Product Launch2 min read

Gemini Spark Now Uses Saved Chrome Passwords for Tasks

By , Senior AI ConsultantPublished

Google's AI agent Gemini Spark can now log into Chrome using your saved passwords to handle errands like starting flight bookings, joining a crowded race among AI companies to build agents that act on your behalf online while raising fresh questions about credential security.

Google has expanded its AI agent Gemini Spark so it can now operate inside Chrome using your saved passwords and logged-in accounts. Once you connect it, Spark can go handle small errands on your own accounts, such as researching flight options and starting a booking, or lining up an apartment viewing. Those are the only two examples Google has given so far, which tells you this is an early rollout, not a finished product.

Spark itself is not new. Google introduced it in May at its developer conference as a "24/7 personal AI agent," built on the Gemini 3.5 model and running on dedicated servers in Google's cloud rather than on your phone or laptop. That matters because it means Spark keeps working on a task even after you close the app or turn off your device, more like a virtual employee than a chatbot you check in on.

The Chrome feature is rolling out first in the United States, with other countries to follow. At the same time, Google has widened access to Spark itself, making it available to Google AI Pro subscribers, who pay around 20 dollars a month, in more than 160 countries. The pricier AI Ultra plan, which costs up to 250 dollars a month, gets the fullest version.

This is not a solo move. OpenAI launched a similar tool called Operator over a year ago and has since built browsing directly into its own browser, called Atlas. Perplexity has done the same with a browser called Comet, which it now gives away for free. Every major AI company is racing to build an assistant that does not just answer questions but logs into your accounts and completes tasks for you. Google's advantage here is scale: it already runs the browser, the email service, and the calendar that most people use every day, so plugging an agent into all of it is a shorter path than building a new browser from scratch.

The catch is security, and it is a real one. Handing an AI system your saved passwords means it can act inside your bank account, your email, or your work systems. Attackers have already found ways to hide instructions inside ordinary webpages that trick these agents into taking actions the user never asked for, including moving money or sending out private data. Google says it has built layered defenses against this, but has not explained what those defenses actually do, and researchers across the industry, including at OpenAI itself, have said this problem may never be fully solved.

Google's one concrete safeguard is that Spark will not finish a payment on its own. It stops short and hands the purchase back to a human to confirm. That is a sensible guardrail, but it only covers the final step. Everything before that, browsing, filling in forms, reading your inbox, still happens with the agent holding your credentials.

For any business thinking about letting staff use tools like this, the practical question is not whether it saves time. It probably will, for simple repetitive tasks like travel booking or scheduling. The real question is whether you have a policy for what accounts an AI agent is allowed to touch, because right now most companies do not, and the tools are shipping faster than the rules around them.

Stay informed

Get AI intelligence like this delivered to your inbox.


You May Also Find Valuable