The Times Australia
Google AI
The Times World News

.

OpenAI’s Atlas browser promises ultimate convenience. But the glossy marketing masks safety risks

  • Written by Uri Gal, Professor in Business Information Systems, University of Sydney



Last week, OpenAI unveiled ChatGPT Atlas[1], a web browser that promises to revolutionise how we interact with the internet. The company’s CEO, Sam Altman, described[2] it as a “once-a-decade opportunity” to rethink how we browse the web.

The promise is compelling: imagine an artificial intelligence (AI) assistant that follows you across every website, remembers your preferences, summarises articles, and handles tedious tasks such as booking flights or ordering groceries on your behalf.

But beneath the glossy marketing lies a more troubling reality. Atlas is designed to be “agentic”, able to autonomously navigate websites and take actions in your logged-in accounts. This introduces security and privacy vulnerabilities that most users are unprepared to manage.

While OpenAI touts innovation, it’s quietly shifting the burden of safety onto unsuspecting consumers who are being asked to trust an AI with their most sensitive digital decisions.

What makes agent mode different

At the heart of Atlas’s appeal is “agent mode”.

Unlike traditional web browsers where you manually navigate the internet, agent mode allows ChatGPT to operate your browser semi-autonomously. For example, when prompted to “find a cocktail bar near you and book a table”, it will search, evaluate options, and attempt to make a reservation.

The technology works by giving ChatGPT access to your browsing context. It can see every open tab, interact with forms, click buttons and navigate between pages just as you would.

Combined with Atlas’s “browser memories” feature, which logs websites you visit and your activities on them, the AI builds an increasingly detailed understanding of your digital life.

This contextual awareness is what enables agent mode to work. But it’s also what makes it dangerously vulnerable.

A perfect storm of security risks

The risks inherent in this design go beyond conventional browser security concerns.

Consider prompt injection attacks[3], where malicious websites embed hidden commands that manipulate the AI’s behaviour.

Imagine visiting what appears to be a legitimate shopping site. The page, however, contains invisible instructions directing ChatGPT to scrape personal data from all open tabs, such as an active medical portal or a draft email, and then extract the sensitive details without ever needing to access a password.

Similarly, malicious code on one website could potentially influence the AI’s behaviour across multiple tabs. For example, a script on a shopping site could trick the AI agent into switching to your open banking tab and submitting a transfer form.

Atlas’s autofill capabilities and form interaction features can become attack vectors. This is especially the case when an AI is making split-second decisions about what information to enter and where to submit it.

The personalisation features compound these risks. Atlas’s browser memories create comprehensive profiles of your behavior: websites you visit, what you search for, what you purchase, and content you read.

While OpenAI promises[4] this data won’t train its models by default, Atlas is still storing more highly personal data in one place. This consolidated trove of information represents a honeypot for hackers.

Should OpenAI’s business model evolve[5], it could also become a gold mine for highly targeted advertising.

OpenAI says it has tried[6] to protect users’ security and has run thousands of hours of focused simulated attacks. It also says it has “added safeguards to address new risks that can come from access to logged-in sites and browsing history while taking actions on your behalf”.

However, the company still acknowledges “agents are susceptible to hidden malicious instructions, [which] could lead to stealing data from sites you’re logged into or taking actions you didn’t intend”.

A downgrade in browser security

This marks a major escalation in browser security risks.

For example, sandboxing is a security approach designed to keep websites isolated and prevent malicious code from accessing data from other tabs. The modern web depends on this separation.

But in Atlas, the AI agent isn’t malicious code – it’s a trusted user with permission to see and act across all sites. This undermines the core principle of browser isolation.

And while most AI safety concerns have focused on the technology producing inaccurate information, prompt injection is more dangerous. It’s not the AI making a mistake; it’s the AI following a hostile command hidden in the environment.

Atlas is especially vulnerable because it gives human-level control to an intelligence layer that can be manipulated by reading a single malicious line of text on an untrusted site.

