Google Warns of Hidden Traps as AI Agents Navigate the Web

Google's Gemini can now execute actions on user computers—clicking, typing, navigating—which creates a new attack surface. Malicious websites can inject hidden instructions that trick AI agents into performing unintended actions: exfiltrating data, making unauthorized purchases, spreading malware. This isn't theoretical. Agentic AI systems (those that take autonomous actions based on what they perceive) are inherently vulnerable to adversarial inputs that would be obvious to humans but opaque to models. Every major AI company is shipping agent capabilities this year. A large-scale compromise of an AI agent fleet would expose both the scale and the liability of autonomous AI systems operating on consumer devices.