Skip to content
AI.info

Ethics & Governance

Atlas lasted 292 days: what a failed AI browser leaves behind

OpenAI shut ChatGPT Atlas down on 9 August 2026, 292 days after launch, and moved its agent into a ChatGPT extension for five other browsers. The product failed on distribution; the standing-access bargain it asked for did not.

Atlas lasted 292 days: what a failed AI browser leaves behind

Gabriele Masetti ·

A browser that lasted 292 days

OpenAI launched ChatGPT Atlas on 21 October 2025 in a livestream: a Chromium browser with ChatGPT in the sidebar and, for paying subscribers, an agent mode that could click, fill forms and finish tasks inside a session the user was already signed into. Sam Altman pitched it as a once-in-a-decade chance to rethink what a browser is for. It shipped on macOS. Windows, iOS and Android were announced as coming soon and never arrived, not as releases and not as public betas.

OpenAI announced the retirement on 9 July 2026 and gave users thirty days. Atlas stopped working on 9 August 2026, 292 days after launch. Bookmarks, open tabs and history transferred nowhere automatically; the help-centre note told people to export bookmarks to an HTML file and import them into another browser before the date.

James Sun of OpenAI announced the shutdown on X, alongside the features that replaced it:

Lastly, with all these updates, we are going to be sunsetting Atlas. All these capabilities were built on what we learned from Atlas users who took a leap of faith on a new browser. — James Sun, OpenAI

The reason OpenAI gave, and the one it did not

OpenAI's help-centre note, "Evolving Atlas into ChatGPT for browser-based agentic work", is brief about the why. It says the company is deprecating Atlas and moving browser-based agentic capabilities into ChatGPT and Codex, and that it is building on what it learned from Atlas to support a more capable browser experience in ChatGPT — multiple tabs, downloads, improved navigation, account login support. The stated reason is consolidation into products people already open. Security appears nowhere in it as a cause.

Analysts supplied the explanations OpenAI did not. Chrome held 69.39% of worldwide browser use in August 2026 on StatCounter's numbers, against 15.83% for Safari and 5.36% for Edge. A new browser has to win a default, and Atlas never had one on any platform, including the one it shipped on. TechCrunch's reading of the shutdown was that OpenAI "appears to have concluded that the browser is a feature, not the destination" — an inference by the reporter, not a company line.

OpenAI's own priorities had turned months earlier. At a March 2026 all-hands reported by the Wall Street Journal, Fidji Simo, then OpenAI's CEO of applications, told staff to stop being pulled off course by peripheral products, naming coding and business productivity as the work that mattered.

We cannot miss this moment because we are distracted by side quests. — Fidji Simo, CEO of Applications, OpenAI

A consumer browser built from a standing start against Chrome, on one desktop platform, fits that description more closely than anything else OpenAI shipped in 2025.

The admissions in OpenAI's own security post

Two months after launch, on 22 December 2025, OpenAI published "Continuously hardening ChatGPT Atlas against prompt injection attacks" and conceded the limit of the design it had already shipped to users.

Prompt injection, much like scams and social engineering on the web, is unlikely to ever be fully "solved." — OpenAI, Continuously hardening ChatGPT Atlas against prompt injection attacks

The same post said agent mode "expands the security threat surface" and described a reinforcement-learning attacker OpenAI had trained against its own product. That attacker, the company wrote, "can steer an agent into executing sophisticated, long-horizon harmful workflows that unfold over tens (or even hundreds) of steps", and produced "novel attack strategies that did not appear in our human red teaming campaign or external reports". The countermeasures offered were containment, not cure: a logged-out mode, confirmation before high-stakes actions, and a rapid-response loop OpenAI argued could materially reduce real-world risk.

The warning was not OpenAI's alone. Earlier in December 2025 the UK's National Cyber Security Centre warned that prompt injection attacks against generative AI applications "may never be totally mitigated".

Read plainly, that is a vendor telling its own users that the core capability it sold them rests on a vulnerability class it does not expect to close. Atlas itself was free to everyone from launch day; agent mode, the part that acted inside logged-in sessions, was gated to Plus, Pro and Business subscribers. The riskiest behaviour was the paid tier.

What was documented while the product was alive

Date Finding Disclosed by
20 Aug 2025 Comet coaxed into email and OTP exfiltration Brave
Oct 2025 "CometJacking" data exfiltration via one link LayerX Security
Oct 2025 "Tainted Memories" CSRF in Atlas memory LayerX Security
21 Oct 2025 Prompt injections hidden in screenshots Brave
11 Mar 2026 "AgenticBlabbering" phishing evasion Guardio Labs

Brave's security team published the first entry on 20 August 2025, against Perplexity's Comet rather than Atlas. Hidden instructions in a Reddit comment made the assistant read the user's email address from account settings, trigger a one-time-password login, fetch the code from the user's own Gmail, and post both back as a reply.

The attack we developed shows that traditional Web security assumptions don't hold for agentic AI, and that we need new security and privacy architectures for agentic browsing. — Brave, Agentic Browser Security: Indirect Prompt Injection in Perplexity Comet

Atlas got its own entry in October 2025, when LayerX Security described "ChatGPT Tainted Memories", a cross-site request forgery it said could piggyback on a logged-in user's credentials to write attacker instructions into ChatGPT's memory, where they would persist into later sessions. LayerX also reported that Atlas shipped without meaningful anti-phishing protection, putting its users up to 90% more exposed to phishing pages than users of Chrome or Edge. OpenAI disputed the memory finding directly.