Think twice before using

Before agentic browsing becomes mainstream, we need rigorous third-party security audits from independent researchers who can stress-test Atlas’s defenses against these risks. We need clearer regulatory frameworks that define liability[7] when AI agents make mistakes or get manipulated. And we need OpenAI to prove, not simply promise, that its safeguards can withstand determined attackers.

For people who are considering downloading Atlas, the advice is straightforward: extreme caution.

If you do use Atlas, think twice before you enable agent mode on websites where you handle sensitive information. Treat browser memories as a security liability and disable them unless you have a compelling reason to share your complete browsing history with an AI. Use Atlas’s incognito mode as your default, and remember that every convenience feature is simultaneously a potential vulnerability.

The future of AI-powered browsing may indeed be inevitable, but it shouldn’t arrive at the expense of user security. OpenAI’s Atlas asks us to trust that innovation will outpace exploitation. History suggests we shouldn’t be so optimistic.

References

  1. ^ ChatGPT Atlas (openai.com)
  2. ^ described (www.abc.net.au)
  3. ^ prompt injection attacks (techcrunch.com)
  4. ^ promises (openai.com)
  5. ^ business model evolve (apnews.com)
  6. ^ says it has tried (openai.com)
  7. ^ define liability (news.bloomberglaw.com)

Read more https://theconversation.com/openais-atlas-browser-promises-ultimate-convenience-but-the-glossy-marketing-masks-safety-risks-268296

Times Magazine

Freak Weather Spikes ‘Allergic Disease’ and Eczema As Temperatures Dip

“Allergic disease” and eczema cases are spiking due to the current freak weather as the Bureau o...

IPECS Phone System in 2026: The Future of Smart Business Communication

By 2026, business communication is no longer just about making and receiving calls. It’s about speed...

With Nvidia’s second-best AI chips headed for China, the US shifts priorities from security to trade

This week, US President Donald Trump approved previously banned exports[1] of Nvidia’s powerful ...

Navman MiVue™ True 4K PRO Surround honest review

If you drive a car, you should have a dashcam. Need convincing? All I ask that you do is search fo...

Australia’s supercomputers are falling behind – and it’s hurting our ability to adapt to climate change

As Earth continues to warm, Australia faces some important decisions. For example, where shou...

Australia’s electric vehicle surge — EVs and hybrids hit record levels

Australians are increasingly embracing electric and hybrid cars, with 2025 shaping up as the str...

The Times Features

Freak Weather Spikes ‘Allergic Disease’ and Eczema As Temperatures Dip

“Allergic disease” and eczema cases are spiking due to the current freak weather as the Bureau o...

The Man Behind Sydney’s New Year’s Eve Midnight Moment: Jono Ma

When the clock strikes midnight on New Year’s Eve, Sydney will ring in 2026 powered by a high-volt...

Australians Can Choose Their Supermarket — But Have Little Independence With Electricity

Australians can choose where they shop for groceries. If one supermarket lifts prices, reduces q...

Sweeten Next Year’s Australia Day with Pure Maple Syrup

Are you on the lookout for some delicious recipes to indulge in with your family and friends this ...

Operation Christmas New Year

Operation Christmas New Year has begun with NSW Police stepping up visibility and cracking down ...

FOLLOW.ART Launches the Nexus Card as the Ultimate Creative-World Holiday Gift

For the holiday season, FOLLOW.ART introduces a new kind of gift for art lovers, cultural supporte...

Bailey Smith & Tammy Hembrow Reunite for Tinder Summer Peak Season

The duo reunite as friends to embrace 2026’s biggest dating trend  After a year of headlines, v...

There is no scientific evidence that consciousness or “souls” exist in other dimensions or universes

1. What science can currently say (and what it can’t) Consciousness in science Modern neurosci...

Brand Mentions are the new online content marketing sensation

In the dynamic world of digital marketing, the currency is attention, and the ultimate signal of t...