← Blog
For businesses

The Browser Isn't Changing. The Actor Behind It Is.

Explore an AI summary

Cloudflare's Kitesurf offers a glimpse into the future of browsing. The bigger story isn't the browser itself—it's who's behind the clicks.


For most of the web's history, enterprise security has operated on a simple assumption:

Someone is behind the browser.

Every login, every session and every click ultimately represented a person making decisions.

That assumption is beginning to change.

Cloudflare's recent introduction of Kitesurf, a browser engine designed specifically for AI agents, isn't just another browser announcement. It's an early signal that the browser is evolving into an execution environment for software acting on behalf of people.

That's a much bigger shift than it first appears.

The next generation of internet traffic won't simply come from people using browsers.

Increasingly, it will come from AI agents researching vendors, comparing products, filling out forms, navigating authenticated applications and completing tasks for the people who delegated them.

Which means the enterprise security question is no longer:

Can an AI agent access my application?

It's becoming:

What should an AI agent be allowed to do once it gets there?

That distinction will define the next decade of browser security.


AI Agents Aren't Just Another Audience

Much of today's conversation around AI focuses on discoverability.

Can ChatGPT find your documentation?

Will AI recommend your products?

Should your website be optimized for AI search?

Those are important questions.

But they're marketing questions.

Security teams should be asking something entirely different.

An AI agent doesn't simply consume information.

It can browse authenticated applications.

Download documents.

Interact with workflows.

Call APIs.

Complete forms.

Modify records.

Execute tasks.

In other words:

AI agents don't just read your business. They can act inside it.

That's not another audience.

That's another actor.


Keep your business safe from online threats

Haven for Business protects every employee from phishing, fake sites, and browser-based attacks.

One Human Prompt Can Generate Thousands of Actions

Imagine an employee asking an AI assistant:

"Research every cybersecurity vendor under 500 employees and compare their pricing."

One prompt.

One employee.

Behind the scenes, that request could generate hundreds—or even thousands—of automated browser interactions across websites and applications.

From the application's perspective, one person has suddenly become machine-scale activity.

Traditional browser security wasn't designed for that.


The Shift Every Enterprise Needs to Understand

The browser isn't changing. The actor behind it is.

For the last thirty years, browser security has asked:

Who is using the browser?

The next thirty years will ask:

What is the browser allowed to do?

That's a fundamentally different security model.


Authentication No Longer Tells the Whole Story

Most enterprise security controls assume that if authentication succeeds, the resulting activity is trustworthy.

That assumption becomes weaker in an agentic world.

An employee may legitimately authorize an AI assistant to reconcile invoices or summarize contracts.

The credentials are valid.

The session is legitimate.

But what if the agent is manipulated by a malicious webpage? What if it attempts an action the employee never intended? What if it encounters prompt injection or other untrusted content while browsing? Cloudflare highlights these emerging risks as part of Kitesurf's design philosophy.

The problem isn't identity.

It's delegated authority.


Don't Block AI. Govern It.

The answer isn't banning AI agents.

Employees will continue using them.

Customers will increasingly rely on them.

Partners will automate procurement.

Developers will automate testing.

AI agents are becoming legitimate participants in modern business.

The challenge isn't stopping them.

It's deciding what they're trusted to do.

Reading public documentation isn't the same as changing payroll information.

Viewing an invoice isn't the same as approving payment.

Comparing products isn't the same as moving money.

Every workflow deserves a different level of trust.

Organizations should begin thinking in terms of:

  • Open — Public information agents can safely consume.

  • Verified — Low-risk workflows requiring trusted identity.

  • Supervised — Actions requiring explicit human approval.

  • Human Only — Critical operations that should never be delegated.

Not because AI is inherently unsafe.

Because business risk isn't equal.


The Next Enterprise Policy

Most organizations already have:

  • Identity policies

  • Password policies

  • Acceptable use policies

  • Data retention policies

Soon they'll need something else.

An AI Action Policy.

Not simply:

Can an AI access this application?

