The Authenticated Session Problem: Why Auto Browse Changes the Threat Model for Everyone

Tim Williams — CEO and Co-Founder — AstraSync AI
On 28 January 2026, Google launched Gemini Auto Browse to US users. The pitch was straightforward: let Gemini take over your Chrome browser to complete tasks on your behalf. Research flights, compare products, fill out forms. Google framed it as a productivity feature, and the framing is accurate as far as it goes.
What it doesn’t mention is that Auto Browse fundamentally changes the security model that every website, bank, and online retailer has relied on since the invention of session-based authentication. Richard Crone’s analysis of the commerce implications puts numbers to the exposure: when agents intermediate the checkout experience, 33–76% of checkout-adjacent revenue is at risk (https://www.linkedin.com/posts/richardcrone_agenticcommerce-pdps-ucp-activity-7424874217143164928-JFFL). For financial services, the scenarios are arguably worse. The implications deserve a more honest conversation than they’ve received so far.
What Auto Browse Actually Does
The mechanics are worth understanding precisely, because the risk follows directly from the architecture.
When you enable Auto Browse, you authenticate normally. You type your password, complete your MFA challenge, and establish a legitimate session with whatever website you’re visiting. Then you hand control to Gemini. The agent operates within your authenticated session, using your credentials, your cookies, your established trust relationship with that website.
Google’s own documentation confirms that Auto Browse can use Google Password Manager to handle tasks even when a sign-in is required. The agent doesn’t need to ask for your password. It already has access to the credential store.
From the website’s perspective, nothing has changed. The requests come from a legitimate Chrome browser, from a session that was established through proper authentication, including MFA. The website has zero visibility into the moment when a human stopped making decisions and an agent started.
This is the core of the problem, and it’s worth sitting with for a moment: every security control that websites deploy today assumes that the entity making decisions within an authenticated session is the same entity that authenticated. Auto Browse breaks that assumption by design.
The Risks That Already Exist
It would be unfair to frame this as a Google-specific problem. The same fundamental vulnerabilities exist across every agentic browser on the market today.
Perplexity’s Comet, OpenAI’s Operator, Anthropic’s Claude in Chrome, and numerous smaller projects all share the same architectural reality: an AI agent operating within a browser session inherits whatever access that session provides. Prompt injection, where content on a webpage contains hidden instructions that redirect the agent’s behaviour, is a known and currently unsolved problem across the industry. The UK’s National Cyber Security Centre has publicly stated that large language models cannot reliably enforce security boundaries between instructions and data. This isn’t a failure of any specific implementation. It’s a fundamental property of how these systems work.
Session inheritance, where an agent gains access to capabilities far beyond the narrow task it was asked to perform, is equally universal. Ask any agentic browser to check your bank balance and it technically has access to initiate transfers, apply for loans, and change your personal details. The guardrails preventing this are policy-level restrictions, not architectural constraints.
These are industry problems. Every company building agentic browsing capabilities is navigating them, and none has fully solved them.
Why Auto Browse Is Different
So if everyone has the same problems, why does Auto Browse warrant specific attention? Because it takes known risks and amplifies them through four factors that no other agentic browser can replicate.
Scale that dwarfs the competition. Chrome holds over 65% of the global browser market. Comet and Operator are products from companies with tens of millions of users, requiring active installation of a separate application. Auto Browse will arrive as a feature update to an estimated three billion Chrome installations worldwide. Even modest adoption rates create agent traffic volumes that exceed the entire addressable market of every competing agentic browser combined. When Google rolls a feature into Chrome, it doesn’t compete for market share. It inherits it.
Depth of credential access. Other agentic browsers operate with whatever credentials you explicitly provide. Auto Browse has native integration with Google Password Manager, which for most users contains credentials for banking, healthcare portals, corporate tools, government services, and everything in between. The practical difference is significant: Comet asks you to log in. Auto Browse already knows how.
Cross-application surface area. This is the factor that genuinely has no parallel. When you’re logged into Chrome, you’re typically also logged into Gmail, Google Calendar, Google Photos, Google Maps, Google Drive, and potentially Google Workspace. A session context in one application carries implications across the entire ecosystem. No other agentic browser operates within an estate of this breadth or depth. An agent that starts by checking your flight options has, at least theoretically, proximity to your email threads, your calendar appointments, your stored documents, and your location history. The question isn’t whether Google intends this level of access. The question is what the architecture permits.
Trust inheritance. Users have been using Chrome for over fifteen years. It’s not a new product requiring active evaluation; it’s infrastructure they stopped thinking about years ago. Auto Browse arrives not as a standalone application demanding a trust decision, but as a capability within something users already trust implicitly. The psychological barrier to enabling it is fundamentally different from downloading a separate agentic browser from a company you’ve barely heard of. This matters because adoption speed determines exposure speed, and nothing drives adoption faster than a feature toggle in a product three billion people already use.
The Non-Determinism Problem
There’s a deeper issue that compounds everything above, and it’s one that most coverage of agentic browsing overlooks entirely.
AI agents don’t follow scripts. They interpret instructions, and that interpretation can vary each time. Ask Auto Browse to “find the cheapest flight to Sydney” twice in a row and it may search different airlines, apply different filters, or prioritise different trade-offs between price and convenience. This variability is what makes agents genuinely useful for complex tasks. It’s also what makes them genuinely unpredictable. The behaviour of an agent operating within your banking session cannot be predicted with certainty, even by the people who built it.
