mnemonic security podcast
Hosted by Robby Peralta from mnemonic, one of Europe’s leading cybersecurity companies, the show features conversations with researchers, founders, operators, and security leaders working across the cybersecurity landscape.
Each episode explores a specific topic within cybersecurity: from incident response, threat intelligence, AI, and geopolitics, to leadership, resilience, and the changing role of security leaders.
The podcast is tailored to cybersecurity practitioners and decision-makers who want grounded conversations about where cybersecurity is going, what organisations should prepare for, and what experienced people are seeing.
mnemonic security podcast
Agentic Browsers
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this short and sweet episode on agentic browsers, we’re joined by Helen Kearney, a leader in helping humanitarian and non-profit organisations use technology strategically, responsibly, and with real impact.
Robby and Helen discuss the challenges and opportunities posed by these new browsers, where their "agentic" abilities create new risks, raise questions about ethical AI use, and heighten concerns around safeguarding sensitive data.
Helen also shares the conversations she’s having across the humanitarian sector as AI tools go mainstream - what’s inspiring, what’s misunderstood, and the developments she believes deserve far more attention.
From our headquarters in Oslo, Norway, and on behalf of our host Robby Peralta, welcome to the mnemonic security podcast.
Robby PeraltaBoy, I have got to say I am thrilled about these new AI browsers. Comet, Atlas, absolute game changers. Finally a browser that doesn't just show you a web page, but goes ahead and acts on your behalf. Automatically, invisibly, enthusiastically. Who wouldn't want that? No more clicking, no more reading, no more thinking. Just an AI roaming through your logged in accounts, poking around your messages, and just doing whatever it feels is helpful. Zero boundaries and full admin rights, baby. And the best part, it follows every instruction it sees. Yours, mine, random strangers, hidden text on a website. Very helpful for us all. So what are you waiting for? They're out there ready to help. But before you run off and install one, a few tiny details worth considering. Helen Kearney, welcome to the podcast.
Helen KearneyThank you. Nice to meet you.
Robby PeraltaYou work with humanitarian and nonprofit organizations and help them to make sound technology choices. And you recently had a post about these infamous agentic browsers. So I wanted to pick your brain about those. But first, what led you to unknotted AI?
Helen KearneySure. For the last 15 to 17 years, I've been working somewhere at the intersection of human rights, humanitarian action, and tech, including AI. So over time, I got really interested in the ethical application of new technology and how new technology can be adopted in safe and responsible ways in low resource settings, in fragile settings. Because nonprofit and humanitarian organizations are often working in some of the most difficult contexts, whether that's a war zone or just a shoestring budget, intense time pressure, and sitting on some incredibly sensitive data, you know, whether that's the address of a secure women's shelter or medical records or child protection case notes or a list of names of people in an LGBTQIA community in a context where that's criminalized. I mean, you can just think like some of the data we're sitting on is incredibly hot, incredibly sensitive. I think we can say that nonprofit and humanitarian organizations are sitting on some of the most sensitive data in the world, about some of the most vulnerable people in the world, in some of the most fragile settings in the world. And they're organizations that are facing intense time and resource constraints very understandably, often looking for ways to alleviate the pressure around admin tasks. And that can be a perfect storm for risk when it comes to hurriedly adapting new new tools that weren't built for the kind of context we work in. So that's what led me to found a knotted AI. We're a group of consultants who support social impact organizations to work with new technologies in safe and responsible ways. And I love this work because it's practical, it's values-driven, and it brings together two worlds that aren't always great at talking to each other, you know, from humanitarian ethics and social impact and cybersecurity.
Robby PeraltaWell, on behalf of uh mnemonic and all the listeners, thank you so much for all the great work that you are doing and have done. Never thought about a lot of the things that you just said. The organizations you work with, they have a lot of important work to do, have very little time, and here comes AI to sort of maybe help them along. And that's that's what you're trying to help them do, I guess, and enable that uh the safe use of that technology. And you posted a cautionary note, as I mentioned, about agentic browsers. Can you just walk us through the context behind that?
