The browser is rapidly becoming one of the most valuable pieces of digital real estate in the artificial-intelligence economy. It already knows which pages a user has open, what they are researching and how they move across the web. As AI becomes increasingly capable of summarising information, comparing alternatives and eventually carrying out tasks on a user’s behalf, that context gives browsers an advantage that standalone chatbots do not naturally possess. Mozilla is betting that this opportunity can also become a point of differentiation for Firefox. Rather than competing only on how much artificial intelligence can be added to the browser, the organisation is attempting to build an AI experience around user choice, privacy and the ability to decide when the technology should be involved at all.
Speaking at Ai4 2026 in Las Vegas, Mozilla Senior Director of AI and Machine Learning Shruti Kamath argued that the central question is increasingly not whether browsers will contain AI, but how much authority those systems should have over users’ data and actions. The stakes are considerable because browsers occupy an unusually privileged position. A conventional AI assistant normally begins with whatever the user provides in a conversation, while a browser can potentially understand the pages already open, previous browsing activity and the wider context of a task. It can move between websites and, as agentic systems become more capable, could eventually perform actions across them. The same characteristics that make browser AI useful therefore create significant privacy and security questions.
Mozilla’s response has been to make AI participation configurable rather than universal. Firefox includes controls allowing users to disable AI functions entirely or selectively enable individual capabilities, including functions connected with translation, tab organisation and web content. Users who do not want AI integrated into their browsing can therefore choose not to use it. That approach reflects a broader strategic question emerging across consumer technology: AI products become more useful when they have greater context, but gaining that context frequently means accessing more information about users. Browsers sit directly at that boundary because a sufficiently powerful browser assistant could understand research projects, shopping decisions, travel planning and work activity.
Mozilla is attempting to address part of that tension through on-device processing. Several Firefox capabilities use local models rather than sending every piece of information to external servers. Suggested tab organisation is one example, while Firefox’s translation technology also makes extensive use of local processing. Keeping certain tasks on the device can reduce the amount of browsing information that needs to leave the user’s computer and can make some functions work without continuously depending on a cloud service. The distinction is not absolute, however. Not every Firefox AI feature operates entirely locally, and different functions, hardware and models require different approaches. That makes transparency about when information leaves a device increasingly important.
Mozilla’s larger experiment is Smart Window, a separate AI-assisted browsing environment within Firefox. Rather than replacing the conventional browser window, Smart Window is intended to sit alongside standard and private browsing. It can use context supplied by the user to help research subjects, compare information across tabs, retrieve previously viewed material and work through multi-step tasks without requiring information to be continually transferred between a browser and a separate chatbot. A travel-planning session, for example, could involve several hotel pages, transport options and articles, while the assistant helps compare them. Similarly, a user researching products or recipes can ask it to extract information from several pages and organise the results.
The underlying idea is that AI becomes more useful when it operates within the activity already taking place rather than requiring users to repeatedly explain what they are doing. Smart Window also illustrates Mozilla’s attempt to avoid locking users into a single AI provider. Firefox supports model choice and is developing ways for technically advanced users to connect compatible models themselves, including locally hosted alternatives. This provider-neutral approach represents a different philosophy from systems designed around one vertically integrated AI ecosystem. A browser controlled by the same company providing the operating system, search engine, advertising platform or AI model can potentially concentrate several layers of digital activity within one organisation. Mozilla’s proposition is that the browser can instead act as an intermediary through which people retain greater choice.
Whether consumers will value that flexibility enough to change browser behaviour remains uncertain. Convenience has historically been one of the strongest forces in consumer technology, and many users may simply accept the AI experience supplied by the browser already installed on their device. Firefox therefore faces the challenge of making greater control useful and understandable rather than presenting it primarily as a philosophical advantage. Security may become an even greater differentiator as browser assistants move from answering questions towards performing actions.
