Someone installs Comet because a colleague recommended it, or switches on Claude in Chrome because it came with the subscription. An hour later a language model is reading along in the CRM.
An AI browser is a web browser, or an extension in an existing one, with an AI assistant that can read the pages you have open and, in agent mode, click, fill in forms and place orders on the user's behalf. For an organisation that adds two risks at once: what's on screen goes to an AI service, and a web page can steer that agent through hidden instructions.
Gartner advises organisations to block AI browsers for now. That's a defensible position, but the picture in the EU looks different from US coverage, and a blanket ban isn't the only outcome.
Which AI browsers will you find on EU workstations in October 2026?
The AI browsers turning up on European workstations aren't the same ones you read about in US coverage. Some features aren't available in the EU at all, and the product the 2025 debate centred on no longer exists.
| Product | Status in the Netherlands (9 October 2026) | Central management |
|---|---|---|
| Perplexity Comet | standalone browser for Windows and macOS, free | Comet Enterprise with MDM management |
| Claude in Chrome (Anthropic) | extension, generally available on paid plans since 26 August 2026 | Team and Enterprise: on/off, allowed and blocked domains |
| Browser in the ChatGPT desktop app (OpenAI) | replaces ChatGPT Atlas, which stopped working on 9 August 2026 | managed configuration via MDM |
| Gemini in Chrome (Google) | not available in the EU or EEA | Chrome policy GeminiSettings |
| Browsing with Copilot in Edge (Microsoft) | business agent mode in preview, EEA tenants excluded | Edge policy AllowBrowsingWithCopilot |
| Opera Neon, Dia | standalone browsers with agent features | no central AI settings found |
According to Google's admin documentation, no EU country is on the list of regions where Gemini in Chrome works. The UK is. Microsoft's documentation on browsing with Copilot says "only tenants outside of the European Economic Area may participate at this time". And with a work profile in Edge, Copilot has no access to page content by default in the EU.
So the agents you need to manage in the EU today don't come from your workplace platform vendor. They come from third parties: Perplexity, Anthropic, OpenAI, Opera. Those are exactly the ones employees install themselves or switch on through a personal subscription.
Why does Gartner advise blocking AI browsers?
In December 2025 Gartner published Cybersecurity Must Block AI Browsers for Now, with the core advice that CISOs should block them "until enterprise-ready AI browsers are released in GA". The report names two kinds of risk.
The first is data loss. According to Gartner, sensitive data such as the active page, browsing history and open tabs is often sent to the cloud AI back end, and default settings put user experience ahead of security.
The second is that the agent can be steered by what it reads. That's indirect prompt injection: a web page, email or document contains instructions the model follows as if the user gave them. In August 2025, Brave researchers showed that Comet could be made to send off the user's email address and a one-time Gmail code by text hidden behind a spoiler tag on Reddit. Their conclusion: the web's existing protections, such as the same-origin policy, are "effectively useless" once an agent acts on your behalf.
The vendors don't promise a fix. OpenAI wrote in December 2025 that prompt injection, like scams on the web, "is unlikely to ever be fully 'solved'". Anthropic reported that in its first Claude in Chrome test, 23.6% of attacks succeeded without mitigations and 11.2% with them. By general availability in August 2026, newer models and extra classifiers had pushed those rates down sharply, but Anthropic still wrote that prompt injection "remains a moving target". The UK's NCSC calls language models "inherently confusable", because they draw no hard line between instructions and data. How these attacks work, and how to protect your own agents, is covered in securing AI agents against prompt injection.
When does an AI browser become a data breach?
An AI browser becomes a data breach when personal data reaches the AI service without a legal basis or agreement in place. The Dutch Data Protection Authority reported back in 2024 that it had received several breach notifications caused by staff sharing personal data with a chatbot, such as patients' medical details at a GP practice. Where that happens against the employer's rules, the regulator treats it as a personal data breach, often with a duty to report.
