Google dropped $32 billion on Wiz last week. Largest cybersecurity acquisition in history, and the whole thesis boils down to one thing: cloud infrastructure is a security nightmare that companies will pay almost anything to get under control. I kept thinking about that number while testing three different cloud browser agent platforms over the weekend, because every single one of them asked me to either log into my accounts on their remote browser or hand over session cookies.

No. Absolutely not.

The blank browser problem

Cloud browser agents work by spinning up a Chromium instance on someone else’s server. A fresh profile, no extensions, no cookies, no history. It is a browser that has never been used by anyone for anything, and the AI agent is supposed to accomplish real work inside it.

So when a cloud agent needs to check your email, it cannot just open Gmail. You are not logged in on that machine. When it needs to pull data from your company’s dashboard, same problem. The agent either needs your credentials forwarded to the remote environment, or it needs to operate in a world where authentication does not exist, which means it can only work on public pages that anyone could access without logging in.

This is the fundamental limitation that cloud browser agent companies downplay in their marketing, and it makes a massive difference in what the AI can actually do for you. The whole point of a browser agent is handling the tedious stuff you do every day in web apps where you already have accounts, sessions, and context built up over months or years of usage.

Session data on someone else’s computer

Even if you decide to authenticate on a cloud browser, your session tokens are now sitting on infrastructure you do not control. Your cookies, your OAuth tokens, your saved form data, all of it living on a VM in some data center, accessible to the platform operator and potentially to anyone who compromises their infrastructure.

And infrastructure gets compromised. That is what the Wiz acquisition is about. That is what every major cloud breach of the past three years has been about.

I read a thread on r/MachineLearning last month where someone described piping their browser session into a cloud agent platform so it could automate LinkedIn outreach. They were sending their LinkedIn session cookie, which contains their full authentication state, through a third-party relay to a remote browser they could not inspect. The convenience was real, but damn, the attack surface was enormous.

Your Chrome is already the right execution environment

Local browser agents skip all of this because they run where the work actually happens. A Chrome extension that operates in your side panel already has access to every tab, every logged-in session, every piece of context that makes your browser yours. No credentials leave your machine. No session tokens get copied to a remote VM.

Dassi works this way. It lives inside Chrome, sees the page you are on, and acts on it directly. When you ask it to summarize a report in your company’s internal tool, it does not need your password because you are already logged in. When it fills out a form or drafts a reply in Gmail, it is working with your real browser state, not a simulation of it running three thousand miles away.

Cloud agents solve a problem that does not need solving

The pitch for cloud browser agents usually centers on scalability and parallelism, running dozens of browser instances simultaneously to scrape or automate at volume. And for that specific use case, sure, remote browsers make sense because you are operating on public pages where authentication is irrelevant.

But that is not what most people need from an AI browser agent. Most people need help with the five or six web apps they use every day for work, apps they are already signed into, apps that contain context and data specific to their workflow. For that, a cloud browser is actively worse than what you already have open on your screen right now.

The local browser agent approach is not a compromise or a stepping stone toward some future cloud version. It is the correct architecture for the actual problem, which is making AI useful inside the authenticated, personalized, context-rich browser sessions where real knowledge work gets done.

I keep waiting for someone in the cloud browser agent space to explain how they plan to solve the authentication problem without becoming a security liability. So far the answer seems to be “trust us,” which, after watching Google pay $32 billion to address cloud security gaps, is not particularly reassuring. The companies building browser-native AI have already moved past that question entirely.