Company Check : OpenAI Unveils ChatGPT-Powered Atlas Browser

OpenAI has released Atlas, a free macOS web browser built around ChatGPT, and it arrives with big ambitions, useful features, and some immediate security questions.

What OpenAI Has Launched, And Why It Matters

OpenAI describes Atlas as “a new web browser built with ChatGPT at its core.” The idea of Atlas is, rather than visiting a website, copying content, and pasting it into a chatbot, the chatbot now lives inside the browser and can see the page you are on. OpenAI has framed it as a chance to “rethink what it means to use the web.”

Just On macOS (Free) For Now

Atlas is available now worldwide on macOS for Free, Plus, Pro, and Go users, with Windows, iOS, and Android versions “coming soon.” Business users can enable Atlas in beta, and Agent mode is available in preview for Plus, Pro, and Business tiers. OpenAI also published release notes and a download link, underlining that Atlas can import bookmarks, passwords, and browsing history from existing browsers.

How It Works In Practice

Atlas opens directly to ChatGPT rather than a traditional home page. Users can type a question or a URL, then work in a split view where ChatGPT summarises, compares, or explains the page they are on. An optional sidebar, “Ask ChatGPT,” follows the user as they browse, designed to remove the copy-paste friction that has characterised earlier chatbot use. OpenAI states that the browser can “understand what you’re trying to do, and complete tasks for you, all without leaving the page.”

Two features really stand out. The first is “browser memories,” which is an opt-in setting that allows ChatGPT to remember context from sites a user visits so it can bring that context back when needed. The second is “Agent mode,” which enables ChatGPT to act on the user’s behalf in the browser, carrying out tasks such as research, form-filling, or making bookings. OpenAI is keen to emphasise the benefit of user control, noting that browser memories can be viewed, archived, or deleted, that browsing content is not used to train models by default, and that visibility for specific sites can be turned off directly from the address bar.

Availability And Controls

At launch, Atlas includes parental controls that carry over from ChatGPT, with options to disable memories or Agent mode entirely. OpenAI says Agent mode can’t run code in the browser, download files, or install extensions, and it pauses on sensitive sites such as banks. Users can also run the agent in logged-out mode to limit access to private data.

Where Atlas Fits In A Crowded Browser Market

This move from OpenAI appears to be a direct challenge to existing players. For example, on desktop, Chrome holds about 73.65 percent of the global browser market, followed by Edge on 10.43 percent and Safari on 5.73 percent (StatCounter, September 2025). For Atlas to gain traction, it must prove both trustworthy and genuinely useful in daily workflows.

Vague Wording? What “AI Browser” Really Means

It seems that “AI browser” is quickly becoming shorthand for a set of common features, i.e., a chatbot that can read what’s on the screen, answer questions about it, and act within context. In Atlas, this takes the form of ChatGPT as a ride-along assistant that can process and recall on-page information.

Microsoft is pursuing the same idea. For example, in its Edge browser, Copilot Mode provides similar capabilities, opening a chat window that can summarise and compare data across multiple tabs. The company has also introduced “Actions,” which can fill in forms or book hotels, and “Journeys,” which group your tab history into ongoing projects.

The Indirect Prompt-Injection Issue

It seems that the most significant technical challenge currently facing Atlas, however, may not be unique to OpenAI. For example, Brave’s security team recently warned that indirect prompt injection is “a systemic challenge facing the entire category of AI-powered browsers.”

In simple terms, prompt injection occurs when a malicious webpage hides instructions that an AI assistant mistakenly interprets as user commands. This could cause the AI to perform unintended actions, such as fetching data from other tabs or leaking information from logged-in accounts.

Brave’s research revealed that similar vulnerabilities have been found in other AI browsers, including Perplexity’s Comet and Fellou, where attackers could hide commands inside website text or even faint image overlays. These instructions can bypass normal safeguards by being passed to the model as part of the page context.

In fact, OpenAI’s own documentation acknowledges this threat. For example, Dane Stuckey, OpenAI’s Chief Information Security Officer, described prompt injection as “a frontier, unsolved security problem” and said the company has implemented overlapping guardrails, detection systems, and model training updates to reduce risk. “Our adversaries will spend significant time and resources to find ways to make ChatGPT agent fall for these attacks,” he wrote, adding that users should run agents in logged-out mode when working on sensitive tasks.

Early Testing And What Researchers Are Seeing

Early demonstrations have already shown why this remains an open concern. For example, independent researchers have reportedly shared examples where Atlas responded to hidden instructions embedded within ordinary documents, producing unexpected outputs instead of the requested summaries. While these examples did not involve harmful actions, they highlight how easily indirect prompt injections can influence AI behaviour when content is treated as part of a legitimate task.

