Google is rolling out Gemini-powered options in Chrome for Android on the finish of June, together with an “auto browse” functionality that may take actions on the net on a person’s behalf.
It’s the clearest signal but that the AI browser wars are transferring past chatbots and into autonomous territory – with actual implications for the way organisations take into consideration system administration, knowledge governance, and acceptable use insurance policies.
What’s Really Launching
Constructed on Gemini 3.1, the replace brings three headline options to Chrome on Android.
First, a persistent AI assistant that lives contained in the browser and might reply questions on no matter web page you’re viewing – summarising articles, explaining complicated subjects, and pulling info from linked Google providers like Gmail, Calendar, and Maintain.
Second, a picture era and modifying device referred to as Nano Banana that lets customers create or modify visuals straight within the browser – turning a webpage into an infographic, as an illustration, or reimagining a photograph with totally different content material.
Third, and most vital, is auto browse. The function lets Chrome act as an autonomous agent, taking multi-step actions throughout the online on a person’s instruction.
Any workflow that entails navigating web sites, filling varieties, or triggering transactions is, in precept, inside scope.
Auto browse will likely be restricted to AI Professional and Extremely subscribers at launch, on Android 12 or larger gadgets within the US.
Why IT Leaders Ought to Pay Consideration
Agentic AI within the browser is a basically totally different danger profile to a chatbot.
When an worker asks ChatGPT a query, the reply stays within the chat window. When an agentic browser begins navigating web sites, submitting varieties, and interacting with third-party providers on a person’s behalf, the blast radius of a mistake – or a malicious immediate – grows significantly.
Google has acknowledged this with a affirmation step earlier than “delicate duties” like purchases or social media posts.
However the definition of delicate is subjective, and in an enterprise context, loads of consequential actions gained’t journey that filter.
An agent that may learn a Gmail inbox and act on its contents is, successfully, working with the identical permissions because the person.
That’s a privilege IT groups will wish to consider carefully about earlier than it lands on managed gadgets.
The immediate injection danger is especially price noting. Google says auto browse is protected in opposition to it, however immediate injection – the place malicious content material on a webpage hijacks AI directions – stays one of many tougher issues in agentic AI safety.
Organisations searching delicate provider portals, monetary platforms, or customer-facing instruments will wish to perceive precisely what these protections seem like in apply earlier than they’re snug.
The Larger Image
This launch is a part of a broader arms race.
Microsoft has been embedding Copilot deeper into Edge. Apple is integrating its personal AI options throughout Safari and iOS.
The browser, lengthy a comparatively impartial piece of enterprise infrastructure, is turning into a battleground for AI platform lock-in – and the function units are advancing quick.
For IT and safety leaders, the problem isn’t simply evaluating one product.
It’s preserving tempo with a class that’s transferring from passive help to energetic company in a matter of months.
Cell system administration insurance policies, acceptable use pointers, and knowledge loss prevention instruments have been largely written for a world the place browsers displayed content material. They weren’t written for browsers that act.
The Private Intelligence function – which lets Gemini tailor responses primarily based on a person’s pursuits, household particulars, and searching habits – may also increase flags in organisations with strict knowledge dealing with necessities.
Google says customers stay in management, however privateness groups will wish to scrutinise what knowledge is used, the place it’s processed, and the way it interacts with company Google Workspace accounts.
What’s Subsequent
The rollout begins on the finish of June within the US, whereas worldwide availability hasn’t been confirmed.
For many enterprise IT groups, the instant motion is consciousness – flagging this to safety and compliance stakeholders earlier than it seems on worker gadgets, and beginning the dialog about what guardrails, if any, should be in place.

