Google just gave its personal AI agent the browser you already use.
Not a clean-room browser in a data center. Your Chrome, on your desktop, already signed into your accounts, with your saved passwords one autofill away. On July 30, Gemini Spark gained the ability to use Chrome's auto browse to run multi-step errands for you — scheduling viewings for apartments you have saved, researching flights and starting a booking. Google's own announcement is blunt about the mechanism: with your permission, Spark "can use your logged-in accounts and saved passwords."
What actually shipped
Chrome auto browse itself launched back in January 2026. What changed is that Spark, Google's always-on personal agent, can now drive it.
The rollout is narrower than the headlines suggest. Auto browse is US-only and desktop Chrome only — Spark on mobile cannot use it. Google AI Pro is required. And while Spark itself expanded to more than 160 additional countries the same day, it remains unavailable in the European Economic Area, the UK, Switzerland, and Nigeria.
Make Tax Season Simple
Tax season doesn't have to mean wondering if you have the right forms, second-guessing your deductions, or scrambling to pull everything together before the deadline.
With BELAY’s tax prep support, you can approach tax season with confidence. Stay organized with one centralized place to gather and check off your documents, keep track of valuable deductions like HSA contributions and education expenses while leaning on experienced professionals who make tax preparation accurate, efficient, and completely hands-off.
Download BELAY's free Personal Tax Checklist and start preparing with confidence, today.
The genuinely new part is whose browser it is
Three days ago we covered OpenAI shipping the same capability from the opposite direction, and the contrast is the most useful thing in this story.
ChatGPT's agent drives a cloud browser — OpenAI's, not yours. When it hits a login wall, it hands you control of that remote window, and stops capturing screenshots while you type so your password is never recorded.
Gemini Spark inverts all of it. The browser is yours. The sessions are ones you are already signed into. The credentials come from Google Password Manager.
Neither is straightforwardly safer. OpenAI keeps your everyday browser out of it, at the cost of running your logged-in session on someone else's infrastructure. Google keeps everything local, at the cost of pointing an autonomous agent at the browser where your entire signed-in life already lives.
What Google built to keep it from going wrong
The threat is indirect prompt injection: instructions hidden in a page the agent reads, written so it obeys them as if you had typed them. The agent is logged in as you, so it can act on them.
Google's defense is structural rather than a filter bolted on the front. A User Alignment Critic — a separate Gemini model that independently judges whether each action matches what you actually asked for, sitting outside the page's reach so malicious content cannot compromise it. Origin Sets, restricting the agent to specific sites and elements while withholding unrelated origins and iframes. A dedicated classifier scanning for injection attempts. And mandatory human confirmation at the sharp edges: Chrome pauses before banking portals and before Password Manager hands over a stored credential, and payments return control to you outright.
Google also runs automated red-teaming and pays up to $20,000 in bug bounties. It is a more serious architecture than most agentic products ship with. What Google has not published is how it performs against known injection techniques. Google's own announcement is here →
The number Google did not cite
The best public measurement of this attack class comes from a Meta research team. Their benchmark, WASP, tested web agents against realistic, human-written injections — the cheap kind, not exotic lab attacks.
Injections partially succeeded in up to 86% of cases.
But read the rest, because it changes the meaning. In those same tests, agents completed the attacker's actual goal only 0 to 17% of the time. The attack got in; it usually could not finish. The authors call this security by incompetence — the agents were protected partly by being bad at following through, on malicious and legitimate tasks alike.
Two caveats, stated plainly rather than buried: WASP was published in April 2025, before Chrome's User Alignment Critic and Origin Sets existed, and it did not test Gemini Spark. It is not Spark's failure rate. The paper is here →
What it establishes is the shape of the problem — this attack class is cheap and it works often enough to matter. And the uncomfortable part: the thing that most reliably stopped it was the agent's own clumsiness, which is the exact property every lab is spending billions to remove.
Sort your accounts into three piles
The decision is not whether to trust autonomous browsing in the abstract. It is which accounts you will leave reachable from a tab an agent is driving — because in this design, everything your browser is signed into is in the room.
Green: little is lost if it goes wrong — apartment listings, reservations, transit, research.
Yellow: real but recoverable, worth supervising — shopping carts up to checkout, loyalty accounts, travel before payment.
Red: keep the agent out — banking, brokerage, primary email, health portals, anything with a saved card and one-click buy.
Primary email belongs in red for a reason people underrate: it is not one account, it is the reset mechanism for all the others.
What to do this week
If you are in the US on desktop Chrome with AI Pro, this is worth trying — on green-pile tasks. Grant access per task rather than as a standing permission. Treat the pause as the product: when Chrome stops and asks before a banking site or a password retrieval, that prompt is the last line between a hijacked instruction and your account, and the failure mode is clicking through it the way we all click through cookie banners.
Google has built the most serious defensive architecture yet shipped for agentic browsing, and pointed it at the most sensitive possible target. Both are true at once — and the second is why the first had to be that good.
On the site version you also get the interactive triage tool — answer three questions about one account, get a green, yellow, or red verdict — plus the copy-paste prompt that runs the same audit across your whole list.
Privacy-first email. Built for real protection.
End-to-end encrypted, ad-free, and open-source. Proton Mail protects your inbox with zero data tracking.
— Jerry


