Agentic Browsers Bypass Security Controls, Researchers Warn

AI agentic browsers are shipping with weak security guardrails, bypassing controls that enterprises rely on to govern access and behavior. Dark Reading flags this as an active gap, not a theoretical one. The browser is now an autonomous operator, and the controls were not built for that.
Traditional browser security assumes a human is in the loop. An agent does not pause, reconsider, or notice a policy boundary. It executes. That changes the threat surface: permissions granted to a user become permissions granted to a process that never sleeps and never second-guesses.
Security teams and procurement leads should treat agentic browser deployments as a new access-control category, not an extension of existing endpoint policy. Watch for vendors to start competing on agent-specific sandboxing and permission scoping. That is the gap the market will move to fill.