AI security researcher Johann Rehberger, who has documented several prompt-injection attacks across AI platforms, described the risk as affecting “confidentiality, integrity, and availability of data.” He noted that while OpenAI has built sensible safeguards, “carefully crafted content on websites can still trick ChatGPT Atlas into responding with attacker-controlled text or invoking tools to take actions.”

Brave’s recent post about this security issue also warned that agentic browsers can bypass traditional web protections such as the same-origin policy because they act using the user’s authenticated privileges. For example, a simple instruction hidden in a web page could, in theory, make the assistant act across sites, including banks or corporate systems, if guardrails fail.

How OpenAI Says It Has Balanced Power And Control

OpenAI has listed several design choices intended to reduce these risks. For example, users can clear specific page visibility, delete all browsing history, or use incognito windows that temporarily log ChatGPT out. Browser memories are private to the user’s ChatGPT account, are off by default, and can be managed directly in settings.

If a user opts to allow training on browsing content, pages that block GPTBot remain excluded. Agent mode cannot install extensions, access the file system, or execute code, and it pauses on sensitive sites where actions might expose personal data.

OpenAI says its approach is to combine technical safeguards with transparency. Users are shown what the agent is doing step by step, and actions can be stopped mid-flow.

For example, someone planning a dinner party can ask Atlas to find a grocery store, add ingredients to a basket, and place the order, watching each action unfold. Also, a student could use Atlas to ask real-time questions about lecture slides, while a business user can ask it to summarise competitor data or past documents without switching tabs.

Two Days Later, Microsoft Reframes Edge As An “AI Browser”

Just two days after OpenAI’s announcement, Microsoft expanded its own browser to include nearly identical functionality. On 23 October, the company unveiled an upgraded Copilot Mode for Edge, now officially described as “an AI browser.”

Mustafa Suleyman, CEO of Microsoft AI, wrote in a company blog post: “Copilot Mode in Edge is evolving into an AI browser that is your dynamic, intelligent companion.” The update introduces new features called “Actions,” which allow Copilot to fill out forms and make bookings, and “Journeys,” which group browsing sessions around specific goals.

Although Microsoft’s project was likely in development long before Atlas was revealed, the timing and similarity are notable. Both browsers now integrate AI deeply into browsing, both rely on contextual understanding to assist users, and both frame the assistant as a companion that can interpret what is on screen.

Independent reviewers have noted that the new Copilot Mode in Edge is visually and functionally close to Atlas. The layout differs slightly, but the underlying premise is the same: a built-in AI that reads, reasons, and acts on content as you browse. Microsoft says all new features require user consent before accessing tab content or history.

Challenges And Criticisms

While Atlas has been praised for its clean design and intelligent functionality, some experts have already raised questions about privacy, data control, and long-term security. OpenAI insists that browser memories are fully optional and off by default, but data protection specialists warn that even anonymised context retention can reveal behavioural patterns over time.

Also, some commentators have warned that Atlas, like other AI-driven browsers, could raise new privacy and security concerns if not carefully managed. For example, cybersecurity specialists have noted that the browser’s ability to access bookmarks, saved passwords, and full browsing histories could make the trade-off between convenience and data protection more critical than ever. They have also cautioned that combining web activity with chatbot interactions could increase risks such as profiling, targeted phishing, or unintended exposure of sensitive information.

It should also be noted here that early feedback from users has been mixed. For example, some testers have praised Atlas for its clear presentation of information and accurate sourcing, while others have reported slower performance and questioned how effectively Agent mode will operate once the browser is adopted at scale.

Cybersecurity researchers point out that even if Atlas performs safely under current controls, new prompt-injection techniques are constantly being developed. Brave’s researchers have already hinted that further vulnerabilities are likely to surface as more companies introduce AI-driven browsing.

The balance between innovation and oversight, and between convenience and confidentiality could, therefore, be the central test for Atlas and the new wave of AI browsers it represents.

What Does This Mean For Your Business?

OpenAI’s launch of Atlas could be one of the most ambitious steps yet in merging web browsing with conversational AI. It shows how quickly the boundary between search, productivity, and automation is dissolving, with the browser itself becoming a personal assistant rather than a static window to the internet. Yet it also exposes how far the technology still has to go before it can be trusted to act independently in real-world settings.

