Google is rolling out Gemini-powered options in Chrome for Android on the finish of June, together with an “auto browse” functionality that may take actions on the internet on a person’s behalf.
It’s the clearest signal but that the AI browser wars are shifting past chatbots and into autonomous territory – with actual implications for a way organisations take into consideration machine administration, information governance, and acceptable use insurance policies.
What’s Really Launching
Constructed on Gemini 3.1, the replace brings three headline options to Chrome on Android.
First, a persistent AI assistant that lives contained in the browser and may reply questions on no matter web page you’re viewing – summarising articles, explaining complicated subjects, and pulling data from linked Google providers like Gmail, Calendar, and Maintain.
Second, a picture era and enhancing software known as Nano Banana that lets customers create or modify visuals instantly within the browser – turning a webpage into an infographic, as an example, or reimagining a photograph with completely different content material.
Third, and most vital, is auto browse. The characteristic lets Chrome act as an autonomous agent, taking multi-step actions throughout the online on a person’s instruction.
Any workflow that entails navigating web sites, filling varieties, or triggering transactions is, in precept, inside scope.
Auto browse will probably be restricted to AI Professional and Extremely subscribers at launch, on Android 12 or increased units within the US.
Why IT Leaders Ought to Pay Consideration
Agentic AI within the browser is a basically completely different threat profile to a chatbot.
When an worker asks ChatGPT a query, the reply stays within the chat window. When an agentic browser begins navigating web sites, submitting varieties, and interacting with third-party providers on a person’s behalf, the blast radius of a mistake – or a malicious immediate – grows significantly.
Google has acknowledged this with a affirmation step earlier than “delicate duties” like purchases or social media posts.
However the definition of delicate is subjective, and in an enterprise context, loads of consequential actions received’t journey that filter.
An agent that may learn a Gmail inbox and act on its contents is, successfully, working with the identical permissions because the person.
That’s a privilege IT groups will need to consider carefully about earlier than it lands on managed units.
The immediate injection threat is especially value noting. Google says auto browse is protected in opposition to it, however immediate injection – the place malicious content material on a webpage hijacks AI directions – stays one of many more durable issues in agentic AI safety.
Organisations searching delicate provider portals, monetary platforms, or customer-facing instruments will need to perceive precisely what these protections appear like in follow earlier than they’re comfy.
The Greater Image
This launch is a part of a broader arms race.
Microsoft has been embedding Copilot deeper into Edge. Apple is integrating its personal AI options throughout Safari and iOS.
The browser, lengthy a comparatively impartial piece of enterprise infrastructure, is turning into a battleground for AI platform lock-in – and the characteristic units are advancing quick.
For IT and safety leaders, the problem isn’t simply evaluating one product.
It’s preserving tempo with a class that’s shifting from passive help to lively company in a matter of months.
Cell machine administration insurance policies, acceptable use tips, and information loss prevention instruments have been largely written for a world the place browsers displayed content material. They weren’t written for browsers that act.
The Private Intelligence characteristic – which lets Gemini tailor responses primarily based on a person’s pursuits, household particulars, and searching habits – can even elevate flags in organisations with strict information dealing with necessities.
Google says customers stay in management, however privateness groups will need to scrutinise what information is used, the place it’s processed, and the way it interacts with company Google Workspace accounts.
What’s Subsequent
The rollout begins on the finish of June within the US, whereas worldwide availability hasn’t been confirmed.
For many enterprise IT groups, the instant motion is consciousness – flagging this to safety and compliance stakeholders earlier than it seems on worker units, and beginning the dialog about what guardrails, if any, should be in place.





