Prompt Injection Isn’t a Bug — It’s a Structural Risk for AI Browsers
-

OpenAI has acknowledged what many security researchers have been warning for months: prompt injection is not a solvable problem, but a permanent risk inherent to AI agents operating on the open web. In its latest update on ChatGPT Atlas, OpenAI admitted that agent mode dramatically expands the attack surface, making manipulation through hidden instructions in emails, documents, and web pages an ongoing threat.Rather than promising total mitigation, OpenAI is shifting toward risk management, mirroring guidance from the U.K.’s National Cyber Security Centre. The framing is important: prompt injection is now treated less like a vulnerability and more like social engineering for machines — something to be reduced, detected, and contained, not eliminated.