Research conducted by OpenAI and the technical assessments it has published indicate that the complete elimination of security risks in browsers operating with artificial intelligence (AI) agents does not appear feasible within the scope of current technological capabilities. It is reported that such systems are exposed to a new generation of attack mechanisms known as “prompt injection” and the complete prevention of these attacks encounters fundamental limitations.
The core of the issue lies in the fact that cybercriminals are able to embed concealed, text-based instructions within emails, text documents (such as PDF and Word files), as well as within web resources. AI agents (including the Atlas browser tested by OpenAI) may process such concealed instructions as contextual prompts when analyzing these materials and may execute them without the user’s awareness.
The conducted tests have demonstrated that, as a result of such attack scenarios, AI agents may perform actions on behalf of the user, including submitting fraudulent requests (such as a resignation letter), exfiltrating sensitive information to external destinations, as well as redirecting to malicious and phishing-related resources. This, in turn, leads to the emergence of additional risks in the context of the widespread implementation of artificial intelligence-based browsers.
In its published assessments, the United Kingdom’s National Cyber Security Centre (NCSC) notes that the failure to remediate the identified technical vulnerabilities in a timely manner could lead to large-scale data breaches and severe cybersecurity incidents in the future. The warning emphasizes that these risks could result in consequences similar to the data breaches previously experienced by international companies such as Sony and Yahoo. In particular, the integration of AI agents into corporate email systems, internal documentation, and business processes further increases these risks.
OpenAI states that, with the aim of mitigating the identified risks, it evaluates its systems through specialized AI-driven testing mechanisms (“hacker” models) and simulated attack scenarios. Nevertheless, the company acknowledges that, due to excessive reliance of language models on contextual input and instructions, it is currently not possible to provide a guarantee for the complete resolution of this issue.
Experts believe that, against the backdrop of the expanding use of AI agents across the public and private sectors, the implementation of additional security mechanisms, the restriction of agent privileges, as well as the establishment of dedicated risk assessment and audit frameworks for artificial intelligence-based systems will be necessary.
References:
© 2011-2026 All rights reserved