Enterprise Adoption3 min read

AI Agents Now Live in Your Browser, Signed In as You

May 8, 2026Synthesized from 1 source: MarkTechPost

OpenAI has given its Codex agent direct access to your signed-in browser sessions on Gmail, Salesforce, LinkedIn, and internal tools, a move that brings AI automation to every web-based workflow but also introduces a security risk that even OpenAI admits cannot be fully solved.

OpenAI launched a Chrome extension for its Codex agent this week that lets it work directly inside your browser, using your existing logins. You do not need to set up any integrations or connect any APIs. If you are logged into Salesforce, Gmail, or your company's internal dashboard, Codex can read and act on them the moment you give it a task.

This is different from every previous AI browser tool. Earlier approaches treated the browser like a camera, taking screenshots, reasoning about what they saw, then clicking. That is slow and fragile. The new extension connects Codex directly into Chrome, so it can work across multiple tabs at once, in the background, without taking over the screen you are actually using.

The practical implication is that almost any repetitive, browser-based task at work becomes automatable without involving IT. Updating CRM records after calls, pulling data from a supplier portal, reviewing dashboards and compiling summaries, cross-referencing tabs. These are tasks that most professionals in operations, procurement, sales, and finance spend hours on every week. None of them required a developer before, and none of them require one now.

Codex has grown to over 4 million weekly users, up 8 times since January. Notably, more than half a million of those users come from free subscription tiers, and OpenAI believes many of them are non-developers. Coding-related activity outside of engineering and IT departments rose 36% inside enterprise accounts over the past six months. The tool has already moved well beyond its original audience.

The security picture, however, is genuinely concerning. The core risk is called prompt injection. It works like this: a malicious actor hides instructions inside a web page or email, written in a way that is invisible to you but readable by the AI. When the agent processes that page, it may follow those hidden instructions instead of yours. In demonstrated attacks, researchers have made AI agents leak complete Salesforce CRM records, forward sensitive emails, and take actions the user never requested. A critical-severity vulnerability discovered in Salesforce's own AI agent platform last year, called ForcedLeak, showed how this works at scale against business data.

OpenAI has acknowledged this directly. The company has stated that this class of attack is unlikely to ever be fully eliminated, comparing it to phishing and social engineering, threats that can be reduced but not removed. Their defence strategy relies on training the AI to recognise and resist these attacks, adding confirmation steps for sensitive actions, and letting users control which websites the agent can access. These are reasonable mitigations, but they depend on the agent making correct judgements under adversarial conditions, which is a probabilistic defence, not a guaranteed one.

The extension is not yet available in the EU or UK. This is almost certainly a regulatory calculation. European data protection rules require clear accountability for automated processing of personal data, and an agent that autonomously reads and acts on email or CRM data under user credentials sits in genuinely contested legal territory.

For businesses, the real decision is not whether to use these tools. Employees will use them regardless, with or without IT approval. The relevant question is whether your company has any visibility into what AI agents are doing inside your systems. An agent logged in as an employee has the same access permissions as that employee. If something goes wrong, because of a malicious web page, a misconfigured task, or an honest mistake by the AI, the audit trail may not exist and the blast radius could be large.

OpenAI's roadmap points toward a combined product where Codex, ChatGPT, and its own browser called Atlas merge into a single workspace. The Chrome extension is a step toward that future, where AI agents are permanently embedded in professional workflows. The infrastructure for governing that future, inside most organisations, does not yet exist.

Stay informed

Get AI intelligence like this delivered to your inbox.


You May Also Find Valuable