Research presented at Black Hat USA 2026 reveals that AI-powered browsers from Opera, Perplexity, and ChatGPT Atlas remain vulnerable to prompt injection attacks despite multiple security guardrails. Demonstrations showed how hidden HTML instructions, invisible text overlays, and spoiler-tagged content can bypass protections. Even browsers with system-level prompting, content tagging, tool scanning, and user approval prompts were compromised. Brave Software's approach layers separate browser profiles, model downgrade thresholds (no lower than Claude Haiku 4.5), and a sentinel model that checks whether proposed tool actions align with the user's original intent. The researcher concludes there is no perfect solution — only overlapping mitigations that reduce but cannot eliminate risk, drawing a parallel to how modern browsers handle security through defense-in-depth.