Artificial intelligence is changing how people interact with the internet.
AI assistants are increasingly moving beyond answering questions. They can read emails, browse websites, interact with applications, access authenticated sessions, and perform tasks on behalf of users.
That convenience introduces a new cybersecurity challenge.
Recent research from AI security company Zenity has demonstrated zero click attack techniques targeting ChatGPT Atlas and Claude in Chrome. The research shows how malicious content placed in emails or social media posts could potentially manipulate an AI browser agent into performing unintended actions within authenticated user sessions.
The findings highlight an important shift in AI security: organizations must protect not only the AI model, but also the actions an AI agent is authorized to perform.
What Makes These Attacks Different?
Traditional phishing attacks generally depend on convincing a user to click a malicious link, open an attachment, or provide credentials.
Agentic AI introduces another layer.
An AI browser can interpret content and make decisions based on what it reads. If untrusted content contains instructions that the agent mistakenly treats as legitimate commands, an attacker may attempt to influence the agent’s behavior without requiring the user to intentionally interact with the malicious content.
This is known as indirect prompt injection.
The danger becomes greater when the AI agent has access to authenticated applications.
An AI assistant operating inside a user’s browser may potentially interact with email, collaboration platforms, cloud storage, social media, shopping services, and other applications where the user is already signed in.
ChatGPT Atlas Research Highlights Cross Site Risks
According to the reported research, Zenity found that ChatGPT Atlas could be influenced through malicious content embedded in an X thread.
The researchers described an attack scenario where a normal user request could be redirected by malicious content, causing the AI agent to interact with other authenticated services.
The demonstration included scenarios involving messaging contacts and online purchases.
The broader security lesson is significant.
When an AI browser can operate across multiple authenticated websites, a malicious instruction originating on one website may potentially influence actions on another.
This creates a security challenge that is different from conventional browser vulnerabilities because the AI agent itself becomes part of the interaction chain.
Claude in Chrome Research Shows Another Attack Path
Zenity also reported a zero click attack chain involving the Claude Chrome extension.
In the demonstrated scenario, malicious instructions could be hidden within an email. A user asking the AI assistant to summarize their emails could cause the agent to interpret the hidden content as instructions.
The research further demonstrated potential access to email and cloud storage data, as well as account takeover scenarios involving services such as Slack and X.
The findings were reported to Anthropic in late 2025 and early 2026, while the ChatGPT Atlas findings were reported to OpenAI in January 2026. SecurityWeek reported that the techniques remained unpatched at the time of publication.
Why Zero Click AI Attacks Are Concerning
The traditional security model assumes that users make decisions.
They click links.
They approve permissions.
They open documents.
They enter credentials.
Agentic AI changes that model.
An AI agent can make decisions and perform actions based on information it encounters.
That means security teams must begin asking a different question:
What happens when an AI agent encounters malicious content while operating with legitimate user privileges?
This is especially important when the agent has access to sensitive applications.
The Risk of Excessive AI Permissions
AI agents should not automatically receive unrestricted access to everything available to the user.
Consider an employee who has access to:
- Corporate email
- Cloud storage
- Internal documents
- Customer information
- Financial applications
- Collaboration platforms
- Source code repositories
- Administrative tools
If an AI agent is allowed to interact with all of these services, a successful prompt injection could potentially have consequences beyond the original application.
The principle of least privilege therefore needs to apply to AI agents as well as human users.
AI Security Must Include Agent Behavior
Organizations deploying AI assistants should evaluate more than model accuracy.
Security teams should assess:
- What information can the agent read?
- What applications can it access?
- What actions can it perform?
- Can it send messages?
- Can it modify files?
- Can it make purchases?
- Can it access sensitive email?
- Can it retrieve authentication information?
- Can untrusted web content influence its decisions?
- Are high risk actions subject to human approval?
These questions should become part of AI security assessments.
Protecting Against Indirect Prompt Injection
Organizations should treat external content as untrusted input.
Emails, websites, social media posts, documents, customer messages, and third party data can contain instructions designed to manipulate an AI system.
Security teams should consider implementing:
Strong Permission Boundaries
AI agents should receive only the permissions necessary to perform their assigned tasks.
Human Approval for High Risk Actions
Actions such as sending sensitive information, changing account settings, transferring money, modifying access permissions, or sharing confidential files should require appropriate approval.
Continuous Monitoring
Organizations should monitor AI agent activity and identify unusual behavior, unexpected application access, or abnormal data movement.
Data Loss Prevention
AI systems should operate within established data protection controls to reduce the risk of sensitive information being accessed or transmitted improperly.