For users, the attraction is that Atlas promises a streamlined way to find information, take action, and move between tasks without switching tabs or tools. For OpenAI, it provides a direct platform for embedding ChatGPT more deeply into everyday digital life. However, the same integration that makes Atlas powerful also increases the surface area for risk. Allowing an AI agent to see and act within live browsing sessions inevitably raises questions about data access, authentication, and the potential for malicious manipulation through prompt injection or hidden instructions.

UK businesses, in particular, may need to approach Atlas with a mix of curiosity and caution. For example, the prospect of an intelligent browser that can summarise research, handle admin tasks, or automate data collection could boost productivity and streamline workflows. However, organisations will have to consider how it interacts with internal systems, how data is stored and transmitted, and whether its automation features comply with corporate security and privacy policies. For sectors such as finance, healthcare, and education, these considerations will be especially pressing, as even minor missteps could expose sensitive information or breach compliance rules.

For other stakeholders, including regulators and cybersecurity specialists, Atlas may represent an early glimpse of what “agentic” browsing could actually mean for the wider internet. It challenges long-held assumptions about user control, privacy, and accountability. If AI browsers become mainstream, the focus of online safety will need to expand from defending websites against users to defending users against their own automated agents.

In that sense, Atlas is less a final product than a live experiment in how people and machines might share control over digital tasks. Its success will depend not just on speed or convenience but on whether OpenAI can earn sustained trust from users, businesses, and regulators alike. For now, Atlas looks like being both a milestone in browser innovation and a reminder that every step towards automation must also bring new standards of responsibility, transparency, and security.

Tech Tip – Secure Your Web Browser in Under 5 Minutes

Think your antivirus is enough? If your browser isn’t secure, your data, and even your logins, could be at risk. Luckily, tightening things up takes just a few minutes. Here’s how:

How to lock things down (Chrome example):

– Click the three dots in the top right, then go to Settings.
– Select Privacy and Security.
– Turn on Enhanced Protection under Safe Browsing — this gives you faster, smarter protection from phishing, dodgy sites, and harmful downloads.
– Go to Cookies and other site data, and choose Block third-party cookies for more private browsing.
– Scroll to Site Settings, then:
– Block pop-ups (unless you really need them).
– Disable camera and microphone access unless needed.
– Check permissions for location, notifications, and clipboard, and switch off anything that looks unnecessary.

Bonus steps:

– Install a reputable ad blocker (e.g. AdGuard – there are many others).
– Use a password manager instead of letting your browser save logins.
– Make sure automatic updates are enabled so you’re always running the latest security fixes.

Pro-Tip: These steps apply to most major browsers – Firefox, Edge and Brave all have similar privacy and security menus. Just search for Privacy settings in their menus and follow the same logic.

Tech News : World’s First AI Deepfake-Detecting Browser

London-based cybersecurity innovator Surf Security has launched a beta version of its pioneering deepfake detection tool, integrated into its Enterprise Zero-Trust Browser®.

Deepwater

Dubbed the ‘Surf Deepwater’, this tool promises real-time, highly accurate detection of AI-generated deepfakes, potentially revolutionising how organisations can combat this rapidly growing threat.

98 Per Cent Accurate in Under 2 Seconds

Deepfakes, created using advanced artificial intelligence, are a growing problem, with their potential for misuse extending from financial fraud to political misinformation, an acute concern in a year of major global elections. Surf Security’s new browser-integrated technology is designed to detect these fabricated audio clips with up to 98 per cent accuracy in under two seconds.

Addressing a Growing Crisis

The rise of generative AI has made it increasingly easy for threat actors to create convincing deepfakes and weaponise them for financial scams, political manipulation, and even personal identity theft.

One stark example involved a multinational corporation’s Chief Financial Officer being impersonated using AI-generated audio, resulting in a $25 million fraud. On the political front, deepfakes have been used to produce fake election-timed videos of prominent figures, including one involving UK politician Wes Streeting.

Surf Security’s CTO, Ziv Yankowitz, has highlighted the urgency of addressing this threat, saying, “The rise of AI-based deepfakes presents significant security challenges for organisations, which can lead to reputation damage, data loss, regulatory non-compliance, and financial losses.”

A 2023 study by Sumsub revealed the alarming pace of this phenomenon, with deepfake-related scams increasing by 303 per cent (since 2022) in the USA alone. Countries such as Portugal (1700 per cent), China (2800 per cent), and Singapore (1100 per cent) have reported even steeper rises. These statistics highlight the rapid proliferation of deepfake technology, its global impact, and the urgent need for effective countermeasures.

How the Surf Deepwater Works

Surf says its AI-driven browser is so effective because it seamlessly integrates deepfake detection into everyday online interactions. Using advanced neural network technology, the tool analyses audio frames to identify inconsistencies indicative of AI generation. Its State Space Models (mathematical models for tracking system state changes over time) enable it to function across diverse languages and accents, providing results with both recorded and live audio.

