OpenAI explains how its AI agents avoid malicious links and prompt injection

0
46

OpenAI explains how its AI agents avoid malicious links

AI agents can perform tasks on behalf of the user, and this often involves controlling a web browser, sorting through emails, and interacting with the internet at large. And since there are lots of places on the internet that can steal your personal data or otherwise cause harm, it's important that these agents know what they're doing.

So, as users migrate away from web browsers and Google Search to AI browsers and agents, AI companies like OpenAI need to make sure these tools don't fall straight into a phishing attempt or click on malicious links.

In a new blog post, OpenAI explains exactly how its AI agents protect users.

One possible solution to this problem would be for OpenAI to simply adopt a curated list of trusted websites its agents are allowed to access. However, as the company explained in the blog post, that would probably be too limiting and would harm the user experience. Instead, OpenAI uses something called an independent web index, which records public URLs that are already known to exist on the internet, independent of any user data.

Mashable Light Speed

So, if a URL is on the index, then the AI agent can open it without a problem. If not, the user will see a warning asking for their permission to move forward.

OpenAI example image of a warning pop-up about an unverified web link

You might see this if the agent tries to access something it shouldn't. Credit: OpenAI

As OpenAI explains in its blog post, "This shifts the safety question from 'Do we trust this site?' to 'Has this specific address appeared publicly on the open web in a way that doesn’t depend on user data?'"

You can see a more technical explainer in a lengthy research paper OpenAI published last year, but the main thing to know is that it's possible for web pages to manipulate AI agents into doing things they shouldn't do. A common form of this is prompt injection, which gives clandestine instructions to the AI model, asking it to retrieve sensitive data or otherwise compromise your cybersecurity.

To be clear, as OpenAI states in the blog post, this is just one layer of security that doesn't necessarily guarantee that what you're about to click on is entirely safe. Websites can contain social engineering or other bad-faith constructs that an AI agent wouldn't necessarily be able to notice.


Disclosure: Ziff Davis, Mashable’s parent company, in April 2025 filed a lawsuit against OpenAI, alleging it infringed Ziff Davis copyrights in training and operating its AI systems.

البحث
الأقسام
إقرأ المزيد
الألعاب
Delta Force's new season features a game mode I'm sure will make a lot of Escape From Tarkov fans envious
Delta Force's new season features a game mode I'm sure will make a lot of Escape From Tarkov fans...
بواسطة Test Blogger6 2026-02-03 18:00:19 0 29
أخرى
Electronics Thermal Management Materials Market Growth Analysis 2023–2031 Backed by a 6.4% CAGR
The Electronics Thermal Management Materials Market encompasses materials specifically engineered...
بواسطة Shalini Sonk 2026-01-30 11:32:23 0 65
الألعاب
Highguard has a 78% positive rating from Steam players who've actually given it a fair shake
Highguard has a 78% positive rating from Steam players who've actually given it a fair shake...
بواسطة Test Blogger6 2026-01-28 06:01:44 0 84
Music
Zoltan Bathory Discusses FFDP's New Album + 20th Anniversary Tour
'By the Time We Tour, We Have to Make a Record' - Zoltan Bathory Discusses Five Finger Death...
بواسطة Test Blogger4 2026-01-23 20:00:20 0 126
Technology
This Acer Nitro WQHD gaming monitor is at a record-low price at Amazon — save $100 right now
Best gaming monitor deal: Acer Nitro WQHD drops to $200, a new record low...
بواسطة Test Blogger7 2026-02-03 12:00:32 0 18