Episode 13 · Article on the episode
The browser as an actor: what Atlas can do and why caution is warranted
Atlas clicks, fills in forms and posts on its own in Agent Mode. That is impressive, and it opens an attack route against which there is currently no robust defence.
The arc of this episode runs from an AOL advert featuring Boris Becker through to Atlas, the AI browser from OpenAI. The difference to everything before it: the browser is no longer a tool, it is an actor.
Among other things it was tried out for an automated LinkedIn post and for clearing out one's own inbox.
What is actually new about it
Summaries and sidebar interaction have long been on offer from Microsoft with Copilot in Edge, and Perplexity and Manus are experimenting with agentic browsing as well.
The difference with Atlas lies in the visibility. You see more directly what is currently happening on the page while tasks are being worked through in Agent Mode: price research, competitor comparisons, automated assessments of a website from the perspective of different user groups.
The last use case is the most useful in practice and is rarely mentioned. Having a website assessed from the perspective of different target groups replaces no user research, and it delivers a usable first pass for a fraction of the effort.
The attack route
Things become critical when it comes to security, and fundamentally so.
Access to your own inbox is particularly delicate. Whoever grants it grants, in practice, access to every password reset and thereby indirectly to all services that can be recovered via that inbox.
With online banking the same question arises even more sharply. The assessment in the episode is unambiguous: an exciting field that is to be treated with caution at present.
The Habsburg effect
The second point of contention is a number: more than half of all online content is now machine generated, and the trend is rising.
From this follows a problem for which the episode picks the image of the Habsburg effect. When language models are increasingly trained on machine generated data, the gene pool narrows. Errors and idiosyncrasies reinforce themselves across generations instead of being balanced out by new sources.
For website operators an unfamiliar task follows from this: in future, content will have to be optimised not for humans alone, but also for the agents that read it. That concerns structure, unambiguous information and machine readable data, and it contradicts much of what has counted as good web design in recent years.
Conclusion
Agentic browsing is the first application in which a model acts in the open web instead of in a controlled environment. That explains both the benefit and the risk.
Anyone who wants to deploy it clarifies three things beforehand. On which pages may the agent act and not merely read? With which access does it work, and is that an access of its own with narrow rights? And which actions require an explicit approval?
For the inbox, the bank and everything touching money or access, the usable answer at present is: no automatic actions. Reading yes, acting no.
That is not a rejection of the technology. It is the recognition that an attack route is open for which there is as yet no solution.