9 Sources
[1]
Google details security measures for Chrome's agentic features | TechCrunch
An increasing number of browsers are experimenting with agentic features that will take actions on your behalf, such as booking tickets or shopping for different items. However, these agentic capabilities also come with security risks that could lead to loss of data or money. Google detailed its
[2]
Google says Chrome's AI creates risks only more AI can fix
'User Alignment Critic' will review agentic actions so bots don't do things like emptying your bank account Google plans to add a second Gemini-based model to Chrome to address the security problems created by adding the first Gemini model to Chrome. In September, Google added a Gemini-powered
[3]
Google Adds Layered Defenses to Chrome to Block Indirect Prompt Injection Threats
Google on Monday announced a set of new security features in Chrome, following the company's addition of agentic artificial intelligence (AI) capabilities to the web browser. To that end, the tech giant said it has implemented layered defenses to make it harder for bad actors to exploit indirect
[4]
Google Chrome adds new security layer for Gemini AI agentic browsing
Google is introducing in the Chrome browser a new defense layer called 'User Alignment Critic' to protect upcoming agentic AI browsing features powered by Gemini. Agentic browsing is an emerging mode in which an AI agent is configured to autonomously perform for the user multi-step tasks on the
[5]
Google adds prompt injection defenses to Chrome
Agents now log activity and seek approval before accessing sensitive sites Google is adding new defenses to the Chrome browser, to make sure its agentic capabilities cannot be abused through indirect prompt injection. Indirect prompt injection is a type of attack in which the AI agent reads
[6]
Google details security guardrails for Chrome's new AI agents
Google detailed its security approach for agentic features within its Chrome browser, which can perform actions on behalf of users. The company previously previewed these capabilities in September, and a wider rollout will occur in coming months. The company has implemented observer models and
[7]
Google Built an AI Watchdog to Stop Chrome's Gemini From Going Rogue - Phandroid
Google just built an AI to babysit another AI, and honestly, it makes a lot of sense. The company announced something called the User Alignment Critic in December 2025, which basically acts as a watchdog for Chrome's Gemini agent to stop it from doing anything stupid or dangerous while browsing for
[8]
Google Shares Safety Guardrails for Chrome Browser's Agentic Capabilities
User confirmation will be required before the agent takes critical steps Google, on Monday, shared the safety measures it is implementing to protect users and their data from bad actors while they use the agentic features in Google Chrome. These agentic features were added to the browser recently,
[9]
Google's increasing Chrome security for agentic AI actions with User Alignment Critic model
User Alignment Critic protects against AI misuse and prompt injection attacks Google is gearing up for a major shift in how people interact with the web. As its Gemini assistant moves beyond simple suggestions and gains the ability to perform actions directly inside Chrome, the browser is being
Share
Copy Link
Google unveiled new security measures for Chrome's agentic features, including a User Alignment Critic model that monitors AI actions and Agent Origin Sets that restrict data access. The company is offering up to $20,000 through its bug bounty program for researchers who find vulnerabilities in these defenses against indirect prompt injection attacks.
Google is rolling out comprehensive security measures for Chrome as the browser prepares to launch agentic features powered by Gemini AI integration. The agentic browsing features, first previewed in September, will enable AI agents to autonomously perform multi-step tasks like booking tickets, shopping, and navigating websites on behalf of users
1
. However, these capabilities introduce serious risks, with Chrome security engineer Nathan Parker identifying indirect prompt injection as "the primary new threat facing all agentic browsers"2
. This threat occurs when AI models ingest malicious content from web pages that instructs them to ignore safety guardrails, potentially leading to unauthorized financial transactions or data leaks3
.
Source: BleepingComputer
At the core of Google Chrome's new AI security architecture is the User Alignment Critic, a separate Gemini-based LLM model that functions as a "high-trust system component" isolated from untrusted content
4
. This oversight mechanism runs after the planner model completes its work, double-checking each proposed action to determine whether it serves the user's stated goal1
. The User Alignment Critic sees only metadata about proposed actions, never accessing unfiltered web content, which prevents attackers from poisoning it through malicious prompts embedded in websites3
. When the critic identifies misaligned actions, it vetoes them and provides feedback to the planner model to reformulate its strategy, returning control to the user after repeated failures3
.
Source: Digit
Google extended Chrome's Site Isolation capabilities through Agent Origin Sets, which ensure AI agents only access data from origins relevant to the current task or explicitly shared by users
3
. A trustworthy gating function categorizes origins into read-only and read-writeable sets for each session1
. Read-only origins contain content Gemini can consume, like product listings on shopping sites while excluding banner ads, whereas read-writeable origins allow the agent to click or type on specific page elements1
. This separation bounds the threat vector of data leaks by ensuring only limited origin data reaches the agent and can only be passed to authorized writable origins1
. The gating function operates independently from untrusted web content and requires planner approval before adding new origins3
.
Source: Hacker News
Related Stories
Google is implementing strict user control measures for sensitive operations within its agentic browsing features. The AI agent will request explicit approval before navigating to banking or healthcare portals that handle sensitive data
5
. For sites requiring authentication, Chrome asks permission before using Google Password Manager credentials, with the agent's model having no exposure to password data1
. Users must also approve consequential actions like making purchases, sending messages, or completing financial transactions2
. Agents create work logs for user observability, allowing people to monitor what actions are being planned and executed on their behalf4
.Google revised its Vulnerability Rewards Program to incentivize security researchers to probe Chrome's agentic safeguards, offering payouts up to $20,000 for demonstrations that breach security boundaries
2
. The company developed automated red-teaming systems that generate test sites and LLM-driven attacks to continuously evaluate defenses, with new protections deployed quickly through Chrome's auto-update mechanism4
. Additional security measures include a prompt-injection classifier running parallel to the planner model's inference, checking each page for indirect prompt injection attempts alongside Safe Browsing and on-device scam detection3
. Google also investigates URLs through an observer model to prevent navigation to harmful model-generated addresses1
. This comprehensive approach comes as IT consultancy Gartner recently recommended enterprises block AI browsers until associated risks can be appropriately managed, highlighting concerns about employees potentially using AI agents to bypass mandatory cybersecurity training3
. The technique of using one machine learning model to moderate another, formalized in a Google DeepMind paper this year as "CaMeL" (CApabilities for MachinE Learning), represents an industry pattern for addressing AI safety challenges2
.Summarized by
Navi
[2]
[4]
[5]
02 Mar 2026•Technology

09 May 2025•Technology

30 Oct 2025•Technology

1
Science and Research

2
Technology

3
Policy and Regulation
