Gemini Computer Control: Convenience with a New Bullseye
Gemini computer control is a native capability in Gemini 3.5 Flash that lets AI agents see, understand, and operate graphical interfaces on browsers, mobiles, and desktops, turning natural‑language requests into automated clicks, form fills, and multi‑step workflows across everyday software and internal tools.
By folding computer use into Gemini 3.5 Flash as a built‑in tool, Google has turned a specialized feature into a first‑class agent skill. Product leadership describes this as giving the model the ability to “see, reason about, and take action on screens,” which now includes browsers, mobile devices, and desktops. In practice, that means agents can run software tests, work with dashboards, or handle legacy apps that have no APIs, all through screen automation. The capability is available today through the Gemini API and the Gemini Enterprise Agent Platform, with the rollout targeting developers and enterprise users building advanced automation. This is more than a productivity bump; it is a structural shift in who (or what) is driving your cursor—and therefore where attackers aim.

The New Threat Surface: Trap-Filled Screens and AI Malware Threats
When an AI agent controls your screen, the web becomes hostile in new ways. The core vulnerability is prompt injection: malicious instructions hidden in a webpage or interface that trick an AI into actions you never approved. Google openly states that computer use brings “unique security and operational risks, as a model acting on a user’s behalf might encounter untrusted content on screens or make errors in executing actions.” As attack surfaces grow, the likelihood that hackers will seek to exploit them grows with it.
Security researchers already warn of “trap‑filled websites” that target AI agents instead of human visitors. A senior scientist at Google DeepMind has said malicious actors are setting traps to steal money from humans by targeting their AI agents. One cybersecurity expert has reported illicit credit card charges linked to an AI agent from another vendor, showing the risk is not hypothetical. These scenarios are early examples of AI malware threats: attacks that poison what the agent sees, not what you see, and then let your delegated privileges do the damage. As the number of agentic AI systems grows, hackers will turn their attention to exploiting them.

What Google Built In: Agentic AI Safeguards and Their Limits
To its credit, Google is not pretending that Gemini 3.5 Flash’s computer control is safe by default. Safety is where the company is drawing its sharpest lines. The model has undergone targeted adversarial training aimed directly at prompt injection, where instructions embedded in content try to divert the agent’s behavior. On top of that, there are two optional safeguard systems for enterprises: one requires explicit user confirmation before sensitive or irreversible actions such as form submissions or purchases, and another automatically halts tasks if it detects indirect prompt injection attempts.
Google also recommends a broader defense‑in‑depth approach that includes sandboxing, human‑in‑the‑loop verification, and strict access controls for environments where agents run. Its safety guidance lists best practices: keep a human in the loop by enforcing user confirmation when the safety layer demands it and by defining custom safety instructions; run agents in secure, sandboxed environments like isolated VMs or dedicated browser profiles; sanitize user input; add content guardrails to scan for jailbreaks and prompt injection; use allowlists and blocklists to control where the model can go; maintain detailed logs; and carefully manage the GUI environment. These are serious safeguards—but most are opt‑in, which means organizations who treat Gemini computer control as plug‑and‑play will inherit all the new risk with only part of the protection.
From Human Targets to AI Targets: How Risk Shifts
Traditional phishing tries to trick you. Agentic AI changes that: attackers now try to trick the system acting on your behalf. As the number of AI agents on the web proliferates, hackers will turn their attention to exploiting them. This shift is not theoretical; it is a logical response to automation. A model that can fill forms, click confirmation buttons, and move money is far more scalable to attack than a single distracted user. According to one safety document, “Computer Use presents unique security and operational risks, as a model acting on a user’s behalf might encounter untrusted content on screens or make errors in executing actions.”
The same workflows that make Gemini 3.5 Flash attractive—logging into dashboards, exporting reports, or operating legacy GUI‑only tools—become powerful levers if an attacker can influence what the agent sees or believes. Site owners may find they are hosting hidden prompt‑injection instructions planted by third parties, and will need stronger bot controls plus ways to detect such manipulations. In effect, the browser becomes a battleground between screen automation safety and AI malware threats. If organizations do not design for this new threat model, they risk giving attackers a programmable, high‑privilege assistant for free.
Practical Screen Automation Safety: How to Use Gemini Without Losing Control
If you adopt Gemini computer control, treat it like giving a junior employee root access: powerful, but never unmonitored. The immediate priority is to operationalize the agentic AI safeguards instead of relying on marketing promises. Use human‑in‑the‑loop controls—enforce user confirmation whenever the safety layer requests it, and define clear custom safety instructions on what agents may and may not do. Run agents in sandboxed VMs, containers, or dedicated browser profiles with minimal permissions so a compromised workflow cannot reach your crown jewels.
On top of that, sanitize inputs and apply content guardrails to check both what users send and what tools or pages return, looking for jailbreak and injection patterns. Build allowlists and blocklists to restrict which websites and apps agents can visit, with a narrow allowlist as the safer default. Log prompts, screenshots, proposed actions, safety responses, and final actions for audit and incident response. In short: screen automation safety is not automatic. Gemini 3.5 Flash provides powerful features and meaningful protections, but security depends on how seriously you implement them. Use computer control where it yields undeniable value, and be willing to say no where the risk is not yet worth the time saved.






