Google is turning Gemini Spark from a background productivity assistant into an AI agent capable of navigating the web and completing multi-step errands inside Chrome.
Through a new Chrome Auto Browse integration, Spark can search websites, move through pages, fill forms and use accounts already signed into the browser. Google says it could schedule apartment viewings from saved listings, research flights and begin the booking process without requiring the user to manually repeat each step.
The update represents a significant expansion of what Spark can do. It also raises an important question: how much control should an AI receive over a browser containing passwords, personal accounts, payment details and years of private activity?
Chrome Gives Spark Access to the Web People Actually Use
Gemini Spark was introduced in May 2026 as a cloud-based personal agent that could work continuously across services including Gmail, Docs and Slides. Because it runs in Google’s cloud, it can continue performing authorised tasks after a laptop is closed or a phone is locked. The system is powered by Gemini 3.5 and Google’s Antigravity agent framework.
Spark previously had web-research capabilities, but the direct Chrome integration gives it access to a more useful environment: the browser in which the owner is already signed into services.
Google’s official Chrome integration announcement says Spark can, with permission, use logged-in accounts and credentials saved through Chrome. That means the agent does not have to stop whenever a website requires an account, as a remote or isolated browser often would.
The integration is initially rolling out in the United States. Google says wider regional availability will follow, although it has not provided a complete expansion schedule for Chrome Auto Browse.
Spark and Gemini in Chrome Are Not Exactly the Same Thing
Gemini has already been present inside Chrome as a browsing assistant. It can summarise pages, answer questions about open tabs, compare information and help users work without leaving the browser.
Chrome also introduced Auto Browse earlier in 2026 for tasks such as completing forms, researching travel, managing subscriptions and placing products into an online shopping cart. Spark’s latest update connects its persistent, background-agent abilities with that existing browser automation.
The difference is important. Ordinary Gemini in Chrome mainly helps with the current browsing session. Spark is designed to manage broader objectives that may involve several services, files and steps.
An apartment-search task could begin with listings stored in an email or document. Spark could review the preferences, open the relevant sites in Chrome and attempt to schedule available viewings. A travel task could combine Calendar dates, Gmail confirmations and live flight information before preparing the first stages of a booking.
This brings Google closer to the idea of an AI assistant that completes work rather than merely explaining how the work should be completed.
It Can Click, Type and Navigate Across Websites
Chrome Auto Browse allows the agent to interact with websites in much the same way a person would. It can open pages, select options, enter information and move between sites while pursuing the assigned objective.
That makes it suitable for repetitive web errands that are individually simple but collectively time-consuming. Researching several flight combinations, checking appointment availability or completing similar forms across multiple websites may involve dozens of clicks that contribute little value beyond moving information from one place to another.
Spark can potentially handle much of that mechanical work while the user concentrates on the decision itself.
The system is not supposed to operate invisibly. Google says Chrome shows a work log detailing the agent’s actions. The user can observe its progress, pause the task, take control of the browser or stop the process.
This transparency becomes essential when an agent can interact with personal accounts. A chatbot mistake produces an incorrect sentence. A browser-agent mistake could select the wrong date, enter information into an unintended form or begin a transaction the user never wanted.
Spark Can Use Saved Passwords, but Not Read Them Directly
The phrase “using saved passwords” may sound as though Spark can open Chrome Password Manager and inspect every credential stored there. Google says its security design does not work that way.
When a task reaches a website requiring authentication, Chrome may use Google Password Manager to complete the sign-in. The agent does not receive direct access to the underlying password. The browser also requires confirmation before allowing an automated sign-in on the user’s behalf.
This separates the AI’s ability to request an authenticated session from its ability to see or copy the credential itself.
Spark is also not intended to complete every consequential step independently. Google says the agent should pause before payments, purchases, messages and other sensitive actions. Depending on the situation, it may request approval or hand the browser back so the person can complete the final step manually.
These controls reduce risk, but they do not remove the need to review what the agent has selected. A technically authorised payment can still be wrong when the flight, date, product or quantity is incorrect.
Prompt Injection Is the Biggest Security Challenge
Giving an AI permission to read webpages creates a security problem that conventional browsers were not originally designed to handle.
A malicious site can contain instructions aimed at the agent rather than the human visitor. These instructions may be visible, hidden in the page or embedded inside user-generated content such as reviews. They could attempt to redirect the agent, make it disclose information or persuade it to perform an action unrelated to the original task.
This technique is called indirect prompt injection. Google describes it as the primary new threat facing agentic browsers because the AI must interpret web content while distinguishing that untrusted content from instructions issued by the user.
Google says Chrome uses a separate “User Alignment Critic” to review actions proposed by the main Gemini model. The critic receives information about the proposed action without being exposed to the potentially malicious page content. It can reject an action when that action does not appear to serve the user’s stated objective.
Chrome also restricts the sites an agent can read from or act upon through task-specific origin controls. An apartment-search agent should not be able to move unexpectedly from a property site into an unrelated banking or medical account simply because a webpage told it to do so.
Google acknowledges that agent security remains an evolving field. Its prompt-injection detector will not necessarily identify every malicious instruction, which is one reason sensitive actions still require human involvement.
The Broader Spark Rollout Is Separate From Chrome Access
Alongside the Chrome announcement, Google expanded general Gemini Spark access to Google AI Pro subscribers in more than 160 additional countries.
That does not mean every newly eligible Spark user immediately receives Chrome Auto Browse. Google has described the browser integration as an initial US rollout, while Spark’s wider availability covers its broader background-agent functions.
Spark can already connect with Google Tasks and Keep, allowing it to turn notes into organised action items. Google has also announced integrations with services including Canva, Dropbox, Instacart, OpenTable and Zillow Rentals, as well as support for custom Model Context Protocol connections.
The expanding connector list suggests that Chrome is only one part of Google’s strategy. Spark is being positioned as a coordination layer that can move between Workspace data, third-party services, local computer files and the public web.
Reliability May Matter More Than Intelligence
The greatest obstacle to widespread adoption may not be whether Spark can open websites. It may be whether users can trust it to make correct choices consistently.
Hands-on testing of Chrome’s earlier Auto Browse system produced mixed results. A Wired reviewer found that it could navigate websites and apply filters but sometimes misunderstood details, made weak selections or failed to perform the promised browser actions.
These problems are significant because many web errands depend on preferences that are difficult to express precisely. Selecting airline seats, evaluating an apartment or choosing an acceptable substitute during grocery shopping involves judgement rather than simple form completion.
Spark may save time when the task has clear rules. It will be less convincing when the agent must infer taste, risk tolerance or unstated priorities.
Chrome Is Becoming a Platform for AI Agents
The Spark integration changes Chrome from a browser that displays information into a system that can act on information.
That shift could make routine online work considerably faster. Instead of opening several sites and repeating the same details, a person could describe the desired result and supervise the agent while it performs the intermediate steps.
It also places more responsibility inside Google’s ecosystem. The same company could potentially understand the request, search the web, read connected emails, access saved accounts and operate the browser used to complete the task.
Google has built confirmations, origin restrictions, action logs and prompt-injection defences around that power. Whether those protections are sufficient will depend on how the system behaves outside controlled demonstrations, particularly when it encounters confusing websites, hostile content and unusual user requests.
Gemini Spark’s new Chrome capability is therefore more than another chatbot feature. It is an early test of whether ordinary users are prepared to let an AI operate the most personal application on their computers and whether the AI can earn that level of trust.