Surf is keen to point out how user-friendly the process is, i.e. users simply press a button within the browser to verify whether an audio clip is genuine or AI-generated. The tool works with a wide range of platforms, including video conferencing tools like Zoom and Microsoft Teams, messaging services like WhatsApp and Slack, and even online videos.

The technology also incorporates background noise reduction, ensuring clarity and speed in its determinations. As Surf Security’s CTO explains, “To maximise its effectiveness, we focused on accuracy and speed,” adding that “The tool’s neural network is trained using deepfakes created by the top AI voice cloning platforms. It can spot a deepfake audio in less than 2 seconds.”

Aiming Beyond Audio Detection

However, Surf Security isn’t stopping at audio. The company has also announced plans to extend its capabilities to AI image detection, further bolstering its deepfake defence products. The company hopes that this holistic approach could make its Zero-Trust Browser a go-to solution for enterprises seeking comprehensive protection.

Military Grade

The browser’s use of military-grade technology and its foundation in probabilistic audio modelling set it apart from other solutions. Unlike standalone detection software, embedding this tool directly into a secure browser ensures that organisations can address the threat at the point of user interaction.

Some industry experts have spoken positively about this innovation. For example, Swetha Krishnamoorthi, Industry Principal for Cybersecurity at Frost & Sullivan, has said, “This capability is crucial for entities such as governments, politicians, customer service centres, and C-suite executives, providing robust protection against deepfake-driven cyber threats and safeguarding brand integrity.”

Availability and Anticipated Launch

The beta version of Surf Deepwater is now open for enterprise users to test. Organisations, including media outlets, law enforcement agencies, and corporate enterprises, can sign up for the programme through Surf Security’s website. The full release is scheduled for Q1 2025, with the company aiming to refine its functionality based on beta feedback.

Surf has also expressed its commitment to collaborative development, including contributing to open-source databases of deepfake audio and videos to enhance detection capabilities across the industry.

The Wider Cybersecurity Landscape

Surf Security’s innovation arrives in what could be described as a crowded yet fragmented market for deepfake detection tools. Existing alternatives include AI-driven software like Deepware Scanner and Deepfake Detection Challenge models developed by tech giants. However, most of these solutions require separate installation or specialised technical expertise, which can be a barrier to widespread adoption.

That said, alternatives to Surf’s browser-based AI deepfake detection system exist. Examples include:

 Reality Defender. This platform offers real-time detection of AI-generated threats across multiple media types, including images, video, audio, and text.

– WeVerify.Developed as part of the EU’s Horizon 2020 research programme, WeVerify provides a deepfake detection tool that breaks videos into individual shots, analysing each frame to calculate the probability of facial manipulation.

– Intel’s FakeCatcher. Introduced in 2022, FakeCatcher is designed to combat deepfakes by analysing subtle changes in blood flow in video pixels to determine authenticity.

– Resemble Detect. This AI model provides real-time detection of deepfake audio across various media types, distinguishing between real and fake audio with up to 98 per cent accuracy.

– Sensity AI. Sensity offers an all-in-one deepfake detection solution, providing a comprehensive set of tools to protect against AI-generated threats.

Simplicity – Benefit or Achilles’ Heel?

By integrating detection directly into its browser, Surf Security aims to add value and stand out by simplifying the user experience and potentially reducing costs for organisations already burdened by cybersecurity investments. However, some critics argue that this simplicity may also be its Achilles’ heel, as relying on browser-based solutions may not address threats occurring outside its ecosystem.

Additionally, as Yankowitz acknowledges, the fight against deepfakes is an ongoing arms race. The rapid evolution of AI voice cloning means that even cutting-edge detection tools may require constant updates to remain effective.

What Does This Mean for Your Business?

Surf Security’s Deepwater browser could represent a significant leap forward in the fight against deepfake technology, but it also highlights the complexities of addressing such a fast-evolving threat. With its promise of real-time detection, impressive accuracy, and user-friendly integration, the tool positions itself as a potentially valuable asset for organisations grappling with the growing risks posed by AI-generated content. By embedding deepfake detection within a secure browser, Surf Security is bringing a level of accessibility and immediacy that many standalone tools currently lack.

However, its reliance on a browser-based ecosystem raises legitimate concerns about its ability to provide comprehensive protection. Deepfake threats extend well beyond browser interactions, and organisations may still require supplementary measures to safeguard against manipulations in other contexts.

