This article was prepared from the source material provided, which includes quotes from The Verge, The Wall Street Journal, Fortune, and Brave's security findings.

OpenAI this week introduced Atlas, a web browser built around ChatGPT that includes an "agent mode" capable of completing tasks such as booking flights or buying groceries online—a process the company calls "vibe lifing." In its announcement, OpenAI said a browser built with ChatGPT "takes us closer to a true super-assistant that understands your world and helps you achieve your goals." Early testing, however, points to usability and security hurdles that the company has yet to address.

Atlas is not the first attempt to embed an AI chatbot into a browser. It joins Perplexity's Comet and Google's Gemini, which is integrated into Chrome. The browser is built on Google's open-source Chromium project, also used by Opera, Arc, and Brave.

Search and Agent Mode Fall Short

The Verge's Emma Roth, who tested Atlas, wrote that "the immediately obvious problem is that ChatGPT simply doesn't feel like an adequate portal to the web." She found ChatGPT's suggestions "aren't always relevant," including local news results that were not actually local to her. Roth noted that Atlas includes a link to Google in the top-right corner of each search results page, which she said is "probably why" the search experience is limited.

Other users reported that Atlas restricts access to many websites, including The New York Times and online banking portals. Roth described the overall experience as "basically a ChatGPT-flavored version of Gemini in Chrome and Perplexity's AI assistant in Comet, and after a bit of early testing, seems to work about as well."

The flagship agent mode was notably slow. Roth asked it to "fill up my Amazon cart with items based on my recent browsing history," which took "ten minutes to add just three items." Comet completed the same task in two minutes. Wall Street Journal columnist Nicole Nguyen wrote that "at times, Atlas struggled with clicking the correct button; it was like watching my toddler feed himself—inefficient but ultimately successful." She said it took 16 minutes for Atlas to "find flights for a coming trip."

Prompt Injection Risks Remain Unresolved

Cybersecurity experts have flagged risks across AI browsers. This week, browser company Brave outlined security flaws in Comet, noting how easily it falls prey to "prompt injections," where hackers deliver hidden messages to an AI to carry out harmful instructions.

George Chalhoub, an assistant professor at the UCL Interaction Center, told Fortune that "there will always be some residual risks around prompt injections because that's just the nature of systems that interpret natural language and execute actions." He added that "the main risk is that it collapses the boundary between the data and the instructions: it could turn an AI agent in a browser from a helpful tool to a potential attack vector against the user." Chalhoub said an attacker could use the agent to extract emails, steal work data, log into Facebook to steal messages, or extract passwords, giving the agent "unfiltered access to all of your accounts." How OpenAI will address the issue with Atlas remains unclear.

Atlas is an early step in OpenAI's broader ambition to build an operating system. Earlier this month, the company introduced apps in ChatGPT and an "Apps SDK" that allows developers to build their own apps, including "mature" ones, using the chatbot.

Editorial Notes