Your browser is quietly turning into something else. This month Cloudflare launched Kitesurf, a cloud-hosted browser designed specifically to be driven by AI agents rather than humans, joining a growing lineup of “agentic” browsers that log in, fill forms, and complete multi-step tasks on your behalf. The pitch is obvious: stop clicking around and let something else do it. The catch is less obvious, and it’s worth understanding before you hand over the keys to something that can act on your accounts without you watching every step.
What an Agentic Browser Actually Does
Traditional browsers show you a page and wait for you to act. Agentic browsers flip that: you give a plain-language instruction — “book the cheapest flight to Denver next Friday” — and the AI navigates, clicks, and fills out forms across multiple sites to get it done, the same way you would, just faster and without the tab-hoarding. Some, like Cloudflare’s Kitesurf, run in the cloud and give developers granular control over exactly what an agent can see and do, which matters a lot if you’re building a product on top of it rather than just using one. Others, like the newer Sigma AI Browser, take the opposite approach and run the assistant locally on your machine specifically so nothing gets sent to a cloud server by default, trading some capability for a much smaller data footprint.
Both approaches are chasing the same idea: the browser stops being a window and starts being a worker. That’s a genuinely useful shift for repetitive tasks — expense reports, price comparisons, appointment booking — the kind of digital chores nobody enjoys doing by hand and that don’t really require a human’s judgment to execute correctly.
The Privacy Trade-Off Nobody Talks About Enough
To do any of this, an agent needs access to the things you’d normally guard closely: saved passwords, payment details, browsing history, sometimes your email inbox to confirm bookings. Security researchers have flagged that LLM-powered browsers are a genuinely new attack surface — a malicious webpage can, in theory, embed instructions that trick an agent into acting against your interests, a problem researchers call prompt injection. It’s a different threat model than a normal virus scanner is built to catch, because nothing is technically “malware” in the traditional sense — it’s just text on a page that a language model happens to interpret as a command.
That’s part of why the privacy-first entrants are gaining traction. Running the assistant locally instead of in the cloud means less of your data leaves your device by default, even if it means the agent is somewhat less capable at complex, multi-site tasks. If you’re going to experiment with any of these tools, a physical privacy screen filter and a dedicated encrypted USB drive for sensitive files are cheap, low-tech ways to add a layer of protection while the software side of this catches up to the risks it’s introducing.
Who’s Actually Building These
Cloudflare’s angle is infrastructure — Kitesurf is aimed at developers building their own agents, not a consumer product you’d install today. Sigma is more consumer-facing, marketing itself directly on the promise of “no tracking, no cloud dependency.” Google, meanwhile, is pushing a different flavor of the same idea: consumer agents that can call stores, check inventory, and complete purchases by phone rather than by browser at all, which sidesteps a lot of the browser-specific security questions by moving the interaction somewhere else entirely. The common thread across all of them is that 2026 is the year “browsing” stopped meaning something a human does exclusively, and every major player wants to own that shift before someone else does.
Should You Actually Use One?
If you’re technical and curious, there’s real value in trying one of these for a narrow, low-stakes task — comparison shopping, gathering research links, or filling out a repetitive form you’d otherwise procrastinate on for a week. Hold off on connecting a saved credit card or letting an agent log into financial accounts until the security track record is longer than a few months; this is genuinely new enough software that “wait and watch” is a reasonable default, not paranoia. A hardware security key for your most sensitive accounts is a smart precaution regardless of whether you touch an AI browser at all, since it protects you even if a password does leak somewhere down the line.
The Bottom Line
Agentic browsers are a legitimately useful idea wrapped in a legitimately new set of risks. Treat the current generation the way you’d treat any brand-new category of software with access to your passwords: useful for small things, not yet trustworthy with the big ones. We’ll keep tracking which of these actually earn that trust — check back for updates as the space matures and the first real security incidents (good or bad) start to shape which approach wins out.