OpenAI Says Prompt Injections a Challenge for AI Browsers, Builds an Attacker to Train ChatGPT Atlas

OpenAI says prompt injections remain a key risk for AI browsers and is using an AI attacker to train ChatGPT Atlas.

Advertisement
Written by Akash Dutta, Edited by Ketan Pratap | Updated: 23 December 2025 12:31 IST
Highlights
  • OpenAI flags prompt injections as an ongoing security issue
  • ChatGPT Atlas is trained using an AI-powered attacker
  • The company says the battle against this attack will be long-term

The AI attacker will help ChatGPT Atlas learn to tackle evolving prompt injection techniques

Photo Credit: Unsplash/Glenn Carstens-Peters

OpenAI called prompt injections “one of the most significant risks” and a “long-term AI security challenge” for artificial intelligence (AI) browsers with agentic capabilities, on Monday. The San Francisco-based AI giant highlighted how the cyberattack technique impacts its ChatGPT Atlas browser and shared a new approach to tackle it. The company is using an AI-powered attacker that simulates real-world prompt injection attempts to train browsers. OpenAI said the goal is not to eliminate the threat, but to continuously harden the system as new attack patterns emerge.

OpenAI Is Using AI to Fight Against Prompt Injections

Prompt injection is a technique where an attacker hides instructions using HTML tricks, such as zero font, white-on-white text, or out-of-margin text. This is hidden within normal-looking content that an AI agent is meant to read, such as a webpage, document, or snippet of text. When it processes that content, it may mistakenly treat the hidden instruction as a legitimate command, even though it was not issued by the user. It can then carry out malicious acts due to the access privilege of the AI browser.

Advertisement

In a post, OpenAI explained that prompt injections can be direct, where an attacker clearly tries to override the model's instructions, or indirect, where malicious prompts are embedded inside otherwise normal content. Because ChatGPT Atlas reads and reasons over third-party webpages, it may encounter instructions that were never intended for it but are crafted to influence its behaviour.

To address this, the AI giant has built an automated AI attacker, effectively a system that continuously generates new prompt injection attempts as a simulation. This attacker is used during training and evaluation to stress-test Atlas, exposing weaknesses before they are exploited outside the lab. OpenAI said this allows its teams to identify vulnerabilities faster and update defences more frequently than relying on manual testing alone.

Advertisement

“Prompt injection, like scams and social engineering, is not something we expect to ever fully solve,” OpenAI wrote in the post, adding that the challenge evolves as AI systems become more capable, gaining more permissions and the ability to take more actions. Instead, the company is focusing on layered defences, combining automated attacks, reinforcement learning and policy enforcement to reduce the impact of malicious instructions.

The company said its AI attacker helps create a rapid feedback loop, where new forms of prompt injection discovered by the system can be used to immediately retrain and adjust Atlas. This mirrors how security teams respond to evolving threats on the web, where attackers constantly adapt to new safeguards.

Advertisement

OpenAI did not claim that Atlas is immune to prompt injections. Instead, it framed the work as part of an ongoing effort to keep pace with a problem that changes alongside the technology itself. As AI browsers become more capable and more widely used, the company said sustained investment in automated testing and defensive training will be necessary to limit abuse.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Flipkart Freedom Sale: Samsung Galaxy S25 FE Deal Teased Ahead of Sale
  2. Itel Ace 3 Heera Feature Phone Debuts in India With This Price Tag
  3. Sony WH-1000XM6 Now Available in Olive Grey Colour Variant in India
  4. Redmi 17 5G With a 6,300mAh Battery Arrives at This Price
  5. Realme 16x 5G India Launch Roundup: Here's Everything We Know So Far
  6. Vivo Revives Its S-Series Lineup in India With the New Vivo S2
  7. OnePlus Responds to India Exit Rumours With Growth
  8. Why Now Is the Smartest Time to Buy a Galaxy Tab S Tablet
  9. Redmi Note 17 5G With an 8,000mAh Battery Arrives in India: See Price
  10. This Motorola Phone Has Reportedly Received the Android 17 Beta Update
  1. Flipkart Freedom Sale: Nothing Phone 4a Series, Reno 15 Series, More to Be Offered at a Discount
  2. Redmi 17 5G Launched With 6,300mAh Battery, 6.9-Inch HD Display: Price, Specifications
  3. Sony WH-1000XM6 Now Available in Olive Grey Colour Variant in India: Price, Availability, Features
  4. HP OmniPad 12 Goes on Sale in India With Snapdragon Chip, Detachable Keyboard
  5. Bitcoin Holds Near $65,000 as ETF Inflows Help Offset Profit-Taking
  6. GTA 6 Third Trailer and Gameplay Speculation Intensifies Ahead of Take-Two Earnings Call
  7. Anthropic Could Build Custom AI Chips for Claude Models, Job Listing Suggests
  8. Google Pixel Tag European Pricing, Launch Date Reportedly Leaked Ahead of Made by Google Event
  9. Flipkart Freedom Sale: Samsung Galaxy S25 FE Confirmed to Be Available at a Discounted Price
  10. Redmi Note 17 5G Launched in India With 8,000mAh Battery, 50-Megapixel Rear Camera: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.