With a chatbot, an employee still has to paste the data in. With an AI browser, the open tab is the input. Anyone with a customer file open in the CRM who asks the sidebar to "summarise this" has shared that file. With an agent that navigates tabs by itself, the employee may not even know which pages the model read.
The gap between a business and a personal account is bigger than it looks. Google's documentation for Gemini in Chrome, for example, says prompts and tab content from business Workspace users aren't used for training, and that users without a business edition fall under consumer terms. An employee who signs in with a personal subscription brings those consumer terms into your customer files. It's the same problem as shadow AI, but with access to everything open in the browser.
Block, allow or contain: how do you decide?
Whether to block, allow or contain depends on what's open in your employees' browsers, not on how good the product is. This is the framework we use with clients:
| Question | Answer that means block |
|---|---|
| Do staff handle special-category personal data, professional secrecy or payment systems in the browser? | yes, and you can't technically exclude those domains |
| Can you enforce that only the business account signs in? | no |
| Can you control per domain where the AI may read and act? | no |
| Is the AI service in your record of processing and covered by a processor agreement? | no |
| Is there a concrete task the agent is needed for? | no, it's "nice to have" |
If any answer in the right-hand column applies, block that product. In practice that gives three categories:
- Block: standalone AI browsers without central management, such as Opera Neon and Dia, and Comet unless you buy Comet Enterprise. On Windows, use App Control for Business or AppLocker.
- Contain: an extension or desktop browser from a vendor you have a business contract with, with an allowlist of domains where the AI may read. Agent actions are off, or limited to a handful of public sites, such as supplier portals without personal data.
- Allow: only for roles with a concrete task, on a business account, recorded in your processing register, with a short instruction on which tabs must be closed.
What we advise against: giving an AI agent access to email or internal systems through the browser. An agent that needs to do a job in your email or ERP is better built as an agent with exactly the integrations it needs, with logging and human approval on the steps that matter. Then you decide what the model sees, not the employee's session. How that works in production is covered in running AI agents in production.
Time saved
Save 6 hours per week on inventorying which AI browsers and extensions are active on workstations and setting browser policy
Which settings should you configure per product?
For every product you contain or allow, these are the settings that make the difference. They're in the vendors' documentation and can be rolled out through MDM or group policy.
Chrome, for all extensions
ExtensionInstallBlocklist set to * blocks all extensions, and ExtensionInstallAllowlist lets through only the approved ones. That's the baseline, because Claude in Chrome and the ChatGPT extension are both extensions.
Claude in Chrome
In Anthropic's admin controls you switch the extension on or off per organisation and manage allowed and blocked domains. Note that on Team plans the extension is on by default. The forceLoginOrgUUID policy makes sure the extension only connects to your organisation, not a personal account. Since August 2026 Claude automatically approves actions it judges safe. Consider switching that off.
The browser in the ChatGPT desktop app
OpenAI supports a managed configuration file (requirements.toml) with a [browser_use] section. Set default_origin_policy to access = "deny" and grant access, uploads and downloads per domain. You can also switch off access to browsing history.
Edge
AllowBrowsingWithCopilot with an empty allowlist disables agent mode. EdgeEntraCopilotPageContext controls whether Copilot may read the page. In the EU it's off by default, but users can turn it on unless you lock the policy.
Chrome with Gemini
It isn't available in the EU yet, but the policies already exist: GeminiSettings set to 1 disables Gemini in Chrome, and GeminiActOnWebSettings set to 1 stops Gemini from acting on web pages. Lock them now and nothing changes on the day Google rolls it out in Europe.
What belongs in your AI policy on AI browsers?
An AI policy that only mentions chatbots misses the browser. Add three rules: which AI browsers and extensions are allowed, and on which account; which systems must never be open while an AI sidebar or agent is in use (think HR, finance and customer files); and who approves an agent action that costs money or sends something.
Also record how you'll check the policy works. A periodic export of installed extensions and applications from your MDM shows whether a Comet or Neon has turned up on a laptop anyway. How AI agents work in general, and where the line sits between an assistant and an agent, is covered in what an AI agent is. The wider measures around company data are in AI data security for businesses.