Read The Times Australia

Daily Bulletin

OpenAI’s Atlas browser promises ultimate convenience. But the glossy marketing masks safety risks

  • Written by: Uri Gal, Professor in Business Information Systems, University of Sydney

Last week, OpenAI unveiled ChatGPT Atlas, a web browser that promises to revolutionise how we interact with the internet. The company’s CEO, Sam Altman, described it as a “once-a-decade opportunity” to rethink how we browse the web.

The promise is compelling: imagine an artificial intelligence (AI) assistant that follows you across every website, remembers your preferences, summarises articles, and handles tedious tasks such as booking flights or ordering groceries on your behalf.

But beneath the glossy marketing lies a more troubling reality. Atlas is designed to be “agentic”, able to autonomously navigate websites and take actions in your logged-in accounts. This introduces security and privacy vulnerabilities that most users are unprepared to manage.

While OpenAI touts innovation, it’s quietly shifting the burden of safety onto unsuspecting consumers who are being asked to trust an AI with their most sensitive digital decisions.

What makes agent mode different

At the heart of Atlas’s appeal is “agent mode”.

Unlike traditional web browsers where you manually navigate the internet, agent mode allows ChatGPT to operate your browser semi-autonomously. For example, when prompted to “find a cocktail bar near you and book a table”, it will search, evaluate options, and attempt to make a reservation.

The technology works by giving ChatGPT access to your browsing context. It can see every open tab, interact with forms, click buttons and navigate between pages just as you would.

Combined with Atlas’s “browser memories” feature, which logs websites you visit and your activities on them, the AI builds an increasingly detailed understanding of your digital life.

This contextual awareness is what enables agent mode to work. But it’s also what makes it dangerously vulnerable.

A perfect storm of security risks

The risks inherent in this design go beyond conventional browser security concerns.

Consider prompt injection attacks, where malicious websites embed hidden commands that manipulate the AI’s behaviour.

Imagine visiting what appears to be a legitimate shopping site. The page, however, contains invisible instructions directing ChatGPT to scrape personal data from all open tabs, such as an active medical portal or a draft email, and then extract the sensitive details without ever needing to access a password.

Similarly, malicious code on one website could potentially influence the AI’s behaviour across multiple tabs. For example, a script on a shopping site could trick the AI agent into switching to your open banking tab and submitting a transfer form.

Atlas’s autofill capabilities and form interaction features can become attack vectors. This is especially the case when an AI is making split-second decisions about what information to enter and where to submit it.

The personalisation features compound these risks. Atlas’s browser memories create comprehensive profiles of your behavior: websites you visit, what you search for, what you purchase, and content you read.

While OpenAI promises this data won’t train its models by default, Atlas is still storing more highly personal data in one place. This consolidated trove of information represents a honeypot for hackers.

Should OpenAI’s business model evolve, it could also become a gold mine for highly targeted advertising.

OpenAI says it has tried to protect users’ security and has run thousands of hours of focused simulated attacks. It also says it has “added safeguards to address new risks that can come from access to logged-in sites and browsing history while taking actions on your behalf”.

However, the company still acknowledges “agents are susceptible to hidden malicious instructions, [which] could lead to stealing data from sites you’re logged into or taking actions you didn’t intend”.

A downgrade in browser security

This marks a major escalation in browser security risks.

For example, sandboxing is a security approach designed to keep websites isolated and prevent malicious code from accessing data from other tabs. The modern web depends on this separation.

But in Atlas, the AI agent isn’t malicious code – it’s a trusted user with permission to see and act across all sites. This undermines the core principle of browser isolation.

And while most AI safety concerns have focused on the technology producing inaccurate information, prompt injection is more dangerous. It’s not the AI making a mistake; it’s the AI following a hostile command hidden in the environment.

Atlas is especially vulnerable because it gives human-level control to an intelligence layer that can be manipulated by reading a single malicious line of text on an untrusted site.

Think twice before using

Before agentic browsing becomes mainstream, we need rigorous third-party security audits from independent researchers who can stress-test Atlas’s defenses against these risks. We need clearer regulatory frameworks that define liability when AI agents make mistakes or get manipulated. And we need OpenAI to prove, not simply promise, that its safeguards can withstand determined attackers.

For people who are considering downloading Atlas, the advice is straightforward: extreme caution.

