Agentic AI platforms have been the highlight of 2025, with their speed and productivity dominating most conversations. However, concerns around privacy and security hardly find a mention.
Recent analysis by US-based web browser company Brave has flagged several risks in current AI browsers.
The company had launched its own browser built-in AI assistant, Leo, two years ago. The AI platform, facially, has the same premise of being privacy-first as its browser.
Since then, competition in the space has heated up with Perplexity’s Comet AI, OpenAI’s Atlas and Microsoft’s Copilot all launching last year. Unlike its peers, Brave’s blend of privacy features and ad blockers presents it as a strong alternative for a niche user base.
The platform has now taken a strong stance to push for privacy across the agentic AI browser arena with a series of probes.
Security gaps in agentic AI browsers
Brave has shown up vulnerabilities in agentic AI browsers like Comet as grave security concerns. It has identified data leakages in such browsers with something as elementary as a on .
Brave’s findings show that several of the existing agentic AI browsers are not protected against hidden prompt commands. This means cyber threats can be machine-encoded as texts into images, making it easier for cyber thefts to occur with just a screenshot.
While agentic browsers are seeing an aggressive push globally to make security and privacy systems attack-proof, weak spots persist.
“There's something fundamental going wrong here, because you could easily slip in some attacks through screenshots that the user might take on a browser and that might lead to the user's email address, or worse, if you're logged into a banking website or your email account, you can easily leak very personal data through that,” says Shivan Kaul Sahib, VP - Privacy & Security, Brave.
The company claims that these vulnerabilities remain despite having been made public to browser platforms.
Evolving cyber threats
In the last decade, almost all tasks done on or via the internet have been prone to cyber threats. The only thing that has changed is the pace at which the cyberattacks have happened.
Online scammers and attackers have used intricate means to dupe websites, emails, and phone numbers to steal user information. Microsoft’s Digital Defence Report highlights that as cyberattacks will evolve, use of AI agents for attacking will also speed up as such tools exhibit faster adaptability against online defences.
Another layer to the issue is how agentic AI browsers are able to take action without user consent . “If users don't distinguish between simple summarisation, like something that they might do on ChatGPT or some of these AI models. If they don't distinguish between that and the agentic mode, where the browser can take actions on your behalf, such as opening websites, that’s the problem. If an attacker is just able to make the output of the summarisation bad that's not ideal. But that's not that worst. The worst thing that can occur is the attacker can now control your browser and get it to take certain actions. That's the problem,” says Sahib.
Storage of data via agentic AI browsers is another contentious issue. “People have Memories and ChatGPT as a feature because they want the model to know more them. What happens with these AI browsers, increasingly, is that we open up… the most personal life (details). I think that many people would not want to even with close family (and friends) what they do with these large systems. And the fact that this data collection exists opens up the possibility of creating interesting profiles for individuals that have not existed in this way before,” says Robin Staab, PhD researcher at the Secure, Reliable, and Intelligent Systems Lab at ETH Zurich.
Safeguards for AI systems are still developing. Generally, web browsers and AI systems fall in separate regulatory ecosystems. Laws like the European Union’s General Data Protection Regulation govern security standards for browser companies, while AI systems are beginning to see regulations like the EU AI Act.
Agentic AI browsers, on the other hand, combine functionality of both worlds, but don’t fit neatly into either as they are not just models or software but intermediaries between users and the internet.
Despite the global appeal of agentic AI browsers, a global benchmark for regulating them remains absent. “We don't really have yet an approach where we can say with certainty that these systems will respect user privacy, that they will respect the sort of safety expectations of users, and at the same time they are already being brought increasingly into the market. These products have some safeguards in place, but as early leads have already shown, these can be very brittle in practice,” says Staab.
ALSO READ | Wipro CTO believes adoption to AI easy but highlights risks
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
