Security researchers are continually uncovering how AI browser agents, such as OpenAI’s new Atlas browser, can be hacked using prompt injection and data exfiltration. This means that a website can subtly trick an AI assistant into doing things on your behalf—such as copying cookies, reading your emails, or clicking malicious links—without your knowledge. The normal rules of web security do not apply here. If an AI agent acts on your behalf while you are logged in, it could transfer money, send emails, or access sensitive corporate data, all because of a single clever prompt.
A report published by Brave highlights the key issues. One example is prompt injection through screenshots: Hidden text inside images can be read by the browser’s AI as a command rather than content. This allows malicious actors to smuggle in invisible instructions. Another is navigation-based injection: Simply ask the AI to open a website, and it then feeds text from that page to the model as if it came from you, changing what happens next. A systemic issue across AI browsers is that the boundary between what the user says and what the web says is often blurred, opening the door to manipulation.
Brave’s research shows that these vulnerabilities are systemic and affect multiple AI browsers. For example, attacks have been demonstrated against OpenAI’s Atlas browser in which the AI executed hidden instructions concealed in barely visible text. Similarly, Perplexity’s Comet remains vulnerable even after attempts to fix it. Researchers warn that users could lose money if attackers exploited their login credentials.
Microsoft and Its Latest AI Developments
On the subject of screenshots, Microsoft’s new Gaming Copilot has raised further concerns by capturing gameplay screenshots for context. Microsoft claims this is intended to improve its understanding of games, not to train new models. Users complain about how difficult it is to disable this feature. The feature collects data from game content, increasing data security risks.
At the same time, investors are still struggling to understand the true economics of Microsoft’s partnership with OpenAI. A new column in the WSJ calls for clearer financial disclosures, while commenters on Hacker News argue that key details are buried in vague line items or broad categories such as “other, net.” The result is that no one knows how much risk, exposure, or profit actually flows between the two companies if the whole AI endeavor were to fail.
Microsoft recently disclosed a 27% stake in OpenAI, valued at $135 billion, following OpenAI’s restructuring. The partnership includes a $250 billion commitment to Azure cloud services and extends Microsoft’s rights to OpenAI models through 2032. Microsoft reported $4.7 billion in OpenAI-related expenses in its annual report, but critics point to a lack of detailed breakdowns or valuations, raising further doubts about transparency.
How Can These Problems Be Addressed?
All these cases point to a growing “AI trust tax.” These episodes underscore how the user experience with agents is racing ahead of the systems intended to secure or explain them. On the product side, agents need stronger permission systems and clearer boundaries—see domain-specific benchmarks such as the new MLEB for legal embeddings—before companies hand over the keys to browsers or internal data.
On the market side, if companies continue spending heavily on AI while providing unclear financial details, it is impossible to assess the true risk. Are the profits real? Are security costs included? Who pays when something fails? So far, we have not seen a legitimate AI security case escalated to the highest levels of legal scrutiny to be examined in the light of the law, as the Supreme Court would do. Until that happens, the market will have to resolve these matters on its own.
For example, if agents are easily exploited, companies will demand airtight permissions, provenance, and auditable evaluations, adding real costs and potentially reducing margins. And if risk disclosures lag behind, investors cannot account for these costs (security teams, red-teaming, compensation) or liabilities (data leaks, account takeovers), widening the gap between the narrative and GAAP.
In the short term, there are simple fixes for web agents: Keep AI browsing separate from normal browsing, ensure that users explicitly confirm before an agent visits websites or reads emails, and make security the default.
For developers, this means sandboxed browsing (isolating the agent’s actions), allowlists (access only to approved sites), and clear activity logs. For platforms, it means giving users obvious off switches and showing what data has been collected, when the feature is active, and how to disable it completely.
Finally, on the business side, companies such as Microsoft need to show not only what they earn from AI, but also how that money flows through the system: from renting GPUs and selling access to models to bundling Copilot seats. That is how we will find out whether AI is generating real growth or merely the result of creative accounting. Or, as we put it: whether we are building true “artificial general intelligence”... or merely “artificial general inflation.”