Helen KearneyYeah, and and I posted, I think it was about a it was over a week ago. So they'd only just come out. I was specifically talking about Atlas, which is OpenAI's um new agentic browser. I'm very wary of these first-generation agentic browsers, even more so now than when I posted that a week ago because I've been playing around with playing around with Atlas. What I wrote wasn't anti-AI, not an a knee-jerk rejection of of all AI, but it was more of a cautionary note of if you're going to use this, do so with your eyes open, understand what's happening, because that's that's the real risk I see in the organizations I work with. Levels of tech literacy uh are not usually very high. And people are really tech specialists, they're first and foremost, they're they're social workers or they're midwives or they're frontline humanitarian workers using these tools. So building tech literacy is um a real priority. But yeah, these agentic browsers, they're not regular browsers like Chrome or Safari. And when you open up, they don't just show you the web, they're working on the web with you. So, you know, I open my laptop in the morning and an agenc browser can look across my tabs, compare information, pull out key details, summarize. It can be a really smart assistant sitting next to you who never sleeps, who can read much more quickly than you can. And when these browsers are in agentic mode, they can even take action on your behalf. So they need they can even click around and fill in forms. So incredibly powerful, tremendous potential, but also quite risky. That kind of help can be transformational for these organizations working on a shoestring budget and needing to, yeah, needing to get a lot of this admin work done. Support with searching, comparing, translating, summarizing, drafting, that can all get much lighter. I mean, just to give a practical example, when I was a policy officer, and this is a more desk-based job, but my boss might come in in the morning and say, Helen, I need a briefing note on girls' education in northern Nigeria, right? And I would open up a bunch of publicly available documents and data from UNICEF and UNESCO and the African Union and local news sources and other NGOs, and I'd pull it all together and I'd summarize it and I'd spend a day or two, you know, pulling out key points, contradictions, policy recommendations with an agentic browser to help me. It won't do the whole work, but it can really help. So that's a really interesting development. But our work in nonprofits and humanitarian organizations is not like, you know, researching different holiday destinations, or I need to buy a new washing machine, our washing machine just broke. So an uh an agentic browser could compare the eco-ratings and the volume and the price. That might be helpful. But on my computer, as a nonprofit or humanitarian professional, I might have refugee case files, child protection notes, a sensitive data, um, HR files, information, you know, in a war zone of convoy movements, staff movements. We just think some of this stuff through and and it's incredibly sensitive. So if that data is mishandled, it can cause real world harm, like like real world harm. And just trying out these first agentick browsers, maybe it's just because it's so new and I'm not used to it, but personally I didn't. I thought it was like when I first gave it a go on my device, obviously not with my real my real files or my real Twitter. I felt it was like uh watching the live CCTV while someone robs your flat. I didn't really like it. They're going in, it's going in through your files, looking for things. Anyway, maybe that part we just need to get used to. But yeah, it's um my caution was really to say the convenience of these shiny new tools doesn't erase our duty of care. So let's slow right down, understand what they're doing before we let them loose.
Robby PeraltaAnd when you were watching this work, like you said it's going into your files, you wrote that it was looking at your data. Did you see what exactly it has access to on your in your browser or your computer? Does it access other parts of your computer, or is it just sitting in the browser and has access to your credentials, anything that's stored in the browser, that's basically it has access to?
Helen KearneyIt can have access to anything. So that's the that's what makes Atlas different from other browsers. And the way it's been just, oh, it's just like an update. It's not an update. It's fundamentally different. It's an AI-first browser. So AI isn't just a bolt-on or an extra, you know, an additional function. It's really the foundation. And the AI can actively engage with whatever you're doing on the web. So, like I said before, it can see all your tabs. I was talking about you, I've I'm looking right now. I've I often have like 60 tabs open.
Robby PeraltaYeah.