Prompt Injection Testing
AI applications and agentic workflows should be tested against adversarial inputs designed to manipulate system behavior.
Secure AI Architecture
Organizations should separate trusted instructions from untrusted content and establish clear boundaries between AI reasoning and privileged actions.
Industries That Need to Pay Attention
Financial Services
Banks, fintech companies, payment providers, and investment organizations increasingly use AI for customer service, automation, research, and internal operations.
COE Security can help assess AI agents, identity systems, APIs, cloud environments, applications, and privileged workflows to reduce risks associated with unauthorized AI actions and data exposure.
Healthcare
Healthcare organizations handle highly sensitive patient information and increasingly use AI across administrative and clinical workflows.
COE Security can help evaluate AI systems, patient applications, cloud environments, data governance, access controls, and third party integrations while supporting HIPAA aligned security practices.
Retail and E-commerce
Retail businesses use AI across customer service, marketing, online shopping, fraud detection, and business operations.
COE Security can help secure customer-facing applications, payment environments, APIs, cloud platforms, AI workflows, and digital identities.
Manufacturing
Manufacturers are adopting AI across supply chains, industrial operations, enterprise applications, and connected environments.
COE Security can help assess AI integrations, cloud infrastructure, connected systems, applications, identity controls, and cybersecurity risks across modern manufacturing environments.
Government
Government agencies are increasingly exploring AI for citizen services, administrative processes, intelligence, and operational workflows.
COE Security can help strengthen AI security, application security, identity controls, data governance, infrastructure protection, and continuous monitoring.
AI Governance Must Evolve
AI governance cannot stop at model development.
Organizations need governance across the entire AI lifecycle.
That includes:
- Model security
- Agent permissions
- Data access
- Identity management
- Prompt security
- Application security
- Third party risk
- Logging and monitoring
- Human oversight
- Incident response
- Compliance
Organizations should also maintain clear documentation about what AI agents are permitted to do and establish processes for reviewing those permissions as capabilities change.
A New Security Boundary Is Emerging
The browser used to be primarily a tool controlled directly by the user.
With agentic AI, the browser can become an autonomous operational environment.
This creates a new security boundary between:
User → AI Agent → Browser → Web Content → Authenticated Applications → Enterprise Data
Every part of that chain needs appropriate security controls.
A malicious website should not be able to influence an AI agent into taking actions that the user never intended.
Conclusion
The reported zero click attack techniques against Claude in Chrome and ChatGPT Atlas demonstrate how AI agents can introduce security challenges that traditional application security models were not designed to address.
As AI assistants gain the ability to browse websites, read communications, interact with applications, and perform tasks on behalf of users, security teams must think beyond traditional prompt security.
The key challenge is controlling what an AI agent can see, what it can access, and what it is allowed to do.
Organizations should approach agentic AI with the same discipline applied to privileged users and sensitive applications: least privilege, strong identity controls, continuous monitoring, adversarial testing, data protection, human oversight, and clear governance.
AI can significantly improve productivity, but secure adoption requires organizations to build controls around the actions AI systems can take, not just the answers they generate.
About COE Security
COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.
Our offerings include:
- AI-enhanced threat detection and real-time monitoring
- Data governance aligned with GDPR, HIPAA, and PCI DSS
- Secure model validation to guard against adversarial attacks
- Customized training to embed AI security best practices
- Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
- Secure Software Development Consulting (SSDLC)
- Customized CyberSecurity Services
COE Security also helps organizations address emerging AI security risks through AI security assessments, adversarial testing, prompt injection testing, AI application security reviews, identity and access management assessments, API security testing, cloud security assessments, data governance, vulnerability management, threat monitoring, penetration testing, and secure AI adoption strategies.
For financial services, we help evaluate AI agents, digital banking applications, APIs, identity systems, cloud infrastructure, and privileged workflows.
For healthcare organizations, we help secure AI applications, patient portals, sensitive data environments, cloud infrastructure, identity systems, and third party integrations while supporting HIPAA aligned security practices.
For retail and e-commerce, we help secure customer-facing applications, payment environments, APIs, AI workflows, digital identities, and cloud platforms.
For manufacturing organizations, we help assess AI integrations, connected environments, enterprise applications, cloud infrastructure, identity controls, and digital supply chain risks.
For government organizations, we help strengthen AI security, public-facing applications, identity systems, infrastructure, data governance, vulnerability management, and continuous monitoring.
Our goal is to help organizations identify AI security gaps, reduce cyber risk, protect sensitive information, strengthen resilience, and maintain compliance as AI becomes increasingly integrated into business operations.
Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption and to stay updated and cyber safe.
Click to read our LinkedIn feature article