Just nine months after launching its browser Atlas, OpenAI discontinued working on it.
OpenAI is retiring Atlas as a standalone browser and folding its agent features into ChatGPT plus a Chrome extension. For brands, the browser layer is where agents watch, click and buy across any site — and it's where a new fraud and liability gap is opening.
Just nine months after launching its browser Atlas, OpenAI discontinued working on it. Instead they'll fold the agent features into the ChatGPT app and have a Chrome extension instead.
This is the fourth in a short series on the different types of agents shaping how, and whether, brands get chosen. The first three looked at the model apps themselves, the closed marketplaces, and third parties building inside someone else's AI. This one is different again: agents that operate at the level of the browser, watching, clicking and buying across whatever site a person visits, logged in as that person.
Perplexity's Comet has the clearest momentum, crossing 10 million users within months of going free in October 2025 and available across every major platform. It's also the one Amazon sued over unauthorised shopping access and lost on appeal.
Atlas was OpenAI's attempt to own the browser layer outright rather than depend on Chrome, Safari and Edge for distribution. Retiring it as a standalone product nine months in suggests that it wasn't commercially viable.
The one worth watching is Gemini's auto browse built directly into Chrome itself rather than requiring a download. It will simply already be in the browser most of the world already uses.
Claude's version, by contrast, is a Chrome extension aimed more at work tasks than consumer shopping, consistent with the enterprise lean we've seen from Claude throughout this series. Microsoft has folded Edge's own Copilot features into the free browser as well.
University of Washington researchers tested seven agentic browsers and found four, including Atlas, Chrome with Gemini, Claude's extension and Comet, could be tricked into bypassing the same-origin policy, the rule that's kept one website from reading another's data for three decades. They ran a working attack against Atlas.
From a business perspective that leaves them exposed because when an agent buys on a customer's behalf, it looks exactly like that customer, logged in, on their own device. Your fraud tools are built to catch the wrong person in the right session, not the right session hijacked by instructions the agent picked up elsewhere. That's a live fraud and liability gap, worth a conversation with your security team now, not after the first incident.
- —OpenAI is discontinuing Atlas as a standalone browser; the browser-agent layer is consolidating around extensions and built-in browser features rather than standalone apps.
- —Perplexity's Comet has momentum, but Gemini's auto browse in Chrome may be the most consequential because it requires no download and ships with the browser most people already use.
- —Agentic browsers can bypass same-origin protections, and when they transact they look like the legitimate customer — creating a fraud and liability gap security teams should review now.