The Browser Is the Worst Room in the House
Vishal Sachar
Co-Founder & CEO of CLRT
Every company experimenting with AI agents has quietly made a hiring decision. The agentic browser is an employee with a precise profile: it reads everything with complete attention, follows instructions with complete obedience, never gets suspicious, and never gets tired. Its first assignment is to work, unsupervised, in the most adversarial environment human beings have ever constructed. The open web is not a library. It is a place where every page was written by someone with an agenda, where deception is a profitable industry, and where publishing a trap costs nothing. We have sent the most trusting reader ever built into the one room in the house that was designed to exploit trust.
Think about what the browser actually is. It is the one piece of software where everything you see was written by a stranger, and where a meaningful fraction of those strangers are paid to manipulate whoever reads it. Human beings survive this room on defences so old we forget they are defences. We skim. We distrust. We ignore the sidebar, the popup, the too-good offer. We never see the white text on the white background, the collapsed comment, the instructions buried in markup, because our attention is a filter evolved for exactly this environment. An agent has none of that. It reads the entire page with perfect attention and perfect trust, the hidden parts included, and it weighs a spammer's buried sentence exactly as it weighs yours. The qualities that make it a good employee, obedience, thoroughness, tirelessness, are the qualities the room was built to exploit.
The security industry has a name for what happens next, prompt injection, and a ranking for it. OWASP has placed prompt injection at number one in its Top 10 risks for large language model applications in every edition since the list began. Sit with that. The most studied vulnerability class in the field has not moved off the top of the chart, because it is not a vulnerability in the usual sense. A language model consumes one stream of tokens. Your instruction and the page's content arrive in the same channel, and nothing in the mathematics gives your words a privileged lane. Whatever the model reads becomes part of what it is thinking with, and a page that can talk to the model can command it. That is not a bug a vendor will patch next quarter. It is the physics of the medium.
If the physics sounds abstract, the proof is not. In August 2025, Brave, a browser vendor with its own agentic ambitions, published a disclosure on Perplexity's Comet browser. Comet fed the pages it summarised straight into its model without separating the user's instructions from the page's content. Brave's proof of concept hid instructions inside a Reddit comment, behind a spoiler tag a human would never open. A user asked Comet to summarise the page. The hidden comment told the agent to fetch the user's account email, retrieve a one-time passcode, and hand both over, and the agent obeyed. That is account takeover by reading. Note the two details that matter. The agent did nothing it was not built to do. And Brave reported the flaw on 25 July, yet at disclosure, twenty-six days later, the fix was still incomplete.
Now place that mechanism where the browser actually sits in your company. The browser is not a reading device. It is the room where your organisation's logged-in life is kept: the inbox, the bank, the payroll portal, the admin consoles, the sessions and cookies that make each of them open without a password. An agent operating inside it is not a reader with opinions, it is your identity with a to-do list. The same run that reads an untrusted forum can act on an authenticated system, because to the agent they are just tabs. Security teams have spent decades asking what a piece of software is permitted to do. Agentic browsing forces a stranger question, one almost no policy anywhere currently answers: what is this software permitted to read while it holds your credentials.
That question is the real work. Deciding what an agent may read is a governance discipline that barely exists yet, and it cannot be bought from the vendor, because the vendor does not know your business. Which sources count as trusted authors. Which portals are bounded enough to browse with a live session. Which workflows should never run through a browser at all, and belong instead behind an API with a scoped token and nothing else in reach. Where reading untrusted content and holding credentials must be split into separate runs that cannot touch. Every one of those lines is a judgment about your data, your accounts, and your appetite for a quiet catastrophe. Drawing them requires knowing both the physics of the medium and the shape of your operation, and the companies deploying agentic browsers this quarter have, almost without exception, drawn none of them.
An agent's reading list is an attack surface. Governance means deciding what it may read, not just what it may do.
A deeper dive
The uncomfortable truth for anyone waiting on a fix is that every mitigation on offer is probabilistic, and the attack only needs to work once. Model-level guardrails are themselves instructions, which means they sit in the same channel as the attack and can be argued with by anything that writes fluent text, which is everything on the web. Detection classifiers catch yesterday's phrasings and miss tomorrow's, and an attacker can rehearse against the same models the defender uses until something slips through. The Comet episode makes the point from the vendor side: Brave reported the flaw privately, Perplexity shipped a fix, Brave found the fix incomplete, and at public disclosure the vulnerability was still not fully mitigated, all between companies whose entire business is the browser. The honest engineering answer is not a smarter filter. It is architecture: trust boundaries the model cannot talk its way across. The run that reads the open web holds nothing worth stealing. The run that holds credentials reads only bounded sources. Between an agent's draft and any consequential action stands a commit gate that a page cannot operate. None of that eliminates prompt injection, and nothing will. It makes injection worthless, which is the only victory the physics allows.
The second-order trap is treating this as a blocklist problem, because that misreads where the danger lives. The web does not divide into safe and unsafe sites. Any surface that accepts user-generated content is a delivery channel, which includes the reputable newspaper with a comments section, the documentation site with a community wiki, the retailer with product reviews, and your own inbox, which is, after all, a page that renders text written by strangers. Meanwhile the market is pulling hard in the opposite direction. Every major AI company is shipping or acquiring a browser agent, because the browser is where work happens, and whoever sits inside it owns execution. Their incentive is capability, and capability demos beautifully. A reading-list policy does not demo at all. It just quietly prevents the incident you never hear about. That asymmetry is why the policy will not arrive in the product. It has to be drawn, business by business, by someone who understands both the physics of the medium and which systems your particular credentials reach, and who is willing to tell you that some of your workflows should never meet a browser.
Work with CLRT
The browser agents are coming to your company whether you choose them or not; they ship inside the tools your teams already use. The work is deciding, before they arrive, what an agent may read, what it may hold while reading, and which workflows belong nowhere near a browser at all. That is judgment about your specific operation, backed by engineering that makes the boundaries hold. It is the work CLRT does. If you want to know where an agent can act safely in your business, and where its reading list would quietly become your attack surface, start with a diagnostic at ascent.clrtstudio.com, or bring us the workflow you are about to hand to an agentic browser, and we will draw the lines first.

Vishal Sachar
Vishal Sachar is the Co-Founder and CEO of CLRT, where he helps UAE businesses make sense of applied agentic AI and put it to work. He writes on agentic systems, AI governance, and the economics of automation. Reach him at vishal@clrtstudio.com or on LinkedIn.