An AI system capable of browsing autonomously is exposed to information that may contain hidden instructions designed to manipulate it. A malicious webpage could theoretically attempt to instruct an agent to reveal private information, visit another site or perform an action the user never requested. This problem, generally known as prompt injection, has become one of the central security difficulties surrounding AI agents. Browsers are particularly exposed because they routinely encounter untrusted content from across the internet. An agent that can simultaneously read private information, process instructions embedded in web pages and communicate externally creates a potentially dangerous combination.
Mozilla says it is designing its assistant so that untrusted webpage content cannot automatically gain the same authority as instructions explicitly supplied by the user. Actions can be constrained by policies controlling which tools the assistant uses and which pages it may access. The broader objective is to prevent a hidden instruction inside a webpage from acquiring enough authority to redirect the browser or transmit information without the user’s involvement. This issue will become increasingly important as the industry moves towards autonomous browsing. Today’s browser AI mainly summarises, organises, compares and answers questions, but the next stage involves agents capable of navigating websites, completing forms, making reservations, purchasing products or carrying out other tasks independently.
Mozilla acknowledges that fully agentic browsing remains an active security challenge. Giving an AI system access to personal context while allowing it to interact freely with arbitrary websites creates risks that are difficult to eliminate completely. Progress towards autonomous browsing may therefore depend as much on security architecture and permission systems as improvements in the underlying AI models. The question of who controls the agent could eventually become more consequential than the quality of its conversational responses.
Firefox’s AI strategy is also closely connected to Mozilla’s longstanding position on browser independence. Firefox runs on Gecko, one of the few major browser engines not controlled by either Google or Apple. Browser engines determine how web standards are implemented and therefore influence the technical direction of the internet itself. Maintaining an independent engine provides another centre of decision-making as AI becomes embedded more deeply in browsing. Mozilla is extending that argument to artificial intelligence: if a small number of companies control dominant browsers, AI assistants and underlying models simultaneously, they could gain considerable influence over how information is discovered and which services users encounter.
Privacy remains part of that positioning beyond AI. Firefox has expanded tracking protection, supports extensions such as uBlock Origin and is introducing additional privacy capabilities, including browser-level VPN protection in supported markets. Mozilla is therefore attempting to connect AI with an existing privacy and user-control identity rather than treating artificial intelligence as an entirely separate product category. The difficulty is that increasingly sophisticated browser assistants inherently benefit from greater access to context, making it harder to maintain the traditional boundary between a browser that simply displays the web and one that actively interprets what the user is doing.
That tension may ultimately define the next phase of browser competition. For years, performance, compatibility, extensions and search integration were among the primary differentiators. AI introduces a new layer in which browsers could become research assistants, shopping advisers, personal organisers and eventually autonomous agents. The browser would no longer simply provide access to websites but increasingly decide how information from those websites is organised and presented. That could also change the economics of the internet if people increasingly ask browsers to summarise articles rather than opening them, compare products without visiting individual retail pages or retrieve information from several sources without navigating through those sites directly.
Publishers, retailers and online businesses may consequently have to adapt to a web where the browser itself becomes a more powerful intermediary between users and content. Mozilla’s strategy suggests that the competition will not solely concern which browser has the most capable AI. It may also depend on which organisation users trust with the enormous amount of personal context required to make that intelligence genuinely useful. A system that knows which pages someone has visited, what they are researching and what they intend to do next can provide remarkably relevant assistance, but it also occupies an unusually sensitive position.
Firefox is therefore attempting to establish a different measure of progress: AI that becomes more capable without automatically becoming more intrusive. Model choice, local processing, explicit controls and constrained agent behaviour are all parts of that approach. None eliminates the risks associated with AI-assisted browsing, and some of the most ambitious autonomous capabilities remain under development. But the direction is becoming clear. Browsers are evolving from passive gateways to the web into intelligent environments capable of understanding and acting on user context. The competitive question may therefore shift from which browser loads a webpage fastest to something considerably more consequential: which browser should be trusted to understand what its user is trying to accomplish and, eventually, to act on that person’s behalf?
Source: CIJ.World Research & Analysis Team