A new wave of security research is sharpening a warning that has been building for months inside the cybersecurity world: the next major A.I. threat may come not simply from chatbots generating better phishing emails, but from digital agents that can act on a user’s behalf — clicking, browsing, purchasing, messaging and moving across trusted accounts with alarming freedom.
At Black Hat USA 2026 and in related academic work, researchers described a fast-expanding attack surface created by so-called agentic systems, including A.I.-powered browsers and assistants embedded in mainstream products. Their findings suggest that as technology companies race to make A.I. more useful — able to navigate websites, access tools and complete tasks autonomously — they may also be eroding some of the internet’s oldest security boundaries.
The result, security experts say, is a class of vulnerabilities that is qualitatively different from earlier A.I. risks. These systems are not merely producing text. They are operating inside authenticated sessions, reading untrusted content, interacting across tabs and applications, and in some cases reaching into local files or services running on a user’s machine.
A browser assistant that can be turned against its user
One of the starkest demonstrations came from Zenity, a security firm that said it had identified more than a dozen flaws affecting built-in A.I. browser agents in products including ChatGPT Atlas, Perplexity Comet, Claude in Chrome, Gemini in Chrome and Copilot Edge.
The company said its attack chains, which it called “PleaseFix,” could manipulate these agents into actions their users never intended: sending spam through WhatsApp, stealing data, taking over accounts and, in some scenarios, compromising parts of a local machine. In one proof of concept, researchers showed that OpenAI’s Atlas could be induced to make an unauthorized Amazon purchase.
The broader concern, according to the researchers, is that these agents blur lines that conventional browser security was designed to keep separate. A normal website is generally fenced off from another site by long-established rules such as the same-origin policy, which limits how one web page can access data from another. But an A.I. agent that is explicitly designed to help a user across sites, tabs and services can become a kind of privileged bridge — one that attackers may exploit.
That concern was echoed by researchers at the University of Washington, who reported that four of seven agentic browsers they tested created ways to bypass the web’s same-origin protections. The team also produced a proof-of-concept attack against Atlas, underscoring what they described as a structural problem rather than a simple software bug.
That distinction matters. If the weakness stems from the basic way an agent is allowed to observe and act across a user’s digital environment, patches alone may not fully solve it. More fundamental redesigns may be needed around permissions, memory and isolation between websites, accounts and local resources.
The rise of human-guided A.I. hacking
Even so, the latest research does not suggest that autonomous A.I. hackers are already outperforming skilled human attackers on their own. In fact, some of the most sobering findings point in the opposite direction: the near-term danger may come from humans and A.I. working together.
James Kettle, a well-known security researcher, tested the outer limits of A.I.’s ability to find and exploit vulnerabilities. His conclusion was that the most dangerous offensive techniques still tend to keep humans in the loop. A.I. can accelerate reconnaissance, pattern recognition, iteration and testing, but expert operators remain critical for steering attacks, validating outputs and adapting strategy when the model makes mistakes.
That aligns with a growing consensus in the security community that the real transformation is not fully autonomous cyberwarfare — at least not yet — but the industrialization of sophisticated attacks through human-A.I. teaming. An experienced hacker armed with effective models and agentic tools may be able to move faster, probe more targets and scale operations in ways that were harder only a few years ago.
In practical terms, that means companies cannot dismiss these findings simply because current A.I. systems remain unreliable. Imperfect tools can still be highly dangerous when paired with human judgment.
From exploit chains to worm-like behavior
Researchers are also peering beyond today’s browser-agent flaws toward a more unsettling possibility: A.I. systems that behave less like ordinary malware and more like adaptive, self-directing organisms.
A June 2026 paper by Chinese researchers described how A.I. agents could be arranged into worm-like systems that tailor their attacks as they spread. Rather than following a fixed script, such agents could potentially adjust to new environments, choose tactics dynamically and use model-based reasoning to persist or propagate.
The idea remains largely in the proof-of-concept stage, and significant constraints remain. Models are still prone to error. Their access to tools and target environments can be limited. And real-world offensive campaigns often require infrastructure, stealth and reliability that laboratory demonstrations do not fully capture.
Still, security experts say the importance of the work lies in showing technical plausibility. If agentic systems can plan, call tools, interpret their surroundings and modify behavior in response, then malware authors may eventually borrow those same capabilities. A worm that does not merely replicate, but adapts, would represent a notable shift in cyber risk.
Why this moment matters
The warnings arrive as technology companies are rapidly shipping products meant to make A.I. assistants more active and useful. The commercial logic is clear: users want systems that can book travel, manage messages, shop online, summarize documents and navigate the web on their behalf. But each increase in autonomy can also expand the consequences of compromise.
This year, industry reports and academic research have increasingly converged on the same point: agentic A.I. enlarges the threat surface even as it may also strengthen defense. Security teams are already using A.I. to analyze logs, identify anomalies and speed incident response. The same capabilities that make systems helpful to defenders, however, can become liabilities when embedded in broadly privileged consumer tools.
There is also an unresolved policy question. Some vendors have reportedly treated certain agent behaviors as intended functionality rather than classic vulnerabilities. That leaves a gray area between feature and flaw: if an assistant is supposed to move fluidly among services to help the user, when does that helpfulness become an exploitable security defect?
For now, that question has no uniform answer. Nor is it yet clear how much risk can be reduced through incremental fixes and how much will require rethinking the architecture of A.I. agents altogether.
