Most of us already have a complicated working relationship with our browser. It holds our email, our shopping, our research and seventeen tabs we absolutely intend to read. Agentic browsing adds another possibility: asking the browser to do some of the work inside those tabs.
The appeal is easy to understand. Instead of manually comparing three products, copying details into a document and filling out a form, you describe the result you want. An AI system attempts the intermediate steps. The important word is âattemptsâ: the difference between a useful assistant and an expensive misunderstanding is often hidden in those steps.
What makes browsing agentic?
A summarizer reads a page and returns an answer. An agent can also use tools to navigate, enter information and interact with a website. Depending on the product and permissions, that might include preparing a booking, organizing information or taking action in an account.
Imagine asking for flights to Milan below a fixed budget. Finding candidates is one level of responsibility. Selecting a nonrefundable ticket and submitting payment is another. An agent should have clear boundaries between those stages, rather than treating your interest in Italy as unlimited purchasing authority.
Products use âAI browserâ and âagentic browserâ broadly. A chat sidebar, automatic tab grouping and a tool that completes transactions are different capabilities, even if the landing pages use similar adjectives.
Comet: moving from answers to actions
Perplexity introduced Comet in July 2025. Its launch announcement describes a browser assistant intended to combine research with actions such as scheduling meetings and working with information across pages. Access initially began with Perplexity Max subscribers and invitations.
That is the productâs intended direction, rather than a guarantee that it can complete any task on any website. A site may require a login, an extra verification step or a choice that the user has not specified.
Access to live web information can help an assistant answer questions about changing prices or availability. It does not make every source correct or every action safe. A page can be current and still misleading; the assistant can also misunderstand perfectly accurate information.
As of this articleâs early-March perspective, an anticipated iOS release should not be treated as a tested, already-shipping version. Mobile availability and feature parity need their own confirmation, rather than being inferred from the desktop product.
Norton Neo: assistance and user controls
Nortonâs December 2, 2025 announcement opened Neo globally after an early-access release in May. That separates the first testing phase from broader availability.
In its description of Neoâs features, Norton emphasizes summaries, tab organization and personalization. It says users can inspect, edit or delete what the browser remembers and turn memory off. It also describes Web Shield protections against malicious sites.
Those controls are useful things to examine. They do not establish that all AI processing happens on your device, that nothing is transmitted to a service or that Neo is immune to malicious instructions. Storage, inference and model training are separate questions; âprivacy-firstâ is not a detailed answer to all three.
Norton also announced Android availability on March 6, 2026, with iOS described as coming later. Again, the name of a product is not proof that every platform has the same features at the same time.
When a webpage tries to become the boss
Indirect prompt injection is one of the distinctive risks of this category. A page contains instructions planted by somebody else; the assistant encounters them while doing your task and mistakenly treats them as directions it should follow.
Braveâs August 2025 Comet research demonstrated this problem using webpage content that redirected an assistant toward authenticated information. Its disclosure timeline describes an initial fix, further testing and remaining concerns. Brave is a browser competitor, but the published demonstration and timeline are more useful evidence than a blanket claim that the issue was permanently solved.
Brave subsequently reported another route through screenshots in October 2025. The point is not that a historical test proves every current version has the same flaw. It shows why checking one input format or patching one example does not establish complete protection.
Ordinary browser isolation still matters. The added problem is that an agent may be permitted to cross between sites on your behalf. If it follows the wrong instructions while doing so, legitimate capabilities can be used toward an illegitimate goal.
The permissions matter as much as the model
For an experiment with public information, the risk is relatively contained: ask the assistant to compare a few pages, show its sources and explain its result. A workflow involving email, purchases or private records deserves tighter boundaries.
A useful setup makes it clear which accounts the agent can access, which actions require confirmation and how to stop it. Preparing an email for review is different from sending it; assembling a shopping cart is different from paying. The interface should make those distinctions obvious.
It should also show enough evidence to check the outcome. âDoneâ is encouraging, but a booking reference is better. We already have a cat who confidently announces that dinner has happened when dinner has merely been requested.
A promising change, without the autopilot fantasy
Agentic browsing could remove tedious work from everyday tasks. That value depends on reliability, sensible access limits and a clear handover when judgment is needed.
The best question is therefore more specific than âWhich browser has the smartest AI?â Ask which task it can complete, what information it needs and where you remain in control. A browser that knows when to ask can be more useful than one determined to finish at any cost.