Helen KearneyIt can look across the tabs, summarize, analyze, compare, extract, and with a gentic mode enabled, it can take multi-step action. So in some use cases, that might be cool. You know, next week, one of my friends having a birthday, we want to go for dinner, there are 10 of us. Maybe I want to reserve a restaurant. I could say, I want a restaurant within five kilometres of here. This is the price limit, should have vegetarian options, needs to have a table for 10, look it up. You know, and that multi-step action, it can look at a map, it can look at the reviews, it can look at the prices, it can that kind of low-risk gift case, maybe that's useful. Atlas also has a memory component. And again, it's a setting that you need to enable, but I want people to understand that that setting's there. So it can remember what you've looked at before. In my earlier case about the research policy paper on girls' education in northern Nigeria, Atlas could say, Oh, but six months ago, the African Union said that. You know, I might have forgotten that, I may have read that. That kind of thing can be, can be helpful. But in your computer, you've got access to safeguarding files, HR files, and that memory component is there. It just opens up a whole new level of risk. And I think, I think the psychological barrier to oversharing is just getting lower and lower. Like people I see putting too much information into Chat GPT or Claude or Gemini, whatever they're working with, is just getting even lower. When you use Atlas, because the experience can be quite seamless, you can forget that everything is getting shared with a third party and you can forget to switch it off. And that's where it can get, I think, quite risky.
Robby PeraltaI just want to say something real quick. Like one thing is oversharing with Claude and Gemini and all those things, but I'm looking at my browser as we're speaking, right? I have both my private emails are open in there. I have LinkedIn open, uh, I have Facebook open. And since I do have, they're not open right now, but I do have, you know, ChatGPT Perplexity. There are there are, you know, tabs in my browser. I have my password manager, I have my VPN client in there. That's all uh accessible to a tool like this. So it's not just what you're writing in that that one context, it's everything in there. So that uh that right there is enough to me never to install that. And I'm very glad I didn't do that.
Helen KearneyIt gives you pause, doesn't it? I mean It does. And then and then imagine the how turbocharged the risk is if one of your folders, if one of your files, uh your tabs has got beneficiary data. But those those people in a humanitarian setting, they never they never consented to their data being shared in that way, or the address of a safe shelter for women that have experienced violence. You know, those addresses that should stay completely confidential. Anyway, so I tested, I started testing Atlas myself, and just out of professional curiosity, I wanted to get a sense of how easy it was to override the guardrails and jailbreak it. Yeah, I'm not a tech expert, I'm not a professional hacker. I timed myself, it took 13 minutes to go online, to find code in a completely legit public, publicly available website that could be copied and pasted, and then very easily get Atlas to behave in ways that it shouldn't do. And with a genetic mode enabled, it can start taking actions on your behalf with prompt injection. So it can delete files, it could send an email, it can copy content and send it elsewhere. The risk the yeah, I can you can just start thinking about where the where these risks are that bit, but they're pretty, they're pretty important.
Robby PeraltaAll it has to do is go to a website that has a hidden prompt injection in there, and there you go.
Helen KearneyUh-huh. Exactly. I mean, I mean, this tech is this tech is amazing and uh and can start doing some things that are really interesting, but it's arguably not totally responsible of OpenAI to go ahead and launch something with such flimsy cardrails. How quickly people found that they could be overridden.
Robby PeraltaAnd you were not the only person I've seen posting cautionary warnings on LinkedIn about this. And if you do find a use case for this agentic browser mode, uh, because I'm sure they do exist, but I guess then that's kind of back to the days where you have a dedicated device to that which doesn't have access to that's only doing one thing, doesn't have any of your logins, doesn't have any cookies, anything that's relevant or could be sensitive, maybe that's what you have to do if you absolutely need to have that use case, I guess.
Helen KearneyYeah. Separate out your separate out your devices. So when you're going through publicly available documents, like, you know, trying to summarize publicly available reports from UNICEF/UNES CO all that, kind of no problem. They're already in the public domain. If that's on a separate device, then I've got another device where my child protection notes or HR case files are and agentic AI doesn't go anywhere near it.