To our knowledge, this issue doesn't impact ChatGPT Atlas, which isn't vulnerable to this kind of cross-site request forgery (CSRF) attack. — OpenAI spokesperson, quoted by The Register

Guardio Labs published the sharpest result on 11 March 2026, after Atlas's fate was effectively sealed and Comet was still shipping. Researchers intercepted the traffic between Comet's agent and Perplexity's servers with a Burp Suite extension, fed the agent's own narrated reasoning into an adversarial loop, and rebuilt a fake pet-store refund page until the browser handed over credentials without objection. Four iterations, under four minutes.

When your AI Browser explains why it stopped, it teaches attackers how to bypass it. — Guardio Labs, AgenticBlabbering

Brave's later work on instructions hidden in near-invisible text inside screenshots, tested against Comet, Fellou and Opera Neon, stated the consequence in ordinary language: "If you're signed into sensitive accounts like your bank or your email provider in your browser, simply summarizing a Reddit post could result in an attacker being able to steal money or your private data."

Why the standalone browser was the wrong container

None of those findings killed Atlas, and it would be an invention to say they did. What they show is that the risk was never specific to the shell it ran in. Every incident above turns on the same mechanic: an agent with standing access to logged-in accounts, reading untrusted text it cannot reliably distinguish from its instructions. Moving that agent from a browser window into a desktop app or an extension moves nothing about the mechanic.

The container was wrong for a duller reason. A browser has to be downloaded, made default and used for everything, and roughly seven in ten people already had Chrome doing that job. Shipping on macOS alone capped the addressable audience at a slice of one desktop platform for the product's entire life, while Comet reached Windows, macOS, Android and iOS in the same period.

OpenAI's replacement concedes the point. The ChatGPT browser extension works in Chrome, Edge, Brave, Opera and Vivaldi — Opera without side chat — and OpenAI's own documentation lists what installing it grants: "Read and change all your data on all websites", "Read and change your browsing history on all your signed-in devices", "Access the page debugger", plus bookmarks, downloads and tab groups. The standing-access bargain did not shrink when the browser died. It moved into a permissions dialog inside someone else's browser, and gained four more of them.

What outlived Atlas

Comet is the clearest survivor. Perplexity released it for Windows and macOS on 9 July 2025, opened it to free download in October 2025, shipped Android on 20 November 2025 and iOS on 18 March 2026, and put its agentic browsing inside Samsung Internet.

The economics tightened in September 2026: on the 15th, Perplexity moved Comet's "Control browser" feature behind metered Computer credits, with new Pro subscribers given a one-time 4,000 and Max subscribers 35,000 plus 10,000 a month. Agentic browsing turns out to be expensive to run, which is its own kind of verdict.

Dia survived by being bought. Atlassian completed its $610 million acquisition of The Browser Company on 21 October 2025 — the same day Atlas launched — and Dia has kept shipping weekly since. It reached version 1.49.0 on 17 September 2026. Cross-device sync for tabs, profiles, memory and shortcuts arrived earlier in 2026 with v1.26.0; the Microsoft connections that feed Outlook, Teams and SharePoint into its Morning Brief came with v1.48.0 on 10 September 2026.

Dia is generally available on macOS 14 or later, Apple silicon only, and the Windows build is still unreleased behind a beta waitlist. Two of the three browsers named in most 2025 coverage of this category are alive; the one with the largest company behind it is not.

The bargain nobody retired

The security community stopped treating these as one-off bugs. On 9 December 2025 the OWASP Gen AI Security Project published its Top 10 for Agentic Applications, the first peer-reviewed taxonomy aimed at autonomous systems. Its first entry, ASI01 Agent Goal Hijack, covers exactly the webpage-embedded instructions used against Comet and Atlas, on the stated grounds that models cannot reliably separate instructions from content.

ASI02 Tool Misuse covers autofill and email-send turned against their owner; ASI06 Memory and Context Poisoning covers what LayerX claimed to find in Atlas; ASI03 Identity and Privilege Abuse names the design tension itself.

Regulators are closer to observing than acting. Gartner analysts Dennis Xu, Evgeny Mirolyubov and John Watts recommended in December 2025 that organisations block AI browsers outright, on the finding that "default AI browser settings prioritize user experience over security".

The UK Information Commissioner's Office published its Tech Futures report on agentic AI on 8 January 2026, flagging unclear controller and processor roles across the supply chain, purpose creep from open-ended tasks, more automated decisions with legal effect, and reduced transparency — risks it treated as systemic to the category, naming no vendor.

The EU moved in the opposite direction. The Digital Omnibus on AI, in force since 27 July 2026, deferred the AI Act's high-risk obligations for stand-alone Annex III systems from August 2026 to 2 December 2027, and for AI embedded in regulated products under Annex I to 2 August 2028. The Article 50 transparency duties, which require telling people they are dealing with an AI system, still applied from 2 August 2026. An agent buying something on a saved card now has until December 2027 before the heavier obligations bite.

What the next one will still ask for

Atlas is a useful failure precisely because it failed for commercial reasons while the thing worth worrying about carried on without it. A standalone browser lost to distribution. The agent that needed your cookies, your inbox and your saved card to be worth using did not lose anything; it got installed somewhere with better distribution.

The checks worth running have not changed with the packaging. Whether a logged-out or unauthenticated mode exists for tasks that do not need an account. Whether purchases, sends and deletes require explicit confirmation rather than happening silently. Whether memory and training-data retention are separate switches. Whether the vendor discloses its own vulnerabilities, or waits for Brave, LayerX and Guardio to do it.

Atlas answered some of those questions well and still shut down, which tells you the answers were never what decided its fate — and are still the only part of it that matters to anyone who grants the next agent an account.

Explore

More articles