Security teams spent years standardizing Zero Trust enforcement on managed browsers. AI desktop apps now embed their own, and that assumption breaks.
In a blog post published September 9, 2026, Zscaler’s Joby Menon and Nishant Sharma describe the ChatGPT desktop app as shipping a full Chromium browser inside it, so the app’s agent can open pages, fill forms, and click through sites on a user’s behalf. Zscaler ties this to OpenAI folding its Atlas browser into the unified desktop app in July 2026. Independent outlets frame that timeline more as a deprecation of standalone Atlas, so treat the exact framing as contested.
Zscaler’s core argument is a governance one. When an AI app opens a page in its own embedded browser, that page runs under the user’s identity, cookies, and access, but sits outside IT-deployed browser controls unless a security extension is loaded into the embedded browser itself. In the authors’ words, “‘Just ask ChatGPT to open it for you’ starts to look like the shortest path around your controls.”
Zscaler says its own extension now runs inside that embedded browser and applies the same page monitoring, clipboard blocking, URL category blocking, DLP inspection, and file upload/download policy it uses in standard browsers. Those are vendor product claims, single-sourced and not independently verified.
The actionable question for CISOs: do your existing browser DLP and session policies explicitly cover app-embedded Chromium instances? Zscaler indicates other AI apps ship the same pattern, so a general policy stance may beat a one-off fix.
Source: Zscaler



Leave a Reply