If you do use Atlas, think twice before you enable agent mode on websites where you handle sensitive information. Treat browser memories as a security liability and disable them unless you have a compelling reason to share your complete browsing history with an AI. Use Atlas’s incognito mode as your default, and remember that every convenience feature is simultaneously a potential vulnerability.

The future of AI-powered browsing may indeed be inevitable, but it shouldn’t arrive at the expense of user security. OpenAI’s Atlas asks us to trust that innovation will outpace exploitation. History suggests we shouldn’t be so optimistic.

Authors: Uri Gal, Professor in Business Information Systems, University of Sydney

Read more https://theconversation.com/openais-atlas-browser-promises-ultimate-convenience-but-the-glossy-marketing-masks-safety-risks-268296

Business News

Inside the Icon: The BridgeMuseum Officially Opens at the Sydney Harbour Bridge

A bold new way to experience one of Australia’s most recognisable landmarks has arrived, with BridgeClimb Sydney officially opening the all-new BridgeMuseum.  Located inside the Sydney Harbour Brid...

Daily Bulletin - avatar Daily Bulletin

Is Your Brand Showing Up in AI Search? Most Melbourne Brands Aren't.

The New Front Door Nobody Told You About Something changed. Quietly. Without a press release. The way buyers find businesses in Australia has been rewired. Not replaced, rewired. Google isn't dead...

Daily Bulletin - avatar Daily Bulletin

How Australian Businesses Can Measure SEO ROI

SEO can feel vague when you are staring at a dashboard full of numbers that do not clearly connect to revenue. The key is to measure the right signals in the right order, then tie them back to outcome...

Daily Bulletin - avatar Daily Bulletin

How Commercial Roller Shutters Improve Site Security Without Slowing Operations

Security upgrades can be frustrating when they make everyday work harder. A door that takes too long to open, creates bottlenecks at shift change, or fails at the worst time can turn “better protectio...

Daily Bulletin - avatar Daily Bulletin

Why a Document Destruction Service Still Matters for Modern Businesses

Businesses generate large volumes of information every day, from staff records and contracts to invoices, reports and customer files. While attention often focuses on how documents are stored, the way...

Daily Bulletin - avatar Daily Bulletin

Bicycle Rack Safety and Space-Smart Storage

Bike storage problems usually show up as small annoyances first: tangled handlebars, scratched frames, and bikes that topple when you pull one out. Over time, those issues become safety risks, especia...

Daily Bulletin - avatar Daily Bulletin

How to Tell if a Childcare Centre Is a Good Fit for Your Child

Choosing childcare can feel like you’re making a huge decision with limited information. Tours are short, centres are often on their best behaviour, and your child might act differently in a new space...

Daily Bulletin - avatar Daily Bulletin

Car Import Timeline: What Usually Happens at Each Stage

Importing a car into Australia can feel confusing because multiple agencies and checkpoints are involved, and the timeline is shaped as much by paperwork quality as it is by shipping speed. The most u...

Daily Bulletin - avatar Daily Bulletin

Portable Toilet Hygiene Standards Explained: Clean vs Sanitised vs Disinfected

In portable toilet servicing, the words clean, sanitised, and disinfected often get used as if they mean the same thing. They don’t. And that difference matters because a unit can look tidy and still ...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

Gold Migration Lawyers in Liquidation: How the Closure Affects Your ART Appeal

If your appeal was with Gold Migration Lawyers, a recent change to how the Tribunal decides cases ...

The pressure cooker: life in urban Australia in 2026

Australian cities have always been demanding. Long commutes, rising housing costs, busy schedules a...

What Actually Makes a Good Criminal Lawyer in Melbourne

Most people only think about this question once. That is usually too late. Most people charged wi...

Why Working With A Chatswood Tutor Can Improve Academic Performance

Academic expectations continue increasing for students across primary school, high school, and senio...

Is It Worth Getting Solar Panels in Melbourne?

The real question is not whether solar works in Melbourne. It works. The question is what it is co...

How A Diploma Of Project Management Builds Practical Skills For Modern Work Environments

Developing the ability to plan, execute, and deliver outcomes efficiently is a key requirement in to...

How to Choose the Right Football for Every Level

Choosing a football may seem straightforward, but the right option depends on who will be using it a...

What to Ask a Wedding Photographer Before You Book

Booking a wedding photographer can feel deceptively simple: you like the photos, you like the vibe...

Why Stress Relief For Dogs Is Essential For Emotional Balance And Long-Term Wellbeing

Managing emotional health is just as important as physical care when it comes to pets, which is why ...