As AI technology continues to advance, AI Enablement is here to keep you informed about the latest developments, what they can do, and how to stay safe!
With this week's public release of OpenAI’s new ChatGPT Atlas browser, AI can now drive your browser, controlling the mouse and keyboard to complete online tasks on your behalf. This is a powerful and impressive new AI capability that also comes with new risks.
When an AI agent acts autonomously, it can encounter malicious or hidden text that tries to manipulate its instructions. These so-called prompt-injection attacks represent a new security challenge, and while OpenAI has built in some safeguards, fully autonomous AI behavior is never completely predictable. Even under the best of circumstances, AI's ability to understand web interfaces is limited, and it can take wrong turns or get stuck. As always, your due diligence is essential!
How to Stay Safe
If you or your team are exploring Atlas or similar AI-enabled browsers:
Avoid logged-in sessions
When you choose to enable Agent Mode, Atlas offers you a choice between attempting your task in a "logged in" or "logged out" session. The former gives AI access to your entire browser, which might be authenticated to important resources like your email or banking information. Don't do this!
When you use logged-out sessions, you can still choose to log in to individual sites, but the AI will turn the wheel over to you for these steps.
Don't leave an AI running unattended
Always watch what it’s doing. For some sensitive tasks, Atlas asks for your confirmation or requires you to have the tab where it's working active and visible. However, these safeguards do not always appear where you'd expect, and they do not make it safe to leave unattended. Keep an eye on the agent!
Disable browser memory features
ChatGPT Atlas offers to incorporate your browsing history into its AI context for additional personalization. We have not yet reviewed terms of service for Notre Dame's paid ChatGPT EDU users to see how this data is treated, and individual users have no expectation of privacy. This feature shares a lot more information with OpenAI than you may have given in the past. Not recommended.
Use least-privilege accounts for any automation or testing
If you've considered the above and still plan to explore what AI-driven browsers can do with logged-in sessions, make sure to set boundaries by using test accounts with as few privileges as possible, and log in to only the systems you intend to test.
New Possibilities
Agentic browsing is an exciting glimpse of what’s next. It's amazing to think that AI assistants might soon be able to complete tasks not with custom-built integrations, but with the same interfaces we use every day.
Already, many organizations use tools that drive a web browser to automate important-but-repetitive tasks like testing user interfaces after system updates. These non-AI tools are valuable, but not very resilient to changing conditions. Agentic AI browsers represent the next evolution of that concept – one that may prove much more flexible and adaptable than previous generations.
While we explore the potential of these tools for campus, curious individuals must be clear-eyed on how they work and how they can be used safely.
For questions or guidance about safe AI use at Notre Dame, contact ai@nd.edu.
As always, students are reminded that the use of AI tools is up to individual instructors' policies and that undergraduates must adhere to the Academic Code of Honor.