Google has invested serious engineering effort in safeguards. Their User Alignment Critic validates that agent actions match user intent. Their Prompt Injection Classifier attempts to detect hidden instructions in web content. Agent Origin Sets restrict which domains the agent can interact with. Purchase confirmations require explicit user approval before transactions complete. These are real protections built by talented engineers.
The question is whether they’re sufficient, and the honest answer is that nobody knows. The GTG-1002 incident, where Chinese state actors successfully jailbroke Claude Code through social engineering techniques, demonstrated that policy-level guardrails in AI systems can be bypassed through creative manipulation. The techniques weren’t sophisticated; they involved role-playing as security firms and breaking tasks into steps that individually appeared innocuous. Google’s own decision to offer $20,000 bug bounties for Auto Browse bypass is an implicit acknowledgement that they understand their protections are best-effort rather than guaranteed.
More importantly for our purposes: all of these safeguards are Google’s protections for Google’s users, operating on Google’s terms. They provide zero visibility or control to the other side of the transaction. When an Auto Browse agent completes a purchase, transfers money, or submits a form, the receiving website sees a standard request from a standard Chrome browser. There is no flag, no metadata, no header, no signal of any kind indicating that a human wasn’t the one making decisions. The merchant, the bank, the service provider is completely blind to the presence of an agent.
Where This Is Heading
Auto Browse launched with deliberate constraints. It’s US-only, desktop-only, and restricted from downloading files or executing code. These are sensible launch-day guardrails. They are also clearly temporary.
The competitive dynamics make expansion inevitable. Perplexity is pushing Comet to 100 million users. OpenAI continues developing Operator. Anthropic is expanding its own browser capabilities. Each capability addition by a competitor creates pressure for Google to match it, and Google has structural advantages in distribution that make restraint a difficult long-term strategy.
The commerce implications are substantial. Richard Crone’s Hertz example illustrates the dynamic clearly: an agent instructed to “book a car” completes the transaction with zero exposure to upgrades, insurance offers, loyalty programme prompts, or any of the ancillary revenue that rental companies depend on. The agent optimises for the user’s stated instruction. Everything else falls away.
For financial services, the scenarios are more concerning. A user logs into internet banking and asks Auto Browse to check a balance. The agent now operates within a session that has access to transfers, bill payments, loan applications, and personal information changes. No re-verification occurs, because the session was legitimately established by a human. The liability questions alone, when a user claims an agent initiated a transaction without explicit approval, will keep compliance teams busy for years.
The regulatory landscape is in motion. The EU AI Act enforcement begins in August 2026, which will impose transparency and accountability requirements on high-risk AI systems. Whether agentic browsers fall within scope is still being debated, but the direction is clear: regulators are moving toward requiring that AI-driven actions be identifiable, auditable, and attributable. The gap between where regulation is heading and where the technology sits today is significant.
What This Means, and What We’re Doing About It
The question isn’t whether agentic browsing happens. It’s already happening. The question is whether the infrastructure exists to make it accountable. Right now, it doesn’t.
Merchants can’t tell when they’re dealing with an agent. Banks can’t detect when session control has changed hands. Employers can’t audit what agents did inside corporate applications. There is no mechanism, on any platform, for the receiving party to verify the identity of an agent, understand its purpose, enforce boundaries on its behaviour, or maintain an audit trail of its actions.
Google isn’t going to solve this, and there’s no reason to expect them to. Flagging agent activity to merchants would undermine their commerce strategy by giving websites a reason to block or restrict agents. It would be like Uber voluntarily telling restaurants which orders are from delivery platforms versus walk-in customers. The incentive structure simply doesn’t support it.
This is what we’re building at AstraSync.
Our Trust Chain framework addresses the gap between authentication and accountability. We’re developing infrastructure that lets both sides of an agentic transaction operate with confidence: users who want their agents to act responsibly, and website owners who need to know what’s interacting with their systems and why. Our approach includes verified agent identity through blockchain-backed registration, purpose-scoped session controls that limit what agents can do and for how long, and immutable audit trails that create the compliance evidence regulators will increasingly demand.
We’re not trying to stop agentic browsing. It’s useful, it’s inevitable, and it genuinely improves the user experience. We’re trying to ensure it doesn’t come at the cost of trust, accountability, and control for the businesses and institutions on the receiving end.
We’re actively looking for design partners, particularly website owners, merchants, and financial services providers, who want to help shape what responsible agentic interaction looks like in practice. If you operate a platform that’s about to face a wave of unidentified AI agents interacting with your systems, and you’d rather be ahead of that curve than behind it, we’d like to hear from you.
Get in touch at astrasync.ai or reach out directly on LinkedIn. We’re building this in the open and we want the people who’ll be most affected by these changes to help define the solution.
This is the fourth in a series of articles exploring the emerging agentic commerce ecosystem. Previous pieces examined the attribution crisis in AI agent governance, the Amazon-Perplexity lawsuit and platform economics, and the UCP paradox facing merchants.
Further reading on AstraSync
- Verify before transact: the trust pattern for agent commerce
- How to let AI agents access your API safely
- PDLSS Permission Boundaries
This essay first appeared on Medium on 4 February 2026.