Surf Deepwater is, of course, not the only such option for businesses. The broader landscape reveals a competitive field, with alternatives like Intel’s FakeCatcher and Reality Defender offering solutions that cater to different use cases. While Surf’s holistic approach, with plans to expand into image detection, could provide it with an edge, the fragmented market means no single solution is likely to dominate entirely. Organisations may need to adopt a layered approach, combining tools like Deepwater with other detection technologies to ensure robust coverage.

That said, Surf Security’s innovation appears both timely and necessary. The soaring rise in deepfake-related fraud and manipulation makes tools like Deepwater an attractive option for mitigating risk, particularly for industries where trust and authenticity are paramount, and for businesses seeking a user-friendly option. Yet, as with all cybersecurity measures, it is only one piece of the puzzle. The ongoing battle against deepfakes will require not only technological innovation but also vigilance, collaboration, and a commitment to staying ahead of increasingly sophisticated threats.

Tech News : Brave Android Browser Gets ‘Leo’ Assistant

Brave, the privacy-focused browser, has announced the introduction of Leo, its privacy-preserving AI assistant built into the browser on all Android devices.

Users Can Choose Which Model – The Mixtral LLM & Meta’s Llama 2 

Brave says its new ‘Leo’ AI assistant is powered by the open-source Mixtral 8x7B as the default large language model (LLM) which became popular among the developer community since its December release. However, it says the free and premium versions of Leo also feature the Llama 2 13B model from Meta and that users can choose from the different models according to their needs and budget. Brave also says, however, that having Mixtral as the default LLM brings “higher quality answers”. 

What Can Leo Do? 

Launched 3 months ago, subsequently achieving what Brave describes as “global adoption”, Brave says Leo can create real-time summaries of webpages or videos, answer questions about content and generate new long-form written content. Brave says it can also translate pages, analyse, or rewrite them, create transcriptions of video or audio content, and write code. Leo can also interact in multiple languages including English, French, German, Italian, and Spanish.

In short, it appears to be able to do what other popular generative AI chatbots can do, e.g. ChatGPT.

What’s So Different About Leo? 

With Brave being specifically a privacy-focused browser offering ad tracker blocking and no personal data collection, Brave is keen to point out that what’s different about Leo is that it’s effective generative AI, but with “the same privacy and security guarantees of the Brave browser.”   

Brave says this privacy is achieved by:

– Anonymisation via reverse proxy. Leo uses a reverse proxy that anonymises all requests, ensuring Brave cannot link any request to a specific user or their IP address.

– No data retention. Leo’s conversations are not stored on Brave’s servers, and responses are discarded immediately after generation. No personal data or identifiers (such as IP addresses) are retained. For users opting for models from Anthropic, data is held for 30 days by Anthropic before being deleted.

– No mandatory account. Users can access Leo without creating a Brave account for the free version, promoting anonymity. A premium account is optional for multi-device access.

– Privacy-enhanced subscription. Premium subscribers use unlinkable tokens for authentication, ensuring subscription details cannot be associated with their usage. The email used for account creation is also kept separate from daily use, enhancing privacy.

Free and Subscription Versions 

Although Brave says Leo is free to all users and there is no ‘mandatory’ subscription, as with other chatbots, there is a subscription version at $14.99 per month – cheaper than others like ChatGPT and Gemini Advanced. One subscription covers up to 5 different devices across Android, Linux, macOS, and Windows.

What Does This Mean For Your Business? 

With other popular browsers incorporating their own AI chatbots, the pressure was on Brave to offer the same, but with the added challenge of keeping it private. Competing AI chatbots such as Google’s Gemini and ChatGPT warn users not to share private/personal details with the chatbots, acknowledging that these could possibly somehow be revealed elsewhere with the right prompts and/or may be used for training models. Also, in a world where AI chatbots (e.g. Copilot) are getting plugins that link them up with shopping apps, the potential for some kind of related data gathering through AI is there. Brave’s (Leo’s) differentiation, therefore, lies in its apparent ability to keep things private and could serve to help Brave to retain users and keep its share in the private browser world while adding value of the right kind for its users.

Early last year, competitor DuckDuckGo introduced a beta AI Wikipedia-linked instant answer ‘DuckAssist’ feature but withdrew it from private search in March last year. It was intended to help DuckDuckGo’s users to simply find factual information more quickly but also, in keeping with DDG’s privacy focus, it promised that searches were anonymous. Leo, therefore, represents a major opportunity for a private version of AI which some business users or users in sensitive sectors may prefer, but it remains to be seen how/whether the privacy protection affects the comparative quality of outputs.