All Insights

The new wave of AI Browser Agents

Cyber Security โ€ข December 17, 2025 โ€ข Written by: Gareth Jones โ€ข Read time: 2 min

The new wave of ๐€๐ˆ ๐๐ซ๐จ๐ฐ๐ฌ๐ž๐ซ ๐€๐ ๐ž๐ง๐ญ๐ฌ presents a foundational and often overlooked set of security challenges for business leaders and security teams.

How many of you have noticed the ๐š๐ฎ๐ญ๐จ๐ง๐จ๐ฆ๐จ๐ฎ๐ฌ ๐๐ข๐ ๐ข๐ญ๐š๐ฅ ๐š๐ฌ๐ฌ๐ข๐ฌ๐ญ๐š๐ง๐ญ๐ฌ  (AI Mode) built directly into the browser, capable of reading, navigating, and taking actions across multiple websitesโ€”including your company's internal systems?

Having spent a wet and windy Tuesday evening reading how Google is building a layered defence directly into Chrome to secure these ๐œ๐ฅ๐ข๐ž๐ง๐ญ-๐ฌ๐ข๐๐ž ๐š๐ ๐ž๐ง๐ญ๐ข๐œ ๐€๐ˆ ๐œ๐š๐ฉ๐š๐›๐ข๐ฅ๐ข๐ญ๐ข๐ž๐ฌ (the features where the AI acts on your behalf, like summarising a page or performing a multi-step task), it was well worth it.

If you would like a deeper look into the architecture, the link below is great reading on how major vendors are building ๐ฅ๐š๐ฒ๐ž๐ซ๐ž๐ ๐๐ž๐Ÿ๐ž๐ง๐œ๐ž๐ฌ directly into the browser to secure these agentic AI capabilities: https://lnkd.in/eDFGjvdv

As these tools gain traction, organisations must move swiftly to secure the most critical frontier: ๐ญ๐ก๐ž ๐œ๐ฅ๐ข๐ž๐ง๐ญ-๐ฌ๐ข๐๐ž ๐›๐ซ๐จ๐ฐ๐ฌ๐ž๐ซ. We must manage the risk of turning a helpful tool into a highly privileged insider threat.

The danger of an AI agent lies in its combination of ๐ญ๐จ๐ญ๐š๐ฅ ๐ฏ๐ข๐ฌ๐ข๐›๐ข๐ฅ๐ข๐ญ๐ฒ  and ๐ฉ๐ซ๐จ๐ ๐ซ๐š๐ฆ๐ฆ๐š๐›๐ฅ๐ž ๐š๐ฎ๐ญ๐จ๐ง๐จ๐ฆ๐ฒ. They break the traditional security assumption that only a human can initiate a complex series of actions.

At Methods, managing this risk requires a layered, Zero Trust approach that goes beyond simple network firewalls and focuses on ๐ ๐จ๐ฏ๐ž๐ซ๐ง๐š๐ง๐œ๐ž, ๐ฉ๐จ๐ฅ๐ข๐œ๐ฒ, ๐š๐ง๐ ๐œ๐จ๐ง๐ญ๐ซ๐จ๐ฅ  over the agent itself. This strategy aligns closely with the NCSC's guidance on securing AI systems and industry best practices.

The AI browser agent is here to stay, and its capabilities will only grow. The corporate challenge is not to ban it, but to manage it. By immediately implementing strong governance and adopting security models that treat the AI agent as a powerful, but inherently untrusted, system, we can harness the productivity gains while protecting our most valuable assets.

Back to top