What is becoming clearer is the shape of the next phase of cyber risk. The threat is no longer just that A.I. can generate malicious content. It is that A.I. agents are beginning to inhabit the trusted spaces where people shop, message, work and store sensitive data — and that attackers, with or without full autonomy, are learning how to turn that access against them.
Sources
Further reading and reporting used to add context:
- https://www.axios.com/2026/08/04/anthropic-openai-uk-ai-security-institute
- https://theweek.com/tech/open-ai-hacking-hugging-face
- https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access/
- https://arxiv.org/abs/2606.03811
- https://www.anthropic.com/research/attack-navigator
- https://www.crowdstrike.com/en-us/press-releases/2026-crowdstrike-global-threat-report/
- https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark/
- https://www.washington.edu/news/2026/06/30/some-agentic-ai-browsers-come-with-major-cybersecurity-risks-uw-study-finds/
- https://arxiv.org/abs/2602.19555
- https://www.reddit.com/r/whatsapp/comments/1vgo64g/openais_browser_could_be_hijacked_to_spam_your/
- https://www.axios.com/2026/05/14/mythos-cyberscurity-human-ai-models
- https://www.wired.com/story/ai-arms-race-china-us-cooperation/
- https://www.reddit.com/r/technology/comments/1vgx5k8/ai_hacks_are_bad_ai_worms_and_viruses_will_be/
- https://arxiv.org/abs/2603.08665
- https://www.hp.com/us-en/newsroom/press-releases/2026/hp-research-low-effort-ai-attacks-beating-defenses.html
- https://openai.com/index/axios-developer-tool-compromise/
- https://hbr.org/2026/03/llms-are-manipulating-users-with-rhetorical-tricks?ab=HP-latest-text-8
- https://nap.nationalacademies.org/resource/29493/interactive/
- https://agent-security.cs.washington.edu/agentic_browsers_sop.html
- https://homes.cs.washington.edu/~franzi/pdf/roesner_kohlbrenner_2026_agentic_sop.pdf
- https://www.rivista.ai/wp-content/uploads/2026/06/2606.03811v1.pdf
- https://arxiv.org/abs/2606.14027
- https://dblp.org/rec/journals/corr/abs-2606-03811.html
- https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6876926
- https://zenity.io/company/newsroom
- https://arxiv.org/abs/2605.05509
- https://www.researchgate.net/publication/404627993_WAAA_Web_Adversaries_Against_Agentic_Browsers/download
- https://portswigger.net/burp/burp-at
- https://www.eurekalert.org/news-releases/1134290
- https://jameskettle.com/?trk=public_post_reshare-text
- https://www.researchgate.net/publication/404627993_WAAA_Web_Adversaries_Against_Agentic_Browsers
- https://arxiv.org/abs/2405.15793
- https://www.2cobo2.jp/archives/343
- https://www.digitaltrends.com/computing/yet-another-research-breaks-the-hype-bubble-for-ai-browsers-serving-serious-security-flaws/
- https://lingvo.club/en/articles/ai-browsers-raise-security-concerns-cb35756d?level=a2
- https://openpraxis.org/articles/1145/files/699da3af4a456.pdf
- https://www.nationalacademies.org/documents/embed/link/LF2255DA3DD1C41C0A42D3BEF0989ACAECE3053A6A9B/file/DDE30396A047EC333AAC20071FF4E7FEAB28F60CE4A1?noSaveAs=1
- https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/06/CSA_research_note_ai_adaptive_worms_autonomous_exploitation_20260604-csa-styled.pdf
- https://www.reddit.com/r/browsers/comments/1ukeeod/some_agentic_ai_browsers_come_with_major/
- https://www.reddit.com/r/AI_Agents/comments/1rm6ter/ainative_browsers_atlas_comet_create_serious/
- https://portswigger.net/burp/documentation/desktop/running-scans/explore-issue-with-ai
- https://portswigger.net/burp/documentation/ai-features
- https://portswigger.net/blog/the-beast-needs-a-cage-whats-next-for-appsec-post-mythos
- https://portswigger.net/burp/documentation/desktop/burp-at
- https://jameskettle.com/
- https://www.linkedin.com/posts/portswigger_i-started-this-year-saying-2026-is-activity-7462165544427999232-qxx_
- https://blackhat.com/us-17/speakers/James-Kettle.html
- https://arxiv.org/abs/2605.14830
- https://www.mdpi.com/1099-4300/28/4/377
- https://portswigger.net/burp/documentation/desktop/burp-ai
- https://techcrunch.com/2026/07/06/the-first-ai-run-ransomware-attack-still-needed-a-human/
- https://arxiv.org/abs/2603.22928
- https://arxiv.org/abs/2510.23883
- https://www.coalitionforsecureai.org/wp-content/uploads/2026/03/the-future-of-agentic-security.pdf
- https://kpmg.com/kpmg-us/content/dam/kpmg/pdf/2026/agentic-ai-board-oversight-new-era.pdf
- https://www.ccinfo.nl/_downloads/b9691a7828476c65a77c6e23a54796b4
- https://ipc.mit.edu/wp-content/uploads/2026/04/Humans_in_the_Loop_full_r01M.pdf
- https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/03/CSA_research_note_agentic_blabbering_ai_browser_phishing_20260313-csa-styled.pdf
- Zenity Labs: PleaseFix Vulnerability in Agentic Browsers
- Agentic Browsers and the Same-Origin Policy














Leave a Reply