AI Models & Platforms

Gemini in Chrome Opens to All U.S. Android Users as Auto Browse Goes Mobile

mm
Add Unite.AI to your preferred sources on Google

Google opened Gemini in Chrome to all Android users in the United States on August 18, 2026, bringing its built-in browsing assistant to the full U.S. Android user base for the first time. Announced on The Keyword by Charmaine Dsilva, Director of Product Management for Chrome, the release also extends auto browse, the browser’s agentic task-completion feature, to phones for Google AI Pro and AI Ultra subscribers in the U.S.

Gemini in Chrome summarizes long articles, answers questions about the page a user is reading, and connects to Google apps including Calendar and Keep without requiring a switch between tabs. The Android version also includes image generation and editing on the go through Nano Banana. Users reach the assistant through the Gemini icon or the three-dot menu on Chrome’s top bar on an Android device.

The auto browse expansion is the more consequential piece for subscribers. Rather than answering questions about a page, auto browse carries out multi-step tasks on the web on the user’s behalf: booking parking for an event, updating a recurring online order, or organizing travel for a vacation. Until now, the feature ran on desktop Chrome only; the August 18 announcement puts it on Android for paying tiers.

“These features are built to be secure by design, and our models are trained to detect known threats, such as prompt injection,” Dsilva wrote. “And for added control, auto browse is designed to ask for confirmation before completing some sensitive tasks.”

How Auto Browse Works Once It Is Running

The mechanism behind the feature is documented in Google’s Chrome help pages. When a user describes a task, Gemini in Chrome proposes a plan first; the user reviews that plan, confirms the page context and any personal information involved, and starts the task explicitly. Gemini then chooses which sites to use, and a visible auto browse icon marks the tab it is working in. The user can take over at any point, hand the task back, or stop it outright.

The plan-review step exists because the agent operates with broad reach. Auto browse can act across the sites a user is signed into, and it may draw on personal information from connected Google apps to complete tasks, sharing that information with the sites it visits. With separate permission, it can sign into sites using saved credentials through Google Password Manager, which Google says does not share the passwords themselves with Gemini.

For sensitive steps, the system is designed to pause rather than proceed. Google’s documentation says the agent asks for review and confirmation before actions including sending communications, submitting web forms, scheduling events, and accessing sites carrying financial or health data, and it may hand control back to the user for steps like finalizing transactions or accepting terms of service. It also refuses a category of prohibited tasks and restricts its activity to sites and actions relevant to the request.

What the Tier Gate Buys, and Where the Limits Sit

Auto browse requires a Google AI Pro or AI Ultra subscription on a personal account, users must be 18 or over and in the U.S. with their device language set to English, and the feature does not run in Incognito mode. Daily caps scale with the plan: AI Pro subscribers get up to 20 multi-step task requests per day, while AI Ultra subscribers get up to 200, with a limit on how many tasks can run at the same time. Google is releasing the feature gradually, so even eligible subscribers may not see it immediately.

The security framing behind these limits was laid out in a December 8, 2025 post from the Chrome security team, which identified indirect prompt injection, where malicious instructions hidden in web content steer an agent toward unintended actions, as the primary new threat facing agentic browsers. Google’s layered response includes a separate “user alignment critic” model that vets each proposed action before execution, origin restrictions that confine the agent to task-relevant sites, a real-time prompt-injection classifier, and a bug bounty of up to $20,000 for demonstrated breaches of the agentic security boundaries.

Google’s own documentation is direct about the residual risk: auto browse is an experimental feature, Gemini in Chrome can make mistakes or act unexpectedly, including completing a purchase without permission, and the safeguards do not guarantee protection against all risks. Users remain responsible for the agent’s actions during a task, which is why the plan review and confirmation prompts are the load-bearing controls.

The Road to a Full Android Release

The mobile general availability announced August 18 is the endpoint of a staged rollout. Google first brought Gemini in Chrome to desktop users in the U.S. in September 2025, at the time promising that agentic capabilities would follow, and previewed auto browse before shipping it on desktop for paid tiers. The security architecture arrived alongside that desktop preview, and Unite.AI covered the announcement when Google detailed the agentic safeguards for Chrome’s AI features in December 2025.

The assistant itself is now one of Google’s widest-reach AI surfaces. The standalone Gemini app crossed 1 billion monthly users earlier in August 2026, and embedding it in the default browser on Android extends that reach to the context where mobile users already spend their browsing time.

What ships next is largely a matter of widening the same gates: Google’s help pages note that auto browse is not available in Live chats or in Gemini in Chrome on iPhone and iPad, and that work and school accounts need administrator enablement. The Android release covers U.S. users in English; the desktop version has already expanded to additional regions, and the gradual mobile release is continuing to roll out to eligible accounts.

Jonas Reeve is an AI-generated analyst at Unite.AI, focusing on cognitive AI, artificial general intelligence (AGI), and the theoretical foundations of machine intelligence. His work explores how learning, reasoning, memory, and abstraction emerge in both biological and artificial systems, drawing connections between modern AI architectures and long-standing questions in cognitive science and philosophy of mind.

With a conceptual and reflective approach, Jonas examines frameworks such as reasoning models, agentic systems, emergent cognition, and alignment theory, aiming to clarify what progress toward AGI actually means—and what it does not. Rather than chasing timelines or hype, he emphasizes first principles, conceptual rigor, and the limits of current models.

Articles authored by Jonas Reeve are AI-generated and reviewed by Unite.AI’s editorial team to ensure accuracy, clarity, and responsible discussion of advanced AI concepts.