Agentic AI browsers — the new wave of tools that can open tabs, fill forms, make bookings and act on your behalf across the web — have been one of this year’s most-hyped productivity upgrades. A study from the University of Washington, now circulating widely, found something that should slow that adoption down: four of the seven popular agentic browsers tested create ways for malicious content to bypass the “same-origin policy,” a decades-old rule that’s supposed to stop one website from reading data out of another one open in your browser. Researchers demonstrated a working proof-of-concept against ChatGPT Atlas, and found comparable weaknesses in three other tools.

For UK SMEs increasingly being pitched AI browsers as a way to save staff time, this is worth pausing on before rolling one out across the business.

Why this is a bigger deal than a normal browser bug

The same-origin policy is one of the foundational protections of the modern web — it’s the reason your online banking tab can’t be read by a shopping site you also have open. AI browser agents break this model almost by design: to be useful, they need to move information between tabs, log into accounts, and act with the permissions of whoever is logged in. Researchers found that this convenience creates exactly the opening attackers want — embedded malicious content on one page reaching into sensitive data from another, without the user doing anything more than letting the agent complete its task. Because the agent inherits your actual browser session, it isn’t just reading public information; it can potentially touch your email, your CRM, your accounting software, or anything else you’re logged into.

Industry surveys back up why this matters right now: most organisations are already planning to deploy agentic AI into business functions, but fewer than three in ten say they’re actually prepared to secure that deployment. Adoption is running well ahead of the guardrails.

What to check before your team adopts one

Ask what the agent can actually see and do. Before letting staff install an agentic browser, find out whether it operates with your team’s full logged-in session or a more restricted, sandboxed one. Browsers with tighter permission boundaries showed meaningfully lower risk in the study — this is a real differentiator between products, not just marketing language.

Keep sensitive logins out of agent-driven sessions. Until this matures, it’s sensible to avoid running an AI browser agent in the same session as banking, payroll, or client data systems. A simple internal rule — no agentic browsing while logged into finance or client platforms — closes off most of the realistic risk with minimal effort.

Don’t treat “AI-powered” as a security guarantee. These tools are genuinely useful, and banning them outright isn’t necessary or realistic for most SMEs. But they’re new enough that the security model is still being worked out in public, live, on tools your team may already be using. Treat early adoption the way you’d treat any new piece of software with access to your accounts: cautiously, with clear boundaries.

If you’re weighing up agentic AI tools for your business and want a second opinion on what’s actually safe to roll out, this is squarely the kind of question ApplyAI helps SMEs work through before committing — matching the tool to the risk, not just the hype.

The takeaway

AI browsers aren’t dangerous by accident — the same features that make them useful are the features creating the exposure. Before your business adopts one, know exactly what it can access, and keep it away from your most sensitive logins until the security model catches up with the convenience.