The Browser Wants to Be Your Assistant. It Has No Street Smarts.

A new kind of web browser, often called an AI browser, has started arriving on family computers. It does not just show you pages anymore: it offers to act for you. It can summarize what you are reading, fill out forms, compare prices, finish your shopping, even answer your email while you do something else. The pitch is hard to argue with. Who wouldn’t want a tireless assistant built into the window they already use all day?

Before you hand an assistant your keys, though, it is worth asking one calm question: what exactly is it holding?

Are AI browsers safe to use?

Not yet, for anything that matters. A browser assistant can be steered by hidden instructions on the very pages it reads, and it has none of the learned common sense that keeps a person from typing a password into the wrong box. Keep money, passwords, and personal information in human hands.

The problem is structural, not a bug

Simon Willison, the developer who coined the term “prompt injection,” describes the danger as a “lethal trifecta.” A browser assistant combines three things that are individually useful and jointly dangerous. It holds your private information: logins, saved cards, your email. It reads untrusted content all day, because that is what a browser is for. And it can send things out, because that is also what a browser is for.

Put those together and the trouble writes itself. A web page can carry instructions meant for the assistant rather than for you: text you never see, invisible on the page, that the assistant reads and obediently follows. Researchers have already demonstrated attacks that told a browser assistant to send personal information out; the same trick, security experts warn, could quietly change the shipping address on an order so a purchase gets stolen. Security Now walked through the arrival of these browsers in a November 2025 episode titled “Here Come the AI Browsers,” and the picture that emerges is the one worth remembering: an eager, helpful assistant with no street smarts. Like a person, it can click a bad link and put your information where it should not go. Unlike a person, it has no instinct that something feels off, and it acts instantly, holding everything you gave it.

This is not a scare story about one bad product. The makers of these browsers acknowledge, themselves, that the steering problem is unsolved. It is a structural tradeoff, and structural problems call for household rules, not for hoping the next update fixes it.

Two terms for new readers. The FIRM System (FIRM stands for Family Information Resource Management) is the organizational system at the heart of The Recoverable Family, and its job is making sure the right person can reach the right thing at the right time. The SAFE Framework organizes that work into four Areas of Focus: System, At-Home, Financial, and Estate. This is System work, home of the Passwords and Passkeys Module.

The rules the FIRM System already keeps

The reassuring part is that the answer is not new. The FIRM System has always drawn this line: convenience features never hold the keys.

Credentials live in a dedicated password manager, never the browser. This was good practice before assistants arrived; it is essential now. A password saved in the browser sits within reach of whatever the browser’s assistant is doing. A password in a dedicated manager does not.

A person does the sensitive work, slowly. Anything involving money, passwords, or personal information is done by a human being: banking, purchases with a saved card, account changes. The assistant can draft, summarize, and fetch. It does not transact.

Leave the assistant off until you have a reason. Nothing is wrong with you, or your browser, for skipping the feature. If you do experiment, treat it like a curious houseguest: watch what it does, and point it only at sites you already know and trust.

The second story: “anonymous” was never privacy

The same technology that makes a helpful assistant also makes a very good detective. Researchers at ETH Zurich showed that an AI system could match supposedly anonymous accounts to people’s real identities from writing style and small personal details alone. In their tests it found roughly two out of three of the hidden matches, and when it declared a match it was right about nine times in ten, at a cost of a few dollars per person, doing automatically what once took a skilled investigator hours. Security Now covered the research in a March 2026 episode titled “You Can’t Hide from LLMs.” The researchers call the capability an “information microscope,” and their framing deserves a place at the kitchen table: the protection people relied on was never real privacy. It was that unmasking a nickname used to be too expensive to bother with. That cost is gone.

Here is what that means in practice, and it is the same inversion the phishing piece teaches: a message that knows real details of your life is now more likely to be machine-built, not less. The small clues scattered across years of posts, together with the personal information already circulating in data-broker files, add up to a profile that a scam can wear convincingly. So assume anything posted under a nickname can be traced to you, and post accordingly. Do not reuse the same handle across parts of your life you would rather keep separate. And talk to the teenagers: the accounts they think of as throwaway are not as disposable as they feel.

Quick reference

  • Keep browser assistants off unless you have a specific reason and understand what they do.
  • A person handles money, passwords, and personal information. The assistant never transacts.
  • Credentials go in a dedicated password manager, never in a browser with an assistant enabled.
  • Experimenting? Curious-houseguest rules: watch it, and only on sites you trust.
  • Assume “anonymous” accounts can be traced. Separate handles for separate lives; small details add up.
  • A message that knows you gets verified through a channel you already trust before anyone acts on it.
  • Write the household rules down in your Family Guide, so they belong to the family and not to whoever read this article.

The takeaway

Two stories, one habit. When a tool offers to act for you, ask what it is holding. When a message knows you, verify before you trust. Slow is the feature — convenience is exactly what the approach counts on, and a family that has decided its rules in advance does not have to outwit anything in the moment.

If you want to know where your family stands, the Recoverability Assessment takes about ten minutes and tells you plainly.