Robby PeraltaUh I will leave it up to so you would have you talked to any companies that have just said, okay, blanket ban on that then so far?
Helen KearneyBlanket ban on it on the a gentic part. Agentic browsers or AI in general.
Robby PeraltaActually both, yeah. What kind of conversations are you having about AI these days?
Helen KearneyWell, I um nonprofit and humanitarian organizations, I think it's fair to say a lot of them are struggling a little bit and unsure about how to approach this because it's it's huge, it's important, people are using it already. You know, about six months ago, I was still going into organizations and talking to senior management who'd quite confidently tell me that um so we're just starting to use AI in this organization, and we've been discussing it carefully with the board, and now we decided to start thinking through what our approach to AI might be. And then you go in and talk to the teams. And because they weren't clear that there were any rules or any kind of policy, because there wasn't anything in place, of course, good people in good organizations who want to do a good job get presented with a tool and start trying to work out how to use it. Um, and also often as you go down the organogram, you get you get more and more Wild West. So often junior members of staff like building bots, setting up, experimenting with new tools. Yeah, experimentation's great, but let's have some common sense guardrails in place. And we don't need to wait for perfection. We don't need to wait until we've got that perfect, signed off 40-page AI policy, just some straightforward rules that are good enough to move forward.
Robby PeraltaUm Yeah, would you mind sharing some examples of what those have been?
Helen KearneyUm, that point I made about data being processed and stored temporarily and potentially accessible for abuse detection and debugging, that's an important thing. I just want people to understand how this stuff is working. So even if it's set, even if an AI tool is set not to train on your data, the data will still be being, it'll be quite standard for it to be being stored for uh for a few hours. And that's not necessarily sinister, that's just normal in any kind of machine learning system. And most AI providers will be, will be doing that kind of temporary data storage. People just need to know that it's happening when they're working with really sensitive data. And even if that's getting that's getting deleted after a few hours, it's leaving your device and going to another server that may, I mean, we're working across different jurisdictions. That'll be going out to another server in a different jurisdiction. Let's just say I'm working with sensitive data. Right now I'm sitting in France and it off it goes to a server in the US. If that's got any personally identifiable information on it, that's a GDPR issue right there. And that data going out and sitting somewhere else is long enough, just a few hours, long enough for a breach or a misconfiguration, or for an engineer that's looking, looking at debugging. There are human beings looking at it. It's not just robots, right? An engineer to see something they shouldn't have. That's the human risk. And then there's also the structural risk. In countries where, I mean, like the US, data held by AI providers can be accessed, um, can be subject to a lawful access request, so subpuened, or through like the US Cloud Act or new legislation that's coming in. So just thinking through how sensitive that data is and whose hands it can get into and where the risks are. And then in countries with weak rule of law, like, you know, a nonprofit working in a humanitarian setting, it can become quite quickly become a straight-up tool for surveillance, right?
Robby PeraltaYeah. And what I know about uh these um lawful intercept tools, as they call them. What their main target. Those are sort of your kind of clients. So this is uh this would make it very easy if uh everybody had these sort of tools enabled for those organizations and those tools.
Helen KearneyUnderstanding where the risks are. This is my big thing that wakes me up at night, right? Like good people in good organizations trying to do a good job, naively using tools that were not built for the level of confidentiality that we require in a regulatory landscape that's changing, that can change like that.
Robby PeraltaYeah.
Helen KearneyYeah.
Robby PeraltaWell, Helen, I just want to say thank you for dedicating your life basically to helping them do that safely. I mean it from the bottom of my heart. And uh I think we'll wrap it up there. Thank you so much for your time and keep up the great work.
Helen KearneyThank you. Take care. Okay, have a good day. Bye.
Robby PeraltaWell, that's all for today, folks. Thank you for tuning in to the mnemonic security podcast. If you have any concepts or ideas that you'd like us to discuss on future episodes, please feel free to hit me up on LinkedIn or to send us a mail to podcast at mnemonic.no. Thank you for listening. We'll see you next time.