Via 9to5google.com
The integration with Chrome's auto browse feature lets an AI handle flights, apartments, and online tasks using your saved credentials, raising fresh questions about autonomous agents and digital security.
Google just gave its AI agent the keys to your browser. Gemini Spark, the company’s autonomous AI assistant launched in May 2026, can now tap into Chrome’s auto browse feature to handle multi-step online tasks on your behalf, from booking flights to browsing apartment listings.
The integration, announced on July 30, 2026, represents one of the most tangible examples yet of an AI agent operating independently across the open web.
What Gemini Spark actually does #
Gemini Spark runs on Google’s Gemini 3.5 framework and operates in the cloud, meaning it can execute tasks even when your device is powered off.
With the Chrome integration, Spark can access your saved credentials from your desktop browser to log into websites, navigate multi-page workflows, and complete tasks that would normally require you to click through a dozen screens.
Users will see indicators in Chrome’s top bar when Spark is actively browsing. Spark requires explicit user permission before performing sensitive actions like making payments.
The initial rollout is limited to the US, though Google plans to expand to over 160 countries for its Google AI Pro subscribers. Earlier features already included remote browser access and connectivity with MCP tools, plus integration with Google Workspace.
Why crypto should be paying attention #
Second, the credential question. Gemini Spark uses your saved Chrome credentials to log into websites and perform actions. That’s a centralized identity model running through a single company’s infrastructure.
Third, the payments angle. Spark needs permission to make payments, but the infrastructure is clearly being built for a world where AI agents transact autonomously.
The security calculus #
The permission-based model for sensitive actions is a reasonable first step, but it introduces a new class of social engineering risks. If users get accustomed to clicking “approve” on Spark’s payment requests, the gap between legitimate requests and phishing attempts narrows considerably.
The cloud-based execution model also means your browsing sessions, credentials, and transaction data flow through Google’s servers even when your laptop is closed.
Google is rolling this out to AI Pro subscribers first, creating a tiered access model where paying users get AI-powered automation and everyone else gets the standard experience.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our