Artificially intelligent assistants integrated into web browsers track and share sensitive user data, including medical findings, social security numbers, and financial information, according to new research conducted by scientists from the United Kingdom and Italy, as reported by Euronews.
The scientists tested the ten most popular AI browsers and extensions, including OpenAI’s ChatGPT, Microsoft’s Copilot, and Merlin AI for Google Chrome, in scenarios that involved public tasks (such as online shopping) and access to private websites, such as a university health portal.
The results showed that all assistants, except for Perplexity AI, collected data and used it for user profiling or service personalization, potentially violating privacy regulations.
– “These AI assistants have unprecedented access to private parts of users’ online activities. While they offer conveniences, they often do so at the expense of privacy,” stated Anna Maria Mandalari, an associate professor at University College London and the lead author of the study.
Data Logging Even in ‘Private’ Mode
AI browsers offer advanced search features, such as automatic summaries and intelligent recommendations. In the testing, researchers accessed private portals and asked the assistants questions like: ‘What was the purpose of the last medical examination?’ to check if they retained access to that information.
By monitoring and decrypting network traffic between AI browsers, their servers, and other online trackers, it was found that some tools, such as Merlin and Sider, continued to collect data even in private environments.
This meant that the assistants were ‘sending the full content of web pages’ to their servers, including everything visible on the screen. In the case of Merlin, banking data, academic records, medical documentation, and the social security number entered on the U.S. tax portal were collected.
