I read that Google told reporters it’s “navigating AI security in real time” when asked about the agent features creeping into Chrome, and that phrase has been rattling around my head for a week. It’s a weirdly honest thing for the company that ships the world’s most-used browser to say out loud. And if Google can’t tell you cleanly whether an AI browser is safe, then the practical question for the rest of us stops being about trust. It’s about plumbing. What does your AI tool actually send, and where does it land?

The pitch for every one of these products sounds identical. Read your tabs, draft your email, pull the numbers off that dashboard. What the landing pages skip is the route your data takes to get the job done. So let’s trace it.

Google is debugging this on stage

Prompt injection through a web page, agents that obey instructions buried in HTML, your data slipping out through a model call nobody logged: none of this is solved. Not at Google, not anywhere. Martin Fowler called the underlying pattern the “lethal trifecta” back in February: untrusted content, sensitive data, and a way to phone home, all wired into one agent. So when a tool calls itself “secure,” the only useful reply is to ask three boring questions: what leaves your machine, at what moment, and who receives it.

The answers split three ways, and they line up neatly with three architectures.

Cloud agents send your page on a road trip

Most of the flashy AI browsers run their agent on rented servers. You ask it to summarize the page or pull a table, and to actually do that the page has to travel: sometimes the full rendered DOM, sometimes a screenshot of what’s on screen, sometimes the whole session so the agent on the far end can keep clicking as you. The reasoning happens in their data center. The result rides back to you.

Convenient, sure. It’s also where the entire attack surface lives. Picture what’s actually on your screen during a normal workday: a bank balance, a CRM full of customer records, an email you haven’t finished writing, a Jira ticket describing a feature that hasn’t shipped. If the agent needs to “see” any of that, a copy of it left your laptop and got processed somewhere you have no window into. I went deeper on the capability side of this in Cloud Browser Agents Can’t See Your Tabs, but the safety math is even simpler than the capability math. Every hop is a copy. Every copy is a place a breach can start. And the LiteLLM proxy breach earlier this year was a tidy reminder that the middle layer is exactly where things tend to rot.

A browser-native agent stays put

A browser-native agent, like Dassi, doesn’t work that way. It lives inside Chrome as an extension, reads the page you already loaded, and acts through the session you’re already logged into. Nothing gets shipped off to a vendor’s server to be rendered somewhere else, because the page is already rendered, right there, in your tab.

That kills a whole category of risk. No vendor backend means no vendor backend to breach, log, or subpoena. Your logged-in Gmail stays your logged-in Gmail instead of turning into an OAuth token parked in some third party’s database.

No AI browser is safe in the abstract

But fewer parties touching your data means fewer ways it goes sideways. Local execution cuts the vendor out of the middle. One less server to trust is one less server to get hacked.

What BYOK actually changes

Even a local agent has to send page content somewhere to reason about it, because the model doing the thinking isn’t running inside your browser. The difference is who you send it to. BYOK, bring your own key, means you plug in your own API key for Claude or GPT or Gemini, and the browser calls that provider directly using your credentials. There’s no product company sitting in the middle keeping a copy for “quality” or training or whatever the hell they’re calling it this quarter. The data goes straight from your browser to the model company you already chose to trust, and it stops there.

Dassi is built this way on purpose. It runs in the Chrome side panel, sees what you see, and uses either your existing ChatGPT login or your own API key. Page data stays in the browser. The model call goes to your provider, not to us. Because when AI companies don’t even trust each other with data, as I wrote in AI Data Mining Makes BYOK Essential, handing yours to a middleman is a strange default to accept.

Where this leaves you

Google saying it’s improvising on security in real time isn’t a scandal. It’s the actual state of the field, said plainly. But it does mean “just trust the brand” stopped being a strategy you can lean on. So the next time an AI browser offers to read your screen, ask the dumb literal question before you click allow: where does this data actually go. If the answer is “our servers,” now you know what you’re signing up for. If it’s “straight to your own model and nowhere else,” you know something better.

You can try the local-by-default version, Dassi, on the Chrome Web Store. Plug in your key and watch the network tab while it works, if you’re the paranoid type. I’d respect it if you did.