tasks like booking flights, managing email, filling forms, and comparing products across sites.
  • ChatGPT's agentic browsing started life as "Atlas," a standalone browser OpenAI shipped with an agent mode that could complete end-to-end tasks — planning a meal, building the shopping list, adding it all to a cart. OpenAI discontinued Atlas as a separate product in July 2026, folding the same capability into a new agent called ChatGPT Work and a Chrome extension instead.
  • Google ran a similar experiment called Project Mariner, an agent that could operate a browser on Gemini's behalf. Google shut it down in May 2026 and absorbed the underlying tech into Gemini Agent and Google's AI Mode in Search, alongside a related "Auto Browse" feature now built into Chrome itself.

Notice the pattern: within the space of about ten weeks, two major standalone "AI browser" products got killed off — not because the underlying capability failed, but because it made more sense as a feature inside tools people already use than as a whole new browser to switch to. That's worth remembering any time a product tries to sell you on an entirely new browser: the capability tends to outlive the container.

The Genuinely Useful Part

Used well, this is closer to delegating a task to a competent assistant than talking to a chatbot. Concrete, unglamorous, real uses: filling out a repetitive form with data pulled from another tab, checking prices across a handful of vendor sites and building a comparison, drafting and scheduling a batch of routine emails, or running the same research task every morning without you opening a single tab yourself. None of it is flashy. All of it is time.

The Part That Gets Weird

The uncomfortable part isn't the useful stuff — it's what happens when an agent that can act on your behalf reads something it shouldn't trust. Security researchers have already demonstrated this isn't theoretical. Brave's security team showed that Perplexity Comet could be manipulated through indirect prompt injection: hiding invisible instructions inside a webpage that the agent reads as part of "summarizing this page," then having the agent quietly carry out an unrelated, sensitive action — in their demonstration, fetching a one-time password — because it couldn't tell the difference between the page's real content and an attacker's hidden command.

That's the core risk with every tool in this category: an agent that can click and type with your logged-in session is also an agent that can be tricked into clicking and typing with your logged-in session. The industry has responded — Anthropic, for instance, has built in defenses against prompt injection and requires explicit user permission before Claude in Chrome will take higher-risk actions, and lets you restrict which sites it can act on at all — but "researchers can still find ways in" is the honest state of the technology right now, not a solved problem.

What's Actually Changed in the Last Few Months

This is a good moment to notice how fast the ground has shifted just since spring:

  • May 2026: Google quietly retired Project Mariner as a standalone product, folding its agent tech into Gemini Agent and Chrome's built-in Auto Browse.
  • July 2026: OpenAI discontinued the Atlas browser entirely (it stops working in August), replacing it with ChatGPT Work and a Chrome extension.
  • Ongoing: Claude in Chrome and Perplexity Comet remain live, with Comet having completed a full cross-platform rollout (desktop, Android, iOS) and expanded into enterprise use.

The direction is clear even if the products keep changing names: this capability isn't going away, and it's converging toward living inside the browsers and assistants people already have open, rather than asking anyone to adopt a brand-new one.

What This Means If You Run a Small Business

Treat any AI agent you grant browser access to the same way you'd treat a new employee's first week: useful for bounded, well-defined tasks, not yet the one you hand your banking login to unsupervised. A few practical rules worth following right now — limit which sites an agent can act on rather than granting blanket access, keep it off anything tied to payments or account credentials until you've watched it work on lower-stakes tasks first, and treat any request for a one-time password or verification code as a hard stop, human-only action, regardless of what asked for it. If you're evaluating one of these tools for your business, that's a conversation worth having before you turn on "agent mode" and walk away from the screen.

My Take

This is the most significant shift in what AI tools do since the original chatbot boom — not because it's flashy, but because it changes what these tools are allowed to touch. A chatbot that gives bad advice wastes your time. A browser agent that gets fooled by a hidden instruction can act on your accounts. Both the usefulness and the risk are real, and right now they're growing at the same pace. Worth using for the boring, repetitive, low-stakes stuff. Worth watching closely, and keeping on a short leash, for everything else.

Curious whether any of this is worth building into how your business runs — or whether it's a distraction dressed up as a shortcut? Get in touch and we can talk through what actually makes sense for your setup.

Get In Touch