man holding laptop computer with both hands
Photo by Saksham Choudhary on Pexels.com

Learn how AI browsers such as Perplexity Comet and OpenAI Atlas are changing the cybersecurity landscape

AI-powered browsers like Perplexity Comet and OpenAI Atlas promise a smarter, more automated web experience. They can search, fill out forms, remember your habits, connect to your email or calendar, and act as your digital assistant. But this new generation of browsers also introduces unprecedented security and privacy risks: their built-in memory, autonomous actions, and access to online services create new pathways for data leakage and manipulation.

Why These New Tools Change the Security Landscape

An AI browser no longer just displays web pages, it behaves like a mini-agent operating on your device and within your connected services (email, calendar, etc.). While convenient, this shifts the security boundary from your device to the AI system itself: the more capable and connected it becomes, the more attractive it is to attackers seeking to extract sensitive information or hijack automated actions.

For instance, Atlas includes both a “browser memory” and an “agent mode”. It observes your activity, retains information, and can act on your behalf. Comet follows a similar logic. These assistants can be helpful, but they also expose users to prompt manipulation attacks, where malicious instructions are hidden in web content and interpreted by the AI as legitimate actions. Even with built-in controls, most users keep default settings, and early tests already show that some protections fail in real-world conditions.

Beyond Phishing: The New Threats to Watch

The risk is not limited to password theft. Attackers are increasingly targeting the AI agent’s behavior, which has broad permissions over your data: browser memory, emails, calendars, and other connected services.
A common attack, known as a prompt injection, hides a malicious command in a web page or URL. The AI then executes it unknowingly, revealing sensitive data or performing unauthorized actions.

These hidden commands can be deceptively simple: encoded text or invisible instructions that evade traditional filters but are readable by the AI. As a result, the boundary between what is private and what can be transmitted externally becomes dangerously blurry.

Recent Examples: When a Single URL Is Enough

Researchers recently demonstrated a technique called CometJacking, showing that a single malicious link can trigger the AI agent to extract everything it can access, including emails, calendars, and browsing history.
No password theft is required, since the AI already holds the keys. Other experiments have shown that invisible tags or hidden screenshots can trick the AI into sending sensitive data to external servers.

The arrival of Atlas has prompted widespread concern among experts and journalists alike. Its persistent memory and autonomous agent mode greatly expand the attack surface compared to traditional browsers. It is therefore essential to govern data access, control what the AI retains or deletes, and impose strict limits on its actions, otherwise users risk handing too much power to an unpredictable assistant.

How to Secure Your Digital Environment

Three major elements deserve close attention: the agent, the memory, and the connectors.

  • Agent: Clearly define what the AI is allowed to do. Avoid automatic actions without validation.
  • Memory: Limit retention duration, encrypt sensitive data, and separate contexts (personal vs professional) to prevent data mixing.
  • Connectors: Minimize permissions for linked services (email, calendars, cloud storage). Grant only what is strictly necessary.

The Five Main Attack Scenarios Identified by Researchers

  1. URL injection: malicious commands hidden within links.
  2. Page injection: invisible text or code readable by the AI.
  3. Memory exploitation: using stored data as a side channel.
  4. Connector abuse: extracting files, emails, or calendar data.
  5. Automated sensitive actions: such as approving transactions or changing account settings.

For each of these, defenses must ensure that the AI cannot act alone, extract, or transmit data without supervision.

Settings That Make a Difference

Read-only vs Read-write modes:
In Atlas, you can restrict the agent to “logged-out” mode, preventing it from writing or modifying content in your session or connected services. The difference is clearly stated in settings (“logged out”: limited access; “logged in”: extended access with write permissions).

Access to sensitive services (email, calendars, etc.):
You can control which connectors (Gmail, calendar, storage) are linked via OAuth authorization. Only connect essential services, and in both Atlas and Comet, you can revoke these permissions at any time through the settings menu.

Agent memory purge:
Both Atlas and Comet allow you to erase stored data. “Browser memories” can be reset or automatically deleted after each session (“auto-delete” or “clear memory now”).

Prompt, page, and URL filtering:
Browsers like Brave and LayerX already include anti-injection filters and options to block or monitor what the AI agent can read. In Atlas, features such as page visibility and content summarization can be fine-tuned to reduce exposure.

Isolation for sensitive activity:
This is not only possible, it is recommended. Use private browsing, run the agent in disconnected mode, or leverage emote browser isolation (RBI) to contain part of its actions.

Prevention First: Stay in Control When Using AI Browsers

Security architecture is not just an enterprise issue. Individual users, professionals and consumers alike, must validate every permission, segment their contexts, and maintain control over what their AI agent can see and do.
The more integrated these assistants become in daily life, the greater the need for vigilance over data access and memory retention.
And remember, it remains essential to stay alert to the different settings of AI browsers, the permissions you grant them, and the information you decide to share.

And Where Does Reemo Fit In? A Secure Execution Framework

In the enterprise context, a secure access framework must combine execution isolation, network segmentation, fine-grained permission control, and full session traceability.
The goal is not to add yet another tool, but to secure Atlas and Comet browsers. Encapsulate AI browsers within a controlled, observable, and revocable access perimeter, so organizations can benefit from their capabilities without opening a new attack plane. At Reemo, our mission is precisely this: to give teams a secure, governed environment where even the most advanced digital assistants operate within a trusted execution boundary.

Because with AI-driven tools, the question is no longer whether they can act for you, but whether you can still see, control, and contain what they do.

Book a demo of Reemo – Réservez une démo de Reemo

One response to “AI Browsers: Comet, Atlas, What Are the Risks for Your Data and Digital Life?”

  1. […] The term Shadow AI refers to the use of unapproved artificial intelligence tools by employees or departments, outside the governance scope of IT or security. (See also our article on AI browsers like Comet and Atlas) […]

Leave a Reply

Trending

Discover more from Reemo blog

Subscribe now to keep reading and get access to the full archive.

Continue reading