Google has brought Gemini Spark into Chrome, giving its agentic AI the ability to work through logged-in websites and, with permission, use credentials saved in Chrome Password Manager. The feature is rolling out to eligible Google AI Pro and AI Ultra subscribers, PCMag reported, turning Gemini from a sidebar assistant into something that can carry out multi-step browser tasks. The immediate appeal is obvious: Spark can search for a nonstop flight, compare fares, sign in to a travel account, fill in a traveler’s details and stop at the point where the user must approve a purchase. Google says it is designed to hand sensitive actions such as payments back to the user rather than completing them autonomously.
That distinction matters, but it does not make the browser integration routine. An AI agent acting within a user’s active Chrome session can reach the same signed-in sites the user can. In practical terms, permission to use a saved password is permission to cross the line from researching an action to performing it inside a personal account.

A user reviews Gemini-linked travel and password services amid a prompt injection warning and purchase approval dialog.Chrome Becomes the Agent’s Hands​

Google’s own Gemini Spark documentation describes two execution paths: the local Chrome browser and a remote browser instance. When Spark uses local Chrome, the PC must remain on with Chrome running; in return, the agent can work with sites already available to that browser profile and can use saved Password Manager credentials when the user permits it.
A remote browser can continue a task after the local device is closed, but Google says it stops for the user when a site requires sign-in. Remote sessions may also retain browser data such as authentication cookies for later convenience, though Google provides controls to delete that remote browser data.
Spark requires confirmation before each browser task and presents a plan for the sites and actions it intends to use. Users can take over the browser or stop the task, and Google says the agent seeks confirmation for actions including purchases, web-form submissions, communications and data modifications.

Prompt Injection Is Still the Central Risk​

Google says Spark includes enhanced defenses against prompt injection—malicious instructions embedded in webpages, emails, documents or other content that an AI could interpret as commands. The company explicitly warns that agentic AI can make mistakes or act unexpectedly, and that safeguards cannot eliminate all risk.
This is the uncomfortable part of the feature: an agent does not need to expose an actual password to create a damaging outcome. If it is logged in, a compromised or hostile page could try to steer it toward disclosing personal data, sending information elsewhere, modifying files, or taking an unintended account action. Google’s documentation says Spark may share information needed to complete a task with third-party sites, potentially including contact information, files, preferences and other sensitive data.
For Windows users, the sensible first use is low-stakes, reversible work: research, price comparisons, reservation preparation, or filling repetitive but non-sensitive forms. Avoid tasks involving financial accounts, healthcare, enterprise SaaS administration, password changes, tax documents, confidential files or anything where a mistaken submission has real consequences.

Enterprise Chrome Deployments Have a Clear Control Point​

Chrome Enterprise includes a Gemini Spark policy that lets administrators control whether the agent can connect to Chrome and use its auto-browsing capability. Google’s policy documentation warns that enabling it permits Spark to perform autonomous multi-step actions on managed Chrome clients using the active browser session.
That should make the default decision straightforward for most organizations: disable or tightly pilot the feature before allowing it on devices that access business applications. Spark itself is currently limited to personal Google accounts rather than work or school accounts, but that does not remove the risk of an employee using a personal account on a machine or browser profile with access to sensitive resources.
Google AI Pro costs $19.99 per month, while Google AI Ultra costs $99.99 per month. The price of entry is relatively modest; the security decision is not.

References​

  1. Primary source: PCMag
    Published: 2026-07-31T15:34:24+00:00
  2. Related coverage: support.google.com
  3. Related coverage: chromeenterprise.google
  4. Related coverage: blog.google
  5. Related coverage: tech.yahoo.com
  6. Related coverage: gemini.google.com