Google has quietly expanded the capabilities of its Gemini Spark AI agent, allowing it to browse the web and carry out tasks on behalf of users. The update, which rolled out in recent days, marks a significant step in the company's push to embed AI deeper into everyday digital routines.
What Gemini Spark can do
Gemini Spark, previously limited to answering questions and generating text, can now navigate websites, fill out forms, and complete multi-step errands such as booking appointments or ordering products. Users can give the agent a goal — like "find a cheap flight to Chicago next Tuesday and book it" — and Spark will handle the browsing, comparison, and checkout process autonomously.
The feature is available to subscribers of Google One AI Premium, which costs $19.99 a month and includes access to Gemini Advanced. Google says the agent runs in a sandboxed environment and asks for user confirmation before finalizing any transaction.
Privacy and security questions
The integration of an AI agent that can freely browse the web raises obvious privacy and security concerns. Because the agent acts on behalf of a user, it could inadvertently share sensitive information — such as login credentials or payment details — with untrusted sites. Security researchers have also warned that malicious websites could trick the agent into performing unintended actions, like making unauthorized purchases or leaking personal data.
Google has not disclosed how it plans to prevent such scenarios beyond the confirmation step. The company's privacy policy for Gemini states that conversations are reviewed by human trainers, but it is unclear whether that extends to the agent's browsing activity. Users who enable the feature must grant the agent permission to access their Google account and stored payment methods.
Another concern is data collection. As the agent moves across the web, it generates a trail of visited URLs, search queries, and form submissions. Google says this data is used to improve the model, but critics argue that the scope of data gathering is far broader than what users typically expect from a search engine or assistant.
How it compares to rivals
Google is not the first to offer an AI agent with web access. Microsoft's Copilot can browse the web and summarize pages, while OpenAI's ChatGPT Plus has a browsing mode. But Gemini Spark's ability to execute transactions autonomously — without requiring the user to click through each step — sets it apart. That also makes the stakes higher if something goes wrong.
Neither Microsoft nor OpenAI has yet allowed their agents to complete purchases without user approval at each stage. Google's approach gives the agent more autonomy, which could be more convenient but also riskier.
The company has not said whether it will offer refunds if the agent makes a mistake, or how disputes would be handled. For now, users who enable the feature are effectively trusting Google's AI to act as their personal shopper and secretary — with all the convenience and all the potential pitfalls that entails.