But:

  • Can it read?

  • Can it summarize?

  • Can it download?

  • Can it modify?

  • Can it approve?

  • Can it purchase?

  • Can it transfer funds?

  • Can it operate without human supervision?

Those decisions shouldn't be accidental.

They should reflect deliberate business policy.


The Haven for Enterprise Perspective

At Haven for Enterprise, we believe the future isn't about choosing between humans and AI.

It's about ensuring both can work safely.

AI agents should absolutely help employees research faster, automate repetitive work and improve productivity.

But when those interactions reach sensitive business workflows—customer data, financial systems, privileged administration or regulated information—the enterprise should decide exactly how much autonomy is appropriate.

Because the browser is no longer just where people work.

It's becoming where software works on behalf of people.

The organizations that succeed in the agentic era won't be the ones that simply allow AI into the browser.

They'll be the ones that define exactly what AI is allowed to do once it's there.


Frequently Asked Questions

What is Cloudflare Kitesurf?

Cloudflare Kitesurf is a browser engine designed for AI agents rather than human users. It enables software agents to navigate websites, retrieve information and interact with web-based workflows without relying on a traditional browser experience built around tabs, windows and visual interfaces.

Why do AI agents create a new browser security challenge?

Traditional browser security assumes a person is making decisions behind each session. AI agents can perform actions autonomously, operate at machine speed and generate hundreds or thousands of interactions from a single human request.

This means organizations must consider not only who authenticated, but also what authority has been delegated to the agent.

How are AI agents different from traditional bots?

Traditional bots usually follow predetermined rules and perform narrowly defined tasks. AI agents can interpret information, adapt to changing interfaces, make decisions and complete multistep workflows.

That flexibility makes them more useful—but also more difficult to govern using controls designed for predictable automation.

Should enterprises block AI agents?

Not necessarily. AI agents will increasingly support legitimate activities such as research, customer service, procurement, software testing and administrative work.

A more sustainable approach is to determine which information agents may access, which tasks they may complete and which actions require human approval.

What is an AI Action Policy?

An AI Action Policy defines what an AI agent is permitted to do within an application or workflow.

It may specify whether an agent can:

  • Read or summarize information

  • Download files

  • Modify records

  • Submit forms

  • Approve transactions

  • Access sensitive data

  • Complete actions without human supervision

The goal is to govern an agent’s authority, not simply its access.

Why is authentication alone no longer enough?

Authentication can confirm the identity associated with a session, but it may not reveal whether a person or an AI agent is controlling it.

An agent may use legitimate credentials while performing actions the user did not intend, exceeding its delegated authority or responding to malicious instructions encountered online. Enterprises therefore need controls that account for both identity and behavior within the workflow.

What is the difference between AI agent access and AI agent authorization?

Access determines whether an agent can enter an application or view a resource.

Authorization determines what the agent is allowed to do after gaining access.

For example, an agent may be permitted to read an invoice but not approve payment, or summarize account information without changing account settings.

How can enterprises prepare for AI-driven browsing?

Organizations should begin by identifying their most sensitive web workflows and classifying them according to risk.

A practical model is:

  • Open: Agents may safely access public information.

  • Verified: Access requires a recognized identity.

  • Supervised: Actions require human confirmation.

  • Human Only: High-risk workflows cannot be delegated.

Enterprises should also review how agent activity is isolated, monitored and recorded.

What role does browser isolation play in AI agent security?

AI agents may encounter malicious scripts, prompt injection and other untrusted content as they browse. Isolation can reduce the likelihood that an unsafe webpage gains direct access to sensitive data, credentials or downstream systems.

As agents become more autonomous, treating web content as untrusted by default becomes increasingly important.

How does Haven for Enterprise approach the agentic web?

Haven for Enterprise is built around a simple principle: organizations should be able to decide how sensitive web applications and workflows are accessed and automated.

As browsers evolve into execution environments for both people and software, enterprise security must move beyond protecting the login and begin governing what happens inside the session.